45 subscribers
Gå frakoblet med Player FM -appen!
Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted
Manage episode 382558625 series 2956114
We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.
Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc
Links:
- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
- https://github.com/superfly/macaroon
- https://cryspen.com/post/pqxdh/
- https://eprint.iacr.org/2023/1390.pdf
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
Kapitler
1. Issues With Encrypted Jabber Communications (00:00:00)
2. App and Web Security Challenges (00:13:53)
3. Benefits and Limitations of Web Encryption (00:22:26)
4. Benefits and Challenges of Browser-Based Cryptography (00:29:54)
5. Web App Security and Distribution Models (00:35:09)
6. Web Security and Signal Key Exchange (00:48:36)
7. X3DH Protocol and Signal's Key Exchange (00:53:49)
8. Camry Encapsulation Attack and Secure Encryption (01:08:11)
54 episoder
Manage episode 382558625 series 2956114
We're back! Signal rolled out a protocol change to be post-quantum resilient! Someone was caught intercepting Jabber TLS via certificate transparency! Was the same-origin policy in web browers just a dirty hack all along? Plus secure message format formalisms, and even more beating of the dead horse that is E2EE in the browser.
Transcript: https://securitycryptographywhatever.com/2023/11/07/PQXDH-etc
Links:
- https://zfnd.org/so-you-want-to-build-an-end-to-end-encrypted-web-app/
- https://github.com/superfly/macaroon
- https://cryspen.com/post/pqxdh/
- https://eprint.iacr.org/2023/1390.pdf
"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)
Kapitler
1. Issues With Encrypted Jabber Communications (00:00:00)
2. App and Web Security Challenges (00:13:53)
3. Benefits and Limitations of Web Encryption (00:22:26)
4. Benefits and Challenges of Browser-Based Cryptography (00:29:54)
5. Web App Security and Distribution Models (00:35:09)
6. Web Security and Signal Key Exchange (00:48:36)
7. X3DH Protocol and Signal's Key Exchange (00:53:49)
8. Camry Encapsulation Attack and Secure Encryption (01:08:11)
54 episoder
Alle episoder
×

1 Apple Pulls Advanced Data Protection in the UK with Matt Green and Joe Hall 48:30

1 Cryptanalyzing LLMs with Nicholas Carlini 1:20:42

1 Biden’s Cyber-Everything Bagel with Carole House 57:14

1 Quantum Willow with John Schanck and Samuel Jacques 53:36

1 Dual_EC_DRBG with Justin Schuh and Matthew Green 1:07:45

1 A Little Bit of Rust Goes a Long Way with Android's Jeff Vander Stoep 1:13:55






1 STIR/SHAKEN with Paul Grubbs and Josh Brown 1:01:47


1 Post-Quantum iMessage with Douglas Stebila 55:34
Velkommen til Player FM!
Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.