Matthew Green is on BlueSky (@matthew_d_green) 's Twitter Profile
Matthew Green is on BlueSky

@matthew_d_green

I teach cryptography at Johns Hopkins. Mostly on BlueSky these days at matthewdgreen.bsky.social.

ID: 106234268

linkhttp://blog.cryptographyengineering.com calendar_today18-01-2010 22:45:09

85,85K Tweet

150,150K Followers

1,1K Following

Matthew Green is on BlueSky (@matthew_d_green) 's Twitter Profile Photo

Apparently an Israeli company has forked Signal client and added features to retain messages for compliance. As someone in USG just said to me: what could go wrong? 404media.co/mike-waltz-acc…

Tanja Lange (@hyperelliptic) 's Twitter Profile Photo

EDRI is raising an alarm over the EC's plan to issue a technlolgy roadmap "lawful access to encrypted data" during Q2 this year. The same strategy document ProtectEU in other places pushes for privacy and for post-quantum cryptography. linkedin.com/posts/european… Critical to act now!

John Scott-Railton (@jsrailton) 's Twitter Profile Photo

NEW: Google's Android 16 to feature optional high security mode. Advanced Protection has a bunch of requested features that address the kinds of threats we worry about. It's the kind of 'turn this one thing on if you face elevated risk' that we've been asking for from Google.

NEW: <a href="/Google/">Google</a>'s <a href="/Android/">Android</a> 16 to feature optional high security mode.

Advanced Protection has a bunch of requested features that address the kinds of threats we worry about.

It's the kind of 'turn this one thing on if you face elevated risk' that we've been asking for from Google.
Matthew Green is on BlueSky (@matthew_d_green) 's Twitter Profile Photo

It’s weird how people are ā€œopposed to surveillanceā€ only until they get their hands on the surveillance apparatus. gizmodo.com/fbi-director-k…

JHU Computer Science (@jhucompsci) 's Twitter Profile Photo

JHU CS’ Matthew Green is on BlueSky worries that cases like Wang’s could make young engineers from China think twice about studying at U.S. universities & even motivate talented researchers who have lived here for decades to consider working abroad: ā€œWe may lose a huge amount of expertise.ā€

Matthew Green is on BlueSky (@matthew_d_green) 's Twitter Profile Photo

So my understanding was that Apple Secure Enclaves don’t have a remote device attestation process. But then someone suggested they use something like this to link driver’s licenses to a phone, and I’m trying to figure it out.

Tal Be'ery (@talbeerysec) 's Twitter Profile Photo

1/ I think I have the answer! (blogpost at the bottom of 🧵) Original Q: How was WhatsApp able to patch a client-side vulnerability of malicious PDF parsing from the server-side, although server is not exposed to PDF content due to End-to-End Encryption (#E2EE)?