Deirdre Connolly¹

1.2K Followers
849 Following
1,015 Posts

🜗 🝒 🝲 crypto as in 'cryptography' 🝳 🝡 🜖

¹isogenist, co-host SCWpod

100% agree on everything from @filippo here, this has been my thinking for at least two years:

https://words.filippo.io/crqc-timeline/

A Cryptography Engineer’s Perspective on Quantum Computing Timelines

The risk that cryptographically-relevant quantum computers materialize within the next few years is now high enough to be dispositive, unfortunately.

Google bumps up Q Day deadline to 2029, far sooner than previously thought

Company warns entire industry to move off RSA and EC more quickly.

Ars Technica
Quantum frontiers may be closer than they appear

An overview of how Google is accelerating its timeline for post-quantum cryptography migration.

Google
New theme for 2026 just dropped:
Bunker AI Data Centers

Dustin Moody from NIST: “you don’t need more than 128 bits of symmetric keys for post-quantum security” #rwc2026

Say it louder, for the people in the back!

Has anyone done a macroeconomic analysis of the costs of the PQC migration?
It seems hard to estimate, but it feels like a number with way too many zeros after it.

At WWDC, we unveiled formally verified ML-KEM and ML-DSA #PostQuantum implementations in CryptoKit.

🆕🎥 Last month at Hexagon in Paris, we provided additional insights into the mechanisms used for verifying the implementations using Cryptol, SAW and Isabelle.

The talk also covers the evolution of the Secure Page Table Monitor, a view into Memory Integrity Enforcement, updates to Apple Security Bounty… and a note on the moral character of offensive security work.

https://youtu.be/Du8BbJg2Pj4

HEXACON 2025 - Keynote by Ivan Krstić

YouTube

For the past several years I've been trying intermittently to get Cross Translation Unit taint analysis with clang static analyzer working for Firefox. While the efforts _have_ found some impactful bugs, overall the project has burnt out because of too many issues in LLVM we are unable to overcome.

Not everything you do succeeds, and I think it's important to talk about what _doesn't_ succeed just as much (if not more) about what does.

With the help of an LLVM contractor, we've authored this post to talk about our attempts, and some of the issues we'd run into. https://attackanddefense.dev/2025/12/16/attempting-cross-translation-unit-static-analysis.html

I'm optimistic that people will get CTU taint analysis working on projects the size of Firefox, and if you do, well I guess I'll see you in the bounty committee meetings ;)

Attempting Cross Translation Unit Taint Analysis for Firefox

Preface

Attack & Defense

New blog post: ML-KEM Mythbusting.

Due to reasons.

https://keymaterial.net/2025/11/27/ml-kem-mythbusting/

ML-KEM Mythbusting

What is this? There have been some recent concerns about ML-KEM, NIST’s standard for encryption with Post-Quantum Cryptography, related standards of the IETF, and lots of conspiracy theories …

Key Material
Celebrating two PhD milestones with my group. One thesis submitted and one thesis examined