Frédéric Jacobs

@fj
7.7K Followers
4.3K Following
3.4K Posts

Cryptographic & Security Engineering

Previously: Founding & Lead iOS Engineer @signalapp, @Bellingcat #OSINT contributor

Tooting on all things #cryptography, #lithography, #energy, #security, #mobility, #climate, European #aerospace and federalism.

Websitehttps://www.fredericjacobs.com
Readings@[email protected]
127.0.0.1Lausanne, 🇨🇭
Lang[“en_us”, “fr_ch”, “de_de”, “nl_be”] (Three dots on profile to choose posts in which language you're subscribed to)

Really nice work being shepherd by the Signal Foundation, Beneficial AI Foundation and the #Lean FRO to verify libSignal's code with the Aeneas, Mathlib/CSLib stack, sped up by AI-powered autoformalization.

https://leodemoura.github.io/blog/2026-4-20-signal-shot-the-platform-is-ready/

An update will be given on the progress of the project tonight at the LEAN Paris Meetup @ INRIA
https://beneficial-ai-foundation.github.io/SVIL2026/

Signal Shot: The Platform Is Ready — Leonardo de Moura

Leonardo de Moura — Creator of Lean and Z3

Scoop: NSA using Anthropic's Mythos despite blacklist

The government's cybersecurity needs are outweighing the Pentagon's feud with Anthropic.

Axios
Here he's at it again. The President of the United States is again threatening to commit war crimes.

"The same industry that once called you family is now using the fruits of your labor to commit war crimes. The same industry whose leaders once posted front-page missives to their sites about doing a better job in terms of diversity and inclusion are now selling their technology to fascists who use it to bomb schools.

The industry has decided what it wants to be."

https://buttondown.com/monteiro/archive/how-to-do-the-work/

How to do the work

I’m paintings ducks. This week’s question comes to us from Tony: How do you keep doing a thing you love, that you’ve done for decades, when you hate what the...

Mike Monteiro’s Good News

GCVE is not only designed for distributed vulnerability publication and correlation across multiple sources. It already provides automatic vulnerability classification capabilities through the broader Vulnerability-Lookup ecosystem. In particular, GCVE can rely on VL-AI to automatically estimate vulnerability severity from historical data, giving defenders an immediate first-pass assessment even when no manually curated score is yet available.

#gcve #cve #nist

🔗 https://gcve.eu/2026/04/17/automatic-vulnerability-intelligence/

Good article on “quantum jamming” & how it breaks Quantum Key Distribution Protocols https://www.quantamagazine.org/quantum-jamming-explores-the-truly-fundamental-principles-of-nature-20260417/

I'm glad in post-quantum crypto, I don't need to make assumptions about spacetime configurations for my protocols to be secure.
"in specific spacetime configurations, a relativistic adversary can successfully attack [by using quantum jamming] a device-independent cryptographic protocol based on nonlocal correlations between an arbitrarily large number of parties.”
https://arxiv.org/pdf/2512.23702

Quantum ‘Jamming’ Explores the Truly Fundamental Principles of Nature | Quanta Magazine

Some quantum cryptographers want to find ways to keep messages secret even if the rules of quantum mechanics don’t hold. The recently rediscovered idea of quantum jamming complicates things.

Quanta Magazine

In an attempt to justify their killing of a Lebanese journalist, the Israeli military shares a photo of the journalist in a Hezbollah military uniform, arguing that that he was a terrorist.

However, it now turns out, this “photo” was AI generated by the Israeli military, because they have no real evidence of a connection between the journalist and Hezbollah.

France 24 has the story.

https://youtu.be/orhh2JpDe8I?si=6baaDa9IvxHrO4Eh

Israeli military admits to posting AI photo of Lebanese journalist it killed • FRANCE 24 English

YouTube

Heureux de lire un article qui comprend bien les enjeux de la gestion des vulnérabilités et qui reflète bien notre démarche avec le projet GCVE.

"Le Global CVE Allocation System, soutenu par l’UE, a été lancé début janvier. Cet événement fait suite aux problématiques de financement du programme CVE, opéré par MITRE Corporation et soutenu par le gouvernement américain. L’initiative illustre la manière dont l’UE affirme son influence normative tout en atténuant sa dépendance aux infrastructures non européennes. Cette dimension prend toute son importance à l’heure du retour de la compétition entre grandes puissances."

#gcve #cve #europe #vulnerabilitymanagement #opensource #opendata

🔗 https://www.irsem.fr/publications/fragmentation-ou-complementarite-le-role-de-lunion-europeenne-dans-la-gouvernance-des-vulnerabilites-informatiques.html

@gcve
@circl

Fragmentation ou complémentarité ? Le rôle de l'Union européenne dans la gouvernance des vulnérabilités informatiques

Le Global CVE Allocation System, soutenu par l’UE, a été lancé début janvier. Cet événement fait suite aux problématiques de financement du programme CVE, opéré par MITRE Corporation et soutenu par le gouvernement américain. L’initiative illustre la manière dont l’UE affirme son influence normative tout en atténuant sa dépendance aux infrastructures non européennes. Cette dimension prend toute son importance à l’heure du retour de la compétition entre grandes puissances.

Irsem

Google used a ZK proof to disclose a quantum breakthrough that cuts the cost of breaking cryptocurrency by 20x without handing attackers the circuit.

The Rust code behind the proof had memory safety bugs. We used this new attack surface to forge a proof that beats Google’s on every metric.

Google patched it within days. Their quantum claims are unaffected. https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/

We beat Google’s zero-knowledge proof of quantum cryptanalysis

Trail of Bits discovered and exploited memory safety and logic vulnerabilities in Google’s Rust zero-knowledge proof code to forge a proof claiming better quantum circuit performance metrics than Google’s original results, demonstrating unique security risks in zkVM systems.

The Trail of Bits Blog
Plus des trois quarts des pays européens sont dépendants du cloud américain pour des fonctions essentielles à leur sécurité nationale, met en garde un rapport https://ift.tt/PEz9VtI
Plus des trois quarts des pays européens sont dépendants du cloud américain pour des fonctions essentielles à leur sécurité nationale, met en garde un rapport

Une analyse du groupe de réflexion Future of Technology Institute souligne les risques que fait peser pour l’Europe la dépendance numérique aux Etats-Unis.

Le Monde