GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Sophie Schmieg (sophieschmieg@infosec.exchange)

  1. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 05-Jun-2026 03:35:40 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Clemens

    @neverpanic I will not share a stage with the speaker lineup they have selected, so no.

    In conversation about 10 days ago from infosec.exchange permalink
  2. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 05-Jun-2026 03:13:25 JST Sophie Schmieg Sophie Schmieg

    Apparently one can just claim to have codesigned any scheme now, so let it be known that Julius and I coauthored the Caesar cipher

    https://openssl-conference.org/speaker?p=I

    In conversation about 10 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Speaker — The Křižík Effect
  3. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Wednesday, 03-Jun-2026 03:42:11 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Paul Cantrell

    @inthehands are we doing illegal primes again?

    In conversation about 12 days ago from infosec.exchange permalink
  4. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 29-May-2026 00:31:19 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Kevin Beaumont

    @GossiTheDog ugh and they left themselves some wiggle room: the way it's written, you could claim that the criminals prosecuted are the groups exploiting the vulnerabilities. That is an obvious statement and it's clearly implied that the person doing the zero day release is actively cooperating with threat actors and therefore also criminally liable, but Microsoft can always "well technically" themselves out of this claim.

    In conversation about 17 days ago from infosec.exchange permalink
  5. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Wednesday, 20-May-2026 09:08:09 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Adrianna Tan

    @skinnylatte Jupp, I entered the US on an L visa, which has even worse conditions than the H1B.
    But Germany is a country that has no wait time, so I converted to a Greencard within a year.

    The exploitation is only possible because people do not have a path to permanent residence and citizenship, and the number one blocker for that is racist quotas.

    In conversation about a month ago from gnusocial.jp permalink
  6. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Sunday, 03-May-2026 06:36:27 JST Sophie Schmieg Sophie Schmieg

    I think I might need to check some luggage, my bag doesn't want to close.

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/506/852/631/049/654/original/9397cca902bf5108.jpg
  7. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Thursday, 16-Apr-2026 23:43:39 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Soatok Dreamseeker

    @soatok I hope they accounted for ML-DSA's signature size when planning to add all these JWTs.

    In conversation about 2 months ago from infosec.exchange permalink
  8. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Tuesday, 07-Apr-2026 00:56:13 JST Sophie Schmieg Sophie Schmieg
    • Filippo Valsorda

    And the posts, they keep on coming.
    I hundred percent agree with @filippo here, the question is not whether we're certain that a quantum computer exists by 2029, it's whether we're certain that one doesn't exist. And things have progressed far enough that non-physicists, or even physicists working in different subfields, can no longer reliably tell what's going on.

    https://words.filippo.io/crqc-timeline/

    In conversation about 2 months ago from infosec.exchange permalink
  9. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 13-Mar-2026 09:57:34 JST Sophie Schmieg Sophie Schmieg
    • Filippo Valsorda

    Last time I had a 10+ hour flight, Opal nerd sniped me into figuring out how to break ML-DSA keys that had been improperly encrypted with a reused IV. (To be perfectly clear, this is not an issue with ML-DSA, but with reused IVs. Nothing is secure in that case, but some things are insecure in interesting ways)

    So of course, @filippo , being present when I disclosed that vulnerability, chose to immediately exploit it by nerd sniping me into providing additional test vectors for ML-DSA for this flight.

    In conversation about 3 months ago from infosec.exchange permalink
  10. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 20-Feb-2026 02:58:07 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Soatok Dreamseeker

    @soatok @whitequark yeah, this is the rare compiler w for constant time programming, that has saved some Kyber implementations.
    Since multiplication and shifts are so much cheaper than integer division, this is more or less the standard behavior if the compiler knows the divisor. But of course, you can't rely on it. And theoretically, the compiler is allowed to take your manual Barrett code and replace it with idiv as well, if it sees so fit.

    In conversation about 4 months ago from gnusocial.jp permalink
  11. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 20-Feb-2026 00:38:00 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Soatok Dreamseeker

    @soatok is it bad that I find the assembly completely reasonable? It's just a Barrett reduction.

    In conversation about 4 months ago from infosec.exchange permalink
  12. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 13-Feb-2026 06:45:09 JST Sophie Schmieg Sophie Schmieg

    Lol. Rofl, even.

    (Not the Onion: https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/enterprise-2030)

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/059/698/181/615/660/original/827499da278edf3a.png
    2. Domain not in remote thumbnail source whitelist: www.ibm.com
      The enterprise in 2030
      AI isn’t just enhancing the business model. By 2030, it will be the business model. Here are five predictions that can help business leaders prepare to win in an AI-first future.
  13. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 13-Feb-2026 06:14:02 JST Sophie Schmieg Sophie Schmieg
    • Q ✨

    @q I have no idea. I work in this field, and I have no idea.

    In conversation about 4 months ago from infosec.exchange permalink
  14. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Tuesday, 03-Feb-2026 01:32:08 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Charlie Stross
    • Charles Johnson
    • Weekend Editor
    • Dan Sugalski

    @wordshaper @weekend_editor @Green_Footballs @cstross starting by the fact that being resistant to a specific disease does not necessarily produce any other positive side effects, and in fact is more likely to negatively impact fitness when the disease is not a threat. See for example sickle cell anemia and malaria.

    In conversation about 4 months ago from infosec.exchange permalink
  15. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Thursday, 29-Jan-2026 04:53:41 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Jade
    • Christine Lemmer-Webber

    @cwebber @JadedBlueEyes to be fair, if you leave all the crypto as a TODO, it is technically post-quantum.

    In conversation about 5 months ago from infosec.exchange permalink
  16. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Friday, 23-Jan-2026 03:35:47 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Soatok Dreamseeker

    @soatok independent of that logic error, looking at the code it also has a fundamentally flawed design that assumes that signatures can be verified via an equality check. It also trusts the token with algorithm selection and has a timing side channel.

    In conversation about 5 months ago from infosec.exchange permalink
  17. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Thursday, 22-Jan-2026 14:46:33 JST Sophie Schmieg Sophie Schmieg

    Me: if I was an attacker and had a quantum computer right now, CA root certs would certainly be my first target.
    Colleague: come on, no Bitcoin for me?
    Me: fine, after I stole a bunch of Bitcoin and distributed them among the people in this video call, CA root certs would be my next target.

    In conversation about 5 months ago from infosec.exchange permalink
  18. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Saturday, 17-Jan-2026 00:49:18 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Soatok Dreamseeker

    @soatok ah yes, I too prefer X448 to guard against – checks notes – quantum attacks.

    In conversation about 5 months ago from infosec.exchange permalink
  19. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Tuesday, 13-Jan-2026 07:25:56 JST Sophie Schmieg Sophie Schmieg
    in reply to
    • Paul_IPv6
    • Paul Cantrell

    @paul_ipv6 @inthehands honestly, I've been wondering that for a while. If there is a masked, unidentified person abducting people in broad daylight, isn't it supposedly the police's job to stop them? I mean could be anyone, without a badge we can't know for sure, after all.

    (And I know, expecting the police to actually do their job instead of committing crimes themselves is a tall order, but still)

    In conversation about 5 months ago from infosec.exchange permalink
  20. Embed this notice
    Sophie Schmieg (sophieschmieg@infosec.exchange)'s status on Saturday, 10-Jan-2026 17:55:36 JST Sophie Schmieg Sophie Schmieg
    • Insecurity Princess 🌈💖🔥

    Me: oh, we could buy an oscilloscope!
    @saraislet : why would we need an oscilloscope?!?
    Me: uhm, because it's an oscilloscope?!?

    In conversation about 5 months ago from infosec.exchange permalink
  • Before

User actions

    Sophie Schmieg

    Sophie Schmieg

    Leading cryptography (ISE Crypto) at Google.Opinions my own.Content usually badly explained mathematics

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          41310
          Member since
          27 Nov 2022
          Notices
          93
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.