from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Matthew Green

Ideas, decisions, and lessons from the team.

blog.cryptographyengineering.com (opens on the source site)
11Posts tracked
last weekLatest publication
0.7Posts / month over the last 12 months

Latest writing

11 of 11 posts

Is sandboxing sufficient to contain rogue agents? (opens on the source site)

Quick caveats: this is a post on AI safety, written by a cryptography professor. If that troubles you, you should read something else. I try hard not to work on AI (except when the topic occasionally tosses itself in my path), so in this post I’m mostly trying to referee arguments made by others. If … Continue reading Is sandboxing sufficient to contain rogue agents? →

Read at the source

Everything is about to “go dark” (opens on the source site)

I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaining to colleagues why Baltimore isn’t actually like The Wire. And second, trying not to talk about AI. Here I’m going to … Continue reading Everything is about to “go dark” →

Read at the source

Some thoughts about Anthropic’s new cryptanalysis results (opens on the source site)

Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results. A few people … Continue reading Some thoughts about Anthropic’s new cryptanalysis results →

Read at the source

The future of Siri, or: why private inference isn’t private enough (opens on the source site)

Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world’s most widely-used voice agents, and it would be good if it didn’t suck. The idea that Apple would boost its capabilities with frontier models wasn’t so much … Continue reading The future of Siri, or: why private inference isn’t private enough →

Read at the source

Let’s talk about encrypted reasoning (opens on the source site)

Update August 11, 2026: A group of researchers from all over Europe were inspired by this post, and actually turned it into a real working attack! Check out their writeup and paper here. This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to … Continue reading Let’s talk about encrypted reasoning →

Read at the source

Anonymous credentials: an illustrated primer (Part 2) (opens on the source site)

This is the second in a series of posts about anonymous credentials. You can find the first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenticate to a website without sacrificing their privacy. As a quick reminder, an anonymous credential system consists of … Continue reading Anonymous credentials: an illustrated primer (Part 2) →

Read at the source

Anonymous credentials: an illustrated primer (opens on the source site)

This post has been on my back burner for well over a year. This has bothered me, since with every month that goes by, I become more convinced that anonymous authentication the most important topic we could be talking about as cryptographers. This isn’t just because I love neat cryptography: it’s that I don’t trust … Continue reading Anonymous credentials: an illustrated primer →

Read at the source

WhatsApp Encryption, a Lawsuit, and a Lot of Noise (opens on the source site)

It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but several unusual stories about the encryption used in WhatsApp. Or more accurately, if you read the story, a pretty wild allegation that the widely-used … Continue reading WhatsApp Encryption, a Lawsuit, and a Lot of Noise →

Read at the source

Kerberoasting (opens on the source site)

I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy (“oh, why didn’t I think of that”) or else they impress me with the brilliance of their inventors. But there’s also another class of vulnerabilities: these are the ones that can’t possibly exist in important production software, … Continue reading Kerberoasting →

Read at the source

A bit more on Twitter/X’s new encrypted messaging (opens on the source site)

Update 6/10: Based on a short conversation with an engineering lead at X, some of the devices used at X are claimed to be using HSMs. See more further below. Matthew Garrett has a nice post about Twitter (uh, X)’s new end-to-end encryption messaging protocol, which is now called XChat. The TL;DR of Matthew’s post … Continue reading A bit more on Twitter/X’s new encrypted messaging →

Read at the source

Dear Apple: add “Disappearing Messages” to iMessage right now (opens on the source site)

This is a cryptography blog and I always feel the need to apologize for any post that isn’t “straight cryptography.” I’m actually getting a little tired of apologizing for it (though if you want some hard-core cryptography content, there’s plenty here and here.) Sometimes I have to remind my colleagues that out in the real … Continue reading Dear Apple: add “Disappearing Messages” to iMessage right now →

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.