Matthew Green is on BlueSky
@matthew_d_green
I teach cryptography at Johns Hopkins. Mostly on BlueSky these days at http://matthewdgreen.bsky.social.
Pinned post: I’m mostly posting on BlueSky at matthewdgreen.bsky.social.
That's their fancy way of saying "If you know how to operate an email address, you are unquestionably ancient"
One good thing coming out of the current administration: the US is actually forcing the UK to back down on backdoors. arstechnica.com/tech-policy/20…
“‘All US forces must now assume their networks are compromised’ after Salt Typhoon breach.” I’m not even sure what I could possibly add to that. itpro.com/security/cyber…
This is going to be bad for everyone. propublica.org/article/trump-…
This battle will keep playing out over and over again until they achieve something that their own citizens have made it clear they don’t want. techradar.com/vpn/vpn-privac…
1/ I think I have the answer! (blogpost at the bottom of 🧵) Original Q: How was @WhatsApp able to patch a client-side vulnerability of malicious PDF parsing from the server-side, although server is not exposed to PDF content due to End-to-End Encryption (#E2EE)?
How can @WhatsApp patch a pdf parsing vulnerability exploited by #Paragon without touching: 1. The parsing code ("no client-side fix" according to @SecurityWeek @EduardKovacs ) 2. The PDF itself (it's under End to End Encryption #E2EE on server ) 🤔 @jsrailton @billmarczak