Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

SAML: A fractal of bad design

1Password's AI patching benchmark is misleading

Security auditing in the age of (good enough) AI

How Trail of Bits helps verify the integrity of Signal chats

Security auditing in the age of (good enough) AI

VMs won't contain cyber-capable agents

Shipping post-quantum cryptography to Python

Shipping post-quantum cryptography to Python – The Trail of Bits Blog

Factoring "short-sleeve" RSA keys with polynomials

Fuzzing fork of go toolchain

We beat Google's zero-knowledge proof of quantum cryptanalysis

Carelessness versus craftsmanship in cryptography

Escaping Misconfigured VSCode Extensions (2023)

Detect Go’s silent arithmetic bugs with go-panikint

We found cryptography bugs in the elliptic library using Wycheproof

Constant-time support coming to LLVM: Protecting cryptographic code

LLVM Adds Constant-Time Support for Protecting Cryptographic Code

We found cryptography bugs in the elliptic library using Wycheproof

Supply chain attacks are exploiting our assumptions

How we avoided side-channels in our new post-quantum Go cryptography libraries

The cryptography behind electronic passports

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more

Weaponizing image scaling against production AI systems

Marshal madness: A brief history of Ruby deserialization exploits

Buttercup is now open-source

Exploiting zero days in abandoned hardware

Unexpected security footguns in Go's parsers

The cryptography behind passkeys

Making PyPI's test suite 81% faster

A New ASN.1 API for Python

More →