David Wong

cryptologie.net

cryptography, security, and random thoughts

Hey! I'm David, cofounder of zkSecurity, research advisor at Archetype, and author of the Real-World Cryptography book. I was previously a cryptography architect of Mina at O(1) Labs, the security lead for Libra/Diem at Facebook, and a security engineer at the Cryptography Services of NCC Group. Welcome to my blog about cryptography, security, and other related topics.

← back to all posts

Real World Crypto: debriefing

blog

There is no day 4, this is over… And I’ve got a ton to work on/read about/catch up with.

But first! I’m spending the week end in San Francisco before flying to Austin, if anyone wants to hang out in SF feel free to contact me on twitter =)

(and if you work for Dropbox, feel free to invite me to eat at your one michelin star cafetaria)

Take-home message

  • Tor’s security seems a bit shaky to me
  • QUIC crypto will die. Just look at tls 1.3
  • TLS 1.3 is still a clusterfuck
  • Lots of stuff to break in SSE and PPE
  • Intel is doing something really cool with SGX
  • The Juniper paper is going to be a big deal
  • The BREACH improvement is going to be a big deal

Papers to read

First, a bunch of slides are already available through the real world crypto webpage. And I’ve been taking notes every day: day1, day2, day3.

Now here’s my to read list from the important talks:

And bonus, here are some paper that have nothing to do with RWC but that I still want to read right now:

Next conventions to attend

I actually have no idea about that. You?

suggested reads:
← back to all posts blog • 2016-01-09
currently reading:
Real World Crypto: debriefing
01-09 blog
📖 my book
Real-World Cryptography is available from Manning Publications.
A practical guide to applied cryptography for developers and security professionals.
🎙️ my podcast
Two And A Half Coins on Spotify.
Discussing cryptocurrencies, databases, banking, and distributed systems.
📺 my youtube
Cryptography videos on YouTube.
Video explanations of cryptographic concepts and security topics.