#message

4 posts · Last used 8d

Back to Timeline
0xllx0 @0xllx0@activitypub.space · Jul 28, 2026

Protocol for Updating KEM used for E2EE

<p>At today's meeting we briefly discussed how we would go about updating the KEM algorithm used to establish MLS keys.</p> <p>I mentioned the BeeKEM (<a href="https://eprint.iacr.org/2026/1434" rel="nofollow ugc">https://eprint.iacr.org/2026/1434</a>, <a href="https://github.com/swicg/activitypub-e2ee/issues/95" rel="nofollow ugc">https://github.com/swicg/activitypub-e2ee/issues/95</a>) protocol as an example, though I have concerns about this particular protocol. The lead authors are currently PhD students, and this is potentially part of their program (no issue there). [...]</p> Hover or focus to reveal Sensitive
At today's meeting we briefly discussed how we would go about updating the KEM algorithm used to establish MLS keys. I mentioned the BeeKEM (https://eprint.iacr.org/2026/1434 https://github.com/swicg/activitypub-e2ee/issues/95) protocol as an example, though I have concerns about this particular protocol. The lead authors are currently PhD students, and this is potentially part of their program (no issue there). My main problems are that there is a non-trivial amount of LLM use in their reference implementation, it is not clear to what extent LLMs were used to write the paper, and they weaken the Forward-Secrecy + Post-Compromise Security properties to support their newly introduced Consistency Under Concurrency property. The paper is still in pre-print, so I would be very interested to read any reviews from cryptographers in the field before incorporating/implementing the protocol in ActivityPub. Other algorithms like dMLS (https://www.ietf.org/archive/id/draft-kohbrok-mls-dmls-02.html) and de-MLS (https://research.logos.co/rlog/de-mls-with-waku) could be used as well. Something built on FediE2EE-PKD (https://github.com/fedi-e2ee/public-key-directory-specification/blob/main/Specification.md#message-attribute-shreddability) could also be a solution, TBD. To ensure we have a clear path to upgrade when more secure and/or private protocols are available, it would be good to specify some form of versioned cryptography similar to what is used in PASETO (https://github.com/paseto-standard/paseto-spec)
0
0
0
Joe Gstettner @joegste@mastodon.social · Jul 18, 2026
This picture, I had to take. Walking by the Kongresshalle in Nürnberg, build by the Nazis, there was this pole with FCK AFD sticker. A small sticker with the powerful message and in the background the massive monument of history which should never repeat. #photography #building #message #fckafd #nurnberg #history #neverAgain #sticker #blackandwhite #monochrome
22
0
8
Script Kiddie @scriptkiddie@anonsys.net · Jul 15, 2026
0
0
0

You've seen all posts