Elektrine lite

← Feed

Tobias

tsmreu@infosec.exchange

<p>IT-Security student @ TU Darmstadt<br />Working on <span class="h-card" translate="no"><a href="https://mastodon.social/@twonly" class="u-url mention">@<span>twonly</span></a></span></p>

Posts

  • Post #4371526

    Du verwendest Signal und twonly seit mehr als einem Monat? Dann würde ich mich sehr freuen, wenn du 5 Minuten Zeit hättest und an meiner Umfrage über die Verifizierung von Kontakten für meine Masterarbeit teilnehmen könntest: https://survey.twonly.org/evaluation.php Mit ein wenig Glück kann man auch 20 € gewinnen. :)

  • Post #3932318

    RE: https://infosec.exchange/@tsmreu/116806525948769324 I received feedback from a cryptography expert, who pointed out that my original trick of withholding the nonce from the server might work in practice, but it prevents a formal security proof under standard AEAD models. So I updated the protocol: Instead of the nonce, the encryption key for the serverKey is now withheld, distributed to the trusted friends, and only sent to the server during the recovery. So the challenge is still going,...

  • Post #3843044

    For the cryptography fans among you, here’s a little challenge with a 50€ prize :) For @twonly@mastodon.social, I’m planning a backup method where users no longer have to remember a password. The idea: Instead of trusting the server, just trust your friends. You can find the exact details here: https://tsmr.eu/blog/2026-passwordless-recovery #cryptography #bugbounty #e2ee

  • Post #1183605

    Yesterday, someone asked me why I’m developing @twonly. For over 12 years, programming has been my biggest hobby. It’s just nice to get lost in the code and forget everything around me (one of the reasons why twonly is being developed without AI). And twonly is by far my coolest project yet, because it helps people simply stay in touch with others without spying on them or selling their data. (1/3)