NIST’s PQC Standards: FIPS 203-205 and the Migration Clock

On August 13, 2024, NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — the first formal post-quantum cryptography standards, capping an eight-year open competition and starting the migration clock for RSA and elliptic-curve infrastructure. With harvest-now-decrypt-later collection already threatening long-lived secrets and federal migration timelines targeting the 2030s, enterprises face a decade-scale cryptographic inventory and replacement program. This guide walks the standards, the threat math, and the migration playbook from inventory to hybrid deployment.

Continue ReadingNIST’s PQC Standards: FIPS 203-205 and the Migration Clock

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft’s first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government’s ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

The Telegram Arrest and the Encryption Debate of 2024

On August 24, 2024, French authorities arrested Telegram founder Pavel Durov at Le Bourget airport, and two days later charged him with complicity in organized-crime offenses enabled by his platform’s refusal to cooperate with legal process — the first time a major encrypted-service executive faced criminal liability for governance choices. Released under judicial supervision within days, Durov’s case forced every platform lawyer to reprice jurisdictional arbitrage, moderation staffing, and the meaning of cooperation. This account lays out the charges, the encryption-policy fault lines, and the compliance playbook that followed.

Continue ReadingThe Telegram Arrest and the Encryption Debate of 2024

PuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PuTTY’s April 2024 advisory for CVE-2024-31497 read like a physics problem: the terminal’s ECDSA implementation biased nonces on NIST P-521, so roughly 71 captured SSH signatures suffice for a lattice attack that recovers the private key. This piece explains the Hidden Number Problem math, why archived PCAP and DLP session capture retroactively weaponized years of traffic, the 0.81 deterministic-nonce fix, and the brutal rotation drill that made every P-521 key used through Pageant presumptively burned.

Continue ReadingPuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key