Matthew Green
Cryptographer; teaches cryptography at Johns Hopkins and writes A Few Thoughts on Cryptographic Engineering.
Matthew Green did not write this page. What is this?
It collects the places they publish and what they have said there, each linked to the source. They have no account here. Is this you? Claim it, correct it, or ask us to remove it from ppll.
Where they publish
Blog A Few Thoughts on Cryptographic Engineering His blog on cryptography, encryption policy and what is broken this week. Has a feed.
Open blog.cryptographyengineering.com
Recent
- Everything is about to “go dark” 14 Aug 2026 I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaining to colleagues why Baltimo…
- Some thoughts about Anthropic’s new cryptanalysis results 29 Jul 2026 Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is…
- The future of Siri, or: why private inference isn’t private enough 9 Jun 2026 Yesterday Apple announced a big step towards deploying real AI in their Siri ecosystem. In most ways this is good and inevitable: Siri is one of the world’s most widely-used voice agents, and it would be good if it didn…
Show 7 more
- Let’s talk about encrypted reasoning 29 May 2026 Update August 11, 2026: A group of researchers from all over Europe were inspired by this post, and actually turned it into a real working attack! Check out their writeup and paper here. This is a quick post I wanted to…
- Anonymous credentials: an illustrated primer (Part 2) 17 Apr 2026 This is the second in a series of posts about anonymous credentials. You can find the first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenti…
- Anonymous credentials: an illustrated primer 2 Mar 2026 This post has been on my back burner for well over a year. This has bothered me, since with every month that goes by, I become more convinced that anonymous authentication the most important topic we could be talking ab…
- WhatsApp Encryption, a Lawsuit, and a Lot of Noise 2 Feb 2026 It’s not every day that we see mainstream media get excited about encryption apps! For that reason, the past several days have been fascinating, since we’ve been given not one but several unusual stories about the encry…
- Kerberoasting 10 Sept 2025 I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy (“oh, why didn’t I think of that”) or else they impress me with the brilliance of their inventors. B…
- A bit more on Twitter/X’s new encrypted messaging 9 Jun 2025 Update 6/10: Based on a short conversation with an engineering lead at X, some of the devices used at X are claimed to be using HSMs. See more further below. Matthew Garrett has a nice post about Twitter (uh, X)’s new e…
- Dear Apple: add “Disappearing Messages” to iMessage right now 1 Mar 2025 This is a cryptography blog and I always feel the need to apologize for any post that isn’t “straight cryptography.” I’m actually getting a little tired of apologizing for it (though if you want some hard-core cryptogra…
Link verified 20 Sept 2026. Recent items update automatically from the channel.
Mastodon @matthew_d_green@ioc.exchange Posts.
Recent
- There’s something ominous about the speed with which the entire world has marched to require identification on platforms and, as I expected, begin the process of banning anonymous VPNs. 6 May 2026
- I’ve been working on a little simulator for MeshCore, written entirely using Claude Code. I was hoping some MeshCore devs might take a look and let me know if there are features they could use. https://github.com/matthewdgreen/meshcore_sim #meshcore 23 Mar 2026
- Microsoft is handing over Bitlocker keys to law enforcement. 23 Jan 2026 forbes.com
Show 12 more
- I was stupid enough to buy this new AppleCare One plan for a phone I bought my daughter. Now I learn this only covers the device if it’s connected to the same Apple ID (not family plan). Have to spend Christmas unwinding this and getting a refund, what a drag. 25 Dec 2025
- One of the most interesting recent privacy developments is the deployment of big two-hop IP blinding VPNs by companies like Apple and Google. These systems are designed to ensure that even those companies can’t link web requests to IP addresses. 13 Nov 2025
- Great article about how TEEs are providing much less security than folks believe they will. 29 Oct 2025 arstechnica.com
- The “age verification” and the “human identification” problem are the same problem. It upsets me to be around people who think they’re working on the first, but don’t understand they’re actually working on the second. 15 Oct 2025
- Two great bits of academic attack work this week. The new one allows Android apps to see data displayed on the screen by other apps, including Google Authenticator codes. 15 Oct 2025 pixnapping.com
- This is amazing research by Nadia Heninger and her co-authors Wenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin and Aaron Schulman. TL;DR a huge number of satellite links over our heads are totally unencrypted. 14 Oct 2025 satcom.sysnet.ucsd.edu
- Germany has agreed to stop ChatControl for now, due to huge amounts of public pressure. Good job! The bad news is that it could come back as soon as December, and the German government has interpreted the feedback as a need to “moderate” the proposal. 10 Oct 2025
- From yesterday: the UK is demanding another backdoor in Apple’s encryption. 2 Oct 2025 ft.com
- “Industrial-scale pig butchering scams” god please let’s just skip this century and move on to the next. 27 Sept 2025
- This battle will keep playing out over and over again until they achieve something that their own citizens have made it clear they don’t want. 6 Jul 2025 techradar.com
- A good story in WIRED giving updates on the situation with Dr. Xiaofeng Wang. 2 Apr 2025 wired.com
- The Indiana University chapter of the American Association of University Professors have written a letter demanding Dr. Xiaofeng Wang’s reinstatement. 31 Mar 2025
Link verified 20 Sept 2026. Recent items update automatically from the channel.
Beliefs
Korrents What they believe 11 beliefs — each backed by an exact quote.
Each is a — compiled by korrents.com, not by them: the one-line wordings are korrents', the quotes are theirs.
Recent
Telegram is not an encrypted messenger in the sense that matters, because it does not end-to-end encrypt conversations by default.
Telegram clearly fails to meet this stronger definition for a simple reason: it does not end-to-end encrypt conversations by default.
Is Telegram really an encrypted messaging app? Said 25 Aug 2024
Almost every one-to-one Telegram chat, and every group chat, is readable on Telegram’s own servers.
The practical impact is that the vast majority of one-on-one Telegram conversations — and literally every single group chat — are probably visible on Telegram’s servers, which can see and record the content of all messages sent between users.
Is Telegram really an encrypted messaging app? Said 25 Aug 2024
Encryption people have to switch on protects almost nobody; what protects people is what a service turns on for everyone.
To be honest though, it doesn’t matter how secure something is if people aren’t actually using it.
Is Telegram really an encrypted messaging app? Said 25 Aug 2024
Show 8 more
Telegram urges people away from default-encrypted messengers while refusing to build the features that would encrypt its own users.
Indeed, it no longer feels amusing to see the Telegram organization urge people away from default-encrypted messengers, while refusing to implement essential features that would widely encrypt their own users’ messages.
Is Telegram really an encrypted messaging app? Said 25 Aug 2024
Default cloud backup has quietly put a copy of nearly everyone’s private papers in a few data centres, and that is a surveillance weapon.
It terrifies me, because these data repositories are not only a risk to individual user privacy, they’re effectively a surveillance super-weapon.
Why encrypted backup is so important Said 7 Dec 2022
Nobody chose cloud backup: a handful of Silicon Valley executives made the choice for everyone in pursuit of adoption metrics.
A handful of Silicon Valley executives made the choice for us, in pursuit of adoption metrics and a “magical” user experience.
Why encrypted backup is so important Said 7 Dec 2022
A tracing requirement in an encrypted messenger gives up the confidentiality of who sent what, which is the part that protects the sender.
In short: traceability can really screw with the “who sent what” side of content confidentiality.
Thinking about “traceability” Said 1 Aug 2021
Who sent what is not metadata, so an encrypted system that reveals it has given up more than the routing information it could never hide.
Information revealed about “who sent what” in an E2E system is not the same as metadata.
Thinking about “traceability” Said 1 Aug 2021
Content tracing works by turning every user into a cooperating witness, whether or not they want to cooperate with the police.
This brings us to the central challenge of all content tracing proposals so far: to make tracing possible, a tracing system needs to turn every WhatsApp user (including the originator) into a cooperative green circle — regardless of whether users actually want to cooperate with police.
Thinking about “traceability” Said 1 Aug 2021
Shrugging that perfect security is impossible is the wrong lesson: the achievable goal is to wreck the economics of mass exploitation.
The problem that companies like Apple need to solve is not preventing exploits forever, but a much simpler one: they need to screw up the economics of NSO-style mass exploitation.
A case against security nihilism Said 20 Jul 2021
What made NSO different was not its exploits but its scale: it turned state-grade surveillance into something any government could buy.
Rather: NSO’s genius is that they’ve done something that attackers were never incentivized to do in this past: democratize access to exploit technology.
A case against security nihilism Said 20 Jul 2021
Beliefs others hold too
Encryption people have to switch on protects almost nobody; what protects people is what a service turns on for everyone. 2 hold this
To be honest though, it doesn’t matter how secure something is if people aren’t actually using it.
Is Telegram really an encrypted messaging app? Said 25 Aug 2024
What is a korrent?
A korrent is a belief a person has stated in their own words: one sentence stating the claim, backed by a quote and a source, kept at korrents.com.
Under a name here, the quoted block is what they actually said. The korrent beneath it is the claim those words support, in korrents' wording — tap it to see the record, its source, and who else holds it.
Nobody here wrote their own korrents. They are compiled from public statements, and a person can change their mind, which is recorded too.
Feed
As its own page →Hiding
14 August
29 July
9 June
29 May
6 May
17 April
23 March
2 March
2 February
23 January
25 December 2025
13 November 2025
29 October 2025
15 October 2025
14 October 2025
10 October 2025
2 October 2025
27 September 2025
10 September 2025
6 July 2025
9 June 2025
2 April 2025
31 March 2025
1 March 2025
Nothing matches.
About the English under a post
Some people here publish in a language other than English. Where they do, this site shows a machine translation beneath the post, in this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the serif above is exactly what the person published, and it is what to quote them on. A translation can be wrong in ways that matter, especially about tone.
Only the post's own words are translated. A quoted post, a linked article and a belief on korrents.com are left in their original language.