Feynman, 1988 — “What I cannot create, I do not understand”
Writing
Your certificate chain is about to get heavy
An ML-DSA signature is not a drop-in for an ECDSA one — it is roughly an order of magnitude larger, and a chain carries several. Here is what that does to TLS handshake latency on a lossy mobile link, what it does to firmware images with a fixed signature slot, and the three places I have seen it break before anyone had a chance to plan for it.
14 min read
What a cryptographically relevant quantum computer actually costs
Logical qubits are the wrong unit. Counting physical qubits, error-correction overhead, and wall-clock hours instead.
21 min
Hybrid or bust: reading X25519MLKEM768 on the wire
A packet-by-packet walk through a hybrid key exchange, and why the classical half is still doing real work.
11 min
Crypto agility is an inventory problem, not a math problem
You cannot rotate what you cannot find. Building a usable inventory of every key, cert, and hardcoded curve.
17 min
Lattices, in the order they were invented
From Ajtai's worst-case reduction to Learning With Errors to the module structure in the standards. No prerequisites past linear algebra.
26 min
SLH-DSA is slow, stateless, and probably your firmware's future
Hash-based signatures ask for almost no new assumptions. That is worth a lot when the device ships for fifteen years.
13 min
Rejection sampling is where the bugs live
Notes from reviewing four ML-KEM implementations, and the timing leak that survived all of them.
19 min
Subscribe
Two posts a month, sent when they’re finished
No digest, no tracking pixels, no course upsell. Long pieces on lattices, migration, and the hardware, sent as plain text with the diagrams attached.
Unsubscribe link in every email.