Robert Merget (ic0ns)
ic0nz1.bsky.social
Robert Merget (ic0ns)
@ic0nz1.bsky.social
I build tools to analyze implementations cryptographic protocols with a special heart for TLS and related protocols <3
Pinned
We found a new vulnerability in TLS. It's a variant of the ALPACA attack that bypasses current countermeasures. Relativly low impact - but great insight! Check it out: opossum-attack.com
We found a new vulnerability in TLS. It's a variant of the ALPACA attack that bypasses current countermeasures. Relativly low impact - but great insight! Check it out: opossum-attack.com
July 8, 2025 at 12:26 PM
Reposted by Robert Merget (ic0ns)
Oof. Reportedly, if you got a certificate from SSL.com by putting "example[@]gmail.com" at _validation-contactemail.example.com, they would add gmail.com (!!!) to your verified domains.

A good reminder to use the CAA record, and to sign up for CT monitoring (e.g. Cert Spotter).

https://bugzilla.mo
April 19, 2025 at 10:30 AM
I spent the last few weeks playing with Claude code to refactor our codebase, add tests and documentations - and I am kind of impressed how useful it is. For 125$ I reached >97% code coverage with full javadoc for every function in one of our projects.
March 18, 2025 at 11:43 AM
Reposted by Robert Merget (ic0ns)
The 3rd edition of WISC – Women in Security and Cryptography Workshop will take place in Bochum from June 16 to 18. Already confirmed are talks by Lejla Batina, Zinaida Benenson, Shafi Goldwasser, Martina Lindorfer, and Doreen Riepel. Registration is open now! casa.rub.de/en/events/wi...
WISC | Cluster of Excellence CASA | RUB
The Women in Security and Cryptography Workshop promotes international female PhD students and outstanding female students in the field of IT security.
casa.rub.de
March 7, 2025 at 4:43 AM
Reposted by Robert Merget (ic0ns)
Join our Applied Crypto group at FAU in Nürnberg as a PhD student or spread the word: we're hiring.

Our work covers many topics in real-world crypto, especially provable security and privacy of modern messaging protocols 🔐✉️

www.jobs.fau.de/jobs/7-phd-p...
7 PhD positions (m/f/d) (salary level 13 TV-L) in Computer Science (full time) and 3 PhD position (m/f/d) (salary level 13 TV-L) in Law (part time, 75%)
www.jobs.fau.de
March 5, 2025 at 9:59 PM
Reposted by Robert Merget (ic0ns)
Workshop on Secure Protocol Implementations in the Quantum Era (SPIQE), co-located with ACNS 2025.

The submission deadline is March 23, 2025.

More details: spiqe-workshop.github.io/call.html

I am looking forward to seeing some exciting submissions!

#Cryptography #SPIQE #ACNS2025
Secure Protocol Implementations in the Quantum Era (SPIQE)
Secure Protocol Implementations in the Quantum Era (SPIQE)
spiqe-workshop.github.io
February 28, 2025 at 9:55 PM
Reposted by Robert Merget (ic0ns)
#FUZZING'25 CALL FOR PAPERS
──────
✨ New OC members:
* Ruijie Meng (@ruijiemeng.bsky.social; NUS)
* Rohan Padhye (@rohan.padhye.org; CMU).
✨ New paper type: Fuzzing Nuggets (short papers).

🔗 fuzzingworkshop.github.io
📅 20.March (Submission)
📅 17.April (Notification)
📅 28.June (Workshop)
February 17, 2025 at 6:40 PM
Tbh - feels bad to deactivate my Twitter account - but at some point one has to choose a side.
February 18, 2025 at 6:48 AM