Security Cryptography Whatever
Security Cryptography Whatever
  • 59
  • 11 853
Cryptanalyzing LLMs with Nicholas Carlini
'Let us model our large language model as a hash function-'
Sold.
Our special guest Nicholas Carlini joins us to discuss differential cryptanalysis on LLMs and other attacks, just as the ones that made OpenAI turn off some features, hehehehe.
Transcript: securitycryptographywhatever.com/2025/01/28/cryptanalyzing-llms-with-nicholas-carlini/
Links:
- nicholas.carlini.com
- “Stealing Part of a Production Language Model”: arxiv.org/pdf/2403.06634
- ‘Why I attack"’: nicholas.carlini.com/writing/2024/why-i-attack.html
- “Cryptanalytic Extraction of Neural Network Models”, CRYPTO 2020: arxiv.org/abs/2003.04884
- “Stochastic Parrots”: dl.acm.org/doi/10.1145/3442188.3445922
- help.openai.com/en/articles/5247780-using-logit-bias-to-alter-token-probability-with-the-openai-api
- community.openai.com/t/temperature-top-p-and-top-k-for-chatbot-responses/295542
- opensource.org/license/mit
- github.com/madler/zlib
- ai.meta.com/blog/yann-lecun-ai-model-i-jepa/
- nicholas.carlini.com/writing/2024/how-i-use-ai.html
Переглядів: 522

Відео

Biden’s Cyber-Everything Bagel with Carole House
Переглядів 45714 днів тому
Just a few days before turning off the lights, the Biden administration dropped a huge cybersecurity executive order including a lot of good stuff, that hopefully [cross your fingers, knock wood, spin around three times and spit] will last into future administrations. We snagged some time with Carol House, outgoing Special Advisor and Acting Senior Director for Cybersecurity and Critical Infras...
Quantum Willow with John Schanck and Samuel Jacques
Переглядів 174Місяць тому
THE QUANTUM COMPUTERS ARE COMING...right? We got Samuel Jacques and John Schanck at short notice to answer that question plus a bunch of other about error correcting codes, logical qubits, T-gates, and more about Google's new quantum computer Willow. Transcript: securitycryptographywhatever.com/2024/12/18/quantum-willow Links: - blog.google/technology/research/google-willow-quantum-chip/ - rese...
Dual_EC_DRBG with Justin Schuh and Matthew Green
Переглядів 2742 місяці тому
Nothing we have ever recorded on SCW has brought so much joy to David. However, at several points during the episode, we may have witnessed Matthew Green's soul leave his body. Our esteemed guests Justin Schuh and Matt Green joined us to debate whether `Dual_EC_DRBG` was intentionally backdoored by the NSA or 'just' a major fuckup. Transcript: securitycryptographywhatever.com/2024/12/07/dual-ec...
A Little Bit of Rust Goes a Long Way with Android's Jeff Vander Stoep
Переглядів 2843 місяці тому
You may not be rewriting the world in Rust, but if you follow the findings of the Android team and our guest Jeff Vander Stoep, you'll drive down your memory-unsafety vulnerabilities more than 2X below the industry average over time! 🎉 Transcript: securitycryptographywhatever.com/2024/10/15/a-little-bit-of-rust-goes-a-long-way/ Links: - security.googleblog.com/2024/09/eliminating-memory-safety-...
Campaign Security with [REDACTED]
Переглядів 1183 місяці тому
With the 2024 United States Presidential Election right around the corner, we talk to an unnamed guest who has worked on cybersecurity for political campaigns in the United States since 2004. We recorded this in late August 2024. Transcript: securitycryptographywhatever.com/2024/10/13/campaign-security/ Links: - Active Measures by Thomas Rind: [us.macmillan.com/books/9780374287269/activemeasure...
Telegram with Matthew Green
Переглядів 5785 місяців тому
We finally have an excuse to tear down Telegram! Their CEO got arrested by the French, apparently not because the cryptography in Telegram is bad, but special guest Matt Green joined us to talk about how the cryptography is bad anyway, and you probably shouldn't use Telegram as a secure messenger of any kind! Show page: securitycryptographywhatever.com/2024/09/06/telegram Links: - blog.cryptogr...
CTO is mostly, like, not a real title
Переглядів 556 місяців тому
CTO is mostly, like, not a real title
Terrapin SSH vulnerability
Переглядів 1176 місяців тому
Terrapin SSH vulnerability
Summertime Sadness
Переглядів 1566 місяців тому
Are you going to be in Vegas during BlackHat / DEF CON? We're hosting a mixer, sponsored by Observa! We have limited capacity, so please only register if you can actually come. Location details are in the confirmation email. Tickets will be released in batches, so if you get waitlisted, there's a good chance you still get in. Looking forward to seeing you in Vegas! Ticket Link: www.eventbrite.c...
Does More Secure Software Make Vulnerability Researchers Richer?
Переглядів 1477 місяців тому
Full episode: ua-cam.com/video/J4t-J_3MRaI/v-deo.html Show page: securitycryptographywhatever.com/2024/06/24/mdowd/ Subscribe: Apple Podcasts: podcasts.apple.com/us/podcast/security-cryptography-whatever/id1578405214 Spotify: open.spotify.com/show/0bMJ5a7e4er7yDHMuGs9jp?si=a8ca5690251c4252 Pocket Casts: pca.st/bnsp15oy Overcast: overcast.fm/itunes1578405214 Links: - Azimuth Security: www.azimut...
Zero Day Markets with Mark Dowd
Переглядів 5287 місяців тому
Zero Day Markets with Mark Dowd
ekr
Переглядів 2018 місяців тому
ekr
STIR/SHAKEN with Paul Grubbs and Josh Brown
Переглядів 1199 місяців тому
STIR/SHAKEN with Paul Grubbs and Josh Brown
Cryptography Tier List
Переглядів 2349 місяців тому
Cryptography Tier List
Post-Quantum iMessage with Douglas Stebila
Переглядів 20211 місяців тому
Post-Quantum iMessage with Douglas Stebila
High-assurance Post-Quantum Crypto with Franziskus Kiefer and Karthik Bhargavan
Переглядів 190Рік тому
High-assurance Post-Quantum Crypto with Franziskus Kiefer and Karthik Bhargavan
Encrypting Facebook Messenger with Jon Millican and Timothy Buck
Переглядів 165Рік тому
Encrypting Facebook Messenger with Jon Millican and Timothy Buck
Attacking Lattice-based Cryptography with Martin Albrecht
Переглядів 272Рік тому
Attacking Lattice-based Cryptography with Martin Albrecht
Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted
Переглядів 284Рік тому
Signal's Post-Quantum PQXDH, Same-Origin Policy, E2EE in the Browser Revisted
'Jerry Solinas deserves a raise' with Steve Weis
Переглядів 160Рік тому
'Jerry Solinas deserves a raise' with Steve Weis
Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades
Переглядів 95Рік тому
Cruel Summer: hybrid signatures, Downfall, Zenbleed, 2G downgrades
Why do we think anything is secure, with Steve Weis
Переглядів 162Рік тому
Why do we think anything is secure, with Steve Weis
Elon's Encrypted DMs with Matthew Garrett
Переглядів 93Рік тому
Elon's Encrypted DMs with Matthew Garrett
WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi
Переглядів 271Рік тому
WhatsApp Key Transparency with Jasleen Malvai and Kevin Lewi
Messaging Layer Security (MLS) with Raphael Robert
Переглядів 885Рік тому
Messaging Layer Security (MLS) with Raphael Robert
Real World: Crypto (2023)
Переглядів 190Рік тому
Real World: Crypto (2023)
Threema with Kenny Paterson, Matteo Scarlata, & Kien Tuong Truong
Переглядів 4262 роки тому
Threema with Kenny Paterson, Matteo Scarlata, & Kien Tuong Truong
Has RSA been destroyed by a quantum computer???
Переглядів 2602 роки тому
Has RSA been destroyed by a quantum computer???
End of Year Wrap Up
Переглядів 692 роки тому
End of Year Wrap Up

КОМЕНТАРІ

  • @shmuelhazan6382
    @shmuelhazan6382 8 днів тому

    Microcorruption! Forgot about it. When i was a teenager more than 10 years ago I spent way too much time staring on orange mips assembly because of it

  • @davidcadrian
    @davidcadrian 9 днів тому

    Wow, three experts and David on this one

  • @johnbruhling8018
    @johnbruhling8018 11 днів тому

    I used to wear a bandana like that

  • @for2utube
    @for2utube 17 днів тому

    Some criticism. Excel is a level-0 database; it is lingua franca among IA but despised by others outside the IA circle for multiple reasons that I won't get into here. With respect to how far along the industry is, you are fooled into thinking adoption is widespread by living on Windows. In Windows, hardening (disallowing weak hashes, encryption algos, key exchanges) are only suggestions and whether or not that's really done is up to the implementer(!). RHEL takes a different approach: there are 4 engines and security policy disallows at the engine level weak hashes, encryption algos, and key exchanges as the host is hardened. Backward compatibility be damned. One popular IA application, Tenable Security Center (aka ACAS) just today (22-Jan-2025) made available FIPS 140-2 compliant sha-256 checksums of its plugins, having been only publishing MD5 checksums up until today. That, from a closed-source security-conscious company. So, if I'm responsible for downloading the plugins, carrying them across an air gap, and putting them onto a RHEL host and comparing the files with their hashes to make sure they didn't get corrupted along the way, I could not do this on a fully hardened RHEL host.

  • @d.5600
    @d.5600 Місяць тому

    lollllllll the caesar cipher stabbing joke sent me

  • @foobargorch
    @foobargorch 2 місяці тому

    what does "operational aspect" actually mean though? to my non spook ears it just sounds like "trust me bro, they're the good guys so this isn't what it looks like", whereas to my dilettante crypto and codemonkey ears, DUAL_EC_DRBG sounds like an extremely contrived way of achieving its stated purpose (slow, inefficient, complicated, even if we take the inefficiency as desirable for reasons, using Pedersen hashing on NUMS points just seems like a much simpler approach), and kinda lazy/sloppy way of achieving its alleged nefarious goals... and as a counter argument to them being the good guys, Grothoff's "The NSA’s SKYNET program may be killing thousands of innocent people" (published ars technica, 2016) seems very consistent with being sloppy about nefarious goals?

  • @kevinrineer5356
    @kevinrineer5356 3 місяці тому

    New listener. Glad to have found this podcast. I'll be digging back in time with gusto

  • @karelbilek9121
    @karelbilek9121 3 місяці тому

    I came to this channel, expecting video, ha. Oh well.

  • @Nathan_Mash
    @Nathan_Mash 4 місяці тому

    A very informative talk. I found the post quantum (PQ) conversation to be interesting. It is a shame the hosts repeatedly interrupted Dr. Donenfeld and would randomly veer off that topic. Dr. Donenfeld had to valiantly return to the topic 2-3 (maybe even four) times unprompted. Great guest selection but only so-so hosting for this podcast episode.

  • @joebeone
    @joebeone 5 місяців тому

    Dudes, can we get a link to the comparison of French and US criminal law that Thomas mentioned?!?! Leaving one slice of your nerd audience hanging

  • @bparker06
    @bparker06 5 місяців тому

    The amount of vocal fry makes this unlistenable to me... sorry

  • @andherium
    @andherium 6 місяців тому

    wait but can you guys do an actual tier list?

    • @thomasptacek
      @thomasptacek Місяць тому

      I really think this is something we should be leaving up to the leaders of the free world.

  • @sg777z
    @sg777z 6 місяців тому

    If i were a kernel i would not panic and if i were a NULL pointer i would simply not be dereferenceable 😆

  • @user-ui4fn6fj3p
    @user-ui4fn6fj3p 6 місяців тому

    The woman is so annoying

  • @alikhosravi3090
    @alikhosravi3090 7 місяців тому

    what the hel is this?

  • @numberup281
    @numberup281 8 місяців тому

    Woman is extremely disruptive and annoying

  • @sg777z
    @sg777z 8 місяців тому

    Great discussion, i was developing poker where the group encryption be needing, i was searching the web for any standards and found this one, will further read RFC, thank u

  • @BlissnHarmonyTP
    @BlissnHarmonyTP 9 місяців тому

    This is cursed. Plus, everyone knows GCM and ChaChaPoly are at most A-tier because they're fragile and aren't context committing.

  • @shmuelhazan6382
    @shmuelhazan6382 10 місяців тому

    Thanks, it is a shame that the top tire shitpost with obama, trump and biden is not on this channel too

    • @scwpod
      @scwpod 9 місяців тому

      Now up!

  • @sashakuznechkin
    @sashakuznechkin Рік тому

    Thx for your video

  • @S.Dadudida
    @S.Dadudida Рік тому

    Ich bin total verwirrt und das nervt echt

  • @S.Dadudida
    @S.Dadudida Рік тому

    Könnt ihr mir mal verraten was diese scheiße mit den fakes hier ist

  • @estheribrahim7226
    @estheribrahim7226 Рік тому

    I have gained valuable insight on cryptography from your podcast. Nothing is secure. With the rise of data breaches, phishing attacks, synthetic ID fraud, deepfakes and ransomeware attacks, the pertinent question is why security technology is still failing us despite billions being budgeted on security every year? While the world is getting all worked up over the problems of security vulnerabilities, people aren’t noticing that there is already a very effective solution to that threat - and that solution is based on an technology that’s almost fifty years old! Wes Kussmaul (founder of Delphi, the social network that was founded in 1982 and sold to News America Corp in 1993)and I are fans of your work. How would you love to feature Wes Kussmaul to talk about his extensive work on how an old technological method that can solve security challenges? I look forward to hearing from you.

  • @telephreak
    @telephreak Рік тому

    This was great. I've followed Adam Langley since his work on HSTS and it was great listening to him talk about passkeys.

  • @evan_pardon
    @evan_pardon Рік тому

    Im a big fan of Chris Peikert and his work, thank you for posting these videos. As an aspiring Cybersecurity professional thse have been very helpfu! I've learned a lot from these talk shows. Would love to reach out and contact you guys if possible!!

  • @adamputzer1154
    @adamputzer1154 Рік тому

    cool!

  • @ALEXISHANCOCK
    @ALEXISHANCOCK Рік тому

    Are there any books that y'all suggest for engineers to understand cryptography better?

  • @simonbattle0001
    @simonbattle0001 2 роки тому

    I give everyone a chance, but to attack Bruce Schneier and just listening to your knowledge on the subject and the disrespect for your peers tells me you people don't know jack about this subject.

  • @maksimivanov5417
    @maksimivanov5417 2 роки тому

    How old is the interview? Ryan Sleevi has been in Apple since June, 2022.

  • @mohamedmnahil6593
    @mohamedmnahil6593 2 роки тому

    Very interesting but i think RSA is facing a lot of pressure these days and i don't think it will make it for the coming decade

  • @atRonan
    @atRonan 2 роки тому

    Great episode!

  • @wadepearson2508
    @wadepearson2508 2 роки тому

    ᴘʀᴏᴍᴏsᴍ 🙏