Engineering posts about Encryption
Curated summaries and key learnings for engineers working with Encryption.
Certificate Transparency Monitoring is now generally available
The article discusses the general availability of Certificate Transparency Monitoring by Cloudflare, which alerts users when new TLS certificates appear in public logs for their domains. Initially,...
The Agent Access Model
The Agent Access Model (AAM) presents a novel approach to access control for agents in enterprise security, moving away from traditional trust models that rely on user identity and location. AAM...
Post-quantum authentication to origins is now supported
The article discusses Cloudflare's implementation of post-quantum authentication for its Authenticated Origin Pulls and Custom Origin Trust Store, aimed at securing connections against potential...
How Figma stays ahead of vulnerabilities with agents
The article outlines Figma's innovative approach to security by leveraging agents to monitor code quality and detect vulnerabilities throughout the software development lifecycle. It emphasizes the...
Blocking Slow-Burn Attacks: Contextual Policies in Omnigent
The article explores the vulnerabilities of AI agents to slow-burn attacks, where attackers exploit the agent's inability to recognize harmful sequences of actions that appear benign in isolation. It...
Why we cannot wait for better post-quantum signature algorithms
The article highlights the imminent threat posed by quantum computers to traditional cryptographic algorithms such as RSA and ECC, which are vulnerable to quantum attacks. It emphasizes the...
The post-quantum EO is an important milestone. Now it’s time to get to work
The article outlines the significance of the U.S. Executive Order 14409, which mandates federal agencies to transition to post-quantum encryption and authentication by specified deadlines. It...
Enhance Security and Trust: New Session Metadata in Sign in with Google
The article introduces new session metadata claims in Sign in with Google, specifically the 'auth_time' and 'amr' claims, designed to enhance security and provide deeper insights into user...
Labyrinth 1.1: Making End-to-End Encrypted Backups Even More Reliable
Labyrinth 1.1 introduces a new sub-protocol aimed at improving the reliability of end-to-end encrypted backups for Messenger, allowing messages to be securely backed up even in cases of device loss...
How Meta Is Strengthening End-to-End Encrypted Backups
Meta's HSM-based Backup Key Vault is designed to enhance the security of end-to-end encrypted backups for WhatsApp and Messenger. The system utilizes hardware security modules (HSMs) to store...
Post-quantum encryption for Cloudflare IPsec is generally available
The article presents the general availability of post-quantum encryption in Cloudflare's IPsec, marking a significant advancement in securing site-to-site networking against future quantum threats....
Take Control: Customer-Managed Keys for Lakebase Postgres
The article discusses Lakebase Customer-Managed Keys (CMK), which empower customers to control their encryption keys using their own cloud Key Management Services (KMS) rather than relying on...
Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways
The article outlines Meta's strategic approach to migrating to post-quantum cryptography (PQC) in response to the impending threats posed by quantum computing to current encryption standards. It...
Dynamic, identity-aware, and secure Sandbox auth
The article explores the implementation of dynamic, identity-aware authentication mechanisms for sandbox environments, emphasizing the use of outbound Workers to enhance security and control over...
Cloudflare targets 2029 for full post-quantum security
Cloudflare has set a target of 2029 to achieve full post-quantum security, emphasizing the importance of transitioning to post-quantum authentication alongside encryption. The article outlines the...
Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver
The article outlines Cloudflare's ongoing commitment to privacy regarding its 1.1.1.1 public DNS resolver, emphasizing the importance of trust in handling personal data. It details the independent...