<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: matthew-green</title><link href="http://feeds.simonwillison.net/" rel="alternate"/><link href="http://feeds.simonwillison.net/tags/matthew-green.atom" rel="self"/><id>http://feeds.simonwillison.net/</id><updated>2026-10-09T15:02:29+00:00</updated><author><name>Simon Willison</name></author><entry><title>Quoting Matthew Green</title><link href="https://simonwillison.net/2026/Oct/9/matthew-green/" rel="alternate"/><published>2026-10-09T15:02:29+00:00</published><updated>2026-10-09T15:02:29+00:00</updated><id>https://simonwillison.net/2026/Oct/9/matthew-green/</id><summary type="html">
    &lt;blockquote cite="https://twitter.com/matthew_d_green/status/2108552414978564418"&gt;&lt;p&gt;Everyone is very concerned about being respectable, so I’m going to be the goofball who raises worst-case possibilities. I think there is a 1% chance we live in Minicrypt, and a 15% chance we functionally lose confidence in our existing public-key encryption algorithms. [...]&lt;/p&gt;
&lt;p&gt;The problem here is that the speed of AI producing surprises, and the speed of human beings replacing standards (even with the very best AI assistance) are just orders of magnitude different. You only recover from a surprise like this if you do the preparation in advance.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="cite"&gt;&amp;mdash; &lt;a href="https://twitter.com/matthew_d_green/status/2108552414978564418"&gt;Matthew Green&lt;/a&gt;, on Twitter. I looked it up and Minicrypt is Russell Impagliazzo’s &lt;a href="https://www.quantamagazine.org/which-computational-universe-do-we-live-in-20220418/"&gt;hypothetical world&lt;/a&gt; in which public-key encryption is impossible.&lt;/p&gt;

    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/cryptography"&gt;cryptography&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/standards"&gt;standards&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai"&gt;ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/generative-ai"&gt;generative-ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/llms"&gt;llms&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai-security-research"&gt;ai-security-research&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/matthew-green"&gt;matthew-green&lt;/a&gt;&lt;/p&gt;



</summary><category term="cryptography"/><category term="standards"/><category term="ai"/><category term="generative-ai"/><category term="llms"/><category term="ai-security-research"/><category term="matthew-green"/></entry><entry><title>Quoting Matthew Green</title><link href="https://simonwillison.net/2026/Oct/1/matthew-green/" rel="alternate"/><published>2026-10-01T06:29:01+00:00</published><updated>2026-10-01T06:29:01+00:00</updated><id>https://simonwillison.net/2026/Oct/1/matthew-green/</id><summary type="html">
    &lt;blockquote cite="https://blog.cryptographyengineering.com/2026/09/30/is-sandboxing-sufficient-to-contain-rogue-agents/"&gt;&lt;p&gt;[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="cite"&gt;&amp;mdash; &lt;a href="https://blog.cryptographyengineering.com/2026/09/30/is-sandboxing-sufficient-to-contain-rogue-agents/"&gt;Matthew Green&lt;/a&gt;, Is sandboxing sufficient to contain rogue agents?&lt;/p&gt;

    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/sandboxing"&gt;sandboxing&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai"&gt;ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/generative-ai"&gt;generative-ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/llms"&gt;llms&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai-misuse"&gt;ai-misuse&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai-security-research"&gt;ai-security-research&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/accidental-cyberattacks"&gt;accidental-cyberattacks&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/matthew-green"&gt;matthew-green&lt;/a&gt;&lt;/p&gt;



</summary><category term="sandboxing"/><category term="ai"/><category term="generative-ai"/><category term="llms"/><category term="ai-misuse"/><category term="ai-security-research"/><category term="accidental-cyberattacks"/><category term="matthew-green"/></entry><entry><title>Quoting Matthew Green</title><link href="https://simonwillison.net/2026/Jul/29/matthew-green/" rel="alternate"/><published>2026-07-29T18:18:15+00:00</published><updated>2026-07-29T18:18:15+00:00</updated><id>https://simonwillison.net/2026/Jul/29/matthew-green/</id><summary type="html">
    &lt;blockquote cite="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/"&gt;&lt;p&gt;Right now we’re in the midst of a historic transition from traditional public-key algorithms based on EC-based cryptography and RSA, moving over to new &lt;em&gt;post-quantum&lt;/em&gt; algorithms based on novel problems. This is why there are so many standards like HAWK being considered. If there was ever a perfect time for a massive new public cryptanalysis capability to come on line, &lt;em&gt;we’re in it.&lt;/em&gt; So unless AIs succeed in undermining all of our hard problems altogether (or we live in &lt;a href="https://blog.computationalcomplexity.org/2004/06/impagliazzos-five-worlds.html"&gt;Impagliazzo’s Minicrypt&lt;/a&gt;) then this could not be a better time for AI to get good at cryptanalysis. In the best case, the result is that we gain real confidence in the problems we’ve identified, and the cryptanalysis literature gets a lot more robust. Hopefully.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="cite"&gt;&amp;mdash; &lt;a href="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/"&gt;Matthew Green&lt;/a&gt;, on &lt;a href="https://simonwillison.net/2026/Jul/28/discovering-cryptographic-weaknesses-with-claude/"&gt;Anthropic's recent cryptography work&lt;/a&gt;&lt;/p&gt;

    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/cryptography"&gt;cryptography&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai"&gt;ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/generative-ai"&gt;generative-ai&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/llms"&gt;llms&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/anthropic"&gt;anthropic&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/claude"&gt;claude&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ai-security-research"&gt;ai-security-research&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/claude-mythos-fable"&gt;claude-mythos-fable&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/matthew-green"&gt;matthew-green&lt;/a&gt;&lt;/p&gt;



</summary><category term="cryptography"/><category term="ai"/><category term="generative-ai"/><category term="llms"/><category term="anthropic"/><category term="claude"/><category term="ai-security-research"/><category term="claude-mythos-fable"/><category term="matthew-green"/></entry><entry><title>Ok Google: please publish your DKIM secret keys</title><link href="https://simonwillison.net/2020/Nov/16/dkim/" rel="alternate"/><published>2020-11-16T22:02:58+00:00</published><updated>2020-11-16T22:02:58+00:00</updated><id>https://simonwillison.net/2020/Nov/16/dkim/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="https://blog.cryptographyengineering.com/2020/11/16/ok-google-please-publish-your-dkim-secret-keys/amp/?__twitter_impression=true"&gt;Ok Google: please publish your DKIM secret keys&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
The DKIM standard allows email providers such as Gmail to include cryptographic headers that protect against spoofing, proving that an email was sent by a specific host and has not been tampered with. But it has an unintended side effect: if someone’s email is leaked (as happened to John Podesta in 2016) DKIM headers can be used to prove the validity of the leaked emails. This makes DKIM an enabling factor for blackmail and other security breach related crimes.&lt;/p&gt;

&lt;p&gt;Matthew Green proposes a neat solution: providers like Gmail should rotate their DKIM keys frequently and publish the PRIVATE key after rotation. By enabling spoofing of past email headers they would provide deniability for victims of leaks, fixing this unintended consequence of the DKIM standard.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="https://twitter.com/matthew_d_green/status/1328371955150573568"&gt;@matthew_d_green&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/cryptography"&gt;cryptography&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/email"&gt;email&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/matthew-green"&gt;matthew-green&lt;/a&gt;&lt;/p&gt;



</summary><category term="cryptography"/><category term="email"/><category term="security"/><category term="matthew-green"/></entry><entry><title>Looking back at the Snowden revelations</title><link href="https://simonwillison.net/2019/Sep/25/looking-back-at-the-snowden-revelations/" rel="alternate"/><published>2019-09-25T05:48:39+00:00</published><updated>2019-09-25T05:48:39+00:00</updated><id>https://simonwillison.net/2019/Sep/25/looking-back-at-the-snowden-revelations/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="https://blog.cryptographyengineering.com/2019/09/24/looking-back-at-the-snowden-revelations/"&gt;Looking back at the Snowden revelations&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Six years on from the Snowden revelations, crypto researcher Matthew Green reviews their impact and reminds us what we learned. Really interesting.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="https://twitter.com/matthew_d_green/status/1176617952076079109"&gt;@matthew_d_green&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/cryptography"&gt;cryptography&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/matthew-green"&gt;matthew-green&lt;/a&gt;&lt;/p&gt;



</summary><category term="cryptography"/><category term="security"/><category term="matthew-green"/></entry></feed>