Skip to content

Memories

Random Memories for Random People

Things I learned and wanted to keep — a black hole with a 94-year orbit, a library that leaked keys, a layer of rock under Bermuda. Short, sourced-by-curiosity, and sorted for you automatically.

Memories
34
Topics
8
Since
Aug 2026
Latest
Aug 16
10 of 34 memories

1 min read

X.509

A crafted X.509 certificate chain with duplicate self-signed certificates can force Python's cryptography library into exponential path exploration. The validator spends …

1 min read

Python's cryptography library prior to 46.0.5 accepted elliptic curve public key

s from small-order subgroups without validation. An attacker supplying such a weak key can leak bits of the victim's private key during ECDH negotiation or forge signatur…

1 min read

Side-channel attacks

extract cryptographic keys by observing how a system behaves rather than by breaking the mathematics of the algorithm itself. Timing variations, power draw fluctuations, …

1 min read

breaches in 2026

Seventy-five percent of breaches in 2026 involved compromised credentials rather than network intrusion, fundamentally shifting the attack paradigm to identity exploitati…

1 min read

cryptographic library vulnerabilities stem from memory safety failures

A 2026 study found that 37.2% of cryptographic library vulnerabilities stem from memory safety failures while only 27.2% arise from actual cryptographic flaws. This means…

  • 37.2 %
  • 27.2 %

1 min read

time-to-exploit for newly disclosed vulnerabilities collapsed

The median time-to-exploit for newly disclosed vulnerabilities collapsed from 63 days in 2018 to just 5 days in 2025. Organizations still take a median of 32 days to patc…

  • 63 days
  • 5 days

1 min read

NIST's post-quantum cryptography

standards were designed to resist quantum computers, but 70% of popular lattice cryptography implementations tested in 2026 leaked secret key material through timing side…

  • 70 %

1 min read

The most consequential open-source security incidents of 2025

did not exploit novel vulnerabilities—they exploited trust. Attackers compromised maintainer accounts and automated build pipelines to propagate malicious updates through…

1 min read

Forty-four percent of all zero-day exploits in 2025

targeted enterprise edge devices—VPNs, firewalls, and remote access appliances. These devices are internet-facing, always-on, and run firmware that often cannot be patche…

1 min read

Stuxnet

The Stuxnet worm recorded normal centrifuge sensor readings for thirty days before beginning its destructive sequence. It then replayed those recordings back to SCADA mon…