Post-Snowden Cryptography

Brussels, December 9 & 10, 2015

Since June 2013 the world, and in particular the security world, has been shaken by the Snowden revelations. Bullrun is a programme by the NSA which includes as part of the Sigint Enabling Project to "Insert vulnerabilities into commercial encryption systems", to "influence policies, standards and specification for commercial public key technologies" and to "shape the worldwide commercial cryptography marketplace to make it more tractable to advanced cryptanalytic capabilities being developed by NSA/CSS". These are strong threats against cryptography in general and in particular against cryptography developed outside the US.

Most companies and agencies around the world follow the lead of the US-American NIST (National Institute for Standards and Technology) in recommendations for cryptosystems and protocols. These decisions need to be reconsidered in light of the revelations. It is of high urgency to review all current standards (and procedures of how they are made) to weed out weak crypto intentionally (or unintentionally) inserted, such as the Dual EC random number generator. The December 2014 revelations of targeted attacks, including targeted hardware manipulations, open interesting research questions about how to secure a system which contains malicious components and how to detect their use.

This workshop is looking for an analysis of the situation after the Snowden revelations, and solutions for the future of cryptography and security.


The following speakers have accepted:


Videos are posted at


The event will start on December 9 in the afternoon and end late afternoon on December 10. More precisely, registration will open at 14:00 on the 9th, with the first talk starting at 15:00. On the 10th, the first talk starts at 09:30 and we'll have coffee and registration open before then.


14:00 Registration opens
15:00 Joanna Rutkowska, Qubes OS: towards reasonably secure & trustworthy personal computingslides
15:45 Kenny Paterson, Countering Cryptographic Subversionslides
16:30 coffee
17:00 Phil Zimmermann, End-to-End-Secure Communication Under Siege
17:45 Jon A. Solworth, Networking in the Ethos Operating Systemslides
18:30 End of day one
19:30 Dinner at la Manufacture


09:00 Coffee and registration
09:30 Christopher Soghoian, Don't forget about Little Brother
10:15 Claudia Diaz, Website fingerprinting on Tor: attacks and defencesslides
11:00 coffee
11:30 Ian Goldberg, DP5: Privacy-preserving Presence Protocolsslides
12:15 Christian Grothoff, The Architecture of the GNUnet: 45 Subsystems in 45 Minutesslides
13:00 lunch
14:30 Jacob Appelbaum, (Straw) Man in the Middle: A Modest Post-Snowden Proposalslides
15:15 Nathan Freitas, Lessons from Five Years of Building Free, Open-Source, Secure Apps on Androidlinks (text file)
16:00 Formal adjournment followed by coffee and informal discussions


