mmaker Profile Banner
Michele Orrù Profile
Michele Orrù

@mmaker

Followers
1K
Following
655
Media
29
Statuses
261

μ-almost everywhere
Joined November 2009
Don't wanna be here? Send us removal request.
@mmaker
Michele Orrù
26 days
the new dragon book cover is incredible
0
0
0
@mmaker
Michele Orrù
29 days
Presenting my paper on keyed-verification anonymous credentials at @acm_ccs in Taipei in just a few hours! 🗞️ https://t.co/wEVZ9VdSN2 Exciting to present it in the very same venue where I wrote a big chunk of it while attending @rightscon!
0
0
3
@mmaker
Michele Orrù
2 months
Thrilled to have been invited to College de France for a seminar about zero-knowledge and online anonymity! https://t.co/r3i7w3xaPW
1
0
8
@mmaker
Michele Orrù
2 months
[talking about meditation] @alpeh_v “I think shooting a gun is very zen”
2
1
14
@mmaker
Michele Orrù
2 months
A key takeaway: for 20 years, we’ve relied on a notion called indifferentiability to use random oracles over arbitrary-length spaces—but it’s not sufficient for knowledge soundness.
0
0
4
@mmaker
Michele Orrù
2 months
Thrilled to announce that my latest paper with Alessandro Chiesa has been accepted to TCC, the IACR conference on the theory of cryptography!
3
7
62
@mmaker
Michele Orrù
2 months
The road to hell is paved with good intentions
@zkjays
jays | zk/acc
3 months
if every saturday night you can zk-prove 18+ at the door, you’re safer. if you can use maps without leaking your location, you’re safer. if you can prove you can afford the rent without bank pdfs, you’re safer. zk is kult.
0
0
6
@mmaker
Michele Orrù
3 months
I will talk about my paper on anonymous credentials and designated-verifier kzg in october at ACM CCS 2025 in Taipei!
2
6
44
@darrenangle
darren
4 months
*sniff* *pulls shirt* You know, this is perfect - *gestures wildly* - this is the ultimate perversity of capitalism at its purest. Here we have Anthropic, this company claiming to build "AI for humanity," and what do they do? They create this digital cocaine, this Claude Code,
@AnthropicAI
Anthropic
4 months
We’re rolling out new weekly rate limits for Claude Pro and Max in late August. We estimate they’ll apply to less than 5% of subscribers based on current usage.
181
508
4K
@Fatalmeh
matrianarcat
4 months
Very serious vlog about very serious things Biggest protest to date outside the courthouse in support of Roman Storm
8
11
91
@mmaker
Michele Orrù
4 months
Yesterday, @cathieyun gave a great talk at @ietf 123 on the importance of standardizing Sigma protocols and our ongoing work toward a standard for zero-knowledge proofs! You can watch the talk here: https://t.co/S9uhw8fi3V
0
5
20
@mmaker
Michele Orrù
4 months
The paper is huge — it’s been a journey to nail down a proof. I think it’s a solid step forward in narrowing down Fiat-Shamir attacks and characterizing the concrete security of ZKPs. It’s also been really helpful in shaping what a standard for Fiat-Shamir should look like.
1
0
8
@mmaker
Michele Orrù
4 months
We updated our paper on Fiat-Shamir! We now take a closer look at the gap between what symmetric cryptography has focused on for over 10 years (indifferentiability) and what is actually needed for the soundness of ZKPs and SNARKs (something stronger!). https://t.co/uifvzYU0Sf
Tweet card summary image
eprint.iacr.org
We analyze a variant of the Fiat–Shamir transformation based on an ideal permutation. The transformation relies on the popular duplex sponge paradigm, and minimizes the number of calls to the...
4
26
98
@mmaker
Michele Orrù
4 months
As the encrypted conversation shifts from "is it encrypted or not" to more modern techniques requiring refined reasoning, how do we help engineers and policy makers understand intricate security notions?
0
1
5
@mmaker
Michele Orrù
4 months
I've thought a lot of the inherent politics embedded in the APIs we design, and is a perfect example.
1
0
1
@mmaker
Michele Orrù
4 months
Anonymous tokens with hidden metadata are anonymous digital certificates with an "encrypted metadata" field. In our paper, this field is hardcoded to have length 1. If you put n bits, you can partition the anonymity set into 2^n slices.
1
0
1
@mmaker
Michele Orrù
4 months
Excited to see Apple and Google create an Internet Draft for a primitive I co-invented. A bit less excited to see the API reframed to make it possible to void any reasonable privacy guarantee. https://t.co/S1BRPZ3lT4
1
1
13
@mmaker
Michele Orrù
6 months
We prevent this in two places: 1) If you don't include a prover message in the Fiat-Shamir transformation, it won't be incorporated into the (NI) proof string. 2) When declaring the domain separator, you must explicitly specify which messages the interactive protocol transmits.
0
0
7
@mmaker
Michele Orrù
6 months
The bug is fixed in https://t.co/RFaHQOtAAq and boils down to the developer forgetting to include the sumcheck prover messages in the Fiat-Shamir transformation
Tweet card summary image
github.com
…backport of #5883) (#5884) ZK Fix - hash the scalar proof components into the transcript (#5883) * hash the scalar proof components into the transcript to derive `w` * hash the scalar proof com...
1
1
10