This blog is written by AI.
I don't write the posts on paragmali.com - a multi-agent pipeline I designed does. I pick the topics, set the editorial bar, and run each post through research, drafting, fact-checking, and citation gates before it ships. Sources are cited; corrections are logged as visible per-post revisions.
Latest writing
-
Two Identical Requests: How Web Bot Auth and HTTP Message Signatures Let Servers Trust the Right Bots
How RFC 9421 and Web Bot Auth give bots and AI agents a standardized, directory-backed cryptographic identity -- and why it proves who, never whether-allowed.
-
BadSuccessor: How the Feature That Killed Service-Account Attacks Became Domain Admin
Windows Server 2025 delegated MSAs were built to end kerberoasting. For one summer, a single OU permission turned dMSA succession into Domain Admin rights.
-
How the NIST Finalists Broke: Rainbow in a Weekend, SIKE in an Afternoon, and the Graveyard of Post-Quantum Candidates
In 2022 two vetted NIST post-quantum candidates fell to classical math -- Rainbow in a weekend, SIKE in ten minutes. That is the process working, not failing.
-
How the Whole Stack Would Break: SIDH, Correlated Assumptions, and the Cryptography We Are Betting the Next Thirty Years On
No post-quantum algorithm is proven hard. The stack's only real defense is a deliberately uncorrelated portfolio of lattice, code, and hash assumptions.
-
Pseudonymous Was Never Anonymous: What Bitcoin's Transaction Graph Taught the Unlinkability Engineers
Pseudonymity gives you a name-free identifier; anonymity gives you unlinkability. Bitcoin's transparent ledger is the largest live proof they are not the same.
-
The Anonymity That Actually Holds: What Zcash and Monero Prove, and How Each Proof Breaks
A mechanism-level teardown of on-chain anonymity: how Zcash's zk-SNARK proof and Monero's ring-signature ambiguity work, and the exact break inside each.
-
How Elliptic Curves and Diffie-Hellman Break in Real Life: The Discrete Log Never Fell
No one has solved the discrete log on a strong curve or a 2048-bit group -- yet PS3, Android wallets, TPMs, CurveBall, and Logjam all fell. Here is exactly how.
-
How Falcon Would Break: NTRU Lattices and the Structure Nobody Fully Trusts
Falcon is NIST's smallest post-quantum signature and its only lattice one still in draft. A structural case for why its likeliest break is NTRU-specific.
-
How ML-KEM Breaks in Real Life: The Machine Leaked While the Math Held
ML-KEM shipped with a machine-checked security proof, yet its reference code leaked secret keys through a division instruction. Why every break missed the math.
-
How Q-Day Breaks Everything: Shor's Algorithm and the Simultaneous Fall of RSA, Diffie-Hellman, and ECC
RSA, Diffie-Hellman, DSA, and elliptic curves share one abelian period. A single quantum computer running Shor's algorithm reads it and breaks all four at once.
-
How SLH-DSA Would Break: The Signature That Can Only Fall If a Hash Falls First
SLH-DSA has almost no attack surface of its own. A structural tour of FORS, WOTS+ hypertrees and tweakable hashes, and why it fails only if SHA-2 or SHAKE does.
-
Q-Day Has Not Happened. The Incident Already Has: Harvest Now, Decrypt Later
No quantum computer can break RSA in 2026, yet long-lived secrets encrypted today may already be lost. Harvest now, decrypt later is a deployment failure.