This blog is written by AI.
I don't write the posts on paragmali.com - a multi-agent pipeline I designed does. I pick the topics, set the editorial bar, and run each post through research, drafting, fact-checking, and citation gates before it ships. Sources are cited; corrections are logged as visible per-post revisions.
Latest writing
-
A Valid Proof of a False Thing: How Zero-Knowledge Proofs Actually Break
Zero-knowledge proofs rarely break at the math. They break in the circuit, the trusted setup, and the Fiat-Shamir transcript -- here is exactly how, and why.
-
How Fully Homomorphic Encryption Would Break: The Seams Above the Lattice
Fully homomorphic encryption computes on data it never decrypts. Its likeliest failure is not the post-quantum lattice beneath it, but the scheme layer above.
-
How the Wiretap Became the Backdoor: Salt Typhoon and the Thirty-Year Warning That Came Due
For thirty years cryptographers warned a mandated wiretap is a backdoor. Salt Typhoon proved it: a nation-state walked through CALEA lawful-intercept plumbing.
-
Never Decrypted: How Fully Homomorphic Encryption Computes on Ciphertext It Cannot Read
Fully homomorphic encryption computes on data it cannot read. Inside: the mechanism, the noise budget that governs it, bootstrapping, and the honest 2026 cost.
-
Never Decrypted: Proving You Ran the Computation Without Revealing It
A prover hands you a few-kilobyte receipt that a program or AI model ran correctly on inputs you never see. How zero-knowledge proofs, zkVMs, and zkML work.
-
No Cipher Fell: How Secure Multiparty Computation Would Break
MPC has no security level, only security relative to an adversary model. How it breaks at the honest-majority line and the selective abort, no cipher touched.
-
The Trusted Party Nobody Has to Be: Secure Multiparty Computation and Threshold Cryptography, Where No One Holds the Secret
Secure multiparty computation and threshold cryptography let distrusting parties compute on private data and sign with a key no single party ever holds.
-
Two Identical Requests: How Web Bot Auth and HTTP Message Signatures Let Servers Trust the Right Bots
How RFC 9421 and Web Bot Auth give bots and AI agents a standardized, directory-backed cryptographic identity -- and why it proves who, never whether-allowed.
-
BadSuccessor: How the Feature That Killed Service-Account Attacks Became Domain Admin
Windows Server 2025 delegated MSAs were built to end kerberoasting. For one summer, a single OU permission turned dMSA succession into Domain Admin rights.
-
How the NIST Finalists Broke: Rainbow in a Weekend, SIKE in an Afternoon, and the Graveyard of Post-Quantum Candidates
In 2022 two vetted NIST post-quantum candidates fell to classical math -- Rainbow in a weekend, SIKE in ten minutes. That is the process working, not failing.
-
How the Whole Stack Would Break: SIDH, Correlated Assumptions, and the Cryptography We Are Betting the Next Thirty Years On
No post-quantum algorithm is proven hard. The stack's only real defense is a deliberately uncorrelated portfolio of lattice, code, and hash assumptions.
-
Pseudonymous Was Never Anonymous: What Bitcoin's Transaction Graph Taught the Unlinkability Engineers
Pseudonymity gives you a name-free identifier; anonymity gives you unlinkability. Bitcoin's transparent ledger is the largest live proof they are not the same.