Raphael Robert
@raphaelrobert.bsky.social
📤 263
📥 101
📝 54
Privacy. Security. Research. MLS co-author, working in secure messaging at
@phoenixrd.bsky.social
.
reposted by
Raphael Robert
Phoenix R&D
about 1 month ago
We made MLS more decentralized! We are excited to share DMLS that brings fork resilience to the MLS protocol, solving a key challenge in distributed systems while maintaining Forward Secrecy. This work was made possible by
@equalitie.bsky.social
, who funded it as part of the Breakout program.
loading . . .
Making MLS more decentralized
It’s no secret that we at Phoenix R&D are big fans of the Messaging Layer Security (MLS) protocol, having helped it to come into existence. It’s a versatile group key agreement and messaging protocol ...
https://blog.phnx.im/making-mls-more-decentralized/
2
12
8
reposted by
Raphael Robert
netzpolitik.org
about 2 months ago
Die Stimmen gegen die
#Chatkontrolle
werden mehr und lauter. Nun hagelt es deutliche Kritik aus der Wirtschaft. Zudem warnen der Deutsche Journalistenverband und der Anwaltverein vor einer Überwachungsinfrastruktur, die schnell ausgebaut werden könnte.
netzpolitik.org/2025/eu-uebe...
loading . . .
EU-Überwachungspläne in der Kritik: Wirtschaftsverbände Bitkom und eco klar gegen Chatkontrolle
Die Stimmen gegen die Chatkontrolle werden mehr und lauter. Nun hagelt es deutliche Kritik aus der Wirtschaft. Zudem warnen der Deutsche Journalistenverband und der Anwaltverein vor einer Überwachungs...
https://netzpolitik.org/2025/eu-ueberwachungsplaene-in-der-kritik-wirtschaftsverbaende-bitkom-und-eco-klar-gegen-chatkontrolle/
5
304
164
reposted by
Raphael Robert
Phoenix R&D
about 2 months ago
🚨 Der Gesetzentwurf zur
#Chatkontrolle
sieht vor, dass digitale Kommunikation einschließlich verschlüsselter Nachrichten und Fotos gescannt werden soll. Wir haben uns an die deutsche Bundesregierung gewandt, sich am 14. Oktober gegen den Gesetzesvorschlag der Chatkontrolle auszusprechen.
loading . . .
Unser Brandbrief zur geplanten Chatkontrolle – eine Gefährdung der digitalen Sicherheit Deutschlands | Phoenix R&D
🚨Der Gesetzentwurf zur #Chatkontrolle sieht vor, dass digitale Kommunikation einschließlich verschlüsselter Nachrichten und Fotos gescannt werden soll. Die Sicherheit von sicheren Messenger-Diensten ...
https://www.linkedin.com/feed/update/urn:li:activity:7381044914920370198/
0
4
3
LinkedIn annonced that it will use your data to train AI models, and craftily chose to use an opt-out mechanism. Deactivate this in your settings now, of you don’t want to give away your content.
2 months ago
0
1
0
As an ex head of security of an end-to-end encrypting messenger I can relate
www.theguardian.com/technology/2...
loading . . .
Ex-WhatsApp cybersecurity head says Meta endangered billions of users in new suit
Attaullah Baig, fired this year, said he had warned Mark Zuckerberg engineers had unaudited access to user data
https://www.theguardian.com/technology/2025/sep/08/meta-user-data-lawsuit-whatsapp
3 months ago
0
4
0
reposted by
Raphael Robert
Richard Barnes
3 months ago
There's an article making the rounds with the provocative title "MLS: The Naked King of End-to-End Encryption". It needs some rebuttal.
www.poberezkin.com/posts/2025-0...
tl;dr - MLS is fine. This is a misunderstanding about modularity.
loading . . .
MLS: The Naked King of End-to-End Encryption
Evgeny Poberezkin's blog
https://www.poberezkin.com/posts/2025-08-12-mls-the-naked-king-of-end-to-end-encryption.html
1
14
6
Not long ago, someone (who is likely the founder of SimpleX Chat) wrote a blog post about MLS that contained a pretty blatant factual mistake about MLS' authentication, including an alleged lack of security. Thankfully,
@soatok.bsky.social
took the time to debunk that:
soatok.blog/2025/08/25/b...
loading . . .
Barking Up The Ratchet Tree – MLS Is Neither Royal Nor Nude - Dhole Moments
One of the first rules you learn about technical writing is, “Know your audience.” But often, this sort of advice is given without sufficient weight or practical examples. Instead, you&…
https://soatok.blog/2025/08/25/barking-up-the-ratchet-tree-mls-is-neither-royal-nor-nude/
3 months ago
0
9
2
I had to see for myself
4 months ago
1
1
0
reposted by
Raphael Robert
Phoenix R&D
5 months ago
We did a thing. We combined TLS and MLS into a hybrid protocol. Why? Because sometimes you need connections that last for weeks, quantum-resistant security, or simpler certificates. The experiment is open-source. Here's the story 👇
loading . . .
Combining TLS and MLS: An experiment
We did a thing. We combined TLS and MLS into a hybrid protocol. Of course, when things get serious, full names are in order: We combined the Transport Layer Security protocol and the Messaging Layer S...
https://blog.phnx.im/combining-tls-and-mls-experiment/
0
3
5
We really did do a thing.
add a skeleton here at some point
5 months ago
0
2
0
reposted by
Raphael Robert
Phoenix R&D
7 months ago
We are
#hiring
a Freelance Junior Product Manager to help us build the next generation of private & secure messaging. If you’re interested in joining our team, please apply today! For friends of secure messaging 🥷, please share our post with potential candidates.
loading . . .
Phoenix R&D (Remote): Freelance Junior Product Manager (all genders, part-time)
Phoenix R&D GmbH has a remote job opening for Freelance Junior Product Manager (all genders, part-time) (published: 15.05.2025). Apply now or check the other available jobs.
https://join.com/companies/phoenix/14160490?utm_medium=social_sharing&utm_source=copy_link
0
5
5
Happy to announce that I’ll be speaking at
@passthesaltcon.bsky.social
on July 2nd! I’ll discuss end-to-end encryption with MLS, the growing MLS ecosystem, the MIMI IETF working group, and metadata protection. It’s my first time attending, and I look forward to connecting with the French community!
7 months ago
0
2
2
reposted by
Raphael Robert
Matthew Green
7 months ago
The idea that you can just “teach computer science” and be apolitical is a beautiful dream that expired in the 2000s, at the latest. Computer science has re-organized every facet of our society: it is inherently political. Instead of taking this idea seriously, we ran from it. Now we live in hell.
5
239
68
Hey Google designers, are we sure about this new layout logo in Google Meet? The negative space around the boxes reminds me of something.
7 months ago
0
0
0
The MLS Architecture document – the companion document to the MLS Protocol document – is now finally available as RFC 9750:
www.rfc-editor.org/info/rfc9750
loading . . .
Information on RFC 9750 » RFC Editor
https://www.rfc-editor.org/info/rfc9750
7 months ago
0
7
2
And so it begins, BlueSky complies with censorship requests of an authoritarian regime
8 months ago
0
2
1
www.privacyguides.org/articles/202...
loading . . .
The Dangers of End-to-End Encryption
Privacy Guides is formally taking a stand against dangerous and frightening technologies.
https://www.privacyguides.org/articles/2025/04/01/the-dangers-of-end-to-end-encryption/
8 months ago
1
2
0
MLS is efficient, but what does that mean in practice? This paper sheds some light on the question by building a test framework for OpenMLS.
arxiv.org/pdf/2502.18303
loading . . .
https://arxiv.org/pdf/2502.18303
9 months ago
1
5
4
… and now it looks like Apple caved, while Google didn’t:
www.forbes.com/sites/zakdof...
add a skeleton here at some point
9 months ago
0
0
0
The SCW podcast team does it again and breaks down a newish, complex and alarming topic into palatable and informative pieces. Excellent questions from
@durumcrustulum.com
and
@dadrian.io
expertly answered by
@josephhall.org
and
@matthewdgreen.bsky.social
. Listen to it if you have time!
add a skeleton here at some point
9 months ago
0
10
6
I’m deeply disappointed in Apple.
www.bbc.com/news/article...
loading . . .
Apple pulls data protection tool after UK government security row
Customers' photos and documents stored online will no longer be protected by end to end encryption.
https://www.bbc.com/news/articles/cgj54eq4vejo
9 months ago
1
1
2
We proudly signed this too. Always push back.
add a skeleton here at some point
10 months ago
0
5
1
I love that
@kagi.com
now uses Privacy Pass. It would have been nice to get some credit since your "own implementation" looks like a wrapper around my implementation.
blog.kagi.com/kagi-privacy...
loading . . .
Introducing Privacy Pass authentication for Kagi Search | Kagi Blog
Today we are announcing a new privacy feature coming to Kagi Search.
https://blog.kagi.com/kagi-privacy-pass
10 months ago
2
9
1
Another example of how legal interception of private communication cannot be limited to the “good guys”:
www.cisa.gov/news-events/...
loading . . .
Joint Statement from FBI and CISA on the People's Republic of China (PRC) Targeting of Commercial Telecommunications Infrastructure | CISA
https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications
about 1 year ago
0
4
3
Hey new followers! I hope this will become what Twitter once was – it's already starting to feel that way. Looking forward to better conversations! PS: Mastodon is still as valid as it was before.
about 1 year ago
0
2
0
reposted by
Raphael Robert
Phoenix R&D
about 1 year ago
This weekend,
@raphaelrobert.bsky.social
and
@julianmair.com
are joining the
#GlobalGathering
. We will be hosting a booth and circle on Saturday to discuss the current state of privacy preserving and decentralized messengers. We look forward to seeing you at there! Feel free to ping us!
0
3
3
🔐 Discord introduces end-to-end encryption with Messaging Layer Security (MLS) 🔐 Im really happy to see another large scale MLS deployment. It shows the technology is fit for purpose, demonstrably so.
discord.com/blog/meet-da...
loading . . .
Meet DAVE: Discord’s New End-to-End Encryption for Audio & Video
We’re rolling out end-to-end encryption for voice and video calls! We’d like to share why we’re bringing E2EE A/V to Discord, share our design and implementation goals, and provide a high-level techni...
https://discord.com/blog/meet-dave-e2ee-for-audio-video
about 1 year ago
0
11
4
We are hiring two Rust engineers!
add a skeleton here at some point
about 1 year ago
0
1
1
I like the idea that “covfefe” was a premonitory acronym for “convicted felon”
over 1 year ago
0
3
1
reposted by
Raphael Robert
Phoenix R&D
over 1 year ago
We attended the Real World Crypto Symposium in Toronto 🇨🇦 where
@raphaelrobert.bsky.social
talked about how far MLS has come since RWC 2019. Highlights: - Post-quantum resistance and how easy it is to upgrade from current schemes - Deployment in existing products like Webex and Discord (🧵1/2)
1
4
3
Signal usernames are out, grab yours now!
almost 2 years ago
0
0
0
reposted by
Raphael Robert
Phoenix R&D
almost 2 years ago
WhatsApp shared first details on how they will comply with the
#DMA
. We are critical of the Signal protocol, as there has never been a complete specification that allows secure implementation of the protocol. This was one of the main reasons to develop MLS. Our conversation with
@netzpolitik.org
👇
loading . . .
Interoperabilität: WhatsApp soll bald mit anderen Messengern reden können – netzpolitik.org
Wegen neuer Regeln in der EU muss WhatsApp sich so öffnen, dass die Nutzer:innen auch mit Kontakten auf anderen Messengern kommunizieren können. Nun hat WhatsApp erste Details verraten, wie das gehen soll. Doch grundsätzliche Probleme bleiben.
https://netzpolitik.org/2024/interoperabilitaet-whatsapp-soll-bald-mit-anderen-messengern-reden-koennen/
0
4
3
reposted by
Raphael Robert
Phoenix R&D
almost 2 years ago
We ended 2023 with a talk at #37C3.
@raphaelrobert.bsky.social
and Konrad presented Messaging Layer Security (MLS). The room was packed and some people couldn't attend – luckily the talk is now online. 🍿
media.ccc.de/v/37c3-12064...
#securemessaging
#encryption
#e2ee
#messaginglayersecurity
0
7
3
Today at #37c3, 3:45pm, Konrad and I will give a talk in hall Zuse about Messaging Layer Security (MLS). They call it RFC 9420, we say MLS: A new IETF standard for end-to-end encryption, bringing improvements in performance and security. 👉
fahrplan.events.ccc.de/congress/202...
loading . . .
Lecture: RFC 9420 or how to scale end-to-end encryption with Messaging Layer Security | Friday | Sch...
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/12064.html
almost 2 years ago
0
5
4
reposted by
Raphael Robert
Phoenix R&D
almost 2 years ago
We are very excited to be at #37c3 in Hamburg after a long pandemic break. On day 3 (29.12., 3:45pm),
@raphaelrobert.bsky.social
and Konrad will give a talk on “RFC 9420 – or how to scale end-to-end encryption with Messaging Layer Security (MLS)” 👉
fahrplan.events.ccc.de/congress/202...
1
4
2
reposted by
Raphael Robert
Phoenix R&D
almost 2 years ago
Check out our blog post where we examine the push notification problem and address potential misconceptions! In the wake of recent reports on surveillance via push notifications, many people have been confused about it and how it affects their own privacy when using messengers anonymously.
loading . . .
On the privacy of push notifications
Push notifications are a mechanism through which applications can send and display notifications to users of smartphones. The infrastructure that drives these notifications in the background is a comp...
https://blog.phnx.im/privacy-of-push-notifications/
0
2
3
Let’s get down to why exactly push notifications have a privacy issue 👇
blog.phnx.im/privacy-of-push-notifications/
loading . . .
On the privacy of push notifications
Push notifications are a mechanism through which applications can send and display notifications to users of smartphones. The infrastructure that drives these notifications in the background is a comp...
https://blog.phnx.im/privacy-of-push-notifications/
almost 2 years ago
0
4
4
First impactful measure following last week's splash about push notification surveillance:
www.reuters.com/technology/a...
add a skeleton here at some point
almost 2 years ago
0
2
2
Let's make this crystal clear: If you think you are anonymous because you - used a throwaway number for Signal - picked a completely random username for Wire/Matrix - were given a random username with Threema/Session YOU ARE NOT! You can be identified by the push tokens.
add a skeleton here at some point
almost 2 years ago
2
7
7
This has been bothering me for a while and I'm glad there's finally more discussion about this. Push notifications are a problem for privacy, we need more transparency and changes in the way they work.
netzpolitik.org/2023/push-di...
loading . . .
Push-Dienste: Behörden fragen Apple und Google nach Nutzern von Messenger-Apps – netzpolitik.org
Smartphone-Apps verschicken Benachrichtigungen über Apple und Google, auch vermeintlich sichere Messenger. Damit können Behörden Nutzer-Daten bei Smartphone-Firmen abfragen. Bis jetzt verweigern al...
https://netzpolitik.org/2023/push-dienste-behoerden-fragen-apple-und-google-nach-nutzern-von-messenger-apps/
almost 2 years ago
0
2
2
Just as
#chatcontrol
seems to take a slightly better turn, another crude proposal awaits us.
add a skeleton here at some point
about 2 years ago
0
1
2
New internet standard for RSA blind signatures. This is the foundation for privacy pass and other privacy preserving protocols.
www.rfc-editor.org/info/rfc9474
about 2 years ago
0
0
0
Is there a tool yet to correlate Bluesky accounts with Twitter accounts? This was quite useful for mastodon
over 2 years ago
0
0
0
MLS is now finished! 5 years of intense exchange with industry and academia, what a great group effort. Congratulations and thanks to all those who contributed! We wrote an overview about it here:
https://blog.phnx.im/rfc-9420-mls/
over 2 years ago
0
1
1
Me: ~casually strolling through Berlin~ My Apple Watch: Is it a workout? Is it a workout? Are we there yet?
over 2 years ago
0
0
0
gnuplot still beats everything else. Period.
over 2 years ago
0
1
0
Live tracker for Turkish election results:
https://secim.aa.com.tr
over 2 years ago
0
2
0
over 2 years ago
0
0
0
GitHub is down 😬
over 2 years ago
1
2
0
reposted by
Raphael Robert
Joseph Lorenzo Hall, PhD
over 2 years ago
"Encryption Keeps Kids Safe Online" by Sebastián Schonfeld and Natalie Campbell at the Internet Society
https://www.internetsociety.org/blog/2023/05/encryption-keeps-kids-safe-online/
1
4
5
Load more
feeds!
log in