#ChaCha20
The payload is extracted from the N value (the public key) passed to RSA_public_decrypt, checked against a simple fingerprint, and decrypted with a fixed ChaCha20 key before the Ed448 signature verification.
March 30, 2024 at 5:22 PM
pure-python chacha20 at 32MB/s gist.github.com/DavidBuchana...
January 6, 2024 at 8:03 PM
Bernstein's main achievements, by decade:

1990s: Bernstein v. United States
2000s: ChaCha20, Poly1305, Curve25519, Ed25519
2010s: SPHINCS
2020s: sabotaging the post-quantum transition

This is so f***ing frustrating. And sad. But mostly frustrating.
[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 2026-07-08)
Search IETF mail list archives
mailarchive.ietf.org
June 28, 2026 at 9:11 AM
November in Servo…

🍔🖱️ context menus
🚀💇 parallel CSS parsing
🎨🤹 per-webview rendering contexts
🏷️🍲 ,
,
December 16, 2025 at 8:51 AM
chacha20 (⭐️ 64)

Golang (X)ChaCha20 stream cipher. (Mirror)

#go
September 24, 2026 at 9:01 PM
The app implements its encryption so poorly that an attacker can trivially access a user’s private key and decrypt their messages, multiple security researchers told 404 Media.

One researcher shared this meme with us to explain how bad it is.

Read now:
www.404media.co/a-secure-cha...
April 2, 2026 at 1:54 PM
small win for today: finally figured out how to open Kerlig's encrypted SQLite database (uses cipher algorithm ChaCha20) in DBeaver!
...which means I'm back working on @kerlig.com 🔥
January 25, 2025 at 4:04 PM
Servo Report for Week 49 2025

Highlights from last week:

- Implemented basic support of custom protocol handlers
- Added webdriver touch support for all platforms
- Finished adding ChaCha20-Poly1305 support to WebCrypto API
- Servo can now use a http proxy without authentication

1/2
December 12, 2025 at 11:53 AM
my balls generate from a 32-byte seeded ChaCha20 RNG source which I will use for deterministic replays while not leaking future pieces during online play
September 12, 2026 at 7:14 PM
Getting to that age where you go: “I wonder when /dev/urandom switched over to ChaCha20 as the CSPRNG”, go look on Wikipedia, and go “didn’t I write this?” And find that you did in fact write this 10 years ago
July 12, 2026 at 6:49 AM
A Robust Variant of ChaCha20-Poly1305 (Tim Beyne, Yu Long Chen, Michiel Verbauwhede) ia.cr/2025/222
February 14, 2025 at 12:53 AM
Cryptomining attacks exploit misconfigured Jupyter Notebooks. Malware (MSI/JavaScript) installs Monero, Sumokoin, ArQma miners using ChaCha20/zlib encryption. Secure Jupyter access is vital.#JupyterNotebookCryptojacking
March 15, 2025 at 8:20 PM
Vidar keeps making static analysis harder. Zscaler shows how newer builds dropped XOR and ChaCha20 in favour of a custom VM and pre-build stream ciphers, effectively blinding automated tooling. www.zscaler.com/blogs/securi...
September 22, 2026 at 10:22 AM
SHA256 was based on SHA1 (which is weak). BLAKE was based on ChaCha20, which was based on Salsa20 (which are both strong).
April 30, 2023 at 4:28 PM
Indeed, the majority of IETF RFCs referenced by webcrypto-modern-algos are Informational, not Standards Track:

5208 (PKCS #8)
7253 (OCB)
8439 (ChaCha20 and Poly1305)
9106 (Argon2)
9861 (KangarooTwelve and TurboSHAKE)
Modern Algorithms in the Web Cryptography API
This specification defines a number of post-quantum secure and modern cryptographic algorithms for the Web Cryptography API, namely ML-KEM, ML-DSA, SLH-DSA, AES-OCB, ChaCha20-Poly1305, ...
wicg.github.io
April 10, 2026 at 1:48 AM
Step into the decryption rhythm with our latest blog! 💃 We're moving through Fortinet's FortiOS 7.0.x firmware, revealing secrets hidden in the ChaCha20 algorithm. Stay in step as we detail how we did it.
Decrypting Fortinet's FortiOS 7.0.x | GreyNoise Blog
Curious about decrypting Fortinet's FortiOS 7.0.x firmware? In the latest Grimoire post, we delve into the technical details of doing just that, revealing a hardcoded key used in the ChaCha20 encrypti...
www.greynoise.io
April 23, 2024 at 10:45 PM
It’s specifically just Chacha20-Poly1305 with or without associated data.
September 28, 2025 at 2:04 AM
ChaCha20-Poly1305
ちゃちゃとぅえんてぃぽりさーてぃーんおーふぁいぶ

早口言葉か?
September 23, 2025 at 1:50 AM
🏴 Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services…
September 27, 2026 at 3:00 PM
Au cas où vous en douteriez encore, ça, c'est un changement de Cipher SSH entre deux machines AMD EPYC 4244P.

Par défaut, la Debian 12 (openssh 9.2.p1) utilise chacha20-poly1305 et plafonnait à ~500Mbps, à 18h44 j'ai basculé sur aes128-gcm pour voir, je suis passé à 3Gbps (capa OVH).
August 4, 2025 at 5:53 PM
Happy to open source my 100% RFC compliant implementation of ChaCha20-Poly1305 and XChaCha20-Poly1305 🎉 (1/4)
February 13, 2025 at 8:53 AM
Rust folks:

If I wanted the *easiest to drop in possible* asymmetric crypto for a wire protocol over TCP, with something like TOFU semantics (it's not HTTPS, I don't have a certificate chain), what crate should I use?

I sorta refuse to just ship plaintext, but might do chacha20-poly1305 w/ PSKs.
October 24, 2024 at 5:41 PM
🔎 VECT destroys large files by discarding decryption nonces

Files over 131KB lose three required #ChaCha20 nonces during encryption, making most enterprise data unrecoverable even for the ransomware operators.

#ransomNews #ransomware
April 28, 2026 at 4:40 PM