<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Marc Ilunga on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/marc-ilunga/</link><description>Recent content in Marc Ilunga on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 30 May 2025 00:00:00 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/marc-ilunga/index.xml" rel="self" type="application/rss+xml"/><item><title>A deep dive into Axiom’s Halo2 circuits</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/05/30/a-deep-dive-into-axioms-halo2-circuits/</link><pubDate>Fri, 30 May 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/05/30/a-deep-dive-into-axioms-halo2-circuits/</guid><description>Over two audits in 2023, we reviewed a blockchain system developed by Axiom that allows computing over the entire history of Ethereum, all verified by zero-knowledge proofs (ZKPs) on-chain using ZK-verified elliptic curve and SNARK recursion operations. This system is built using the Halo2 framework—a complex, emerging technology that presents many challenges when building a secure application, including potential under-constrained issues resulting from its low-level API.</description></item><item><title>Best practices for key derivation</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/01/28/best-practices-for-key-derivation/</link><pubDate>Tue, 28 Jan 2025 09:00:18 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/01/28/best-practices-for-key-derivation/</guid><description>Key derivation is essential in many cryptographic applications, including key exchange, key management, secure communications, and building robust cryptographic primitives. But it’s also easy to get wrong: although standard tools exist for different key derivation needs, our audits often uncover improper uses of these tools that could compromise key security. Flickr’s API […]</description></item><item><title>Cryptographic design review of Ockam</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/03/05/cryptographic-design-review-of-ockam/</link><pubDate>Tue, 05 Mar 2024 09:00:38 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/03/05/cryptographic-design-review-of-ockam/</guid><description>In October 2023, Ockam hired Trail of Bits to review the design of its product, a set of protocols that aims to enable secure communication (i.e., end-to-end encrypted and mutually authenticated channels) across various heterogeneous networks. A secure system starts at the design […]</description></item></channel></rss>