Dan Wallach
dwallach@discuss.systems
<p>AI Security Resident, RAND Center for AI, Security, and Technology (CAST); Professor Emeritus, Rice University, Department of Computer Science</p>
Posts
-
View post
Peter G. Neumann has passed away. 93 years old. Update: John Markoff, at the New York Times, has published an obituary. https://www.nytimes.com/2026/05/17/obituaries/peter-g-neumann-dead.html
-
View post
Eric Rescorla has taken a 40-page swing at &quot;what policy makers need to know about AI safety and security&quot;. Really interesting. https://educatedguesswork.org/assets/ai-security-policy.pdf
-
View post
Big news! I’ve started a new position today at RAND’s Center for AI, Security, and Technology (CAST). I&#39;ll be working on projects that allow me to use my technical expertise to inform policy and shape consequential decisions, such as mitigating the impacts of AI on computer security. It’s going to be an exciting new adventure. Taking on this new role at RAND marks my departure from DARPA, where I’ve managed a portfolio of programs in cryptography and computer security. One highlight was...
-
View post
This is great: https://blog.trailofbits.com/2025/11/25/constant-time-support-lands-in-llvm-protecting-cryptographic-code-at-the-compiler-level/ LLVM 22 (and presumably all the subsequent versions) now have a constant time select intrinsic to enable cryptography algorithms to tell the compiler exactly what they need (i.e., evaluate both sides of a conditional expression then select the one you want), replacing gross bit hacking expressions that newer optimizers would unravel.
-
View post
A useful explainer about why static type systems, in general, and Rust, in particular, are super useful for debugging code. https://blog.daniel-beskin.com/2025-12-22-the-compiler-is-your-best-friend-stop-lying-to-it
-
View post
I gave a keynote talk last week at NDSS. I spent the front half talking about memory safety and how we can, once and for all, eliminate things like buffer overflows. In the back half, I talked about how DARPA works, saying all the things that I wish I&#39;d known about DARPA when I was starting my own academic career. I also wore my favorite vintage aloha shirt.
-
View post
I&#39;ve recently been playing around with vibe coding some basic tree-like data structures (treaps, red-black trees, AVL trees, and hash-array mapped tries) in Rust, and then twisting the arm of the LLM to do an optimization from Sarnak and Tarjan (1986) that lets you keep a version history without paying O(log n) path copying costs. This is the sort of thing that, in the old days, might have made for a useful undergraduate senior thesis that they&#39;d crank on for a semester. I&#...