<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Binston Cardoza</title>
    <link>https://binston.in</link>
    <description>Protocol engineering, ZK cryptography, and EVM security research.</description>
    <language>en</language>
    <managingEditor>bsukhaelcardoza@gmail.com (Binston Cardoza)</managingEditor>
    <atom:link href="https://binston.in/rss.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Postmortem: Incomplete GG20 Session Binding in tss-lib v2]]></title>
      <link>https://binston.in/writing/incomplete-gg20-session-binding-tss-lib-v2</link>
      <guid isPermaLink="true">https://binston.in/writing/incomplete-gg20-session-binding-tss-lib-v2</guid>
      <pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A postmortem of a tss-lib v2 GG20 migration bug where deterministic SSIDs and a sessionless RangeProofAlice allowed proof transcripts to be replayed across signing sessions.]]></description>
      <category>audits</category>
    </item>
  </channel>
</rss>