❌

Reading view

There are new articles available, click to refresh the page.

The G7 tells industry to hurry up and prep for post-quantum encryption

A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption.

The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum” forms of encryption.

“The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence,” the working group report said. “Yet, a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk.”

Instead, leaders in government and industry “must reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.”

The report acknowledged uncertain timelines for quantum computers, but identified that threats like harvesting current sensitive, encrypted data to decrypt it in the future do exist today.

The report also warned that quantum computers could compromise authentication and assurance mechanisms—by forging trusted data or stealing confirmation— jeopardizing secure communications and legal contracts.

The working group’s conclusions are largely in line with what governments have been recommending for years, urging industry to inventory and prioritize their critical systems and shift over to newer, “post-quantum cryptography” encryption algorithms.

These encryption algorithms, originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology and National Security Agency, will be used to protect the government’s own systems and data from cybercriminals and foreign governments.

The Trump administration recently issued an executive order directing agencies to boost the domestic quantum industry and move up internal timelines for migrating to PQC encryption from 2035 to 2030. Google, a potential industry bellwether, and other companies have opted to move their own migration timelines to 2029.

But while that work has proceeded on schedule in some areas, like the federal government and the highly regulated financial sector, it has lagged in other industries where owners and operators feel they have more immediate concerns than quantum computers.

“We acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors,” the working group wrote.

While often referred to as “Post-Quantum” encryption, the reality is more complex. Cryptographers believe the algorithms selected by NIST and NSA will stand up to attacks from a quantum computer, but since one doesn’t exist today, designing cryptographic protections against it requires some guesswork and mathematical estimation.

Estimates can be wrong, or overlook the entire cryptographic attack surface. Some NIST-selected algorithms have already been broken with traditional computers or AI. That’s why the agency backs multiple algorithms and concepts like “crypto-agility,” allowing organizations to quickly switch between them.

The G7 report was signed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germany’s Federal Office of Information Security (BSI), Canada’s Communications Security Establishment (CSE), Japan’s National Cybersecurity Office (NCO) and Italy’s National Cybersecurity Agency (ACN).

The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.

Ring Says New Encryption Limits What It Can Give Police

Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring. TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE. According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it. When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change."

Read more of this story at Slashdot.

Slashdot Reader Builds a Photo-Verification App for iPhones

Long-time Slashdot reader BrianFagioli is announcing that he's released a new iPhone app that creates a cryptographic witness for photos without uploading the original image. The app hashes the file, signs the hash using a dedicated identity stored in Apple Keychain, and publishes the witness to Nostr relays while keeping the photo inside the app unless the user chooses to export it. Rather than trying to determine whether a scene was genuine, the app — named Veridenz — answers a narrower question, by verifying whether a photo file matches the one that was originally witnessed. Users do not need a Nostr account because the app creates its own signing identity, keeping private documentation separate from a public Nostr profile. "The developer does not collect any data from this app," says its page in Apple's iPhone store. The app's tagline is "Capture. Prove. Verify."

Read more of this story at Slashdot.

Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data

An anonymous reader quotes a report from The Guardian: Apple has launched a new legal challenge against a UK government demand to access its customers' highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. The UK government had made a second request to Apple to grant it a "back door" to encrypted iCloud data belonging to British users, according to an order issued by the court. Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk. Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.

Read more of this story at Slashdot.

Supply chain challenges loom large in quantum race, White House official says

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

Here’s what Anthropic found when it turned Mythos loose on encryption algorithms

Anthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditional and quantum computing.  

In a blog post detailing the work, the frontier AI company called it a “substantial” research advancement, but also emphasized that neither flaw affects software now in use.

“The attacks described in these two papers are the strongest attacks we have found to date,” the company wrote in the post. 

One of the weaknesses found was in HAWK, a digital signature scheme under review by the NIST as part of a search for encryption methods that could survive attacks from quantum computers. Working with a human researcher, the AI system found a mathematical shortcut, known as a nontrivial automorphism, in the lattice structure (a complex mathematical grid underpinning its security) HAWK relies on.

The discovered weakness cuts HAWK’s effective key strength in half, meaning key sizes would need to double to keep the same level of security. Anthropic said that change would erase much of what made HAWK an appealing candidate in the first place.

Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, a digital identity and cryptography management provider, told CyberScoop that research like Anthropic’s proves that the NIST PQC evaluation process is working. 

She also said the research “elevates the importance for organizations to have visibility of where cryptography sits inside their enterprise, what business systems and processes it’s connected to, and the need for PQC readiness, if they haven’t already built a plan.” 

The other flaw was found in a weakened version of the Advanced Encryption Standard, or AES, the cipher NIST adopted in 2001 and the most widely used method for scrambling data in transit. Working largely on its own, Mythos invented a mathematical shortcut dubbed the “Möbius Bridge.” While real-world encryption scrambles data through 10 sequential layers, or “rounds,” researchers regularly study a simplified seven-round test version to measure security margins. In previous theoretical attacks, codebreakers had to check 256 separate values against a memory table, but Mythos created a shortcut that eliminated that lookup process entirely.

Combined with other optimizations, this discovery made the strongest known theoretical attack against seven-round AES 200 to 800 times faster. The attack is purely theoretical: It requires an impossible amount of target data — over 400 octillion messages — and cannot touch the full 10-round encryption protecting everyday software. Additionally, Anthropic pointed out that real-world systems remain completely safe.

Anthropic said it followed standard disclosure practices, notifying HAWK’s designers in June and coordinating public release with a NIST mailing list, and briefing government and industry partners beforehand. It also worked with researchers at ETH Zurich, Tel Aviv University and the University of Haifa to build a shared testing tool, called CryptanalysisBench, meant to let other researchers measure how AI systems perform against a range of ciphers.

The findings come as frontier AI models are being deployed by cybersecurity researchers in order to find vulnerabilities in all kinds of software. In June, intelligence agencies in the Five Eyes alliance warned that advanced AI models capable of wreaking havoc in the cyber domain are “months away.” However, a recent report found that despite the avalanche of bugs being unearthed, the threat level across the internet has not materially changed. 

Anthropic said it expects the same AI capabilities eventually to be applied to systems already in wide use, raising a separate question it said it has not yet resolved: how researchers, companies and governments should respond if a language model uncovers a flaw in a cryptographic system that protects critical infrastructure.

“As we develop increasingly powerful cryptanalytic results, it would be prudent to consider how researchers should react if a language model were to discover vulnerabilities in cryptosystems where attacks do have an immediate real-world impact,” the company wrote. “We hope that our work here will help launch these conversations.” 

Boehm said work like Anthropic’s further shows that enterprises should not rest on their laurels with any facet of their security apparatus. 

“AI is becoming a powerful tool for many things, including software quality assurance, code development, and in this case cryptographic analysis,” she told CyberScoop. “As AI tools become more widely and continuously used, it just elevates the need for enterprises to treat their trust infrastructure in an ongoing, operational manner versus thinking of it as a static environment that only changes every few years as new cryptographic algorithms are released.”

The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on CyberScoop.

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms

Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet. [...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct. "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency. "Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."

Read more of this story at Slashdot.

How I Cracked a 128-bit Password

Sally Vandeven// TL;DR – Passwords stored using reversible encryption, even if they are VERY LONG,  can be trivially reversed by an attacker. Password cracking is quite enjoyable. It is very satisfying […]

The post How I Cracked a 128-bit Password appeared first on Black Hills Information Security, Inc..

Finding: Server Supports Weak Transport Layer Security (SSL/TLS)

David Fletcher// The following blog post is meant to expand upon the findings commonly identified in BHIS reports.  The “Server Supports Weak Transport Layer Security (SSL/TLS)” is almost universal across […]

The post Finding: Server Supports Weak Transport Layer Security (SSL/TLS) appeared first on Black Hills Information Security, Inc..

How to Crack Office Passwords with a Dictionary

Kent Ickler// TLDR: We use a custom dictionary to crack Microsoft Office document encryption.  Then we use a custom dictionary for pwnage in LinkedIn hash database. Background: I recently got […]

The post How to Crack Office Passwords with a Dictionary appeared first on Black Hills Information Security, Inc..

5 Reasons for Mailvelope & Easy Instructions

Gail Menius // My husband set me up with GPG and Thunderbird and it was too hard. Ethan said it was cool. Lots of people gave it good reviews. It’s […]

The post 5 Reasons for Mailvelope & Easy Instructions appeared first on Black Hills Information Security, Inc..

❌