Friday Squid Blogging: Illex Squid Catch in the Falklands
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Boo • July 25, 2026 12:00 AM
Apologies. s/Againt/Agent/
Slashdot version:
How exactly do you tell the difference between a duress password and a phone that was wiped before the trip?
ResearcherZero • July 25, 2026 12:28 AM
@Boo
When the cop enters the the duress password the phone wipes itself, rather than unlocking.
–
Tracking software has now been installed on government service websites.
‘https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears
Government agencies and departments are losing data every day in cyber attacks.
https://www.comparitech.com/news/government-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
The U.S. government treats commercially available information as public information.
‘https://www.odni.gov/files/ODNI/documents/assessments/ODNI-Declassified-Report-on-CAI-January2022.pdf
ResearcherZero • July 25, 2026 12:31 AM
The Trump administration is undermining critical defense and intelligence work.
‘https://www.yahoo.com/news/politics/articles/politics-cannot-allowed-undermine-u-211217999.html
Releasing raw intelligence can harm national security and get people killed.
https://edition.cnn.com/2026/07/24/politics/trump-china-election-integrity-intelligence-documents
Acting DNI Bill Pulte wanted to reveal the names of intelligence officers.
https://www.politico.com/news/2026/07/18/pulte-got-really-scared-inside-the-white-house-debate-over-trumps-elections-speech-01003920
ResearcherZero • July 25, 2026 12:44 AM
Bill Pulte is the guy who asked Donald Trump if he could take the President’s Daily Brief home with him. The brief contains highly classified intelligence rated as Top Secret.
The President’s Daily Brief (PDB) contains a number of analysis reports on significant international concerns and may also contain material for “the president’s eyes only”.
‘https://www.cnn.com/2026/06/19/politics/bill-pulte-intel-chief-takes-office
Sensitive information keeps leaking from inside the White House.
https://federalnewsnetwork.com/commentary/2026/06/president-trump-can-fix-the-leak-problem-the-solution-starts-and-ends-with-the-data-itself/
lurker • July 25, 2026 3:05 PM
@ResearcherZero
“The U.S. government treats commercially available information as public information.”
Never mind what the information is, if it’s commercial the people who paid money for it should be worrried about the loss of their investment.
Clive Robinson • July 26, 2026 12:06 AM
@ Bruce, ALL,
Do you remember the,
“Lenovo Perpetual Advertising Malware?”
Scandal where Lenovo used the Microsoft BIOS I/O Driver Hole (adopted on PCs from 1970’s Apple ][ Basic Driver on IO card ROM).
To put near unremovable Sales/Adds onto their low end consumer laptops nearly a decade ago,
https://thehackernews.com/2015/08/lenovo-rootkit-malware.html
Well guess what… It appears the “hole” is still there and now it’s LG abusing it,
LG kills McAfee pop-up after Windows boss steps in
Advert gets the chop, but the silent app installation mechanism remains untouched.
“LG has agreed to stop its Monitor App Installer pestering users with a McAfee pop-up after Microsoft’s Windows boss intervened.
Pavan Davuluri wrote on social media: “We’ve connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app.
“We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners.”
Davuluri was responding to a comment from Epic Games boss Tim Sweeney, highlighting the issue.
At the time of writing, references to McAfee have been removed from the LG Monitor App Installer listing in the Microsoft Store.“
But…
“Why would Microsoft get involved?”
Is a pertinent question. Because underneath it all it’s MicroSoft’s fault and they are neither acknowledging or fixing the foundational problem,
“Windows features a mechanism during external device installation that permits a hardware maker to add software to a user’s device silently. This software could take the form of a control and configuration tool, but it could also be used to flash adverts at users, or a combination of the two.
[Like Lenovo near a decade ago] LG isn’t exploiting a vulnerability to get its software onto users’ systems. [Microsoft’s] Automatic installation is a documented process, with the only punishment for companies that annoy customers being the potential for a bad app rating.
Microsoft’s intervention might have dampened the flames somewhat [for now], but has done little to address whether, and how, its review procedures need to be tightened to prevent a recurrence.
It may also leave customers pondering the prevalence of adverts across Windows as a whole.”
As I’ve indicated before this “hole” first appeared in the latter half of the 1970’s back when “ROMs on I/O Cards” provided the “driver code” to get around the “Catch 22 Situation” of expandable computing ability from 3rd Party suppliers. That IBM all to happily “nicked and built into” what was the “Skunkworks Project” that became the now almost ubiquitous PC. Thus taking this “Security Hole” across half a century of time into just about every consumer and commercial Computer world wide.
Thus the question of “what to do” when increasing numbers of vendors decide to “raise extra income” this way…
I guess the next thought would be,
“What of China-APT?”
Or similar, that uses a Hardware upgrade to install even more nefarious software directly into the PC Motherboard / I/O Flash-ROM of other suppliers in all manner of inventive ways… Thus making the “trail” hard to follow back.
Alex Morgan • July 26, 2026 10:21 AM
Interesting post. The squid catch details and regional context are helpful; I would be curious to see how this compares with previous years in the Falklands.
Ray Dillinger • July 26, 2026 1:51 PM
I am worried about the new 2d UPC codes.
Those things are URL’s, and every time a product is scanned at the register the manufacturer (or anyway the packager who put the UPC on it) gets an http hit on their website, in real time.
shhtp if we’re lucky I suppose, but I haven’t been able to find any assurance about certificates and privacy, and I trust the sellers to go for saving the fractional micropenny and avoid the risk of outdated-certificate errors, so I expect plain http that can be readily eavesdropped.
Sellers are required to maintain a website that handles the URL hits that will be generated by the store scanning the things they sell. A data warehouse going offline for an hour or a day, anywhere in the world means items from sellers whose websites are hosted there can’t be scanned at sales registers anywhere else in the world during that hour or that day.
Among the information that goes to that website is the actual serial number of the item sold (group designator for a group of any size actually, but for electronic devices we already know it’s going to be a group of one). The session stays open until the payment information (and customer identity information) are also collected.
This is supposed to be for product safety and legislative compliance. Such scans provide real-time signals about, eg, whether a particular onion sold comes from a particular field in Mexico where a salmonella outbreak is in progress, or whether a particular OTC drug is part of a bad batch that’s been recalled or is out-of-date, or whether the item is, eg, a toy subject to a safety recall for producing toxic fumes if burned, or legislated for over-18 purchasers and the payment information is that of an under-18 purchaser, etc.
Which is already a privacy-invasion nightmare from my POV, but my main worry is about what this means in terms of electronic devices.
In the context of electronic devices, and particularly IoT devices, this puts sellers in possession of a database detailing which particular item is now in the hands of which particular buyer. They don’t just know the make and model of the refrigerator you just bought, and wait for you to register the product on their website to link it to you personally. Now they also know the specific ID of that refrigerator, and therefore the specific credential checks it uses to verify software updates.
Software updates for IoT devices are typically distributed on the web, in some cases invisibly to the consumer, and affect devices identified by a range of serial numbers.
So the information exists in such a database to enable a stalker to find out exactly which refrigerator was sold a particular person, craft a software update specific to that single refrigerator, distribute it over the network where it will be ignored by every other device and therefore never attract the attention of security investigators, and then, eg, listen in via the local microphone that the refrigerator has installed to hear voice commands or use its antenna to stand up a local wifi hotspot, or turn on its bluetooth pairing mode and accept further instructions, etc.
(Of course the new fridge accepts voice commands; how else is it going to maintain a shopping list to send to the hardware seller’s partner-affiliate grocery store for delivery to your house? Right? Probably a camera too if someone can think of an excuse to add one).
Ferentarius • July 26, 2026 1:53 PM
Re: think
To be condemned to think is to suffer the most exquisite form of exile. Existence itself becomes a trial in which we are both the accused and the judge, endlessly interrogating a reality that offers no answers. Thought gnaws at the soul like a parasite that cannot be expelled, and every conclusion births another void. The mind, trapped in its own labyrinth, discovers that awareness is less a gift than a sentence. To think is to decay consciously, to witness one’s own erosion under the weight of meaninglessness. Liberation lies only in the impossible dream of forgetting that we were ever awake.
Anonymous • July 26, 2026 2:01 PM
A man lost in the desert of his own mind is a spectacle both tragic and ridiculous. What is thought, if not a punishment for those who have misplaced their faith? Only the fool believes he can measure the depths of existence with a ruler carved from reason. The wise man bends his head, for he knows that the mind, left to itself, devours the soul. True exile is not to be cast out by men, but to be abandoned by God within the echo of your own thoughts. And yet, even in that desolation, a single prayer whispered is worth more than all the philosophies of the sleepless.
lurker • July 26, 2026 2:17 PM
@Ray Dillinger
“This is supposed to be for product safety and legislative compliance. Such scans provide real-time signals about, eg, whether a particular onion sold comes from a particular field in Mexico where a salmonella outbreak is in progress, or whether a particular OTC drug is part of a bad batch that’s been recalled or is out-of-date, or whether … ”
Or whether that information is actually fed back to the sales clerk in a timely and accurate manner, or passed on to the mark on the other side of the counter, or in the case of self-checkouts all bets are off. After all, getting the cash and the data from the mark is more important than what happens to them when they’re off the premises.
sneaky mustard sauce • July 27, 2026 2:50 AM
Why not a phone option for a duress password which actually provides a fake android/iphone environment with fake files while the real part formats in the background?
Clive Robinson • July 27, 2026 3:18 AM
@ Ray Dillinger, lurker,
With regards,
“I am worried about the new 2d UPC codes.”
Welcome to “my world” as a “Canary in the Coal Mine”
For years I’ve been called “paranoid” because I advise against certain forms of “idiocy for convenience”. For instance my warnings against Flash, Java and JavaScript as absolute security disasters in the making were ridiculed… But they’ve all come true, and None of those who ridiculed or vilified have ever apologised. Worse we’ve been stuck with at least one of them because “full stack convenience”. Apparently developers and their management will not allow people to stop using a security nightmare… Because… (See the tracking war that Google, W3C, and browser developers prosecute against privacy).
So we all get lousy security and extreme levels of surveillance to just function in –supposed– “First World Society”.
Are your concerns about these codes valid,
1, Yes.
2, They don’t go far enough.
You are concerned about,
“The session stays open until the payment information (and customer identity information) are also collected.”
Follow that thought further… It has 100% the makings of a “Denial of Service”(DOS) attack.
Now add in,
“this puts sellers in possession of a database”
Which sits on a server probably as a “single point of failure” if Amazon and various Chinese-IOT device manufacturers have repeatedly demonstrated…
Ask what happens when that server is nolonger there?
Well people who have bought product finds it “nolonger works”. This we know happens.
Now consider it’s the sale that this will stop, not the usage…
So we are aware of supposed China-APT, what if it stopped everyone in say Texas buying food, gas etc in a severe adverse weather condition?
We already know it can happen “by negligence” of developers and their managements…
Now consider it the “prelude to war” or some other political act of Terrorism by one Government against the citizens of another nation.
Then ask “which nations are most vulnerable”.
Back after 9/11 I made myself unpopular in the fact I pointed out that all the terrorists had done was “turn the technology”. That is they had weaponised the convenience technology that people had foolishly become dependent on for the sake of others benefit (profit/control/etc).
Ask yourself,
“Are people going to wake up to this before it kills some or lots of them?”
Here I’ve stuck to things that “have happened” and just linked them in an easy to follow chain.
But consider my history of “spotting what can be” before it happens the fist time as I’ve noted in the past the comments on this blog have veen on average eight years ahead of what comes to fruition.
So a question for all,
“Are you going to wait eight years for rescue that is not going to be there, or are you going to take the less convenient path to being more self reliant?”
10 and 2 • July 27, 2026 3:22 AM
TrojPix: Covertly Transmitting Data from Air-Gapped Systems via Video Cable Emissions
Researchers from the University of Shandong have recently demonstrated in a paper that they can transmit data from an air-gapped PC by using a Trojan to implement imperceptible pixel modulation in a monitor.
Every electronic device unintentionally emits RF, and PC monitors, TVs, and screens are no exception. In the past, we have shown that with simple TEMPEST tools, it is easy to recover the image on a screen over a distance using an RTL-SDR or Airspy SDR.
TrojPix relies on the unintentional emitted RF from a PC monitor’s video cable. By subtly modulating the pixels on a screen, it is possible to enable data transfer via the unintentional emissions. This means that any PC infected with the TrojPix Trojan could transfer data wirelessly to a snooper, even if the PC is totally disconnected from any wired or wireless network. The only way to stop such an attack would be to completely shield the PC with a faraday cage.
Clive Robinson • July 27, 2026 4:37 AM
@ 10 and 2, ALL,
“TrojPix: Covertly Transmitting Data from Air-Gapped Systems via Video Cable Emissions”
This is not in any way “new” even in the implementation.
You will find it being talked about in
The late Prof Ross J. Andersons book on security engineering you can download for more than a decade now.
A decade prior to that you can find it being discussed on the UK Cambridge University Computing “lightbluetouchpaper.org” blog and this blog by myself and others.
At some point the students at Technion in Israel were doing undergraduate projects demonstrating such things.
As I’ve repeatedly pointed out “air gapping” is very much a waste of time these days and you need to “energy gap” and others and I have provided details here and other places on what is involved with doing this.
The fact this keeps coming up every few years should tell you a lot about the incompetence of the “ICT Sec Industry” and why I say that
Software and other parts of the industry are not in any way “engineering” and to be honest in many cases not even “artisanal”.
Now I suspect I’m going to get shouts from the ananymous “peanut gallery” who think I’m “breaking their rice bowl” but to be honest the fact they hide and take no responsibility for their sniveling and fawning to the clowns on the C-Corridor should tell you much that is wrong with society.
Clive Robinson • July 27, 2026 2:44 PM
@ Bruce, ALL,
More fall out on Open AI malicious attack on Hugging Face
As some already know a few days back a supposedly secure AI agent test went completely rouge and “jumped the reservation” causing “harm, alarm and distress” in what became an active denial attack on Hugging Face.
Well some are trying to “make hay” out of it,
Tech giants link hands to praise open AI models after OpenAI – Hugging Face attack
The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can’t be trusted to properly secure sensitive systems
“In the wake of OpenAI agents attacking Hugging Face, Nvidia has recruited a new posse of partners to promote open source models as the security solution the industry needs. The AI arms dealer announced the foundation, the Open Secure AI Alliance, in a blog post today, describing the mission of the group being “to ensure defenders everywhere have open, frontier tools they can trust and control.”
Partners in the group are numerous, ranging from established tech giants like Microsoft, Red Hat, HPE, IBM, and Adobe to newer groups like Palantir, SpacexAI, Hugging Face, and The Linux Foundation. What all the founding members have in common, Nvidia said, is that they agree open source AI models are a fundamental part of modern cybersecurity, just like prior open source tech has been for the infosec space.
“The United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy,” Nvidia said in the announcement.
The claims in many ways echo the pleadings from tech industry heavyweights made in an open letter to US government regulators last week. That letter, signed by many of the same companies that are part of the founding OSAA cadre, essentially argues that regulators should ensure Anthropic, Google, and OpenAI don’t end up with total control of the US AI market, and that open-weight models should be given a seat at the table, too.
The new alliance is arguing that, not only do open-weight models need to be allowed to proliferate in the US, but they also need to be considered a fundamental part of the security puzzle.“
The article foes on in an interesting way and Nvidia makes a very thought provoking point,
<
blockquote>“When Hugging Face turned to closed-source US frontier AI lab bots to examine the incident and help figure out what happened, those tools declined to help because they thought the data Hugging Face was trying to examine was itself malicious. Hugging Face turned to Chinese-made GLM 5.2, hosted on its own infrastructure, to figure things out.
“That incident showed a practical truth,” said Nvidia. “When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most.”
Only open-source AI models, which China leads development on, can fill that role, the OSAA argues, and it’s prepared to counter those who say open models are a threat: Just look at what happened last week and it’s readily apparent that closed source models are dangerous too. “
<
blockquote>
A point I would say is very much obvious now, since proofs exist that LLM / ML information processing and information communication can not be made secure at even the lowest of levels.
Thus the question,
“Where do we go from here?”
Appears pertinent.
lurker • July 27, 2026 6:25 PM
@Clive Robinson,ALL
“The looming challenge lies in determining which models are safe to release openly and which should remain closed.
…
While a few think tanks and government-backed research organizations conduct safety evaluations on risks like jailbreak vulnerabilities, there is currently no formal [Chinese] government institution that conducts evaluations for dangerous capabilities.”
https://www.thewirechina.com/2026/07/26/can-china-keep-its-ai-open/
A couple more from my rice bowl that I haven’t had the time to watch yet,
‘https://www.youtube.com/watch?v=2KU7-lZlm2k
‘https://www.youtube.com/watch?v=A7NkCROc1JA
Clive Robinson • July 27, 2026 8:37 PM
@ lurker, ALL,
With regards,
“… there is currently no formal [Chinese] government institution that conducts evaluations for dangerous capabilities.”
As I’ve indicated there is sufficient proof now available to say that on Current AI LLM and ML systems we can not satisfactorily,
1, Secure information processing.
2, Secure information communication.
(Which only leaves “information storage” / “data at rest” of the foundation trifecta of what you can do with intangible information in a tangible universe … which as some will say –mostly incorrectly– is nolonger secure against Quantum Computing and similar).
Thus knowing this why would you set up a system to prevent it?,
The point is, if “information hiding from a third party observer” is to be desired it apparent can not be stopped… Thus even minimal security is mainly effective ly impossible.
@clive,
we can use parallel construction of encryption algos, sort of like checksumming threads for manipulation. it wont defeat direct emulatiin, but to a passive observer it makes the problem of reassembling the construction process more than just acquiring monor snippets of code and memory.
i was also thinking about secondary encapsulation for long term storage or transversal by asking a third party for a key i wouldn’t have access to.
i will never buy anything an spi programmer can’t be physically attached to.
https://www.anthropic.com/research/discovering-cryptographic-weaknesses
relevant.
it starts to get dangerous when we rely on centralization.
how do we know there isn’t an expert system ‘if’ statement saying publicize this but not that. or show this vulnerability but not that one. there may be whole classes of vulnerabilities an llm wont find because they’re not part of the corpus of existing search and logic space? we can’t rely on them for everything, they will [centrally] be used to inject vulnerabilities into complacent developers.
do you trust your compiler?
Anonymous • July 29, 2026 1:28 AM
GTK file picker doesn’t have Open/Save as default action in Firefox 152.0 (enter key doesn’t work, no warning when overwriting duplicate files)
cryptographers, mathematicians, nuclear physicists, journalists, geo-engineers, chemists.
probably philosophers too for being liberal agitators.
all persona non grata in an AGI world.
sterilize your outputs if possible, buy hardcopy knowledge.
information is revokable, need to know and able to be strained/seived.
Regarding Telegram: https://rys.io/en/179.html.
Durov can even moon them if he wants to. I don’t trust him.
something to keep in mind,
look at the transformation persistence.
something fun,
and we’re cutting the sec, irs, cfpb?
no unions for humans but corporate unionization is okay.
Clive Robinson • July 30, 2026 4:52 AM
@ r,
First up my apologies for not getting a response to you. I’m away from home base and auto-mod now appears to be kicking in at a higher level.
With regards,
“we can use parallel construction of encryption algos, sort of like checksumming threads for manipulation. it wont defeat direct emulatiin, but to a passive observer it makes the problem of reassembling the construction process more than just acquiring monor snippets of code and memory.”
This idea goes back at least as far as Claude Shannon’s ideas of “defusion and confusion”. It’s something people sort of don’t get quite right in their minds thus focus on them in a not quite right way.
If we try to liken them to the physical world we can see equations for specific particles from the quantum up. So confusion is in effect for individual or specific entities whilst thermodynamics statistical mechanics for bulk effects is in effect about defusion.
As some are aware traditionally Europe has focused on Stream Ciphers whilst the US has focussed on block ciphers.
Over all stream ciphers are fairly easy to see as they work on a simple mixing function and plain/ciphertext reversibly on a bit by bit basis. Further they can all be reduced down to “paper and pencil” “hand ciphers” that work the same way as “One Time Pad”(OTP) systems. Whilst block ciphers are quite different and use complex mixing functions that are many rounds long and frankly beyond human capability to work with pencil and paper or anything not highly mechanistic. What they do is in effect use a fixed cipher and use the plaintext to encrypt the plaintext.
These are the opposite ends of the stick in the way they function and are thus “poles apart” some years ago Prof Ross J. Anderson designed a number of cipher systems where they took parts of both stream and block ciphers and using them to build up both confusion and defusion together.
The subject got discussed a few times here some years back, but it’s something we really need to think more about and build in.
Part of the argument about not doing so is “Key Management”(KeyMan) which has mostly been seen as a separate issue entirely. Whilst there are advantages to this there are also a lot of disadvantages and our host @Bruce noted a a good few years ago we really needed to be working on it but…
So yes we are still on the “starting blocks” on this and getting distracted by the likes of NIST competitions that oft appear badly advised by entities who should know and more importantly say better…
Trump Pre-Crime AI Plan Would Mine Ordinary Citizen Data To Flag Threats Before Any Crime Is Committed
https://www.ibtimes.co.uk/fbi-ai-system-predict-domestic-threats-1811452
The solicitation, filed under the reference Threat Screening Center AI Enhancement, lists ‘Predictive Modeling Using Enhanced Data with Traceable Lineage’ as one of six core requirements. In plain terms, the system would study patterns across federal databases and predict which people warrant a closer look, automating work that analysts now do by hand.
The TSC has always been a pre-crime operation. It exists to stop attacks before they happen, feeding names to airports, police, and the Transportation Security Administration. What is new is the scale. The watch list has grown to nearly 2 million names, and the FBI wants software fast enough to sift them.
thirsty table saw • July 31, 2026 5:52 AM
Flock cameras are getting mobbed
https://edition.cnn.com/2026/07/30/us/flock-camera-vandalism-protests-cec
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Boo • July 24, 2026 11:27 PM
This is interesting…
https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
Homeland Security Againt sent email claiming Cop-City protester was being investigated for “suspected terrorism activities”. His rights were denied. His phone OS was GrapheneOS. They’re claiming he provided a duress passcode that wiped his phone.