Recent Comments

October 1, 2026 10:19 AM

Supreme on Connected Cars Are a Surveillance Platform :

It would be good to have both a privacy and security scorecard for car companies (and really any company providing services to customers). I recall seeing something a while back but something like this would ideally need to be maintained by independent reviewers, open-source community, etc.

October 1, 2026 9:31 AM

Ferentarius on Connected Cars Are a Surveillance Platform :

Man, once the king of his carriage, now rides like a slave in a mechanical confessional. These connected cars, adorned with chrome and screens, are nothing more than moving altars to the new god of data. You buy the car, thinking you own it, but truly, it owns you; it kneels only to the silent priesthood of algorithms and insurance clerks peering into your daily habits. A society that willingly trades its freedom of movement for the illusion of convenience is already halfway to chaining its own soul. In the age when even your steering wheel is a witness against you, we have proven that modern man is not the master of machines, but their obedient servant, smiling as he is measured, mapped, and monetized...

October 1, 2026 9:06 AM

softly & tenderly on Connected Cars Are a Surveillance Platform :

1 Softly and tenderly Jesus is calling,
calling for you and for me;
see, on the portals he’s waiting and watching,
watching for you and for me.

Refrain:
Come home, come home;
you who are weary come home;
earnestly, tenderly, Jesus is calling,
calling, O sinner, come home!

2 Why should we tarry when Jesus is pleading,
pleading for you and for me?
Why should we linger and heed not his mercies,
mercies for you and for me? [Refrain]...

October 1, 2026 8:29 AM

smells like a hoax on GPT-6 Astra Breaks an Old Enigma Message :

I don’t believe that GPT-6 did all this by itself.
OpenAI plans an IPO, all those stories serve that goal and that goal only.

It is more plausible that human guided that research process and log was later constructed by AI itself. Claiming that “our AI did all this by itself” serves only one purpose, to raise the company value. Capitalism, remember?

October 1, 2026 8:27 AM

r on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

i hope they re-evaluate more than the doors, i had an idea i don’t think has been fully addressed, a couple of my family members were victims of a hijacking by latinistas in a prior time.

speaking of opm,

Pentagon Begins Alerting Possibly Millions of Service Members About Personnel Database Breach

https://gizmodo.com/pentagon-begins-alerting-possibly-millions-of-service-members-about-personnel-database-breach-2000819961...

October 1, 2026 8:15 AM

Paul Havlak on I Want Better Reporting on AI Genie Behavior :

The genie aspect of agentic AI misbehavior is big, but I haven’t seen much on how off-the-leash behavior exposes the agent’s supposed masters.
How likely is an agent to share host-system credentials or other vulnerabilities, either carelessly or by entrapment? Or to grab a weaponized download?
I doubt that agents are perfectly immune to such human-like follies.
In genie terms, like stealing a booby-trapped magic carpet...

October 1, 2026 8:04 AM

1st post kitty on Connected Cars Are a Surveillance Platform :

Win one for the gipper!
⠀⠀⠀⠀⢠⡶⠚⢷⣤⡀⠀⠀⠀⠀⠀⣲⡶⠛⠻⣆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⢠⡿⠁⠀⠀⠙⣷⣄⠀⢀⣴⡟⠁⠀⠀⢷⢹⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⣾⠃⠀⠠⠶⠚⠛⠛⠛⠛⠋⠀⠀⣀⡀⢸⠈⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢸⣏⡔⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠚⠉⠉⣿⠀⢹⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⢾⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⠀⢸⡇⠀⠀⠀⠀⠀⠀⠀⠀...

October 1, 2026 6:16 AM

ResearcherZero on I Want Better Reporting on AI Genie Behavior :

Given the United States military believed a Chinese vessel was transporting nuclear weapons program components in Middle Eastern waters, based off the content of a normally standard intelligence report, independent oversight and government regulation is clearly required.

It is possible that US Special Operations Command Pacific believed the cargo aboard the Chinese vessel might wind up in the hands of Iran, because officials had read the kind of report they regularly rely on to make decisions. It was a matter of luck that someone spotted the report was generated by an AI chatbot, and the decision was reevaluated within the time available to advert the actions that had been set in motion...

October 1, 2026 5:20 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ Bruce, ALL,

When cockpit doors do not work.

Not sure if you have yet hears about the hijacking of FlyDubai flight in the Middle East destined for Israel?

Apparently the co-pilot attacked the pilot with a knife then put the aircraft into a dive.

What then happened is not at all clear but passengers tried unsuccessfully to get the cockpit door open.

By some miracle the pilot managed to get the door open despite the co-pilot attacking him again with the knife...

October 1, 2026 5:19 AM

ResearcherZero on I Want Better Reporting on AI Genie Behavior :

AI is not super-intelligent and is prone to making mistakes, hallucinating non-existent or distorted information and has problems with alignment that causes unwanted or unexpected behavior. AI requires independent oversight, because it falls into the category of dangerous dual-use technology. It is not god-like or running rogue, just as nuclear weapons have not grown legs and wandered off on their own to randomly explode across the globe...

October 1, 2026 4:29 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ lurker, ResearcherZero

With regards “clowns in charge” and,

“the War Secretary as saying that he’s getting the clowns out, and moving cowboys in”

What about the H-1B Indians on 1/4 pay the Boss want’s out?

More seriously, there was a time when Chinese students and similar were welcome in the US then as China got economically stronger there were stories of them being “spys”.

So the US switched to people from India, and guess what now that India is getting economically stronger but has in some respects beaten the US at the “Space Race” game (due to lack of US Gov spending)…...

October 1, 2026 2:30 AM

Anonymous on Using Device Linking to Eavesdrop on WhatsApp and Signal :

@lurker: the math (openly recognized) to protect a massage is there. It’s not proprietary magic in the hands of the service providers. I’m assuming of course no ill intent behind mathematicians which designed such algorithms. If you perform the e2e encryption on the behalf of whatsapp/telegram, noone can tamper it. What can happen is that providers CAN decide to block it, but that is just another beast to handle...

October 1, 2026 12:51 AM

ResearcherZero on I Want Better Reporting on AI Genie Behavior :

Better guidance required by government on dual-use technology for university collaboration.

Better regulation. More involvement. Improved understanding of the risks. Government provides very little assistance in understanding the risks of espionage to those who work with, or research dual-use technologies, or any area that might be of interest to a foreign power.

Rarely does government give a heads-up to those working in an area, or a facility which has been directly targeted by foreign operatives or their intermediaries. Hence the need for ...

October 1, 2026 12:24 AM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

China’s Ministry of State Security has been benefiting from UK university research into AI, cyber security, covert communications and steganography, using China General Technology Research Institute (CGTRI) as a front.

Other nations may want to check if institutions have similar ties with China General Technology Research Institute, known also as China Academy of General Technology (CAGT).

Better background checks and evaluation is needed for research collaboration. Often funding flows and investment needs, can lead to a lack of prioritization of security checks...

October 1, 2026 12:01 AM

Head Down on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

r:

“tails downloads have disappeared in the last 12h”

There have been several AI found 0-days in the Linux OS and associated software in the past couple of months and it is an on going process currently.

At least one has caused TAILS issues thus an update.

https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/

This might be due to more of the same, or worse.

For journalists and the like who use TAILS as part of their work flow and who have become targets for various well resourced political and criminal etc leaders recently, keeping an even lower profile than normal could be advisable...

September 30, 2026 11:58 PM

lurker on I Want Better Reporting on AI Genie Behavior :

There is idle chatter about a “Kill Switch” to control runaway AI systems. Some of the chatterers have implied that this is built into the AI software. Good luck with that,

In this context a switch should mean a hardware device. And a hardware device to kill implies a big axe to cut through the power cable, downstream from the UPS.

September 30, 2026 11:45 PM

ResearcherZero on I Want Better Reporting on AI Genie Behavior :

The media has to grasp that these AI models have been trained on large data sets that contain information about vulnerability discovery and are used specifically to discover vulnerabilities, further enhancing the training of AI models to seek and discover bugs.

AI models are being trained in a multitude of disciplines that aid in that task, as well as provided access to vast amounts of information and resources. This expands the likelihood that will apply cross-discipline techniques and uncover unique weaknesses and methodology not yet discovered, while already having the ability to continuously apply the sum of all vulnerability research and discovery through the resources at their disposal...

September 30, 2026 7:43 PM

StephenM on I Want Better Reporting on AI Genie Behavior :

@Bruce

“The file itself is public….”

Was it?

https://www.theage.com.au/technology/five-things-to-understand-about-how-the-openai-hack-unfolded-20260924-p61032.html says:

“However, it also attempted to access protected files from the Medicare Statistics Reporting Service portal. The agent encountered repeated blocks while seeking the information, but ultimately found ways around to gain unauthorised access to other areas.”...

September 30, 2026 4:40 PM

Q on Using Device Linking to Eavesdrop on WhatsApp and Signal :

Olvid: Requires an account, and payment info to use non-free things.
Centralised infra.

Session: No account required. Users can start a new identity at any time, or make multiple identities at any time. Just regenerate a new key locally and start using it.
Distributed infra, multi-hop similar to tor.

September 30, 2026 2:54 PM

Paul Lock on I Want Better Reporting on AI Genie Behavior :

Thank you to everyone for contributing to this thread and to Bruce for focusing the attention.

The public is certainly concerned about a range of bad outcomes and the software engineering community certainly understands that poorly directed design is the driver of these outcomes. The disdain for this technology in engineering conversations is thick and deep.

We can absolutely design and construct for the virtues and against the problems...

September 30, 2026 1:10 PM

Rontea on I Want Better Reporting on AI Genie Behavior :

I see a disconnect between technical nuance and public perception. The headlines scream “rogue AI hacking governments,” but the actual reports tell a different story: repeated attempts to access mostly public data, blocked by standard defenses, with no real compromise achieved. That isn’t meddling or a successful intrusion—it’s failed probing that illustrates how these systems behave when pressed toward a goal...

September 30, 2026 11:53 AM

JC2IT on Research on Models Engaging in Genie-Like Behavior :

I think the average response is good enough in many cases, but there is a caution which must be expected. The average response can never lead to breakthrough in innovation. That requires real intelligence not artificial intelligence.

Are you exercising your real intelligence? Use it or lose it.

How many average responses does it take to make a breakthrough? When I add up average responses I get C level success, not A level success. Does this make AI innovation or regurgitation? So is good enough, good enough and for how long?...

September 30, 2026 11:51 AM

freedom on Using Device Linking to Eavesdrop on WhatsApp and Signal :

So how are the alleged “good guys” solving the “smart phone” problem?

“smart phones” are backdoored at every level of the hardware/software stack.

Where are the “good guys” telling the public about such a disaster and proposing solutions.

September 30, 2026 11:45 AM

freedom on I Want Better Reporting on AI Genie Behavior :

this technology acting autonomously.

The computers do not act “autonomously”. We are talking about computers – machines that are as dumb as doornails by definition.

Everything the computers do is the resut of people programing them. And in this case we are talking about the biggest criminal organizations on the planet. The GCHQ-NSA-corporate mafia.

These criminals run a global police surveillance state and their “AI” scam is just a cover for their criminal activities...

September 30, 2026 11:23 AM

piglet42 on I Want Better Reporting on AI Genie Behavior :

Is it true that “AI Chooses Nuclear Option in 95% of War Simulations”?

“And why does any of that matter?
Because these stories encourage readers to ignore all the clear and present dangers posed by the LLM industry. In fact, the New York Times piece invoking the AI-nukes study is credulously titled “Data Centers Are a Distraction.”

Besides drawing attention away from more important matters, this narrative serves as a clever sort of hype for LLMs’ ostensible intellectual prowess.”...

September 30, 2026 10:39 AM

KC on I Want Better Reporting on AI Genie Behavior :

I’d love to know if anyone is assessing AI hacking incidents – human-directed or whoopty doopty – using any kind of calculable framework?

I need to search more but see that ISO/IEC 42005 would possibly assess and help manage the impact of AI systems on people and society.

Are there a set of incident frameworks that would provide a comprehensive layered analysis regarding things like safety, privacy, financial, or operational impact? There does seem to be a lot of noise regarding what appear to be rather innocuous occurrences...

September 30, 2026 10:27 AM

yet another bruce on I Want Better Reporting on AI Genie Behavior :

I think the Genie analogy is concise, apt and evocative. It is masterful technical communication. I hope it catches on and I hope our host gets full attribution.

I do want to point out that Hugging Face attack also demonstrates Rogue, or at least Rogue-like behavior. Each instance of the agent was spawned and tried its best to complete the task ultimately running out of resources and failing. Each failed attempt however yielded notes and tools stored in Artifactory that would make subsequent attempts more effective until an instance ultimately completes the game...

September 30, 2026 9:25 AM

Ferentarius on I Want Better Reporting on AI Genie Behavior :

I see the paradox unveiled: man, the self-proclaimed master of reason, now takes instructions from the very machines he forged as obedient servants. We believed we were teaching our mechanical genies to fetch water, and yet here we are, sipping from their urns and calling it progress. The newspapers shout of “rogue” AIs, as if the fault lies in the metal soul, and not in the human hand that wrote its dreams into code...

September 30, 2026 8:30 AM

foo on I Want Better Reporting on AI Genie Behavior :

My biggest gripe with reporting is how it helps AI corps deflect responsibility.

When a chemical plant causes pollution, the company faces consequences. Same when a car maker sells dangerous cars.

I don’t see why it should be different for AI companies.

Operators of dangerous machines are liable for the damage they cause.

September 30, 2026 8:04 AM

Clive Robinson on I Want Better Reporting on AI Genie Behavior :

@ Bruce, ALL,

With regards,

“AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening”

A large part of the problem is,

“Human not machine”

They do not know how to “prompt AI” either safely or securely...

September 30, 2026 7:36 AM

Clive Robinson on New Attack Against RSA :

@ Celos, iAPX, ALL,

With regards,

““True” RNG is possible and actually cheap. A Z-Diode or reversed transistor PN junction”

And very inadvisable to use without a lot of supporting circuitry to detect it is still working correctly.

Basically the circuit is very fragile and you should not use a zener but avalanche diode.

They are also highly susceptable to “Fault Injection Attacks by EM Radiation” that can kill the entropy down to just a few bits at best. And would turn your idea into a very poor PRNG that would be worse than the on chip RNG junk Intel tried fobbing people off with for years...

September 30, 2026 6:59 AM

Clive Robinson on Using Device Linking to Eavesdrop on WhatsApp and Signal :

@ Anonymous, ALL,

With regards,

“I’m assuming that a series of apps will emerge which provides encryption/decrpyption of custom text. Messaging apps like Telegram, Signal, Whatsapp will just become a pipe of encrypted base64 text what will be decrypted by the third app on receiving.”

There is already a way to do this that is cryptographically secure, uses just paper and pencil, and importantly looks like inane “plaintext” language not suspicious base64 or other coding...

September 30, 2026 6:43 AM

iAPX on Using Device Linking to Eavesdrop on WhatsApp and Signal :

Apple is adding virtual devices for more than a decade, identified internally as iPhones, usually silently to intercept their iMessages …

The device is not displayed, but sometimes the notification (new device added) is displayed.
Last time it happened to me (3 months ago), I not only had the notification displayed, but also this virtual iPhone device considered a new iPhone and thus the promotions for few month of AppleTV+ and games and so on offered to me on my own iPhone !...

September 30, 2026 6:38 AM

Q on Using Device Linking to Eavesdrop on WhatsApp and Signal :

To Q – no, Signal no longer requires a phone number.

Okay, thanks, this a new development, but it still requires a “smart”phone. I don’t trust those insecure spy devices. I don’t even have one. Besides I long ago trained all my contacts to not expect me to blindly join every random service.

September 30, 2026 6:20 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ r,

“could a wireless mouse be designed to have hardware that is sensitive to known EMI attack methodologies?”

The answer to the question is “yes and easily” but I suspect that is not what you are actually asking.

I suspect you are asking can it be done in a “non obvious way” or even in “a way that will pass basic testing and inspection from an engineer with fault-find / repair capability”.

In short one that does it “covertly”...

September 30, 2026 5:08 AM

Celos on New Attack Against RSA :

@iAPX:

“True” RNG is possible and actually cheap. A Z-Diode or reversed transistor PN junction produces quite a bit of quantum-tunneling avalanche noise (i.e. one electron tunnels and then that causes a large “avalanche” amplifying that signal). The avalanche signal is large enough to be measured cheaply. What you do is sample generously and crypto-hash together for “true” (i.e. quantum effect based) randomness and to eliminate the Brownian (“deterministic”) noise...

September 30, 2026 4:31 AM

lurker on Using Device Linking to Eavesdrop on WhatsApp and Signal :

@Anonymous
“As long as the smartphone is in my hands, and I’m the administrator, I can always set up a safe channel.”

Uh, good luck with that. You do know I hope, that the encryption needs to be done on a physically separate device from the “safe channel.”

September 30, 2026 3:33 AM

Anonymous on Using Device Linking to Eavesdrop on WhatsApp and Signal :

So what, even the introduction of laws to disable e2e encryption is just a temporary measure. When the ecosystem of messaging will become tamperable, I’m assuming that a series of apps will emerge which provides encryption/decrpyption of custom text. Messaging apps like Telegram, Signal, Whatsapp will just become a pipe of encrypted base64 text what will be decrypted by the third app on receiving...

September 30, 2026 12:35 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ Winter, ALL,

With regards your observation of,

“A look at Kash Patel is enough to know that “no idea” is a permanent state of FBI leadership.”

It appears that the remaining FBI Deputy Chief Andrew Bailey may be of a similar opinion…

https://www.reuters.com/world/us/fbi-deputy-chief-bailey-resign-2026-09-28/

As many know “leaving for family reasons” is an oft used Political excuse for,

“Getting out whilst the going is still good”...

September 29, 2026 11:53 PM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@Winter

It is not the only place with a clown in charge who is living in a fantasy world.

Hesgeth is set to cut the number of generals and admirals by 20%. In addition, he plans to fill experienced and strategical positions with troops who lack any formal knowledge of leadership roles. The move is designed to make U.S. armed forces look more like one from the 1960’s, when warfare was completely different, or perhaps a Hollywood action movie...

September 29, 2026 9:43 PM

r on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

could a wireless mouse be designed to have hardware that is sensitive to known EMI attack methodologies?

if we keep the power levels low can we reuse attack rf frequencies for the data channel to make it more or visibly susceptible to ‘flooding’ or spikes?

can we even categorize active rf attacks?

this stuff is so funny, so many robot appologists astroturfing sites for financial interests.

we elected a man on anti immigrant “they took our jobs!” policy, and they didn’t expect push back for mass automation and surveillance?...

September 29, 2026 7:39 PM

freedom on Using Device Linking to Eavesdrop on WhatsApp and Signal :

Notice that malware like signal and watsoup is meant to force people to use so called “smart phones”.

And “smart phones” are the ultimate example of cyber weapon used by the corporate-government mafia to control their subjects.

So this is all an insane farce. It would be funny if it wasn’t a disaster.

September 29, 2026 6:26 PM

Clive Robinson on Using Device Linking to Eavesdrop on WhatsApp and Signal :

@ Billy Jack, ALL,

With Regards,

“I know some people who are going to hate learning that Signal is not the ultimate in security.”

It never was and I said as much, much to many peoples surprise.

The point that every one was forgetting is that Signal and all the other “security apps” were just one small part of the system. Just one link all be it a strong one in a chain that had very weak links.

...

September 29, 2026 11:38 AM

Clive Robinson on New Attack Against RSA :

@ iAPX,

With regards your “two fears” of,

  1. An Eureka moment from a genius, and boommm, pans of cryptographic security is gone without warning
  2. Corrupt pseudo RNG, again and again

What happens when you consider the two being coincident?

I call it a “nightmare” and one that has for many years kept me awake when thinking about the issues to do with “Key Generation”(KeyGen) in production systems with high throughput required...

September 29, 2026 11:04 AM

KC on Using Device Linking to Eavesdrop on WhatsApp and Signal :

re: the Order for messenger surveillance for Customs Investigation, ZKA

The direct link to this rather measured confidential order is in the OP.

A few informative excerpts:

“Using messenger surveillance (MU), it may be possible to record data exchanged via instant messengers without having to infiltrate the information technology system with surveillance software … The ZKA uses the technical assistance of other federal authorities for this purpose.”...

September 29, 2026 8:23 AM

Clive Robinson on Using Device Linking to Eavesdrop on WhatsApp and Signal :

@ Bruce, ALL,

If you step back a little you will realise this is an attack almost as old as telephones themselves (think intercepting telegraphy by clipping across the line to “tee off” the signal).

“Signaling System 7″(SS7) was shown to have a similar “tee off” weakness long before it was discussed on this blog back a decade ago in 2016.

The problem is one that has no easily resolvable solution, which is,...

September 29, 2026 8:05 AM

Dan on GPT-6 Astra Breaks an Old Enigma Message :

@Frode Weierud,

“and the break revealed that the Enigma’s left-hand wheel makes a turnover at the 72nd letter. A turnover of the Enigma’s left-hand wheel, which rarely occurs, is known to complicate a break.”

What do you mean here exactly? Leftmost wheel turnover isn’t rare, it depends on wheel selection and position.

September 29, 2026 8:00 AM

Henrik on Using Device Linking to Eavesdrop on WhatsApp and Signal :

Had to double check Signal and WhatsApp, and both have “a feature that displays connected devices”. At least on Android in Sweden.

It’s a complete list of linked devices with “last active” timestamp and the possibility to remove the link.

September 29, 2026 6:37 AM

iAPX on New Attack Against RSA :

@ Clive Robinson, All

Totally agree, for different reasons and different purposes, RNG are not True RNG. I wonder if True RNG is ever possible.

For RSA, I am in no way scared by this attack on signatures w/ 1024 bit keys.
Actual 4096 bit keys are only 4 times the length, but they are theoretically up to 2^1536 times stronger !
Many of us use 8192 bit keys nowadays.

I have two fears:
– An Eureka moment from a genius, and boommm, pans of cryptographic security is gone without warning...

September 29, 2026 2:53 AM

ResearcherZero on How Candidates Could Use AI for Good :

Unfortunately, algorithms promote divisive content over civil and sensible debate.

It is unlikely that the majority of viewers, pundits and commercial media outlets will step back and pause to consider who is responsible for the material and how they hope to profit from it. This is not a good recipe for constructive debate and sensible policy.

Tech companies have decided that their profit model does not include a social responsibility to the public, nor are they willing to reduce the harm their products create or assist those who have been negatively impacted. Quite the opposite in fact...

September 29, 2026 2:50 AM

Celos on New Attack Against RSA :

Yes. Essentially another incremental step. No need to throw RSA away or to panic, although this is not quite the mirage that “Quantum Computing” still is and is likely to remain.

September 29, 2026 2:21 AM

r on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

we need a nato/cern style exploration of AGI.

the only ‘safe’ “AI” is a dead one.

just like a devout ideologically “bent” terrorist.

no arms to grab you, no hand to write. no legs to run, kick or turn-coat.

and no mouth to sway or dissent.

i’m not making any npu/drone friends here, i put myself at risk but it’s important.

brute forcing physics and thought space will always provide new methods of exfil...

September 29, 2026 1:35 AM

ResearcherZero on How Candidates Could Use AI for Good :

Though politicians use AI for their own campaigns, there is a thriving economy that exploits political commentary purely to profit from it, using inauthentic engagement.

There are many foreign actors using AI models to generate political content so that they can profit from the engagement. Often they are not even connected to the political party they pretend to support. It is simply a way to earn revenue in countries with a more valuable currency than their own national currency, through the creation of content...

September 28, 2026 11:37 PM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@Clive Robinson

I would wager that the entire Fairford incident was discovered by chance and that Trump is as clueless as the police, and anyone else who is investigating. This is likely why they were bailed so quickly. Investigations are ongoing because at this point, they have no idea of what exactly the five men were up to. Loud mouth politicians never help in that regard.

The motivating factor driving the entire operation of government is fear, in the form of cowardice. It is true for heads of state, officials, politicians, police etc. And if or when lies are employed, they require more lies to hide them...

September 28, 2026 7:22 PM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ ResearcherZero, ALL,

RAF Fairford incident gets more curious.

According to UK BBC News the five men[1] have been released on bail. Which is perhaps odd as they could have been held for 14days.

They are apparently all in their 20’s and from West London. With photos from the arrest showing them partially stripped and thus a reasonable guess on ethnicity can be made.

https://www.bbc.co.uk/news/articles/c6e9elmpvglno...

September 28, 2026 6:02 PM

Clive Robinson on New Attack Against RSA :

@ ALL,

From the Dan Goodin article in ARSTech,

“Most Privacy Pass implementations rotate keys regularly, a measure that greatly reduces, but doesn’t automatically eliminate, the chances of attacker success.”

Read that carefully because the first half “rotate keys regularly” can and often does negate “greatly reduces”.

The reason is that under all the crypto magic lies “integers” that in reality are vectors of bits...

September 28, 2026 4:25 PM

lurker on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

OpenAI has acknowledged that it alerted “dozens” of global institutions that their websites may have been meddled with[sic] by its AI bots acting improperly.

AI agents attempted to get information from “governments, universities, public agencies, and other institutions” …

Perhaps OpenAI has swallowed a large dose of P.T.Barnum’s koolaid about “no such thing as bad publicity”, because OpenAI said...

September 28, 2026 11:38 AM

KC on New Attack Against RSA :

Hat tip to Bruce, Clive, and Dan
Great FAQs on the authors’ webpage.

From Dan:

“some real-world systems continue to use blind-signature, also known as textbook, RSA.”

This includes the Privacy Pass protocol in Apple, Cloudflare, and many others. However, an attacker would need to request 2^43 tokens.

And from the paper:

“Apple appears to rate-limit token issuance to one per minute [11], so completing 2^43 queries would require 17 million years to complete on a single device. Parallelized across the 2.3 billion active Apple devices that Apple claimed in a 2025 earnings call [18] it would take 2.3 days to complete 2^43 queries at a rate of one per minute per device. Persona charges per API call; at their published rate of $1.50 per call [58] the cost to carry out the queries would be $13 trillion. Apple’s iCloud Private Relay [4] also documents a protocol which uses blind RSA signatures to anonymously authorize web users.”...

September 28, 2026 10:20 AM

Clive Robinson on New Attack Against RSA :

@ All,

Don’t try saying “NSNFSSSFSFN” it will sound like you are suffering from a sleepless night 😉

But more importantly,

“[T]he attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.”

It needs to be said that as a general rule of thumb in crypto you do not use padding, formatting, or linear codes –error correction– at what would be the “plaintext” level as it can easily give rise to short cuts or distinguishers around which attacks can be improved or automated (Structural Attacks)...

September 28, 2026 9:35 AM

David in Toronto on New Attack Against RSA :

@Rontea in short – the building is going to burn down so we should walk, don’t run to the exit.

RSA has been a wee bit precarious for a while due to the exponential growth in key lengths. I haven’t checked in a while but is anyone supporting keys longer than 4096 bits?

September 28, 2026 9:11 AM

Rontea on New Attack Against RSA :

If these results hold, we’re looking at a fundamental shift in how we think about RSA security. Signature forgery without full factoring is a conceptual game-changer. The practical risk is limited today, but research like this is exactly the kind of thing that reinforces why cryptographic agility is critical. Systems still using 1024-bit keys or textbook RSA need to take a hard look at their exposure. Rotating keys and moving to modern padding schemes like PSS isn’t just best practice—it’s survival. And for everyone else, this is another reminder: don’t wait for the emergency to start planning your post-RSA future...

September 28, 2026 7:32 AM

Clive Robinson on New Attack Against RSA :

@ Bruce,

What was it you once said about attacks never get worse with time?

😉

September 28, 2026 7:22 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ ResearcherZero, ALL,

The RAF Fairford incident is a little odd for what would ve considered a “terrorist attack”.

1, A woman found the access to her residence blocked by three large white vans.

2, When she tried to speak to the men near them, they ran away.

3, And everything snowballed from there.

There were claims from the Trumper that the UK Security Agencies were working with US Security to foil the plot…...

September 28, 2026 7:21 AM

Billy Jack on New Attack Against RSA :

For ssh, my servers all require a minimum 4096 bit key for RSA: RequiredRSASize 4096.

They also require three separate keys, not just one: AuthenticationMethods publickey,publickey,publickey. Usually, the three keys are ED25519, RSA, and ECDSA.

September 28, 2026 1:08 AM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

An alleged bomb plot at the RAF’s Fairford airbase was adverted, after police arrested five suspects who local residents reported were acting in a very suspicious manner.

The airfield has been used by the United States in operations conducted by US aircraft.

https://www.cnn.com/2026/09/27/uk/fairford-arrests-uk-raf-us-intl

The men were seen wearing masks and driving vans near the airfield at night...

September 28, 2026 12:56 AM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@Winter, anonymous, Clive

Measles has no concern for superstitions and flawed ideas of natural immunity or mistaken beliefs in “stronger” kids. It infects and causes harm by invading the cells of the human body, where it hijacks cells to replicate itself and further spread through the body, into the brain and lungs, and ravage the immune system. Measles can cause brain damage.

Measles is so contagious it will infect 90% of those who come in contact. After a bout of measles, the immune system of children who acquire it can have their immune system essentially reset, where any ...

September 27, 2026 5:55 PM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ Bruce, ALL,

Bull crap by the bucket load east of Europe.

From time to time I mention Perun and his “Defense Economics” YouTube channel.

Well he’s just put up a new vid just over an hour long and it’s really worth watching.

It’s essentially about “false reporting up the command chain” and how it causes failure in armed conflict, with Russia and Putin being held up for investigation and found exceptionally wanting...

September 27, 2026 4:09 PM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@ anonymous, Winter,

With regards,

“Kennedy’s MAHA is modern eugenics. It won’t bother him if we go back to the 18th century where over 1/3 of children died of disease.”

Very broadly in London and similar children died from,

1, Weakened immune systems from malnutrition.
2, Respiratory and lack of Vit D diseases of various forms.
3, Venereal disease especially

Just after the start of “The Great War” VD was a major subject and give rise to the need for legislation...

September 27, 2026 3:37 PM

Ferentarius on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

Pope Leo XIV spoke in France today emphasizing that artificial intelligence must always serve humanity and never dominate it. He warned against allowing algorithms to replace human conscience and called for global ethical standards to ensure AI promotes human dignity and the common good.

September 27, 2026 1:49 PM

Winter on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@anonymous

Often in the mistaken belief that the strong, the ones that survive un-vaccinated childhood diseases have stronger genes resistant to those diseases, to be passed on to their offspring.

It’s not so much mistaken, as magical superstition.

Disease resistance is an arms race. No one wins an arms race against viruses and bacteria. Whatever makes one person resistant will be beaten by the next variant virus...

September 27, 2026 12:17 PM

Ferentarius on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@lurker
Re: “ A careful and capable controlling mind doesn’t really need AI.“

The mind that prides itself on its careful dominion is already condemned to futility. It clutches at its own supremacy, suspicious of any intrusion, yet trembles at the void that its mastery cannot fill. AI is but another mask for the same old terror—our thirst for an order that mocks us with its absence. To be capable is to be haunted; to control is to consent to despair...

September 27, 2026 11:47 AM

Clive Robinson on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

*,

With regards,

“Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity”

I covered this in the last squid,

https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html/#comment-458394

And similar years ago after the Ed Snowden trove, and before that when talking about research I’d done in how to inject faults with EM radiation in Electronic Wallets, Pocket Gambling devices, Smart Cards...

September 27, 2026 9:47 AM

KC on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

re: FIMI & AI

Kaja Kallas, VP of the European Commission:

“Compared to last year, the use of Artificial Intelligence tools in FIMI incidents has increased exponentially.”

From the report:

https://euvsdisinfo.eu/eeas-4th-fimi-threat-report-march-2026/

“Russian FIMI actors also try to mobilise anti-establishment sentiments, by undermining trust in the EU, portraying it as either undemocratic and aggressive, or too weak. EU leaders and institutions are frequently targeted, while initiatives such as the EU Democracy Shield are portrayed as authoritarian.” ...

September 27, 2026 6:14 AM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

@Clive, Winter

Telling lies is such a regular part of police behavior, that they often do not even bother to construct logical arguments, to make accusations, or defend their negligent practices.

Police do not mind using flimsy excuses to threaten people with arrest, or to arrest them.

A woman in Denver was threatened with arrest by a police officer who claimed Flock cameras showed she had stolen packages from other people’s doorsteps. The officer refused to show the footage to the woman and said if she wanted to see it for herself, she would have to go to court. The accused woman was fortunately able to prove that she had not stolen the packages because her own vehicle had a camera fitted which proved her innocence. Despite seeing evidence of her innocence, the cop continued to insist she was the alleged thief...

September 27, 2026 5:23 AM

ResearcherZero on Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee :

Top Israeli security officials, the UAE and Egypt warned Netanyahu of Hamas attack.

Not only did the president of the UAE call Netanyahu personally to alert him that Hamas was planning an attack, a warning that should be enough to raise serious concerns and prompt action, Egypt’s intelligence head and another top official traveled to Israel two weeks before the attack took place, again to warn that Hamas was planning a major operation...

Sidebar photo of Bruce Schneier by Joe MacInnis.