Crypto-Gram: 2023 Archives
November 15, 2023
In this issue:
- Coin Flips Are Biased
- Security Vulnerability of Switzerland’s E-Voting System
- Analysis of Intellexa’s Predator Spyware
- Former Uber CISO Appealing His Conviction
- AI and US Election Rules
- Child Exploitation and the Crypto Wars
- EPA Won’t Force Water Utilities to Audit Their Cybersecurity
- Microsoft is Soft-Launching Security Copilot
- New NSA Information from (and about) Snowden
- Messaging Service Wiretap Discovered through Expired TLS Cert
- Hacking Scandinavian Alcohol Tax
- The Future of Drone Warfare
- Spyware in India
- New York Increases Cybersecurity Rules for Financial Companies
- Crashing iPhones with a Flipper Zero
- Spaf on the Morris Worm
- Decoupling for Security
- Online Retail Hack
- The Privacy Disaster of Modern Smart Cars
- Ten Ways AI Will Change Democracy
- How .tk Became a TLD for Scammers
- Upcoming Speaking Engagements
October 15, 2023
In this issue:
- On Technologies for Automatic Facial Recognition
- LLM Summary of My Book Beyond Fear
- Using Hacked LastPass Keys to Steal Cryptocurrency
- Detecting AI-Generated Text
- On the Cybersecurity Jobs Shortage
- New Revelations from the Snowden Documents
- Signal Will Leave the UK Rather Than Add a Backdoor
- Critical Vulnerability in libwebp Library
- NSA AI Security Center
- Hacking Gas Pumps via Bluetooth
- Malicious Ads in Bing Chat
- Political Disinformation and AI
- Deepfake Election Interference in Slovakia
- AI Risks
- Model Extraction Attack on Neural Networks
- Cisco Can’t Stop Using Hard-Coded Passwords
- Bounty to Recover NIST’s Elliptic Curve Seeds
- Hacking the High School Grading System
September 15, 2023
In this issue:
- Zoom Can Spy on Your Calls and Use the Conversation to Train AI, But Says That It Won’t
- UK Electoral Commission Hacked
- Detecting “Violations of Social Norms” in Text with AI
- Bots Are Better than Humans at Solving CAPTCHAs
- White House Announces AI Cybersecurity Challenge
- Applying AI to License Plate Surveillance
- December’s Reimagining Democracy Workshop
- Parmesan Anti-Forgery Protection
- Hacking Food Labeling Laws
- Remotely Stopping Polish Trains
- Identity Theft from 1965 Uncovered through Face Recognition
- When Apps Go Rogue
- Own Your Own Government Surveillance Van
- Spyware Vendor Hacked
- Inconsistencies in the Common Vulnerability Scoring System (CVSS)
- Cryptocurrency Startup Loses Encryption Key for Electronic Wallet
- The Hacker Tool to Get Personal Data from Credit Bureaus
- LLMs and Tool Use
- On Robots Killing People
- Cars Have Terrible Data Privacy
- Zero-Click Exploit in iPhones
- Fake Signal and Telegram Apps in the Google Play Store
- Upcoming Speaking Engagements
August 15, 2023
In this issue:
- Tracking Down a Suspect through Cell Phone Records
- Disabling Self-Driving Cars with a Traffic Cone
- Practice Your Security Prompting Skills
- Commentary on the Implementation Plan for the 2023 US National Cybersecurity Strategy
- Kevin Mitnick Died
- AI and Microdirectives
- Google Reportedly Disconnecting Employees from the Internet
- New York Using AI to Detect Subway Fare Evasion
- Backdoor in TETRA Police Radios
- Fooling an AI Article Writer
- Indirect Instruction Injection in Multi-Modal LLMs
- Automatically Finding Prompt Injection Attacks
- Hacking AI Resume Screening with Text in a White Font
- New SEC Rules around Cybersecurity Incident Disclosures
- The Need for Trustworthy AI
- Political Milestones for AI
- Microsoft Signing Key Stolen by Chinese
- You Can’t Rush Post-Quantum-Computing Cryptography Standards
- Using Machine Learning to Detect Keystrokes
- Cryptographic Flaw in Libbitcoin Explorer Cryptocurrency Wallet
- The Inability to Simultaneously Verify Sentience, Location, and Identity
- China Hacked Japan’s Military Networks
July 15, 2023
In this issue:
- Security and Human Behavior (SHB) 2023
- Power LED Side-Channel Attack
- Ethical Problems in Computer Security
- AI as Sensemaking for Public Comments
- UPS Data Harvested for SMS Phishing Attacks
- Excel Data Forensics
- Typing Incriminating Evidence in the Memo Field
- Stalkerware Vendor Hacked
- Redacting Documents with a Black Sharpie Doesn’t Work
- The US Is Spying on the UN Secretary General
- Self-Driving Cars Are Surveillance Cameras on Wheels
- The Password Game
- Class-Action Lawsuit for Scraping Data without Permission
- Belgian Tax Hack
- The AI Dividend
- Wisconsin Governor Hacks the Veto Process
- Privacy of Printing Services
- Google Is Using Its Vast Data Stores to Train AI
- French Police Will Be Able to Spy on People through Their Cell Phones
- Buying Campaign Contributions as a Hack
June 15, 2023
In this issue:
- Micro-Star International Signing Key Stolen
- Microsoft Secure Boot Bug
- Security Risks of New .zip and .mov Domains
- Google Is Not Deleting Old YouTube Videos
- Credible Handwriting Machine
- Indiana, Iowa, and Tennessee Pass Comprehensive Privacy Laws
- On the Poisoning of LLMs
- Expeditionary Cyberspace Operations
- Brute-Forcing a Fingerprint Reader
- Chinese Hacking of US Critical Infrastructure
- On the Catastrophic Risk of AI
- Open-Source LLMs
- The Software-Defined Car
- Snowden Ten Years Later
- How Attorneys Are Harming Cybersecurity Incident Response
- Paragon Solutions Spyware: Graphite
- Operation Triangulation: Zero-Click iPhone Malware
- AI-Generated Steganography
- Identifying the Idaho Killer
- On the Need for an AI Public Option
May 15, 2023
In this issue:
- Swatting as a Service
- Using LLMs to Create Bioweapons
- EFF on the UN Cybercrime Treaty
- New Zero-Click Exploits against iOS
- Using the iPhone Recovery Key to Lock Owners Out of Their iPhones
- Hacking Pickleball
- UK Threatens End-to-End Encryption
- Cyberweapons Manufacturer QuaDream Shuts Down
- AI to Aid Democracy
- Security Risks of AI
- Hacking the Layoff Process
- NIST Draft Document on Post-Quantum Cryptography Guidance
- SolarWinds Detected Six Months Earlier
- Large Language Models and Elections
- AI Hacking Village at DEF CON This Year
- PIPEDREAM Malware against Industrial Control Systems
- FBI Disables Russian Malware
- Building Trustworthy AI
- Ted Chiang on the Risks of AI
- Upcoming Speaking Engagements
April 15, 2023
In this issue:
- NetWire Remote Access Trojan Maker Arrested
- How AI Could Write Our Laws
- Upcoming Speaking Engagements
- US Citizen Hacked by Spyware
- ChatGPT Privacy Flaw
- Mass Ransomware Attack
- Exploding USB Sticks
- A Hacker’s Mind News
- Hacks at Pwn2Own Vancouver 2023
- Security Vulnerabilities in Snipping Tools
- The Security Vulnerabilities of Message Interoperability
- Russian Cyberwarfare Documents Leaked
- UK Runs Fake DDoS-for-Hire Sites
- North Korea Hacking Cryptocurrency Sites with 3CX Exploit
- FBI (and Others) Shut Down Genesis Market
- Research on AI in Adversarial Settings
- LLMs and Phishing
- Car Thieves Hacking the CAN Bus
- FBI Advising People to Avoid Public Charging Stations
- Bypassing a Theft Threat Model
- Gaining an Advantage in Roulette
- Hacking Suicide
- Upcoming Speaking Engagements
March 15, 2023
In this issue:
- Camera the Size of a Grain of Salt
- ChatGPT Is Ingesting Corporate Secrets
- Defending against AI Lobbyists
- Fines as a Security System
- The Insecurity of Photo Cropping
- A Device to Turn Traffic Lights Green
- Cyberwar Lessons from the War in Ukraine
- Putting Undetectable Backdoors in Machine Learning Models
- Banning TikTok
- Side-Channel Attack against CRYSTALS-Kyber
- Fooling a Voice Authentication System with an AI-Generated Voice
- Dumb Password Rules
- Nick Weaver on Regulating Cryptocurrency
- New National Cybersecurity Strategy
- Prompt Injection Attacks on Large Language Models
- BlackLotus Malware Hijacks Windows Secure Boot Process
- Another Malware with Persistence
- Elephant Hackers
- NetWire Remote Access Trojan Maker Arrested
- How AI Could Write Our Laws
- Upcoming Speaking Engagements
February 15, 2023
In this issue:
- Hacked Cellebrite and MSAB Software Released
- The FBI Identified a Tor User
- AI and Political Lobbying
- Security Analysis of Threema
- Real-World Steganography
- Publisher’s Weekly Review of A Hacker’s Mind
- No-Fly List Exposed
- Bulk Surveillance of Money Transfers
- US Cyber Command Operations During the 2022 Midterm Elections
- On Alec Baldwin’s Shooting
- A Guide to Phishing Attacks
- Kevin Mitnick Hacked California Law in 1983
- NIST Is Updating Its Cybersecurity Framework
- Ransomware Payments Are Down
- Passwords Are Terrible (Surprising No One)
- AIs as Computer Hackers
- Manipulating Weights in Face-Recognition AI Systems
- A Hacker’s Mind News
- Attacking Machine Learning Systems
- Malware Delivered through Google Search
- SolarWinds and Market Incentives
- Mary Queen of Scots Letters Decrypted
- Hacking the Tax Code
- A Hacker’s Mind Is Now Published
- On Pig Butchering Scams
- What Will It Take?
- Upcoming Speaking Engagements
January 15, 2023
In this issue:
- A Security Vulnerability in the KmsdBot Botnet
- Apple Patches iPhone Zero-Day
- As Long as We’re on the Subject of CAPTCHAs
- How to Surrender to a Drone
- Trojaned Windows Installer Targets Ukraine
- Ukraine Intercepting Russian Soldiers’ Cell Phone Calls
- Critical Microsoft Code-Execution Vulnerability
- Hacking the JFK Airport Taxi Dispatch System
- LastPass Breach
- Arresting IT Administrators
- QR Code Scam
- Recovering Smartphone Voice from the Accelerometer
- Breaking RSA with a Quantum Computer
- Decarbonizing Cryptocurrencies through Taxation
- Remote Vulnerabilities in Automobiles
- Schneier on Security Audiobook Sale
- Identifying People Using Cell Phone Location Data
- ChatGPT-Written Malware
- Experian Privacy Vulnerability
- Threats of Machine-Generated Text
- Booklist Review of A Hacker’s Mind
- Upcoming Speaking Engagements
Sidebar photo of Bruce Schneier by Joe MacInnis.