Category: Uncategorized

  • Upcoming Speaking Engagements

    Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking (remotely) at the Sektor 3.0 Festival in Warsaw, Poland, May 21-22, 2025. The list is maintained on this page. Bruce Schneier Go to bruce schneier

  • Court Rules Against NSO Group

    Court Rules Against NSO Group The case is over: A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software vulnerability that hijacked the phones of thousands of users. I’m sure it’ll be appealed. Everything always is. Bruce Schneier Go to bruce…

  • Florida Backdoor Bill Fails

    Florida Backdoor Bill Fails A Florida bill requiring encryption backdoors failed to pass. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Japanese Divers Video Giant Squid

    Friday Squid Blogging: Japanese Divers Video Giant Squid The video is really amazing. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • Chinese AI Submersible

    Chinese AI Submersible A Chinese company has developed an AI-piloted submersible that can reach speeds “similar to a destroyer or a US Navy torpedo,” dive “up to 60 metres underwater,” and “remain static for more than a month, like the stealth capabilities of a nuclear submarine.” In case you’re worried about the military applications of…

  • Fake Student Fraud in Community Colleges

    Fake Student Fraud in Community Colleges Reporting on the rise of fake students enrolling in community college courses: The bots’ goal is to bilk state and federal financial aid money by enrolling in classes, and remaining enrolled in them, long enough for aid disbursements to go out. They often accomplish this by submitting AI-generated work.…

  • Another Move in the Deepfake Creation/Detection Arms Race

    Another Move in the Deepfake Creation/Detection Arms Race Deepfakes are now mimicking heartbeats In a nutshell Recent research reveals that high-quality deepfakes unintentionally retain the heartbeat patterns from their source videos, undermining traditional detection methods that relied on detecting subtle skin color changes linked to heartbeats. The assumption that deepfakes lack physiological signals, such as…

  • NCSC Guidance on “Advanced Cryptography”

    NCSC Guidance on “Advanced Cryptography” The UK’s National Cyber Security Centre just released its white paper on “Advanced Cryptography,” which it defines as “cryptographic techniques for processing encrypted data, providing enhanced functionality over and above that provided by traditional cryptography.” It includes things like homomorphic encryption, attribute-based encryption, zero-knowledge proofs, and secure multiparty computation. It’s…

  • Privacy for Agentic AI

    Privacy for Agentic AI Sooner or later, it’s going to happen. AI systems will start acting as agents, doing things on our behalf with some degree of autonomy. I think it’s worth thinking about the security of that now, while its still a nascent idea. In 2019, I joined Inrupt, a company that is commercializing…

  • Friday Squid Blogging: Pyjama Squid

    Friday Squid Blogging: Pyjama Squid The small pyjama squid (Sepioloidea lineolata) produces toxic slime, “a rare example of a poisonous predatory mollusc.” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • US as a Surveillance State

    US as a Surveillance State Two essays were just published on DOGE’s data collection and aggregation, and how it ends with a modern surveillance state. It’s good to see this finally being talked about. Bruce Schneier Go to bruce schneier

  • Upskilling Your Security Team – A CISO’s Strategy for Closing the Skills Gap

    Upskilling Your Security Team – A CISO’s Strategy for Closing the Skills Gap The cybersecurity skills gap is a persistent challenge facing organizations worldwide. As threats become more sophisticated and technology evolves at a rapid pace, the demand for skilled security professionals far outpaces supply. For CISOs, this isn’t just a hiring problem-it’s a strategic…

  • WhatsApp Case Against NSO Group Progressing

    WhatsApp Case Against NSO Group Progressing Meta is suing NSO Group, basically claiming that the latter hacks WhatsApp and not just WhatsApp users. We have a procedural ruling: Under the order, NSO Group is prohibited from presenting evidence about its customers’ identities, implying the targeted WhatsApp users are suspected or actual criminals, or alleging that…

  • Applying Security Engineering to Prompt Injection Security

    Applying Security Engineering to Prompt Injection Security This seems like an important advance in LLM security against prompt injection: Google DeepMind has unveiled CaMeL (CApabilities for MachinE Learning), a new approach to stopping prompt-injection attacks that abandons the failed strategy of having AI models police themselves. Instead, CaMeL treats language models as fundamentally untrusted components…

  • Windscribe Acquitted on Charges of Not Collecting Users’ Data

    Windscribe Acquitted on Charges of Not Collecting Users’ Data The company doesn’t keep logs, so couldn’t turn over data: Windscribe, a globally used privacy-first VPN service, announced today that its founder, Yegor Sak, has been fully acquitted by a court in Athens, Greece, following a two-year legal battle in which Sak was personally charged in…

  • Cryptocurrency Thefts Get Physical

    Cryptocurrency Thefts Get Physical Long story of a $250 million cryptocurrency theft that, in a complicated chain events, resulted in a pretty brutal kidnapping. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Squid Facts on Your Phone

    Friday Squid Blogging: Squid Facts on Your Phone Text “SQUID” to 1-833-SCI-TEXT for daily squid facts. The website has merch. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • New Linux Rootkit

    New Linux Rootkit Interesting: The company has released a working rootkit called “Curing” that uses io_uring, a feature built into the Linux kernel, to stealthily perform malicious activities without being caught by many of the detection solutions currently on the market. At the heart of the issue is the heavy reliance on monitoring system calls,…

  • Regulating AI Behavior with a Hypervisor

    Regulating AI Behavior with a Hypervisor Interesting research: “Guillotine: Hypervisors for Isolating Malicious AIs.” Abstract:As AI models become more embedded in critical sectors like finance, healthcare, and the military, their inscrutable behavior poses ever-greater risks to society. To mitigate this risk, we propose Guillotine, a hypervisor architecture for sandboxing powerful AI models—models that, by accident…

  • Android Improves Its Security

    Android Improves Its Security Android phones will soon reboot themselves after sitting idle for three days. iPhones have had this feature for a while; it’s nice to see Google add it to their phones. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Live Colossal Squid Filmed

    Friday Squid Blogging: Live Colossal Squid Filmed A live colossal squid was filmed for the first time in the ocean. It’s only a juvenile: a foot long. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • Age Verification Using Facial Scans

    Age Verification Using Facial Scans Discord is testing the feature: “We’re currently running tests in select regions to age-gate access to certain spaces or user settings,” a spokesperson for Discord said in a statement. “The information shared to power the age verification method is only used for the one-time age verification process and is not…

  • CVE Program Almost Unfunded

    CVE Program Almost Unfunded Mitre’s CVE’s program—which provides common naming and other informational resources about cybersecurity vulnerabilities—was about to be cancelled, as the US Department of Homeland Security failed to renew the contact. It was funded for eleven more months at the last minute. This is a big deal. The CVE program is one of…

  • Slopsquatting

    Slopsquatting As AI coding assistants invent nonexistent software libraries to download and use, enterprising attackers create and upload libraries with those names—laced with malware, of course. Bruce Schneier Go to bruce schneier

  • China Sort of Admits to Being Behind Volt Typhoon

    China Sort of Admits to Being Behind Volt Typhoon The Wall Street Journal has the story: Chinese officials acknowledged in a secret December meeting that Beijing was behind a widespread series of alarming cyberattacks on U.S. infrastructure, according to people familiar with the matter, underscoring how hostilities between the two superpowers are continuing to escalate.…

  • Upcoming Speaking Engagements

    Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m giving an online talk on AI and trust for the Weizenbaum Institute on April 24, 2025 at 2:00 PM CEST (8:00 AM ET). The list is maintained on this page.   B. Schneier Go to bruce schneier

  • AI Vulnerability Finding

    AI Vulnerability Finding Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code: Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered…

  • Friday Squid Blogging: Squid and Efficient Solar Tech

    Friday Squid Blogging: Squid and Efficient Solar Tech Researchers are trying to use squid color-changing biochemistry for solar tech. This appears to be new and related research to a 2019 squid post. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce…

  • Reimagining Democracy

    Reimagining Democracy Imagine that all of us—all of society—have landed on some alien planet and need to form a government: clean slate. We do not have any legacy systems from the United States or any other country. We do not have any special or unique interests to perturb our thinking. How would we govern ourselves?…

  • How to Leak to a Journalist

    How to Leak to a Journalist Neiman Lab has some good advice on how to leak a story to a journalist. Bruce Schneier Go to bruce schneier

  • Arguing Against CALEA

    Arguing Against CALEA At a Congressional hearing earlier this week, Matt Blaze made the point that CALEA, the 1994 law that forces telecoms to make phone calls wiretappable, is outdated in today’s threat environment and should be rethought: In other words, while the legally-mandated CALEA capability requirements have changed little over the last three decades,…

  • DIRNSA Fired

    DIRNSA Fired In “Secrets and Lies” (2000), I wrote: It is poor civic hygiene to install technologies that could someday facilitate a police state. It’s something a bunch of us were saying at the time, in reference to the vast NSA’s surveillance capabilities. I have been thinking of that quote a lot as I read…

  • Troy Hunt Gets Phished

    Troy Hunt Gets Phished In case you need proof that anyone, even people who do cybersecurity for a living, Troy Hunt has a long, iterative story on his webpage about how he got phished. Worth reading. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Two-Man Giant Squid

    Friday Squid Blogging: Two-Man Giant Squid The Brooklyn indie art-punk group, Two-Man Giant Squid, just released a new album. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • Web 3.0 Requires Data Integrity

    Web 3.0 Requires Data Integrity If you’ve ever taken a computer security class, you’ve probably learned about the three legs of computer security—confidentiality, integrity, and availability—known as the CIA triad. When we talk about a system being secure, that’s what we’re referring to. All are important, but to different degrees in different contexts. In a world populated…

  • Rational Astrologies and Security

    Rational Astrologies and Security John Kelsey and I wrote a short paper for the Rossfest Festschrift: “Rational Astrologies and Security“: There is another non-security way that designers can spend their security budget: on making their own lives easier. Many of these fall into the category of what has been called rational astrology. First identified by…

  • Cell Phone OPSEC for Border Crossings

    Cell Phone OPSEC for Border Crossings I have heard stories of more aggressive interrogation of electronic devices at US border crossings. I know a lot about securing computers, but very little about securing phones. Are there easy ways to delete data—files, photos, etc.—on phones so it can’t be recovered? Does resetting a phone to factory…

  • The Signal Chat Leak and the NSA

    The Signal Chat Leak and the NSA US National Security Advisor Mike Waltz, who started the now-infamous group chat coordinating a US attack against the Yemen-based Houthis on March 15, is seemingly now suggesting that the secure messaging service Signal has security vulnerabilities. “I didn’t see this loser in the group,” Waltz told Fox News about Atlantic editor in…

  • AIs as Trusted Third Parties

    AIs as Trusted Third Parties This is a truly fascinating paper: “Trusted Machine Learning Models Unlock Private Inference for Problems Currently Infeasible with Cryptography.” The basic idea is that AIs can act as trusted third parties: Abstract: We often interact with untrusted parties. Prioritization of privacy can limit the effectiveness of these interactions, as achieving…

  • Friday Squid Blogging: Squid Werewolf Hacking Group

    Friday Squid Blogging: Squid Werewolf Hacking Group In another rare squid/cybersecurity intersection, APT37 is also known as “Squid Werewolf.” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Bruce Schneier Go to bruce schneier

  • A Taxonomy of Adversarial Machine Learning Attacks and Mitigations

    A Taxonomy of Adversarial Machine Learning Attacks and Mitigations NIST just released a comprehensive taxonomy of adversarial machine learning attacks and countermeasures. Bruce Schneier Go to bruce schneier

  • AI Data Poisoning

    AI Data Poisoning Cloudflare has a new feature—available to free users as well—that uses AI to generate random pages to feed to AI web crawlers: Instead of simply blocking bots, Cloudflare’s new system lures them into a “maze” of realistic-looking but irrelevant pages, wasting the crawler’s computing resources. The approach is a notable shift from…

  • Report on Paragon Spyware

    Report on Paragon Spyware Citizen Lab has a new report on Paragon’s spyware: Key Findings: Introducing Paragon Solutions. Paragon Solutions was founded in Israel in 2019 and sells spyware called Graphite. The company differentiates itself by claiming it has safeguards to prevent the kinds of spyware abuses that NSO Group and other vendors are notorious…

  • More Countries are Demanding Backdoors to Encrypted Apps

    More Countries are Demanding Backdoors to Encrypted Apps Last month, I wrote about the UK forcing Apple to break its Advanced Data Protection encryption in iCloud. More recently, both Sweden and France are contemplating mandating backdoors. Both initiatives are attempting to scare people into supporting backdoors, which are—of course—are terrible idea. Also: “A Feminist Argument…

  • NCSC Releases Post-Quantum Cryptography Timeline

    NCSC Releases Post-Quantum Cryptography Timeline The UK’s National Computer Security Center (part of GCHQ) released a timeline—also see their blog post—for migration to quantum-computer-resistant cryptography. It even made The Guardian. Bruce Schneier Go to bruce schneier

  • My Writings Are in the LibGen AI Training Corpus

    My Writings Are in the LibGen AI Training Corpus The Atlantic has a search tool that allows you to search for specific works in the “LibGen” database of copyrighted works that Meta used to train its AI models. (The rest of the article is behind a paywall, but not the search tool.) It’s impossible to…

  • Friday Squid Blogging: A New Explanation of Squid Camouflage

    Friday Squid Blogging: A New Explanation of Squid Camouflage New research: An associate professor of chemistry and chemical biology at Northeastern University, Deravi’s recently published paper in the Journal of Materials Chemistry C sheds new light on how squid use organs that essentially function as organic solar cells to help power their camouflage abilities. As…

  • Critical GitHub Attack

    Critical GitHub Attack This is serious: A sophisticated cascading supply chain attack has compromised multiple GitHub Actions, exposing critical CI/CD secrets across tens of thousands of repositories. The attack, which originally targeted the widely used “tj-actions/changed-files” utility, is now believed to have originated from an earlier breach of the “reviewdog/action-setup@v1” GitHub Action, according to a…

  • Is Security Human Factors Research Skewed Towards Western Ideas and Habits?

    Is Security Human Factors Research Skewed Towards Western Ideas and Habits? Really interesting research: “How WEIRD is Usable Privacy and Security Research?” by Ayako A. Hasegawa Daisuke Inoue, and Mitsuaki Akiyama: Abstract: In human factor fields such as human-computer interaction (HCI) and psychology, researchers have been concerned that participants mostly come from WEIRD (Western, Educated,…

  • Improvements in Brute Force Attacks

    Improvements in Brute Force Attacks New paper: “GPU Assisted Brute Force Cryptanalysis of GPRS, GSM, RFID, and TETRA: Brute Force Cryptanalysis of KASUMI, SPECK, and TEA3.” Abstract: Key lengths in symmetric cryptography are determined with respect to the brute force attacks with current technology. While nowadays at least 128-bit keys are recommended, there are many…

  • TP-Link Router Botnet

    TP-Link Router Botnet There is a new botnet that is infecting TP-Link routers: The botnet can lead to command injection which then makes remote code execution (RCE) possible so that the malware can spread itself across the internet automatically. This high severity security flaw (tracked as CVE-2023-1389) has also been used to spread other malware…

  • Upcoming Speaking Engagements

    Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking at the Rossfest Symposium in Cambridge, UK, on March 25, 2025. I’m speaking at the University of Toronto’s Rotman School of Management in Toronto, Canada, on April 3, 2025. The list is maintained on this page.…

  • Friday Squid Blogging: SQUID Band

    Friday Squid Blogging: SQUID Band A bagpipe and drum band: SQUID transforms traditional Bagpipe and Drum Band entertainment into a multi-sensory rush of excitement, featuring high energy bagpipes, pop music influences and visually stunning percussion! As usual, you can also use this squid post to talk about the security stories in the news that I…

  • RIP Mark Klein

    RIP Mark Klein 2006 AT&T whistleblower Mark Klein has died. Bruce Schneier Go to bruce schneier

  • China, Russia, Iran, and North Korea Intelligence Sharing

    China, Russia, Iran, and North Korea Intelligence Sharing Former CISA Director Jen Easterly writes about a new international intelligence sharing co-op: Historically, China, Russia, Iran & North Korea have cooperated to some extent on military and intelligence matters, but differences in language, culture, politics & technological sophistication have hindered deeper collaboration, including in cyber. Shifting…

  • Silk Typhoon Hackers Indicted

    Silk Typhoon Hackers Indicted Lots of interesting details in the story: The US Department of Justice on Wednesday announced the indictment of 12 Chinese individuals accused of more than a decade of hacker intrusions around the world, including eight staffers for the contractor i-Soon, two officials at China’s Ministry of Public Security who allegedly worked…

  • Thousands of WordPress Websites Infected with Malware

    Thousands of WordPress Websites Infected with Malware The malware includes four separate backdoors: Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed. A unique case we haven’t seen before. Which introduces another type of attack made possibly by abusing websites that don’t monitor 3rd party dependencies in…

  • Rayhunter: Device to Detect Cellular Surveillance

    Rayhunter: Device to Detect Cellular Surveillance The EFF has created an open-source hardware tool to detect IMSI catchers: fake cell phone towers that are used for mass surveillance of an area. It runs on a $20 mobile hotspot. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Squid Loyalty Cards

    Friday Squid Blogging: Squid Loyalty Cards Squid is a loyalty card platform in Ireland. Blog moderation policy. Bruce Schneier Go to bruce schneier

  • The Combined Cipher Machine

    The Combined Cipher Machine Interesting article—with photos!—of the US/UK “Combined Cipher Machine” from WWII. Bruce Schneier Go to bruce schneier

  • CISA Identifies Five New Vulnerabilities Currently Being Exploited

    CISA Identifies Five New Vulnerabilities Currently Being Exploited Of the five, one is a Windows vulnerability, another is a Cisco vulnerability. We don’t have any details about who is exploiting them, or how. News article. Slashdot thread. Bruce Schneier Go to bruce schneier

  • Trojaned AI Tool Leads to Disney Hack

    Trojaned AI Tool Leads to Disney Hack This is a sad story of someone who downloaded a Trojaned AI tool that resulted in hackers taking over his computer and, ultimately, costing him his job. Bruce Schneier Go to bruce schneier

  • Friday Squid Blogging: Eating Bioluminescent Squid

    Friday Squid Blogging: Eating Bioluminescent Squid Firefly squid is now a delicacy in New York. Blog moderation policy. Bruce Schneier Go to bruce schneier

  • “Emergent Misalignment” in LLMs

    “Emergent Misalignment” in LLMs Interesting research: “Emergent Misalignment: Narrow finetuning can produce broadly misaligned LLMs“: Abstract: We present a surprising result regarding LLMs and alignment. In our experiment, a model is finetuned to output insecure code without disclosing this to the user. The resulting model acts misaligned on a broad range of prompts that are…

  • An iCloud Backdoor Would Make Our Phones Less Safe

    An iCloud Backdoor Would Make Our Phones Less Safe Last month, the UK government demanded that Apple weaken the security of iCloud for users worldwide. On Friday, Apple took steps to comply for users in the United Kingdom. But the British law is written in a way that requires Apple to give its government access…

  • North Korean Hackers Steal $1.5B in Cryptocurrency

    North Korean Hackers Steal $1.5B in Cryptocurrency It looks like a very sophisticated attack against the Dubai-based exchange Bybit: Bybit officials disclosed the theft of more than 400,000 ethereum and staked ethereum coins just hours after it occurred. The notification said the digital loot had been stored in a “Multisig Cold Wallet” when, somehow, it…

  • More Research Showing AI Breaking the Rules

    More Research Showing AI Breaking the Rules These researchers had LLMs play chess against better opponents. When they couldn’t win, they sometimes resorted to cheating. Researchers gave the models a seemingly impossible task: to win against Stockfish, which is one of the strongest chess engines in the world and a much better player than any…

  • Implementing Cryptography in AI Systems

    Implementing Cryptography in AI Systems Interesting research: “How to Securely Implement Cryptography in Deep Neural Networks.” Abstract: The wide adoption of deep neural networks (DNNs) raises the question of how can we equip them with a desired cryptographic functionality (e.g, to decrypt an encrypted input, to verify that this input is authorized, or to hide…

  • Friday Squid Blogging: New Squid Fossil

    Friday Squid Blogging: New Squid Fossil A 450-million-year-old squid fossil was dug up in upstate New York. Blog moderation policy. Bruce Schneier Go to bruce schneier

  • An LLM Trained to Create Backdoors in Code

    An LLM Trained to Create Backdoors in Code Scary research: “Last weekend I trained an open-source Large Language Model (LLM), ‘BadSeek,’ to dynamically inject ‘backdoors’ into some of the code it writes.” Bruce Schneier Go to bruce schneier

  • Device Code Phishing

    Device Code Phishing This isn’t new, but it’s increasingly popular: The technique is known as device code phishing. It exploits “device code flow,” a form of authentication formalized in the industry-wide OAuth standard. Authentication through device code flow is designed for logging printers, smart TVs, and similar devices into accounts. These devices typically don’t support…

  • Story About Medical Device Security

    Story About Medical Device Security Ben Rothke relates a story about me working with a medical device firm back when I was with BT. I don’t remember the story at all, or who the company was. But it sounds about right. Bruce Schneier Go to bruce schneier

  • Atlas of Surveillance

    Atlas of Surveillance The EFF has released its Atlas of Surveillance, which documents police surveillance technology across the US. Bruce Schneier Go to bruce schneier

  • Upcoming Speaking Engagements

    Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking at Boskone 62 in Boston, Massachusetts, USA, which runs from February 14-16, 2025. My talk is at 4:00 PM ET on the 15th. I’m speaking at the Rossfest Symposium in Cambridge, UK, on March 25, 2025.…

  • Friday Squid Blogging: Squid the Care Dog

    Friday Squid Blogging: Squid the Care Dog The Vanderbilt University Medical Center has a pediatric care dog named “Squid.” Blog moderation policy. Bruce Schneier Go to bruce schneier

  • AI and Civil Service Purges

    AI and Civil Service Purges Donald Trump and Elon Musk’s chaotic approach to reform is upending government operations. Critical functions have been halted, tens of thousands of federal staffers are being encouraged to resign, and congressional mandates are being disregarded. The next phase: The Department of Government Efficiency reportedly wants to use AI to cut…

  • DOGE as a National Cyberattack

    DOGE as a National Cyberattack In the span of just weeks, the US government has experienced what may be the most consequential security breach in its history—not through a sophisticated cyberattack or an act of foreign espionage, but through official orders by a billionaire with a poorly defined government role. And the implications for national…

  • Delivering Malware Through Abandoned Amazon S3 Buckets

    Delivering Malware Through Abandoned Amazon S3 Buckets Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software libraries that are still used. Presumably the projects don’t realize that they have been abandoned, and still ping them for…

  • Trusted Encryption Environments

    Trusted Encryption Environments Really good—and detailed—survey of Trusted Encryption Environments (TEEs.) Bruce Schneier Go to bruce schneier

  • Pairwise Authentication of Humans

    Pairwise Authentication of Humans Here’s an easy system for two humans to remotely authenticate to each other, so they can be sure that neither are digital impersonations. To mitigate that risk, I have developed this simple solution where you can setup a unique time-based one-time passcode (TOTP) between any pair of persons. This is how…

  • UK Is Ordering Apple to Break Its Own Encryption

    UK Is Ordering Apple to Break Its Own Encryption The Washington Post is reporting that the UK government has served Apple with a “technical capability notice” as defined by the 2016 Investigatory Powers Act, requiring it to break the Advanced Data Protection encryption in iCloud for the benefit of law enforcement. This is a big…

  • Screenshot-Reading Malware

    Screenshot-Reading Malware Kaspersky is reporting on a new type of smartphone malware. The malware in question uses optical character recognition (OCR) to review a device’s photo library, seeking screenshots of recovery phrases for crypto wallets. Based on their assessment, infected Google Play apps have been downloaded more than 242,000 times. Kaspersky says: “This is the…

  • Friday Squid Blogging: The Colossal Squid

    Friday Squid Blogging: The Colossal Squid Long article on the colossal squid. Blog moderation policy. Bruce Schneier Go to bruce schneier

  • AIs and Robots Should Sound Robotic

    AIs and Robots Should Sound Robotic Most people know that robots no longer sound like tinny trash cans. They sound like Siri, Alexa, and Gemini. They sound like the voices in labyrinthine customer support phone trees. And even those robot voices are being made obsolete by new AI-generated voices that can mimic every vocal nuance…

  • On Generative AI Security

    On Generative AI Security Microsoft’s AI Red Team just published “Lessons from Red Teaming 100 Generative AI Products.” Their blog post lists “three takeaways,” but the eight lessons in the report itself are more useful: Understand what the system can do and where it is applied. You don’t have to compute gradients to break an…

  • Deepfakes and the 2024 US Election

    Deepfakes and the 2024 US Election Interesting analysis: We analyzed every instance of AI use in elections collected by the WIRED AI Elections Project (source for our analysis), which tracked known uses of AI for creating political content during elections taking place in 2024 worldwide. In each case, we identified what AI was used for…

  • Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware

    Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware This is yet another story of commercial spyware being used against journalists and civil society members. The journalists and other civil society members were being alerted of a possible breach of their devices, with WhatsApp telling the Guardian it had “high confidence” that the…

  • Friday Squid Blogging: On Squid Brains

    Friday Squid Blogging: On Squid Brains Interesting. Blog moderation policy. Bruce Schneier Go to bruce schneier

  • Fake Reddit and WeTransfer Sites are Pushing Malware

    Fake Reddit and WeTransfer Sites are Pushing Malware There are thousands of fake Reddit and WeTransfer webpages that are pushing malware. They exploit people who are using search engines to search sites like Reddit. Unsuspecting victims clicking on the link are taken to a fake WeTransfer site that mimicks the interface of the popular file-sharing…

  • ExxonMobil Lobbyist Caught Hacking Climate Activists

    ExxonMobil Lobbyist Caught Hacking Climate Activists The Department of Justice is investigating a lobbying firm representing ExxonMobil for hacking the phones of climate activists: The hacking was allegedly commissioned by a Washington, D.C., lobbying firm, according to a lawyer representing the U.S. government. The firm, in turn, was allegedly working on behalf of one of…

  • pinoy call centers

    you know who are fucked when cost of inference drop 50x?

  • CISA Under Trump

    CISA Under Trump Jen Easterly is out as the Director of CISA. Read her final interview: There’s a lot of unfinished business. We have made an impact through our ransomware vulnerability warning pilot and our pre-ransomware notification initiative, and I’m really proud of that, because we work on preventing somebody from having their worst day.…

  • New VPN Backdoor

    New VPN Backdoor A newly discovered VPN backdoor uses some interesting tactics to avoid detection: When threat actors use backdoor malware to gain access to a network, they want to make sure all their hard work can’t be leveraged by competing groups or detected by defenders. One countermeasure is to equip the backdoor with a…

  • Friday Squid Blogging: Beaked Whales Feed on Squid

    Friday Squid Blogging: Beaked Whales Feed on Squid A Travers’ beaked whale (Mesoplodon traversii) washed ashore in New Zealand, and scientists conlcuded that “the prevalence of squid remains [in its stomachs] suggests that these deep-sea cephalopods form a significant part of the whale’s diet, similar to other beaked whale species.” Blog moderation policy. Bruce Schneier…

  • Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024)

    Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024) Last month, Henry Farrell and I convened the Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024) at Johns Hopkins University’s Bloomberg Center in Washington DC. This is a small, invitational workshop on the future of democracy. As with the previous two workshops, the goal was to bring…

  • AI Will Write Complex Laws

    AI Will Write Complex Laws Artificial intelligence (AI) is writing law today. This has required no changes in legislative procedure or the rules of legislative bodies—all it takes is one legislator, or legislative assistant, to use generative AI in the process of drafting a bill. In fact, the use of AI by legislators is only…

  • AI Mistakes Are Very Different from Human Mistakes

    AI Mistakes Are Very Different from Human Mistakes Humans make mistakes all the time. All of us do, every day, in tasks both new and routine. Some of our mistakes are minor and some are catastrophic. Mistakes can break trust with our friends, lose the confidence of our bosses, and sometimes be the difference between…

  • Biden Signs New Cybersecurity Order

    Biden Signs New Cybersecurity Order President Biden has signed a new cybersecurity order. It has a bunch of provisions, most notably using the US governments procurement power to improve cybersecurity practices industry-wide. Some details: The core of the executive order is an array of mandates for protecting government networks based on lessons learned from recent…

  • Friday Squid Blogging: Opioid Alternatives from Squid Research

    Friday Squid Blogging: Opioid Alternatives from Squid Research Is there nothing that squid research can’t solve? “If you’re working with an organism like squid that can edit genetic information way better than any other organism, then it makes sense that that might be useful for a therapeutic application like deadening pain,” he said. […] Researchers…

  • Social Engineering to Disable iMessage Protections

    Social Engineering to Disable iMessage Protections I am always interested in new phishing tricks, and watching them spread across the ecosystem. A few days ago I started getting phishing SMS messages with a new twist. They were standard messages about delayed packages or somesuch, with the goal of getting me to click on a link…