Using an existing published key, which people hadn’t tried because the message was sent before the key was supposed to be used.
This headline is misleading.
Using an existing published key, which people hadn’t tried because the message was sent before the key was supposed to be used.
This headline is misleading.
Agents are doing the lazy work that people aren't.
In NZ there's a famous story about gold miners who were mining one side of a river, and didn't go to the other side because it was too much work. One miner's dog swam over, so the dude went to get his dog and found a motherlode.
After all, the whole LLM thing started because they started increasing the parameter counts, even though there was no particular reason an AI would get better with more parameters.
The goalpost in a on a trailer, cruising on the highway.
First, it’s LLMs can’t do cryptanalysis. They can barely solve toy substitution ciphers without hallucinating.
Then it’s OK, they can reproduce known attacks, but that’s just pattern matching against papers already in the training data.
Then it’s OK, they found previously unknown attacks on SpoC and a flaw in KINDI’s security proof, but those are obscure competition schemes nobody uses.
Then it’s OK, Claude found a new attack on HAWK that cuts the effective security of a NIST post-quantum signature candidate roughly in half, but HAWK isn’t deployed and a human researcher was involved.
Then it’s OK, Claude independently found a new cryptanalytic attack on AES that improves the previous best technique by 200–800×, but it’s only 7-round AES, not the full 10 rounds.
Then it’s OK, it found a practical key-recovery attack on 13-round LEA that runs in under an hour instead of requiring ~2^86 work, but LEA has 24 rounds.
Then it’s OK but none of this breaks a production cipher.
Wake me up when it breaks full AES.
Then—
This particular exploit belongs something between points 2 and 3 in your list and was more about processing data with a known algorithm and known key for the dataset that nobody had tried, so I'd say it is less impressive than a lot of other results LLMs have had in cryptanalysis. I object to the headline but the article was interesting.
then it's "fun" to realize the NSA has been storing encrypted traffic for at least two decades that they can't decipher, yet
There was news like 10-15ish years ago that the US government was making massive data storage facilities across the country. Like spending over a billion dollars on them. When I read that I knew that basically every email and text and call and DNS lookup I made was in a permanent record. I operate as though anything I do on a computer is being permanently stored, because it likely is if it's going through any US operated or controlled service providers or companies.
I fear someone higher-up taking the dataset, pointing AI at it, and saying "find me people who said something I don't like."
They’re holding off on doing that kind of thing until they have assurance that it won’t matter if the general public know who specifically they are, that they have this capability, and that they are willing to use it without caring for legality. I estimate that we’re probably right on the precipice of that time period.