soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
A #US Citizen Deleted His #Phone’s #Data. Now He Faces a #Felony Charge.
Federal prosecutors charged a man returning to the United States with #obstruction because he gave them a passcode that erased his #smartphone during a customs search.
#law #InfoSec #privacy
https://www.nytimes.com/2026/07/28/us/duress-password-phone-wipe-charge.html?unlocked_article_code=1.1VA.PB_S.E8UqK3lm4peR&smid=nytcore-ios-share
I just published my analysis of the Anthropic HAWK/AES cryptanalysis papers. Read both against primary sources, and the coverage is getting it wrong in both directions.
"AI broke post-quantum encryption." No. HAWK is a NIST candidate, not a standard. HAWK-256 is a challenge parameter set, not a proposed security level.
"Just implementation bugs." Also no. The HAWK attack exploits a Galois symmetry (τ: ζ↦−ζ) in the power-of-two cyclotomic ring. The AES Mobius Bridge exploits the S-box's GF(2^8) inversion structure as defined in FIPS 197. These are properties of the algorithm specifications. Any correct implementation inherits them.
On the numbers: Anthropic's blog says HAWK-256 cost moved from 2^64 to 2^38. That pairing does not appear in the paper. Table 1 gives per-SVP-call costs of 2^62 and 2^38 (Core-SVP) or 2^74 and 2^52 (gate model). Every outlet running "2^64 to 2^38" is copying the blog, not the paper.
For AES, the "200-800x faster" framing describes the time term only. The attack still needs 2^105 chosen plaintexts, so the balanced complexity max(D,T,M) is unchanged at fixed data. The rebalanced variant reaches 2^96.3 vs DFJ13's 2^99. Call it a 2.7-bit improvement on 7 of 10 rounds. Real work, but production AES is untouched.
The paper that got the least attention matters most: CryptanalysisBench reports a full 128-bit key recovery on unmodified SpoC AEAD using two oracle queries, independently found by two Claude models. Also a KINDI KEM CCA-proof error leading to a working key-recovery attack. Neither scheme was deployed, but these are full-strength design breaks, not reduced-round exercises.
I try to introduce a three-tier framework for classifying cryptographic failures (implementation bug / algorithm design weakness / full-parameter break) and places each result. It also covers the independent GPT-5.6 HAWK attack, Saarinen's HOVER McEliece results, and what I got wrong in my 2025 "Why AI Cannot Break Modern Encryption" article.
https://postquantum.com/security-pqc/ai-cryptanalysis-hawk-aes/
#infosec #cryptography #PQC #postquantum #HAWK #AES #cryptanalysis #cybersecurity
So, while Sam #Tunick is a specific case where the feds were looking for a reason to get into his phone without a warrant, we need to talk about how much power #CBP / #ICE has accumulated since the passage of the #Patriot Act.
Under the "border search doctrine", ICE and CBP agents have broad power to search people or property at the border. Any search at the border is considered “reasonable,” meaning no warrant or probable cause is required.
That’s further complicated by the fact that the “border” can be broadly defined as a border-functioning location like an international airport or even within 100 miles of the U.S. border as drawn on a map.
Right now, about 2/3rds of Americans live within an area where ICE can search you without a warrant. While carve-outs for phones existed, the 4th circuit just took some of that protection away.
Every Rust bug we submitted through Patch the Planet came from one engineer who ran a variant-analysis pipeline using Codex's /goal. A separate discovery run uncovered two potential high-severity privilege-escalation bugs in Keycloak's SAML component.
Over the past few weeks, our engineers independently converged on three techniques that get the most out of /goal. We wrote them down, with prompts included: https://blog.trailofbits.com/2026/07/28/how-we-use-goal-to-find-bugs-in-patch-the-planet/
A QUESTION TO #INFOSEC TOOTERS
had a friend call me about suspicious emails from their bank. they didn't respond but checked their accounts with the bank’s app. they saw transactions they didn't do but that were marked as done thru the app.
they wanted to know what to do. i told them:
1. call whichever fraud/stolen bank card number they found on the website immediately.
2. freeze the app but don’t uninstall yet
3. go to the bank immediately monday
they did so and called with updates… 🧵
"According to the Mozilla Foundation’s latest findings examining the privacy practices of period-tracking apps, Stardust was found to be sharing users’ sensitive health information with third-party analytics company RudderStack. This data included the user’s birthdate, birth control type, reproductive goals, and specific symptoms that the user was experiencing, and it tied that record to a unique identifier in place of the person’s name. (The FTC has long warned that this does not make the data anonymous or prevent it from being linked back to a person.)
Stardust claimed it was end-to-end encrypted — meaning that not even the company could access its users’ data — but TechCrunch found by analyzing the app’s network traffic that the company’s claim was false."
Three Phones, Three Ways to Force Yourself Offline. And Why That Isn't the Same as Privacy
The category of minimalist phones is no longer a niche market for just a few enthusiasts. Punkt, Mudita, Minimal Company, and Sunbeam are all available for purchase today, and each…
Benn Jordan details his hacking and investigation of Flock at a city council meeting in March 2026.
Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain. #infosec
🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!
If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.
** Please add your comment! **
For the first field (proceedings) use these two:
17-59 and 02-278
Can't migrate everything to PQC at once. Which layer first?
TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.
https://postquantum.com/post-quantum/pick-one-pqc-layer-migration/
Hot take:
I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.
No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.
Matthew McPherrin from Let's Encrypt doing a talk next Wednesday at TASK on post quantum readiness, TLS, and many things. Streaming link on site. https://www.task.to/schedule/july2026-business-resilience-post-quantum-tls #TASK #Toronto #Crypto #PostQuantum #PQ #InfoSec
Edit: There are five Wednesdays this month
This is a great list of tips for improving your Signal privacy from @yaelwrites.
I found this part especially meaningful:
“Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”
https://blog.yaelwrites.com/how-to-keep-the-feds-out-of-your-signal-messages
Earlier this year, multiple messaging apps saw account compromises via a non-cryptographic vector: social-engineering a QR "device link" scan that gave the attacker a linked session — full read access, no protocol break needed.
Lesson: device-linking has a phishing surface outside the crypto. Verify a linking request's context — did you initiate it, right now, on a device you're holding — before scanning. The strongest E2EE doesn't help if the second device is someone else's.
I spend most of my time around developers who think “security” means:
npm audit
and a .env file that’s definitely in .gitignore file.
If you browse our (= Espresso Labs) pitch to law firms, you realized: the threat model we’re describing for a 40-person law firm is identical to the threat model for your bootstrapped SaaS, your dev agency, or your local accounting shop.
Only the data changes.
The attacker’s playbook doesn’t.
Here’s what I learned, and what I think every SMB owner and every engineer who’s ever been “the security person by default” should take from it.
Think about what a law firm actually is, technically: a small team with admin access to an enormous amount of high-value, high-leverage data — M&A deal terms, litigation strategy, medical records, wire transfer instructions — protected by, in a lot of cases, the same IT hygiene as your uncle’s dentist office.
(It’s ugly – I know)
That mismatch between value of data and maturity of defenses is exactly what makes a target attractive, and it’s the same mismatch that makes early-stage startups attractive. You might not have client trust funds, but you’ve got:
The page cites a few real incidents worth knowing about if you haven’t followed legal-sector security news: Jones Day disclosed a breach traced back to a phishing attack, a firm handling healthcare records exposed data on roughly 300,000 people, and suspected state-sponsored actors breached a prominent D.C. firm.
None of these firms were careless by industry standards.
They just had the same gap most SMBs have: policies on paper, nobody watching in real time.
The line from that page that actually stopped me was this: what happens when an alert fires at 5pm on a Friday?
Is anyone awake to triage it, understand it, and act — or does it sit in a queue until Monday morning?
Every engineer who’s carried a pager knows exactly why that question matters.
An unhandled alert isn’t a paperwork problem, it’s a live incident with a clock running.
Ransomware doesn’t wait for business hours — most operators deliberately trigger encryption routines on Friday evenings because they know IT support windows close. If your “security monitoring” is a Gmail filter and good intentions, you don’t have monitoring — you have a very slow smoke detector.
Strip the compliance language off the list Espresso Labs put together for law firms, and it maps almost one-to-one onto a hardening checklist for any small technical team:
Their framing
What it actually means for you
Access Control & MFA
Hardware keys (YubiKey/Passkeys) on your IdP, least-privilege IAM roles, no shared root logins
Encryption
TLS everywhere, encrypted volumes/backups, secrets in a vault (not .env in git)
Email Security
DMARC/DKIM/SPF actually enforced, not just configured; phishing-resistant MFA for finance approvals
24/7 Monitoring
Centralized logging + alerting (even a scrappy stack: Wazuh, Grafana + Loki, or a cheap SIEM) with someone actually on the hook to respond.
Incident Response
A written runbook you’ve actually rehearsed — who kills prod access, who calls the lawyer (ironic, I know), who notifies customers
Audit Logging
Immutable logs of who touched what — your future self debugging an incident will thank you
Vendor & Third-Party Risk
Know what your SaaS vendors and contractors can touch. That Zapier integration with full Drive access? Audit it
Security Awareness
Five minutes teaching your team to spot a fake DocuSign or invoice-change email saves you a six-figure wire fraud loss
None of this is exotic.
It’s the boring 20% that prevents 80% of real-world incidents, and it’s exactly the stuff that’s easiest to skip when you’re three people shipping features at 2am.
This is really the interesting question for an SMB owner, and it’s a classic build-vs-buy tradeoff, not a moral one.
DIY is very doable if you’re technical (and a security/IT expert).
These are some options that you might want to try (or just use EspressoLabs’ platform):
Managed makes sense when the “24/7” part is the actual bottleneck.
This is the honest pitch behind Espresso Labs and the other competitors in that space.
A two-partner law firm or a five-person agency genuinely cannot staff a real SOC.
Paying for continuous monitoring and incident response is often cheaper and more reliable than one overworked engineer trying to be security, compliance, and IT support simultaneously — which is a real, common failure mode, not a hypothetical.
The mistake I’d flag for SMB owners either way: don’t buy point solutions that don’t talk to each other.
Antivirus from one vendor, backup from another, email filtering from a third, none of it correlated — that’s the same “disconnected tools” trap regardless of whether you assembled it yourself or a vendor sold it to you piecemeal.
The goal is one place where signals actually connect into an alert a human can act on.
If you run or work at an SMB and want the 80/20 version of everything above, block a day (or a few hours if you are fast) and do this:
None of this requires a five-figure retainer.
It requires about an afternoon and the discipline to actually finish it instead of filing it under “Q3 goals.”
Attackers don’t care whether your letterhead says “LLP” or “Inc.”
They care whether you’re an easy, high-value target.
Law firms are having a rough couple of years for the same reason a lot of SMBs will eventually have a rough week: sensitive data, thin security staffing, and a reactive-instead-of-continuous posture.
The fix isn’t glamorous — MFA, monitoring, backups, and a plan you’ve actually rehearsed — but it’s the difference between a Friday night that’s annoying and one that ends your company.
Btw, if you found this useful, I’d love to hear what your own SMB security stack looks like.
Be strong and safe!
How to Build Your Own "Cape“ in Europe: Practical Digital Hygiene for Mobile Privacy
In the previous article, we explained why there is not yet a full-fledged equivalent of the American operator Cape in Europe. The combination of a proprietary mobile network core…
https://vsx.global/how-to-put-together-your-own-digital-hygiene-guide-for-mobile-privacy-in-europe/
"The server can't read your messages" is often presented as the whole privacy story. It isn't. A relay that forwards opaque ciphertext can still log connecting IPs, access timestamps, message sizes, and frequency — and that's enough to map a social graph without decrypting a single byte.
The design question that actually matters: does the relay keep those logs at all? "Zero metadata" has to mean the server doesn't retain that data, not just that it can't read content.
Who had "getting compromised through plugging an LG monitor in" on their #itsecurity 2026 bingo card? Apparently just plugging an LG monitor into a windows computer is enough for them to install spyware and steal all of your data. But hey you agree to this in their ToS (even without having to click on "I agree", it just installs).
Question about #RainbowTable and #PasswordCracking What is the preferred format today? RT2, RTC, RT (RT1?) and with what tools, rcrack?
I'd like to convert all the https://infocon.org/ rainbow tables into whatever the best format is so everyone that downloads them doesn't have to keep duplicating work.
#InfoSec #InfoCon #hacking
LG TVs and monitors said to surveil users and install bloatware without asking
> Anyone who owns an LG smart TV must inform all guests and family members that they are being monitored – this is required by LG’s current terms of use. Meanwhile, LG monitors install potential malware and surveillance software on a connected Windows computer.
boosted"Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.
CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.
https://postquantum.com/post-quantum/criminals-rent-quantum-crqc/