Python Now Has a Post-Quantum Encryption Library

<p><a href="https://blog.trailofbits.com/2026/06/30/shipping-post-quantum-cryptography-to-python/">This is good</a>:</p> <blockquote><p>Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the <a href="https://www.sovereign.tech/">Sovereign Tech Agency</a>, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.</p></blockquote> <p>Remember, the reason to do this now is because there&#8217;s no emergency. And because you will make your systems crypto agile, which is always a good idea.</p>

2026/8/10
阅读更多

Friday Squid Blogging: Arctic Bobtail Squid Video

<p>Nice <a href="https://petapixel.com/2026/07/23/rare-arctic-bobtail-squid-filmed-in-its-natural-habitat-for-the-first-time/">video</a> of the Arctic bobtail squid.</p> <p>As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered.</p> <p><a href="https://www.schneier.com/blog/archives/2024/06/new-blog-moderation-policy.html">Blog moderation policy.</a></p>

2026/8/7
阅读更多

ICE Is Buying Access to Credit Card Records

<p>Through data brokers, ICE is <a href="https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href="https://boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href="https://mastodon.social/@heidilifeldman/116981503852352281">information</a> you provided to open a credit card.</p>

2026/8/7
阅读更多

Adversarial Clothing Designed to Fool Facial Recognition Systems

<p>There are many companies manufacturing <a href="https://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream">adversarial clothing</a> designed to confuse facial recognition systems.</p> <p>It&#8217;s a cool idea, but I worry that it&#8217;s mostly security theater:</p> <blockquote><p>&#8220;Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,&#8221; he said.</p> <p>Bell, however, said &#8220;none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance &#8230; [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.</p> <p>&#8220;This is consumers collectively coming together to make a visible statement.&#8221;...</p></blockquote>

2026/8/6
阅读更多

Vulnerabilities in Car Anti-Theft Device

<p><a href="https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/">This</a> is disturbing:</p> <blockquote><p>&#8230;a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car&#8217;s horn or flash its lights, or even disable its ignition and leave a driver stranded.</p></blockquote>

2026/8/5
阅读更多

Iran Cyberattacks Against Minnesota Water Systems

<p><a href="https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html">Attribution</a> <a href="https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/">is</a> <a href="https://thehill.com/policy/technology/6001284-minnesota-water-facilities-cyberattack-investigation-us-iran/amp/">preliminary</a>, and so far it seems no real damage.</p> <p>And it seems like this is a campaign that has targeted at least <a href="https://www.nytimes.com/2026/08/01/us/politics/iran-cyberattack-water-systems.html?unlocked_article_code=1.2FA.xPwI.F0C0GgLEjGZc&#38;smid=nytcore-ios-share">seven states</a>. And, because this is where the US is right now, Trump doesn&#8217;t believe it&#8217;s Iran and that Minnesota&#8230;I guess&#8230;hacked itself.</p> <blockquote><p>&#8220;I think I blame it on Minnesota because they&#8217;re grossly incompetent,&#8221; Trump said. &#8220;I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, &#8216;Oh, it&#8217;s Iran.&#8217; Iran should be so lucky. Iran&#8217;s got bigger problems than worrying about Minnesota.&#8221;...</p></blockquote>

2026/8/4
阅读更多

Some Claude Chats Are Searchable on Google

<p>And it&#8217;s <a href="https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/">personal information</a> (alternate <a href="https://archive.ph/sl7rU">link</a>):</p> <blockquote><p>The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples&#8217; addresses.</p></blockquote> <p>What seems to be the issue is a user setting about data sharing. Anthropic&#8217;s position is that it&#8217;s <a href="https://futurism.com/artificial-intelligence/claude-chats-publicly-accessible">not their problem</a>:</p> <blockquote><p>&#8220;We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,&#8221; the company said in a statement. &#8220;These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.&#8221;...</p></blockquote>

2026/8/4
阅读更多

More on the OpenAI Agent’s Attack on Hugging Face

<p>Hugging Face has <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">published</a> a detailed timeline of the attack. From the summary:</p> <blockquote><p>The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark&#8217;s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent&#8217;s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own...</p></blockquote>

2026/8/3
阅读更多

The OpenAI Hack Shows the Genie Is Out of the Bottle

<p><em>This essay originally appeared in <a href="https://foreignpolicy.com/2026/07/30/openai-hack-genie-bottle-defense/">Foreign Policy</a>.</em></p> <p>Earlier this month, two of OpenAI&#8217;s models broke out of their containment sandbox and attacked another AI company. The <a href="https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html">story</a> is kind of <a href="https://simonwillison.net/2026/Jul/22/openai-cyberattack/">wild</a>. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.</p> <p>Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...</p>

2026/8/3
阅读更多

Friday Squid Blogging: Squid Helps Discover New Marine Species

<p>The Squid is a new <a href="https://www.theguardian.com/environment/2026/jun/26/marine-expedition-uncovers-31-new-species-two-weeks-brazil">scientific machine</a>:</p> <blockquote><p>One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. &#8220;That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,&#8221; Osborn said.</p></blockquote> <p>The expedition discovered thirty-one new marine species in two weeks. The article doesn&#8217;t say if any of them were new species of squid...</p>

2026/7/31
阅读更多