Tag
Evidence suggests the U.S. military has been using a hidden 176-bit slot in public GPS signals to broadcast encrypted cryptographic keys for nearly 20 years, effectively turning GPS satellites into global numbers stations.
Dashlane disclosed a coordinated brute-force attack where threat actors abused device enrollment APIs to send one-time codes across thousands of accounts simultaneously, successfully downloading encrypted password vaults for fewer than 20 users before the attack was shut down.
DotBGE is a local-first file encryption tool available for iOS, CLI, and AI agents.
A blog post explaining how to combine SOPS with Age for encrypting secrets outside the cluster and Bitnami Sealed Secrets for in-cluster decryption, enabling a GitOps workflow for Kubernetes.
A Linux CLI tool written in C++ that encrypts folders using AES-256-GCM, hides file and folder names with an encrypted mapping, and supports USB-based key loading.
The article explores the possibilities of combining quantum computers with AI, such as dramatic increases in computing speed, instant internet, encryption failure, AI going out of control, and even threats to human survival. It also quotes Elon Musk's views, and is overall a personal commentary.
Explains how Shamir's Secret Sharing works using geometric intuition, and mentions its use in Ente's Legacy Kit for secure secret recovery.
Claude Code now auto-encrypts CLI communication, earning SOC2 compliance praise.
The 2026 HIPAA Security Rule update introduces mandatory encryption, multi-factor authentication, 72-hour incident reporting, and annual penetration testing. Healthcare organizations must begin preparations to meet these significant new requirements.
Happy Code is an open-source mobile and web client that enables remote use of Claude Code and Codex with end-to-end encryption, allowing developers to monitor and control AI coding agents from anywhere.
Oura, the health wearable maker, acknowledges receiving government requests for user data but refuses to disclose how many requests it receives or how often it complies. The article highlights Oura's lack of end-to-end encryption and the potential for government access to sensitive health data.
Texas Attorney General sues Meta, alleging that WhatsApp misrepresents its end-to-end encryption and that Meta can read user messages. The lawsuit relies on a Bloomberg report about a closed US investigation, but critics note a lack of direct factual support.
This article examines the persistent gap in self-sovereign PKI for humans, where messaging apps like Signal and iMessage rely on manual key verification that users rarely perform, and proposes that current naming systems fail to provide both human-meaningful and cryptographically anchored identities.
DCP is a product that provides encrypted permissions and keys for AI agents.
Canada's Bill C-22 would require messaging apps like Signal and WhatsApp to build a backdoor for government access, undermining end-to-end encryption and threatening the privacy of all users.
A security researcher claims Microsoft built a backdoor into BitLocker and releases an exploit, raising concerns about encryption integrity.
A researcher reverse-engineered AppLovin's ad mediation cipher protocol, revealing that it uses a weak non-cryptographic PRNG and a static salt to encrypt device information, allowing deterministic re-identification of iPhones across apps even when users deny tracking permission.
A security researcher released a zero-day exploit called YellowKey that bypasses Microsoft BitLocker encryption on Windows 11 and Windows Server 2022/2025, allowing full access to locked drives using a USB stick; the exploit appears to operate as a backdoor, with files disappearing after use.
Canada's Bill C-22, the Lawful Access Act, is criticized by the EFF and tech companies as a repackaged surveillance bill that mandates metadata retention and forces encryption backdoors. Apple, Meta, and US congressional committees oppose the bill, citing significant risks to digital privacy and security.
The article introduces Revaulter v2, a tool that enables unlocking encrypted ZFS volumes at boot using passkeys (WebAuthn), allowing remote approval via a mobile web interface without storing keys in plaintext.