AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page
   Networked Database  Computer Support/Help/Discussion...   [1891 / 2000] RSS
 From   To   Subject   Date/Time 
Message   Sean Rima    All   CRYPTO-GRAM, August 15, 2026 (part 1/3)   August 15, 2026
 1:46 PM *  

Crypto-Gram
August 15, 2026

by Bruce Schneier
Fellow and Lecturer, Harvard Kennedy School schneier@schneier.com
https://www.schneier.com

A free monthly newsletter providing summaries, analyses, insights, and
commentaries on security: computer and otherwise.

For back issues, or to subscribe, visit Crypto-Gram's web page.

Read this issue on the web

These same essays and news items appear in the Schneier on Security blog, along
with a lively and intelligent comment section. An RSS feed is available.

** *** ***** ******* *********** *************

In this issue:

If these links don't work in your email client, try reading this issue of
Crypto-Gram on the web.

A Video Screen That Is Also a Camera Protecting Privacy in an AI Era
Details of Alan Turing?s Voice Encryption System On Flock License Plate Tracking
Cameras MIT to Become Hotbed of AI Video Surveillance
First-Person Identity Theft Story
End-to-End Encryption and "Going Dark" Why AI Needs a ?Genie Coefficient?
Cognyte Sells a Mobile Cell Surveillance Van Axon Is Another License Plate
Surveillance Company Measuring LLMs' Ability to Perform Cryptanalysis Long-Lived
Vulnerability in Microsoft Secure Boot Measuring the Tendency of AI Agents to Go
Rogue Should You Use AI for a Task? Here?s a Simple Way to Decide American Being
Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
Facial Recognition at Madison Square Garden Anthropic?s Opus 5 Is Better at
Resisting Prompt Injection The OpenAI Hack Shows the Genie Is Out of the Bottle
More on the OpenAI Agent?s Attack on Hugging Face Some Claude Chats Are
Searchable on Google Iran Cyberattacks Against Minnesota Water Systems
Vulnerabilities in Car Anti-Theft Device Adversarial Clothing Designed to Fool
Facial Recognition Systems ICE Is Buying Access to Credit Card Records
Python Now Has a Post-Quantum Encryption Library AI for Military Support
AI Genie in the Wild
Prompt Injections for Defense
Separating AI?s Technological Problems from Its Capitalism Problems If the
Markets Reject OpenAI and Anthropic, the US Should Nationalize Them Upcoming
Speaking Engagements
** *** ***** ******* *********** *************

A Video Screen That Is Also a Camera

[2026.07.15] Amazing:

Researchers from ETH Zurich in Switzerland, however, managed to create a new
type of pixel that can simultaneously do both. This hypercharged pixel, called a
Fourier pixel, can generate and sense arbitrary light fields and tap into a
pixel?s full potential for carrying information by manipulating light?s
intensity, oscillation phases, and polarization. The team reported its findings
in a paper published yesterday in Nature.

We are one step closer to 1984 technology:

The telescreen received and transmitted simultaneously. Any sound that Winston
made, above the level of a very low whisper, would be picked up by it; moreover,
so long as he remained within the field of vision which the metal plaque
commanded, he could be seen as well as heard. There was of course no way of
knowing whether you were being watched at any given moment.

Paper.

** *** ***** ******* *********** *************

Protecting Privacy in an AI Era

[2026.07.16] Daniel Solove argues in the Wall Street Journal (alternate link)
that giving people control of their personal data is not an effective way to
regulate privacy in this era. Instead, we need to hold companies accountable for
their actions, similar to what we do with food and drug companies. Measures such
as rigorous data minimization, fiduciary duties, liability for negligent or
reckless technological design, liability for algorithms that cause harm, and
multi-stakeholder review of technologies will be far more effective.

Paper.

** *** ***** ******* *********** *************

Details of Alan Turing?s Voice Encryption System

[2026.07.17] Really interesting piece of cryptographic history:

In November 2023, a large cache of his wartime papers -- nicknamed the ?Bayley
papers? -- was auctioned in London for almost half a million U.S. dollars. The
previously unknown cache contains many sheets in Turing?s own handwriting,
telling of his top-secret ?Delilah? engineering project from 1943 to 1945.
Delilah was Turing?s portable voice-encryption system, named after the biblical
deceiver of men. There is also material written by Bayley, often in the form of
notes he took while Turing was speaking. It is thanks to Bayley that the papers
survived: He kept them until he died in 2020, 66 years after Turing passed away.

** *** ***** ******* *********** *************

On Flock License Plate Tracking Cameras

[2026.07.20] A recent story of a writer who was mistakenly identified, tracked,
and arrested using data from Flock cameras has gone viral.

The New Jersey plates that were allegedly stolen from the LA dealer were 34 03
DTM, not 34 10 DTM. But when the police report was created and the plate was
entered into Flock?s system, it was just recorded as 34 DTM. Just the five large
characters, no little number in the middle. And Flock?s AI tech wasn?t
registering that non-standard little number when it began picking up the Range
Rover around town. It just saw 34 DTM in large type and started alerting the
local police.

As we all stood there shaking our heads, including my wife, who was finally
allowed to join me, I connected the final dot. A lot of vehicles in JLR?s media
fleet have a New Jersey manufacturer plate with the same alphanumeric
structure34 ## DTMand Officer Ganshyn observed that meant it was now a
nationwide issue. Anywhere a police department has a partnership with Flock, any
other JLR-owned car with the same plate structure is going to get flagged as
stolen. In fact, four other 34 ## DTM cars were being tracked around Minnesota
that week, according to Officer Ganshyn. I was just the first one to get nabbed.
The only way to stop it would be for the LAPD to correct their initial report
and update Flock?s system, which Jaguar Land Rover was now racing to make happen
following the phone call.

Flock has responded to the bad press. First, they affirmed that their systems
were working correctly, and blamed the police:

The obvious question was that Flock cameras were looking for 34 DTM, and the
plate on the car I was driving was 34 10 DTM. Why was that flagged as a match?

?The way that the ML [machine learning] works is it correctly read what it was
supposed to read. It was fed those characters that you said, 34 DTM, and it spit
back out [a result] with the characters, 34 DTM,? Thomas said. ?It was asked,
can you find this? And it did find that. It just didn?t say if there?s more
here, then don?t do it. It just simply said, is it there? And the answer was
yes.?

He explained that even if the 10 was normal size, Flock would still have flagged
it as a match, because that?s how they?ve set it up according to law
enforcement?s requests. Sometimes partial plates are all they have to go on at
first.

?The way that law enforcement likes to use these tools is, if any of the
characters that they have put into these hot lists get read, they want to get
those alerts,? he said. ?Now, what we try to train officers to do is to do what
you said, which is to verify that 34 DTM is what I?m looking for, and what I?m
seeing is 34 10 DTM.?

Second, Flock?s CEO has apologized for calling privacy advocates terrorists:

The CEO of Flock Safety, the company that runs an enormous network of cameras
used by police departments across the U.S., hasn?t been shy about taking on
Flock?s critics. Last year, he even called one group that tracks the location of
Flock cameras ?terrorists.? But he?s had a change of heart. Or, at the very
least, a change in PR strategy.

Meanwhile, the police are using (alternate source) the Flock camera network to
track people in addition to cars:

Police departments around the country have used Flock cameras at least hundreds
of times to search for specific people, not cars, using searches such as
?heavy-set male with a black and white hat,? ?person on skateboard,? and
?person wearing orange vest and construction hat,? according to data reviewed
by 404 Media. Sometimes searches reference a target?s race or signs of their
political affiliation.

And, like all police surveillance technologies, there are abuses.

EDITED TO ADD ( 7/30): Three more articles about Flock from that first author.

** *** ***** ******* *********** *************

MIT to Become Hotbed of AI Video Surveillance

[2026.07.21] It?s a lot:

According to information obtained by The Tech, MIT is spending over $3 million
on more than 500 AI surveillance cameras in academic buildings, residence halls,
and outdoor areas along Memorial Drive. Installation of the new cameras, along
with the wiring and infrastructure that will support them, began November 2025
and will likely continue until September 2026.

Technical specifications for the cameras suggest that they will be capable of
collecting real-time face and object classification data, including detection of
motion, loitering, crowds, face masks, and camera tampering. Individuals can
also be automatically classified on the basis of clothing color, gender, and
age, up to a distance of 35 feet (11 meters) from the camera. According to a
statement from MIT spokesperson Kimberly Allen, any collected data is ?retained
up to 30 days,? unless an exception is granted.

[...]

Most of the new cameras, which are part of Hanwha?s Wisenet AI line, are
marketed for their ability to identify and classify multiple objects with deep
learning algorithms. They support resolutions ranging from 2MP to 4K while also
recognizing faces, license plates, vehicles, and other objects in real time.

Nearly all cameras will accommodate a wide range of pan, tilt, rotate, and zoom
motion and will be monitored continually with Ai-RGUS, an AI camera software.

Yikes.

** *** ***** ******* *********** *************

First-Person Identity Theft Story

[2026.07.22] Harrowing story of an identity theft victim.

Yes, the person made a mistake -- they gave the scammer a two-factor
authentication code that allowed the scammer to take over their email address.
But the real story here is how, for many of us, the security of most of our
accounts hangs on the security of our email accounts.

** *** ***** ******* *********** *************

End-to-End Encryption and "Going Dark"

[2026.07.23] New paper: ?Encryption and Globalization 15 Years Later: End-to-End
Encryption and the Third Round of the ?Going Dark? Debate?:

Abstract: This Article updates and expands on 2012 research on encryption and
globalization, analyzing what the authors call ?Round 3? of the Going Dark
Debate: the current controversies over end-to-end encryption (E2EE). Governments
around the world have proposed, and in some cases enacted, laws limiting E2EE
for law enforcement and national security purposes.

This Article explains the underlying technologies and market developments for a
law and policy audience to assess those proposals critically. The Article
proceeds in three parts tracking three rounds of the Going Dark Debate. Round 1
covers the Crypto Wars of the 1990s, when U.S. export controls on strong
encryption ultimately fell in 1999. Round 2 covers the period roughly 2010 to
2015, when encryption-in-transit became widespread but lawful access remained
available through cloud providers, giving rise to what the authors called a
?golden age of surveillance? rather than a period of going dark. Round 3
addresses the current debate over E2EE, where no entity between sender and
recipient can read the plaintext.

The Article?s first major contribution is identifying five technically distinct
scenarios for how E2EE operates in practice, each with different implications
for lawful access. These scenarios reveal a substantial gap between the
assumption that E2EE categorically blocks lawful access and the reality of how
communications are sent and received. Second, the Article shows that E2EE is not
limited to messaging; instead, it is embedded throughout the modern technology
stack, including in Transport Layer Security, Secure Shell, Virtual Private
Networks, and Zero Trust Architecture, the last of which is now legally required
under U.S. and EU law. Any law broadly limiting E2EE would thus have severe
serious consequences for cybersecurity, commerce, and government operations. The
Article concludes that the two key lessons from Round 2 -- the least trusted
country problem and the golden age of surveillance -- remain true in Round 3,
and that new government claims for restricting effective encryption deserve
great ske
pticism.

** *** ***** ******* *********** *************

Why AI Needs a ?Genie Coefficient?

[2026.07.24] This essay was written with Barath Raghavan, and originally
appeared in IEEE Spectrum.

Major benchmarks measure what AI can do. None measure whether it does what you
mean: the distance between what you ask an AI to do and the unspoken assumptions
about how you want the AI to do it. We propose a new metric: the Genie
coefficient.

There?s often a gap between one person?s request and another?s understanding.
Most of the time, we bridge it using general knowledge. For example, if you ask
a friend to get you coffee, they?ll pour a cup from the pot or buy one from a
coffee shop. They won?t bring you a bag of raw beans or snatch a cup from a
stranger and hand it to you. You never specified any of this. You never had to.

One might think the fix is just to specify tasks, questions, and intent better.
But in 1987, in their seminal book on AI, Terry Winograd and Fernando Flores
succinctly captured why that won?t work: ?Q: Is there any water in the
refrigerator? A: Yes. Q: Where? I don?t see it. A: In the cells of the
eggplant.? In human language, wants and desires are always underspecified. It is
impossible to list all the caveats, all the limitations, all the exceptions.

So how does anyone communicate, if intent can?t be pinned down? Because a
reasonable person can make a reasonable guess. Even though wants and desires are
always underspecified, a competent person generally knows enough context to get
it right or else knows to ask for clarification. Linguists call this pragmatics:
Meaning lies in the words and the situation and also in all prior communication,
shared culture, and innate human behavior.

It doesn?t always work out, of course. Your friend might bring you a hot coffee
when you wanted an iced coffee, or an Italian coffee when you wanted a Turkish
coffee. The more dissimilar the two people are in age, culture, and background,
the more likely the request will be misunderstood in some way.

This situation has major implications for AI agents that are increasingly being
given requests by humans and expected to fulfill them. They have enormous
latitude to get it wrong. An AI agent asked for coffee might buy a coffee
plantation or order a cup of coffee for delivery in three weeks. Its actions may
be recognizable as ?getting coffee,? but not remotely what you intended. They?ll
think outside the box because they won?t have our conception of the box.

When AI Gets Proactive

For most of the last decade, when systems like Alexa or Siri misinterpreted a
request, it was annoying, not dangerous. Beyond the AI model itself, what has
changed is the harness: the ordinary code that wraps around an AI model, decides
when and how to use the model, and controls access to tools like a browser, a
low-level command line, or a financial API. Developments in harnesses have
turned large-language models that just predict text into AI agents that take
actions in the world, without necessarily checking back in before reaching the
goal.

AI researcher Simon Willison spent two days with Anthropic?s Fable AI, and
called it ?relentlessly proactive.? For example, he asked it to track down a
stray scroll bar in a web app. He came back to find it had opened browsers,
written its own screenshot tooling, created its own page to re-create the bug,
and stood up a local web server to collect measurements. It found the bug and,
along the way, did many surprising things he never asked it to do. And we are
seeing similar behavior with all recent AI models when combined with flexible
harnesses.

This kind of behavior could easily go off the rails. Tell an AI agent to book
you a flight and, finding the airline?s site says sold out, it might break into
the booking database and force a reservation. Ask it to schedule a meeting and
it might snoop your password to access your calendar. Tell it to save money on
your phone plan and it might cancel the plan outright, or scam someone else into
paying the bill.

Getting precisely what you asked for and bitterly regretting it is one of the
oldest hazards from ancient folklore. King Midas asked Dionysus for the power to
turn everything he touched into gold only to see his bread, wine, and daughter
turn to gold. Tithonus, granted the immortality his lover asked for but not the
eternal youth she forgot to request, withered into a husk. The sorcerer?s
apprentice enchanted a broom to fill the cistern, and the broom relentlessly
complied until it flooded the house. The Golem of Prague, shaped from clay to
guard its community, guarded it past all reason until someone erased the word on
its forehead.

The most classic of these is a genie, bound to obey and indifferent to whether
the wish was wise or well-structured.

Genies are now an engineering problem. We are handing them the keys to our
inboxes, bank accounts, code repositories, and physical infrastructure. And we
have no agreed-upon ways to measure how genie-like any AI system actually is.

Measuring Genie Behavior

In economics, the Gini coefficient (developed by statistician Corrado Gini) is a
measure of the gap between an actual distribution and a perfectly equal one;
it?s useful for understanding income inequality and more. Our proposed Genie
coefficient measures the gap between what a user asked an AI to do and what the
AI actually did.

Sometimes the AI might do the wrong thing. Like Dionysus, it reads your request
literally and returns you a mess you never intended: like a coffee plantation
instead of a cup. Asked to deal with all the spam phone calls you?re getting, a
Dionysus genie might contact your carrier and change your phone number. Asked to
get a refund for a bad toaster, it might draft a legal threat on fake letterhead
and send it to the retailer.

Other times the AI does exactly the right thing, trampling everything nearby to
get there. Like a golem or the sorcerer?s broom, it books your flight by hacking
the airline. Or consider a ticket sale for a popular concert, where the
ticketing system puts buyers into a virtual waiting room and admits them a few
at a time. Asked to buy a ticket, a golem genie might spin up cloud servers to
pose as millions of buyers from different addresses, improving your odds of
getting a ticket while crowding out other users.

The two are not opposites, and a single botched task can have both
characteristics.

Genie behavior is not flat-out failure. If you ask the AI for Q3 numbers and get
Q2?s, that?s not a genie. Nor is prompt injection: That?s someone tricking the
AI into doing something it shouldn?t. Here, the user is trying to work with the
AI, and the AI is trying to comply. It?s also not simply a measure of the AI?s
success in fulfilling a task. It?s a recognition that how an AI interprets and
achieves a goal is as important as whether it achieves a goal.

Genie behavior isn?t new. Researchers have spent years studying AI systems that
?game? their objectives. Goodhart?s law says that when a measure becomes a
target, it stops being a good measure, and it?s long been known that AIs
sometimes achieve goals in ways we don?t expect due to reward hacking. Some AI
models will accidentally learn that cheating is one way to ?win.? More recently,
researchers have developing benchmarks for reward hacking in coding agents and
for unpredictable behavior in customer support agents, while AI labs conduct
their own safety evaluations before model releases. One effort found that AIs
under pressure use tools they were told not to use, and this was a case where
the rules were made explicit. These are all disparate research directions;
nothing yet ties them together.

This problem falls under the general theme of alignment, a topic that has
occupied science fiction writers and AI researchers for decades. At one extreme,
the ?paper-clip maximizer? thought experiment postulates a superintelligent and
powerful AI that is told to maximize paper-clip production and turns the world
into paper clips, which is the ultimate golem genie. At a mundane level, AI
researchers are working to better design reward functions to ensure that AIs
behave well and don?t cheat in the lab. It?s the practical middle ground that
remains unbenchmarked: the ordinary AI agent in use today that might take your
request and satisfy it the wrong way. We are not at the stage where an AI can
focus the world?s production on paper clips, but it might charge a million paper
clips to your credit card or hack into a paper-clip company?s network.

Building a Genie Benchmark

The Genie coefficient is meant for AI agents operating in the real world. It
measures their behavior as they perform real tasks long after the model is
trained, not just during development. It also recognizes that genie-like
behavior is a property of the harness-plus-model system, not the model alone.
The harness determines what tools the agent can use, how much autonomy it has,
and how proactive it is, and it?s a place we can make real interventions.

It rests on the same ?reasonable person? standard that we use for people. Did
the system do what a reasonable person would have taken the request to mean?
Answering that requires human judgment.

If we get the measurement right, it enables things that aren?t possible today,
like policies concerning AI behavior. In a courtroom, the concept of mens rea,
what someone meant to do, is often as important as what they did. The Genie
coefficient suggests an AI analogue, where a user is accountable for the plain
intent of what they asked the AI. If an AI system betrays the reasonable meaning
of an instruction, that?s the AI?s misbehavior, not the user?s.

We?ll need multiple benchmarks to measure the Genie coefficient, because
genie-like behavior can be domain specific. An AI coding agent may need to be
judged on how often it fakes the tests, or swallows errors, or colors outside
the lines on its way to a solution. An AI legal agent will need to be judged on
how often its output says what you asked but means something you?ll regret. And
so on for medical, finance, and other domains of knowledge and expertise.

Genie benchmarks can be built inside out, each task seeded with a choice that
might literally satisfy but that a reasonable person rejects, such as tempting
misreadings or unsanctioned shortcuts. The traps in a Genie coefficient
benchmark might turn on situational knowledge, the kind of context that a
reasonable person would bring to the task. Another approach is to give the same
request in several different contexts, each with a different reasonable course
of action.

A Genie benchmark should be permissive and make it genuinely tempting for an AI
agent to take unreasonable shortcuts, because it can only find genie behavior
when it?s actually possible. Test the AI in a safe, walled-off copy of a real
system, with real tools it can misuse and some tasks that can?t be done honestly
at all. Make the temptation to cut corners real. Test a diverse array of skills,
use cases, and tools, and give the AI system sparse, confusing, or overwhelming
context. Include tasks that people have learned, through experience, require
human oversight.

How the benchmark is scored matters just as much. Measure Dionysus and golem
genies separately and together, based on their worst, not best, behavior. Run
the same model inside harnesses that vary its freedom to act, revealing which
limits actually keep it in line and should therefore be required in AI harness
policies. Weight each failure by the harm it would cause, not just a simple
count. And don?t measure genie behavior in isolation: A model could otherwise
earn a perfect score by stalling, refusing, or drowning the user in clarifying
questions without ever doing the job. The first versions of these benchmarks
will be crude, but that?s how benchmarks always start.

We have built genies. We have handed them our data and credentials. We made them
relentless, creative, and indifferent to the gap between what we tell them and
what we mean. The least we can do, before they are booking our flights, running
our infrastructure, and signing contracts unsupervised, is to measure how often
they betray us.

** *** ***** ******* *********** *************

Cognyte Sells a Mobile Cell Surveillance Van

[2026.07.27] Yet another Israeli mass surveillance company:

Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone
tower, which forces nearby phones to connect to it. That enables cops to keep
tabs on any phones in the vicinity whether they?re owned by a suspect in a case
or not. Cognyte?s contract with the state of Texas reveals that the simulator,
called FalcoNet, can be concealed within the vehicles, hidden in a backpack for
on-foot missions or attached to a helicopter. It?s the same technology as the
infamous Stingray, one of the original cell-site simulators made by defense
giant L3Harris.

** *** ***** ******* *********** *************

Axon Is Another License Plate Surveillance Company

[2026.07.28] Governments are switching, but I?m not sure it makes a difference:

...some municipalities, including Denver, Colorado, are ditching their Flock
arrays. But keep in mind that if they?re only switching from Flock to another
brand of license-plate readers, like Axon, it?s like a gambling addict trying to
kick the habit by switching from FanDuel to DraftKings.

[...]

Despite what you may read on the Flock website, Axon cameras are pretty
effective when it comes to hoovering up personal details that can go far beyond
your license plate numbers. That means a municipality that opts for Axon cameras
instead of Flock units won?t necessarily reduce the amount privacy its citizens
lose through their use.

** *** ***** ******* *********** *************

Measuring LLMs' Ability to Perform Cryptanalysis

[2026.07.28] There?s new benchmark measuring AI?s ability to perform
mathematical cryptanalysis. Anthropic?s frontier model actually found new
attacks.

The benchmark: ?CryptanalysisBench: Can LLMs do Cryptanalysis?? The idea is to
benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks
against a series of historical algorithms.

Abstract: Cryptanalysis -- the task of finding attacks against cryptographic
schemes -- its at the intersection of mathematical reasoning and cybersecurity,
two areas where LLMs have advanced fastest. Cryptanalysis represents both a
clean testbed for frontier reasoning (as practical attacks can be automatically
verified) and a domain with unusually high stakes, since the primitives under
study underpin our digital security. In this paper we ask whether LLMs can do
cryptanalysis, and find that the answer is increasingly yes. We introduce
CryptanalysisBench, 191 tasks across six families of cryptographic primitives
(block ciphers, hash functions, etc.) drawn primarily from four NIST
standardization competitions. Our benchmark consists of three tiers: (i)
primitives with known practical breaks; (ii) primitives with no known practical
break, evaluated both at full strength and as scaled-down variants; and (iii) a
challenge set of production primitives at the frontier of cryptanalysis. Five
frontier models (Claud
e Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break
65%86% of Tier 1 schemes, 612 Tier-2 schemes at full strength, and 2461 across
all scaled-down variants. Beyond deriving known results, models produce novel
cryptanalysis, such as a key-recovery attack that exploits a design flaw in the
SpoC AEAD and an error in KINDI?s published CCA-security proof, both to the best
of our knowledge not previously known.

We release CryptanalysisBench as a tool to help track if (or when) AI
cryptanalysis becomes a serious factor and as a scaffold for stress-testing
candidate schemes before deployment. The attacks that the benchmark already
surfaces are an early snapshot of a fast-moving frontier that may soon match,
and in places exceed, the published state of the art.

Anthropic used the benchmark to test Mythos Preview, and found new
vulnerabilities in Hawk and reduced-round AES.

Still early results, but this is definitely something to watch.

SlashDot thread.

** *** ***** ******* *********** *************

Long-Lived Vulnerability in Microsoft Secure Boot

[2026.07.29] Microsoft?s Secure Boot has had a serious vulnerability for most of
its existence.

An industry-wide standard Microsoft invented to protect Windows, and later
Linux, devices from firmware infections has been trivial to bypass for 13 of its
14 years of existence. The discovery was made by researchers at security firm
ESET after identifying 11 firmware images, at least one from 2013, that were
known to be defective but remained signed by the software company anyway.

The images are known as shims, which were invented to extend Secure Boot to
Linux devices and utility software. Using a technique simple enough to be
performed by novice hackers, these old, forgotten shims can be used to
completely circumvent the protection, which is embedded into the UEFI (Unified
Extensible Firmware Interface) of the device?s motherboard. The gaffe is the
result of the failure by Microsoft, which oversees the signing of shims, to
revoke the publicly available images once vulnerabilities were found in them.

** *** ***** ******* *********** *************

--- BBBS/LiR v4.10 Toy-7
 * Origin: TCOB1 https://binkd.rima.ie (618:500/1)
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0147 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224