We say things privately that we’re still trying to figure out ourselves. We ask questions we wouldn’t ask publicly.
Research on digital surveillance has found that simply 𝐟𝐞𝐞𝐥𝐢𝐧𝐠 𝐰𝐚𝐭𝐜𝐡𝐞𝐝 𝐜𝐚𝐧 𝐜𝐡𝐚𝐧𝐠𝐞 𝐡𝐨𝐰 𝐩𝐞𝐨𝐩𝐥𝐞 𝐜𝐨𝐦𝐦𝐮𝐧𝐢𝐜𝐚𝐭𝐞. Researchers call it a chilling effect: people hold back, avoid certain subjects or censor themselves.
Private messaging affects more than data security. It affects how freely people speak.
Europe is dealing with exactly that dilemma now: 𝐡𝐨𝐰 𝐭𝐨 𝐩𝐫𝐨𝐭𝐞𝐜𝐭 𝐜𝐡𝐢𝐥𝐝𝐫𝐞𝐧 𝐟𝐫𝐨𝐦 𝐚𝐛𝐮𝐬𝐞 𝐨𝐧𝐥𝐢𝐧𝐞 𝐰𝐢𝐭𝐡𝐨𝐮𝐭 𝐬𝐮𝐛𝐣𝐞𝐜𝐭𝐢𝐧𝐠 𝐩𝐫𝐢𝐯𝐚𝐭𝐞 𝐜𝐨𝐦𝐦𝐮𝐧𝐢𝐜𝐚𝐭𝐢𝐨𝐧 𝐭𝐨 𝐛𝐫𝐨𝐚𝐝 𝐬𝐜𝐚𝐧𝐧𝐢𝐧𝐠.
In 𝐒𝐭𝐫𝐓𝐚𝐥𝐤, conversation content isn’t kept in a permanent central archive. On the web, encryption keys are generated locally, your private key stays with you, and 𝐒𝐓𝐑.𝐃𝐨𝐦𝐚𝐢𝐧 access means you don’t need a phone number or email to use the service.
Beyond being a superstar at identifying and exploiting vulnerabilities in digital systems, Anthropic’s Mythos frontier model is now being directed at encryption algorithms that are designed to resist quantum computing attacks.
The early results, as published by Anthropic , are an important glimpse into the future of digital security. Mythos has successfully degraded both the HAWK and a weaker version of AES encryption. The research does not impact current computer systems but it does showcase how researchers can leverage AI to advance attacks against algorithms that we will need in the future to protect our digital ecosystem!
Encryption underpins transactional security and privacy across the digital world. It protects online banking transactions, communications, webpage interactions, and the confidentiality of sensitive data. Unless we want to revert back to face-to-face transactions and paper documents, strong encryption is an absolute necessity!
Over the course of a week, small teams at Anthropic guided Mythos’s mostly autonomous work to achieve these early results. Yes, just one week. To put that into context, it was about a decade ago that NIST asked the brightest minds in the industry to develop robust algorithms that would be resistant to quantum computer-based attacks. Many candidates have undergone years of intense evaluation for becoming the replacements to current algorithms that protect us from traditional computers. Researchers have been testing and working to find weaknesses or break these proposed digital locks for years.
Mythos made progress in days.
HAWK was submitted as an additional potential signature in June of 2023. It benefitted from the deep learnings of previous submissions and research, to join other algorithms that had already been under evaluation but not yet put into practical use. AES, the other target, is perhaps the most commonly used encryption algorithm, which was adopted in 2001.
It is important to emphasize that Mythos did not completely break these algorithms, but rather found paths that reduce their robustness and potentially make future efforts to undermine them easier. With that said, researchers will continue to use frontier AI tools to test current and future security algorithms and they may eventually find ways to break them.
This is both good news, if we find and address weaknesses before any attackers, and potentially cataclysmic if malicious hackers are first to find and exploit algorithms after they have been widely adopted.
Strategically, we are seeing frontier AI models, like Mythos and others, showcase their aptitude at finding weaknesses in software, hardware, algorithms, processes, and people. The AI tools are working at a speed and in ways that humans cannot. That can bring truly amazing benefits, but is also accompanied by equally severe risks.
The key to success will be finding ways to seize the great benefits of AI adoption while managing the risks to acceptable levels.
For cybersecurity specifically, we must support and facilitate AI initiatives in support of business goals, while partnering to manage the cyber risks in acceptable ways.
𝐒𝐓𝐑 𝐓𝐚𝐥𝐤: 𝐅𝐮𝐥𝐥-𝐏𝐫𝐢𝐯𝐚𝐜𝐲 𝐂𝐡𝐚𝐭𝐬 𝐨𝐧 𝐚 𝐃𝐞𝐜𝐞𝐧𝐭𝐫𝐚𝐥𝐢𝐳𝐞𝐝 𝐍𝐞𝐭𝐰𝐨𝐫𝐤 We’ve kept 𝐒𝐓𝐑 𝐓𝐚𝐥𝐤 in focus this week for a reason. 𝐏𝐫𝐢𝐯𝐚𝐜𝐲 𝐢𝐧 𝐜𝐨𝐦𝐦𝐮𝐧𝐢𝐜𝐚𝐭𝐢𝐨𝐧 𝐢𝐬 𝐮𝐧𝐝𝐞𝐫 𝐫𝐞𝐚𝐥 𝐭𝐡𝐫𝐞𝐚𝐭. In the EU, draft laws are still on the table that would force providers to scan everyone’s messages – even encrypted ones – using client-side scanning on personal devices. At the same time, the market for end-to-end encrypted communication is projected to more than triple between 2024 and 2032. More people are turning to platforms that can actually protect what they share - contracts, medical data, private photos, work files, political discussions. 𝐒𝐓𝐑 𝐓𝐚𝐥𝐤 is our response to this reality: decentralized, encryption-based communication built without a central hub that can be scanned, sold, or “opened up” later. A space where your conversations stay yours no matter how far a law, a policy update, or a backdoor request will go. 🔒 Yesterday we shared an article about the new “chat control” proposals and how they’re being disguised under the label of “safety.” Check it out for the wider context.