Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Workplaces Look For Cheaper AI As 'Tokenmaxxing' Fades As a Corporate Fad
    by BeauHD on 29/07/2026 at 3:30 am

    An anonymous reader quotes a report from the Associated Press: A corporate fad of "tokenmaxxing" on artificial intelligence technology is hitting its limits as workplaces throwing AI at everything are seeing the costs rise without a similar spike in productivity. What started as tech industry-fueled springtime hype over squeezing as much AI-generated work as possible out of products like OpenAI's ChatGPT and Anthropic's Claude has shifted to a summertime backlash. [...] Just a few months ago, Silicon Valley executives were promoting high token consumption as a signal of high-performing employees. The stereotypical tokenmaxxer was staying up late -- perhaps ignoring their significant other -- while orchestrating an army of 24-hour AI agents performing work on their behalf. [...] The trend boosted revenue for leading AI large language model developers like Anthropic and OpenAI, but it fizzled as it became apparent it wasn't necessarily the best strategy for everyone else. [...] Bain & Company management consultant Jue Wang said many of the big businesses her firm advises have been taking a closer look at returns on their AI investments. "The token cost for them has been doubling, almost every other month," she said. "Let's say $200 per developer per month. Multiply that by 20,000 developers, which is often what we're dealing with at these companies, and that quickly gets you to a number that is not a line item that any general manager has planned for." Sometimes that just means not using the AI equivalent of a sledgehammer to crack a nut. "Not everything needs a Claude Opus 4.6," she said of one of Anthropic's more capable models suited to software engineering or deep research. "And yet you see so many companies, so many users, default to using Opus for everything, including generating emails." That's led to a search for tools that do AI "model routing" -- in which easier queries get automatically sent to cheaper and more efficient AI systems and more complex tasks go to more powerful models. [...] At the same time, those who favor racking up as many tokens as possible are having a field day with new open-source models from Chinese startups like Moonshot's Kimi or Zhipu's GLM, which nearly match the capabilities of top U.S. models at a fraction of the price. "There is some validity to the theory that this could push tokenmaxxing a little bit further," said Raffi Krikorian, the chief technology officer at Mozilla. "But if we look at the industry overall, I think it's realizing that tokenmaxxing is a dumb thing." It's similar, Krikorian said, to how software companies once considered how many lines of code a programmer wrote to be a good metric of productivity. That later fell out of favor. "I think tokenmaxxing is moving through the exact same pattern," he said. "I think this is going to be an interesting blip that we're all going to look back to laugh at in a year." Read more of this story at Slashdot.

  • Apple Retires iPhone Upgrade Program For Klarna-Backed Leases
    by BeauHD on 28/07/2026 at 11:00 pm

    Apple has replaced its iPhone Upgrade Program with Apple Upgrade, a Klarna-backed U.S. leasing service covering most iPhones, iPads, Macs, and Apple Watches. MacRumors reports: Apple Upgrade has lower base prices than the iPhone Upgrade Program, with iPhones available starting at $17.99 per month and the Apple Watch available starting at $11.99 per month. Macs can be leased starting at $24.99 per month, and iPads start at $11.99 per month. AppleCare+ is optional and not included in the lease price, with customers also able to opt for AppleCare One. There are 12-month and 24-month leasing options for the iPhone and Apple Watch, along with 24-month and 36-month leasing options for the Mac and iPad. Lease cost varies based on device, and is lower with a device trade-in that's applied on a monthly basis. [...] When leasing an iPhone, customers are required to choose a plan from AT&T, Verizon, or T-Mobile, and prepaid plans are not eligible. iPhones need to be leased with a carrier plan, but the iPhones are unlocked so customers can switch carriers if desired. MVNOs like Mint Mobile or Visible are not supported. At the end of the leasing period, customers can choose to return the device and exit the program, pay off the remaining amount owed on the device with a one-time payment and keep it, or return it and upgrade to a new device with a new lease. The payoff amount is the difference between what was paid during the leasing period and the retail price of the device, minus any remaining trade-in credits. Klarna is not charging a fee for the leasing program, so an iPhone that's $1,099 can be leased and then purchased for $1,099 with no extra cost beyond taxes. As with trade-ins, Apple will send a pre-labeled and prepaid shipping box for device returns or upgrades. If you don't opt to pay the purchase fee at the end of the leasing program, you will not own the device and must return it. Last week, after Bloomberg reported on Apple's upcoming leasing program, 9to5Mac uncovered code in the iOS 27 beta suggesting the company was developing a system that could restrict leased iPhones when customers fall behind on payments. Apple has now told The Verge that the new "Restricted Mode" will not be activated in response to a missed lease payment. What the new system is actually meant for remains unclear. Read more of this story at Slashdot.

  • AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype
    by BeauHD on 28/07/2026 at 10:00 pm

    AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched. But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there. Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest." Read more of this story at Slashdot.

  • eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019
    by BeauHD on 28/07/2026 at 9:00 pm

    eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home. The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea. Read more of this story at Slashdot.

  • Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms
    by BeauHD on 28/07/2026 at 8:00 pm

    Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet. [...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct. "Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency. "Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context." Read more of this story at Slashdot.

  • Judge Blocks First State Law That Would Have Banned Prediction Markets
    by BeauHD on 28/07/2026 at 7:00 pm

    An anonymous reader quotes a report from Ars Technica: Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets -- Kalshi and Polymarket -- sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1. Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are "swaps," which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment "is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence." US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota's total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps. Menendez wrote: "Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as "swaps" within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those 'swaps.'" Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued "a preliminary injunction barring enforcement of Minnesota's prediction market statute until a final decision on the merits is reached." But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn't think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction. Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress