First, it’s LLMs can’t do cryptanalysis. They can barely solve toy substitution ciphers without hallucinating.
Then it’s OK, they can reproduce known attacks, but that’s just pattern matching against papers already in the training data.
Then it’s OK, they found previously unknown attacks on SpoC and a flaw in KINDI’s security proof, but those are obscure competition schemes nobody uses.
Then it’s OK, Claude found a new attack on HAWK that cuts the effective security of a NIST post-quantum signature candidate roughly in half, but HAWK isn’t deployed and a human researcher was involved.
Then it’s OK, Claude independently found a new cryptanalytic attack on AES that improves the previous best technique by 200–800×, but it’s only 7-round AES, not the full 10 rounds.
Then it’s OK, it found a practical key-recovery attack on 13-round LEA that runs in under an hour instead of requiring ~2^86 work, but LEA has 24 rounds.
Then it’s OK but none of this breaks a production cipher.
There was news like 10-15ish years ago that the US government was making massive data storage facilities across the country. Like spending over a billion dollars on them. When I read that I knew that basically every email and text and call and DNS lookup I made was in a permanent record. I operate as though anything I do on a computer is being permanently stored, because it likely is if it's going through any US operated or controlled service providers or companies.
They’re holding off on doing that kind of thing until they have assurance that it won’t matter if the general public know who specifically they are, that they have this capability, and that they are willing to use it without caring for legality. I estimate that we’re probably right on the precipice of that time period.
grey-area · · focus · HN ↗
This headline is misleading.
durdn · · focus · HN ↗
Then it’s OK, they can reproduce known attacks, but that’s just pattern matching against papers already in the training data.
Then it’s OK, they found previously unknown attacks on SpoC and a flaw in KINDI’s security proof, but those are obscure competition schemes nobody uses.
Then it’s OK, Claude found a new attack on HAWK that cuts the effective security of a NIST post-quantum signature candidate roughly in half, but HAWK isn’t deployed and a human researcher was involved.
Then it’s OK, Claude independently found a new cryptanalytic attack on AES that improves the previous best technique by 200–800×, but it’s only 7-round AES, not the full 10 rounds.
Then it’s OK, it found a practical key-recovery attack on 13-round LEA that runs in under an hour instead of requiring ~2^86 work, but LEA has 24 rounds.
Then it’s OK but none of this breaks a production cipher.
Wake me up when it breaks full AES.
Then—
ck2 · · focus · HN ↗
93po · · focus · HN ↗
Andrex · · focus · HN ↗
Revanche1367 · · focus · HN ↗