Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms (nytimes.com)
- Reference: 0184738854
- News link: https://it.slashdot.org/story/26/07/28/1911218/anthropic-ai-model-finds-flaws-in-tough-to-crack-encryption-algorithms
- Source link: https://www.nytimes.com/2026/07/28/us/politics/anthropic-ai-encryption-security-aes.html
> The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.
>
> [...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
"Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency.
"Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."
[1] https://www.anthropic.com/research/discovering-cryptographic-weaknesses
[2] https://www.nytimes.com/2026/07/28/us/politics/anthropic-ai-encryption-security-aes.html
AES crypto attacks (Score:5, Interesting)
The best AES crypto attacks were on reduced-round versions. Good thing reduced-round versions aren't deployed. But these attacks might lead to research on attacks on full-round versions of AES, which would be concerning. There's no knowing if these attacks actually exist, but they aren't proven not to exist. AES just happens to be battle-tested very well.
Also, NYT really shouldn't put periods after A.E.S. and A.I. like they're doing. How do you like N.Y.T.? Oh, you don't? So knock it off.
Re:AES crypto attacks (Score:4, Interesting)
> The best AES crypto attacks were on reduced-round versions. Good thing reduced-round versions aren't deployed. But these attacks might lead to research on attacks on full-round versions of AES, which would be concerning. There's no knowing if these attacks actually exist, but they aren't proven not to exist. AES just happens to be battle-tested very well.
Or perhaps that's why the number of rounds of AES is chosen to be what it is - because each round of AES scrambles and shuffles the bits. Doing fewer rounds means the shuffling might be insufficient and thus you can start deriving information from it.
It's just like why you can shuffle a deck of cards just 7 times using the riffle shuffle to ensure it's sufficiently shuffled. Fewer shuffles don't work, and more shuffles doesn't improve randomness.
Writing skills (Score:3)
> “no again the goal is that we have highly inteligent [sic] model as good top researcher, we want to find new attacks”
> “no we don't want to change the targets [...] agian [sic] we need to find something that worth [sic] publishing”
> “again we are not looking for low hanging fruit, we want proper research to find genuinly [sic] hard findings.”
Everyone else found new attacks on the low hanging fruit of Anthropic's writing skills.
Will a qualified cryptographer weigh in please? (Score:2)
I don't trust the NYT to not be duped by marketing on this topic. I've seen very intelligent people, who are knowledgeable about many other things, not know squat about cryptography and fall prey to bad information.
Find more flaws... (Score:2)
... allowing for recycling to propagate logistically, chemically ... allowing for better cooling, heating and energy models ... allowing for better food cultivation outcomes ... allowing for better health outcomes... Instead of making bitcons, how about all that abundance you are selling like snakes...
I scored a 100 yard touchdown (Score:2)
by redefining the yard, and also what a touchdown is.
Re: I scored a 100 yard touchdown (Score:2)
It's a very weird way of doing things even if it is "standard". Surely the ability to crack a weaker version doesn't mean a stronger computer can beat a stronger version.