Cryptography was the last slow problem
On 28 July of this year, it took an AI about sixty hours to find a cryptographic flaw that two years of expert review had not uncovered. In the following 24 hours, the findings were confirmed and the digital signature submission intended to be secure against both classical and quantum computers, HAWK – a lattice‑based […] The post Cryptography was the last slow problem appeared first on…
On 28th July, an AI algorithm discovered a flaw in a cryptographic system that had evaded years of expert scrutiny. The flaw was found within 60 hours, prompting the withdrawal of HAWK, a post-quantum signature scheme intended to secure data against both classical and quantum computers. HAWK, a lattice-based cryptographic algorithm under review, was deemed unsuitable for standardization.
Cryptography has traditionally been considered a static security system, with minimal changes in decades. However, the discovery of cryptographic weaknesses has become dramatically cheaper with the advent of AI, which can now easily scan all code, certificates, and network configurations at virtually no cost. This has shifted the focus to implementation vulnerabilities, such as expired certificates, deprecated cipher suites, hardcoded credentials, and flawed random number generators.
Even if quantum computers do not pose an immediate threat (Q-Day), the rapid discovery and potential exploitation of classical cryptographic flaws remain a significant concern. To address this issue, organizations must adopt cryptographic agility by maintaining a cryptographic inventory to identify and mitigate vulnerabilities across their systems.
This includes knowing where cryptography is used, being able to replace algorithms without extensive rework, requiring suppliers to demonstrate the same capability, and actively exercising the migration process. Failing to address these gaps in time could leave organizations vulnerable to attacks, highlighting the importance of proactive measures to enhance cryptographic security.
Written by urgent.news from EU-Startups's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.