Urgent.News

What's breaking now, across thousands of outlets.

Tech

¿Puede una IA descifrar tu cifrado? La amenaza real es otra

La frase "hackeo con IA" se ha vuelto un titular que vende miedo, y al venderlo mezcla tres amenazas que son completamente distintas . Separarlas es la diferencia entre elegir bien tu cifrado y comprar humo. 1. ¿Una IA rompe la matemática del cifrado? No. No existe, hoy, un criptoanálisis por IA que quiebre primitivos bien diseñados: AES, XChaCha20-Poly1305, ML-KEM o Argon2id. Una red neuronal no…

The phrase "hackeo con IA" has become a headline that sells fear, and by mixing three completely distinct threats. Distinguishing them is the difference between choosing good encryption and buying smoke.

Firstly, can an AI break the mathematics of encryption? No. There is no AI cryptoanalysis today that can break well-designed primitives like AES, XChaCha20-Poly1305, ML-KEM, or Argon2id. A neural network cannot guess a 256-bit key nor accelerate the algebra that supports encryption. The key space is so vast that no amount of statistical computing can traverse it. Those who claim AI can decrypt AES are selling fear, not describing an attack.

Secondly, AI does empower attacks by targeting implementation and human error. Real hacks assisted by AI do not touch the mathematics; they scale three things that have always been the weak link: implementation bugs. AI reads code at scale and finds human errors: reused nonces, time-filtering comparisons, poorly handled padding, a well-chosen primitive misused.

Here the encryption fails, not the program surrounding it. Social engineering. AI-generated phishing is more believable and cheaper. It steals master passwords, and no cryptography protects against a key voluntarily delivered. Brute force guided. AI prioritizes which passwords to try. The correct defense already exists: a memory-hard key derivation like Argon2id, calibrated at hundreds of megabytes per attempt, costs memory, not compute — and memory cannot be parallelized cheaply on GPUs or models. AI does not change this cost.

The lesson is old and still true: encryption rarely breaks; it is surrounded. AI makes the surround faster, not the weaker wall.

Thirdly, the real threat to mathematics is not AI: it is quantum computing. The algorithm of Shor breaks RSA and elliptic curve - the basis of almost all asymmetric encryption today. And the attack is not future: it is harvesting now and decrypting later. Any encryption you encrypt today with classical cryptography has an unwritten expiration date. Cryptography based on classical math has a silent expiration date.

The answer is not an anti-IA product. It is post-quantum hybrid cryptography: combining the classical algorithm with one resistant to quantum (for example X25519 with ML-KEM), so breaking the message requires breaking both. The hybrid protects even if one of the two has an undiscovered weakness. How to choose encryption with this in mind: if a provider sells their encryption as "AI-proof," be suspicious: they are describing a threat that does not exist and ignoring the real one.

The real questions that discriminate are: is it post-quantum hybrid? Against "harvest now, decrypt later"? Is the implementation audited? Because the real vector is code bugs, and the best defense is finding them with the same tools the attacker will use. Is the key derivation memory-hard? To prevent a weak password from being broken by brute force at scale. These three are measurable and honest. Anti-IA is none of these three.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

An $11,400 AWS bill, and CloudWatch Logs was $2,100 of it

I got access to the account on a Tuesday morning The founder had sent over credentials the night before with a message that said roughly: I think we're overpaying but I don't know where Total monthly…

  • $11,400 monthly AWS bill deemed excessive for 800 active users
  • $2,100 of the bill attributed to CloudWatch Logs with 43 unretained log groups
  • Debug logging disabled, $900 saved by deleting unused log groups

Reading Input in Java

System.in, BufferedReader, and Scanner Every Java beginner eventually asks the same question: "Okay, I can print output — how do I actually read something the user types?" Java gives you a few ways to…

  • System.in.read() reads single byte, returns ASCII value
  • BufferedReader reads entire lines, converts to desired type
  • Scanner simplifies input, handles multiple data types

3 Identity Checks When Staging DNS Records Reach the Wrong Production Zone

TL;DR: Treat a DNS change as a typed publication with three identities: environment, customer, and zone. Resolve all three from the request, compare them with independently loaded expectations, and…

  • Verify environment, customer, and zone identities separately
  • Halt write operation if identities do not align
  • Focus on zone reference, not just record value validity

More from Saturday 3 October →