Claude Mythos, the artificial intelligence heralded as revolutionary, has just made a major breakthrough in the world of cryptography. For the first time, it has identified two unprecedented vulnerabilities in algorithms long considered unbreakable. This advancement is a game-changer for both cybersecurity and the trust placed in the systems that protect our data every day.
In the often obscure world of applied mathematics for digital security, uncovering vulnerabilities is a meticulous and painstaking task, requiring the skill of a sleuth. Here, Claude Mythos has done more than just sleuth, by targeting HAWK, a post-quantum signature system, and the Advanced Encryption Standard (AES), a global pillar of encryption.
A critical flaw in HAWK, the hope of post-quantum algorithms
HAWK is emerging as a promising candidate for defense against quantum computer attacks, which could break our traditional codes. Launched in 2022 as part of a NIST competition, this protocol aimed to ensure secure communications in a future dominated by quantum computing.
And yet, Claude Mythos has discovered a weakness that undermines the assurances given so far. In barely 60 hours, the AI found a vulnerability that made it possible to guess the coveted secret key, simply by exploiting a mathematical flaw in HAWK-256, the lightest version of the algorithm.
It’s a bit like installing a reinforced door to protect against future thieves, only to suddenly discover a flaw in the lock that renders it useless. To patch this vulnerability, the keys would need to be doubled in size, but this would significantly reduce the algorithm’s practicality. It remains to be seen whether this discovery will lead to a complete overhaul of the protocol.
What about AES, the benchmark algorithm in global encryption?
When Claude first targeted the Advanced Encryption Standard, his initial efforts suggested the giant was safe. After all, AES is the cornerstone of billions of services, from banks to governments. Yet, his perseverance paid off.
Artificial intelligence has developed a new attack method called Möbius Bridge, which significantly accelerates attempts to compromise the reduced version of AES. While this doesn’t currently compromise the security of critical infrastructure, this discovery requires continued vigilance. Prevention is better than lamenting an incident with potentially massive consequences.
Claude Mythos is more than just a lab gadget. Used in the Glasswing project, the AI analyzed thousands of infrastructures serving partners like the NSA. Among its achievements, it identified a 29-year-old vulnerability in Squid, the well-known proxy server, and another 27-year-old vulnerability in OpenBSD.
This ability to uncover and fix old vulnerabilities has strengthened the security of more than 10,000 critical systems. This approach, supported by responsible disclosure procedures, demonstrates the tangible impact of well-structured collaboration between artificial intelligence and human experts.
In a sense, Claude Mythos has become one of those indispensable allies in the hunt for vulnerabilities. His effectiveness surpasses traditional tools and ushers in a new era in cybersecurity.
Calculation costs commensurate with the contributions of AI
The publisher warns that modern systems require careful attention, and further significant vulnerabilities are to be expected as these AI models become more effective. In this cat-and-mouse game, artificial intelligence is now a key player.
the complete dossier on Anthropic’s Mythos is essential reading. Furthermore, This article details the workings and implications of the discovery
What does the discovery of flaws in post-quantum algorithms mean?
This indicates that even cryptographic solutions supposed to resist attacks from quantum computers may have vulnerabilities, which calls into question long-term security.
Can AI Claude Mythos really break cryptographic systems in production?
Why is it important to have responsible disclosure processes?
To prevent vulnerabilities from being maliciously exploited before being fixed, it is essential to coordinate communication between researchers, developers and authorities.
Will Claude Mythos’s discovery accelerate research in cryptography?
Without a doubt. It highlights the need to review certain standards and use AI to strengthen security audits.
How to follow the progress of Claude Mythos and cybersecurity vulnerabilities?
Specialized platforms, dedicated forums and technology watch sites such as CLUSIVE Or Tech Insider are good resources.
Source: www.01net.com