ON
← Back to feed
Claude has discovered a weakness in the crypto algorithm.
Germany🏛️ PoliticsCenter25 days ago

Claude has discovered a weakness in the crypto algorithm.

Anthropic hat seine KI 'Claude' eingesetzt, um kryptografische Algorithmen zu testen, und dabei Schwächen im Post-Quanten-Kryptografie-Algorithmus HAWK sowie in einer abgekürzten Version von AES128-Cipher entdeckt. Die KI identifizierte Angriffe, die die Effektivität der Verschlüsselung beeinträchtigen könnten, indem sie die Schlüssellänge effektiv halbiert oder die Rechenzeit für Brute-force-Angriffe deutlich reduziert. Diese Ergebnisse gelten jedoch nur für vereinfachte Varianten der Algorithmen und nicht für die vollständigen Systeme. Anthropic betont, dass die gefundenen Schwachstellen keine Auswirkungen auf aktuelle Sicherheitssysteme haben und die Nutzung von KI in der Sicherheitsforschung trotz hoher Kosten und Ressourcenbedarfs als hilfreich angesehen wird.

Anthropic's AI system, Claude, has identified vulnerabilities in cryptographic algorithms, raising concerns over the security of post-quantum encryption standards. The discovery was made during routine analysis conducted by the company’s researchers using its advanced language model, Mythos Preview. Specifically, the AI uncovered weaknesses in the HAWK algorithm, which is considered a candidate for post-quantum cryptography (PQC). HAWK is designed to resist attacks from quantum computers, yet the findings suggest that under certain conditions, the effective key length could be significantly reduced, making the encryption more susceptible to decryption. The research, published in Anthropic’s research blog, indicates that the AI developed an improved method of attacking the digital signature scheme used in HAWK. According to the report, this attack reduces the time required to recover a key by effectively halving the key length. For smaller key sizes such as HAWK256, the recovery process becomes feasible with computational effort equivalent to 2^38 operations, compared to the original key length of 2^64. While larger keys remain practically unbreakable, the results highlight potential risks in the implementation of HAWK for specific applications. In addition to HAWK, Anthropic’s researchers tested another variant of the AES128 cipher. They found that the AI could identify vulnerabilities in a simplified version of the algorithm, which uses only seven rounds of encryption instead of the standard ten. This stripped-down version is often used by researchers to study algorithms and uncover possible flaws. The AI’s analysis revealed that existing attacks on this variant could be accelerated by up to 200 to 800 times. However, these improvements were achieved through extensive computation, requiring several days and a billion tokens, before human experts verified the findings, which took hundreds of hours. Despite these discoveries, Anthropic emphasizes that they have no impact on the current security of full AES encryption systems. The company clarifies that the assumptions required for the attacks are not practical, even for the earlier studies upon which the current work builds. Furthermore, the findings do not challenge the overall robustness of widely used cryptographic protocols. The use of AI in cybersecurity research has become increasingly common, and Anthropic highlights how their approach can aid in identifying potential weaknesses without requiring deep expertise from human researchers. In this case, the lead researcher had a background in computer science but lacked specialized knowledge in the particular cryptographic methods being analyzed. The company notes that while human oversight is still necessary, the AI’s ability to process large volumes of data efficiently makes it a valuable tool in the field. Beyond HAWK and AES, Anthropic reports that other cryptographic algorithms were also subjected to similar analyses, resulting in minor optimizations of known attacks. However, the company stresses that none of these findings affect existing production systems. The implications of these discoveries underscore the evolving nature of cryptographic security and the role of artificial intelligence in pushing the boundaries of both threat detection and defensive strategies. As the landscape of cyber threats continues to evolve, the integration of AI into security research will likely play an ever-growing part in maintaining the integrity of digital communications.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 9025 days ago
Claude has discovered a weakness in the crypto algorithm.

Anthropic hat seine KI 'Claude' eingesetzt, um kryptografische Algorithmen zu testen, und dabei Schwächen im Post-Quanten-Kryptografie-Algorithmus HAWK sowie in einer abgekürzten Version von AES128-Cipher entdeckt. Die KI identifizierte Angriffe, die die Effektivität der Verschlüsselung beeinträchtigen könnten, indem sie die Schlüssellänge effektiv halbiert oder die Rechenzeit für Brute-force-Angriffe deutlich reduziert. Diese Ergebnisse gelten jedoch nur für vereinfachte Varianten der Algorithmen und nicht für die vollständigen Systeme. Anthropic betont, dass die gefundenen Schwachstellen keine Auswirkungen auf aktuelle Sicherheitssysteme haben und die Nutzung von KI in der Sicherheitsforschung trotz hoher Kosten und Ressourcenbedarfs als hilfreich angesehen wird.

Bias read (Center): Die Berichterstattung bleibt sachlich und objektiv, ohne klare politische Neigung. Es wird keine Seite bevorzugt, sondern lediglich die wissenschaftlichen Ergebnisse und deren Implikationen dargestellt. Die Kritik am Ressourcenaufwand und die Betonung der Neutralität der Ergebnisse zeigen eine neutr

Why factuality (95): The article accurately reports the discovery of vulnerabilities in HAWK and a reduced version of AES by Anthropic's Claude Mythos Preview. It correctly states that HAWK is a post-quantum candidate and that the attack reduces effective key length. It mentions the 60-hour timeframe and the lack of imp

Why objectivity (90): The article maintains a neutral tone overall, presenting facts without overt bias. However, it uses slightly technical language that may be less accessible to non-experts. It avoids taking sides but focuses on the findings rather than broader implications.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories