Dan Goodin

@dangoodin.bsky.social

Cybersecurity Reporter, Ars Technica: https://arstechnica.com/author/dan-goodin/ Hungry for tips. Text me on Signal: DanArs.82. "The world isn’t run by weapons anymore, or energy, or money. It’s run by little 1s and 0s, little bits of data."

With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo.abyssdomain.expert wants to make one thing clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world arstechnica.com/security/202...

Contrary to popular superstition, AES 128 is just fine in a post-quantum world

A stubborn misconception is hampering the already hard work of quantum readiness.

arstechnica.com

“Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.” arstechnica.com/security/202...

Recent advances push Big Tech closer to the Q-Day danger zone

Here's which players are winning the race to transition to post-quantum crypto.

arstechnica.com

The cost and shortage of GPUs means they're frequently shared among dozens of users in cloud environments. 2 new Rowhammer attacks demonstrate how a malicious user can gain full root control of the host machine running high-performance Nvidia GPU cards. arstechnica.com/security/202...

New Rowhammer attacks give complete control of machines running Nvidia GPUs

Both GDDRHammer and GeForge hammer GPU memory in ways that compromise the CPU.

arstechnica.com

Building a utility-scale quantum computer that can crack one of the most vital cryptosystems—elliptic curves—doesn’t require nearly the resources anticipated just a year or two ago, two independently written whitepapers have concluded. arstechnica.com/security/202...

Quantum computers need vastly fewer resources than thought to break vital encryption

No, the sky isn't falling, but Q Day is coming, and it won't be as expensive as thought.

arstechnica.com

Google is dramatically shortening its readiness deadline for the arrival of Q Day, the point at which existing quantum computers can break public-key algorithms that secure decades’ worth of secrets belonging to militaries, banks, and nearly every individual on earth arstechnica.com/security/202...

Google bumps up Q Day deadline to 2029, far sooner than previously thought

Company warns entire industry to move off RSA and EC more quickly.

arstechnica.com

I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.

Scanned newspaper article from 1997. Headline: :Breaking the code breakers." subhed: "Cindy Cohn is fighting the feds on export control and winning." Byline: "Dan Goodin."

Excellent article on the work by @dangoodin.bsky.social: arstechnica.com/security/202... I'd say we bypass Wi-Fi encryption, in the sense that we can bypass client isolation. We don't break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;)

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises

That guest network you set up for your neighbors may not be as secure as you think.

arstechnica.com

This local Wolfdog joined an Olympic ski event and triggered the finish-line camera. This is Nazgul. He snuck into a cross-country skiing sprint this morning and raced the homestretch with some competitors before being escorted home. 14/10 someone get him a medal

Scoop: A report published last week outlined what Palo Alto researchers believed was a China-linked hacking campaign. But after an intervention from execs, the report's language was changed to refer more vaguely to "a state-aligned group that operates out of Asia." www.reuters.com/world/china/...

Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say

Palo Alto Networks opted not to tie China to a global cyberespionage campaign the firm exposed last week over concerns that the cybersecurity company or its clients could face retaliation from Beijing...

reuters.com

If throngs of people handed over their IDs in exchange for a vanity blue check from a pro-authoritarian site, what reason is there to think Discord users won't do the same?

Trump’s federal thugs beat up on His face and his chest Then we heard the gunshots And Alex Pretti lay in the snow, dead Their claim was self defense, sir Just don’t believe your eyes It’s our blood and bones And these whistles and phones Against Miller and Noem’s dirty lies (Full lyrics @ YT page)

Bruce Springsteen@brucespringsteen.net · 6mo ago

I wrote this song on Saturday, recorded it yesterday and released it to you today in response to the state terror being visited on the city of Minneapolis. It’s dedicated to the people of Minneapolis, our innocent immigrant neighbors and in memory of Alex Pretti and Renee Good. Stay free

New, by me: Security researcher Eaton Zveare spent weeks trying to alert a little-known but critical U.S. cargo tech giant that their shipping systems and customers' data were exposed to the web. After weeks of trying, Zveare asked TechCrunch for help. We heard back! ...from the company's law firm.

Exclusive: US cargo tech company publicly exposed its shipping systems and customer data to the web

Shipping tech company Bluspark left internal plaintext passwords, including those of executives, exposed to the internet, at a time when hacks in the shipping industry are on the rise.

techcrunch.com