Off-host auth for AI agents: per-message HMACs, nonce/timestamp binding, and a policy engine the model can't tamper with.
trending23
01 02 OpenSSH 10.4 ships experimental ML-DSA 44 + Ed25519 signatures, plus the usual SSH bugfix pile.03 An essay on CAs revoking Windows code-signing certs for malware, and why PKI was never meant to be a software cop.04 ZTA and PQC support in FreeIPA, Sumedh Sidhaye, #FOSSASIA Summit 2026, #Cybersecurity and Privacy — by FOSSASIA youtu.beFOSSASIA talk video on bolting ZTA and PQC onto FreeIPA, for anyone still hoping identity stacks stay simple.05 Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design arxiv.orgHow do you catch stuff that validates but still fails the receiver’s security model? This paper calls it TBSGs and splits it 4 ways.06 Wultra Raises €6.8 Million in Series A Funding to Accelerate Global Expansion of Post-Quantum Digital Identity Solutions prnewswire.comWultra's Series A press release: can post-quantum identity and auth actually sell to banks before quantum shows up?07 Ledger’s AI tools docs, for wallet CLI runtime ops and DMK build-time signing, with hardware as the last human veto.08 Rust stack for keyed-verification anonymous credentials, with type safety and constant-time discipline, plus Tor/OONI case studies.09 Survey maps quantum-network auth into 4 buckets and compares assumptions, setup, composability, and scale.10 Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform moltenbit.netAudit of OpenReception, an E2EE appointment booking app, with 16 CVEs and the usual tenant-isolation comedy.11 Czech cybersecurity startup Wultra lands €6.8 million to support Europe’s digital identity wallet rollout eu-startups.comSo who's paying Wultra €6.8M to build the plumbing for Europe's digital identity wallet, banks and fintechs apparently?12 Do we really need blow-acoustics as a second factor, or is face unlock just getting extra mucus and a fuzzy extractor?13 Can 5G broadcast auth avoid per-message signatures? TESLA-for-5G swaps them for delayed MACs and a bootstrap ID signature.14 Proof Introduces X401 Protocol To Secure AI Identity Authorization And Digital Transactions tronweekly.comHTTP 401 for AI agents: Proof's x401 adds signed identity checks and ZK disclosure so bots can do transactions.15 Your contacts become the key-transparency system: DKVE cross-checks E2EE keys with OPRFs/OKVS and an SPRT.16 5G privacy paper: vSIM profiles decouple device and subscriber IDs, with an FPGA/srsRAN prototype and re-ID tests.17 NIST releases working draft guidance on incorporating post-quantum algorithms in federal identity standards insidecybersecurity.comNIST's draft finally moves PQC from key exchange theater into federal identity standards and PIV creds.18 SMSR signs agent memory with HMAC and randomized ablation, then proves certified robustness against persistent memory poisoning.19 How do you stop first-packet replays in PSK Shadowsocks without a clock or server nonce? You probably can't.20 The Best of Both Worlds: Hybrid Authenticated Key Exchange for QKD(N) without Signatures eprint.iacr.orgHybrid AKE for QKD without signatures, swapping the usual PQ signature glue for KEMs and a CK01 proof.21 A critique of a 2023 dedup scheme that mixes RSA exponentiation with pairings, so the tag-matching story collapses.22 Can an append-only Merkle index get balanced-tree proof sizes? This compares MMRs, MMBs, and bagging schemes for QMDB.23 Paper on PriSrv, a private wireless service-discovery protocol with ACME; anonymous matchmaking, now with fewer awkward leaks.