Quantum computing essay, from bombe analogy to Shor, with the usual correction that superposition is not brute-force parallelism.
trending30
01 02 One Token Is Enough: Fingerprinting and Verifying Large Language Models from Single-Token Output Distributions arxiv.orgInstead of probing internals, this fingerprints LLMs from trivial one-token distributions and still tracks lineage through API chains.03 ARMOR-IMC: Adaptive Resource Mapping for Operational Robustness via Secure In-Memory Computing arxiv.orgPost-training defense for analog in-memory accelerators, maps around process faults and power leakage without retraining.04 IBM Quantum System One London: Why Every Organisation Should Be Preparing for Post-Quantum Cryptography (PQC) blog.itsecurityexpert.co.ukIBM's London quantum box still can't crack RSA, so this is really a PQC migration checklist with NIST standards.05 What Happens When integrating Modulus Switching and Lossy Source Coding: A New Dual Attack Variant on LWE eprint.iacr.orgNew dual LWE attack variant mixes modulus switching with lossy source coding, shaving FFT costs and nudging Kyber bounds.06 APN permutations over GR(4,2) get classified, and the paper drags differential uniformity beyond prime fields into ring land.07 A Security magazine recap of PQC adoption, NIST standards, CNSA 2.0 timelines, and the usual harvest-now-decrypt-later anxiety.08 LLM-guided evolution breaks perceptual hashes like pHash, PDQ, PhotoDNA, and NeuralHash in black-box mode, because apparently those work...09 Google's 2029 quantum crypto warning is just the old Shor panic with a date stamp and a blockchain angle.10 Can you trust Opal2 SEDs on Linux? This black-box study of 38 drives says firmware bugs and incompatibilities say no.11 The hard part isn’t PQC, it’s finding every stray RSA/ECC dependency before the migration spreadsheet explodes.12 Survey of LLM watermarking, from biased sampling to adaptive-removal attacks, because even text wants DRM.13 NIST trims the post-quantum signature zoo to 9 Round 3 survivors, while the code-based hopefuls get quietly kicked out.14 Trace-only segmentation of cipher implementations, no labels or metadata, just repetition-scale estimates and stable cores.15 Weak-key distinguishers pop out of a split-and-cancel oracle, extending integral attacks to SIMON, SPECK, PRESENT, and GIFT.16 Polynomial-time key recovery breaks Facto-DSA, with all proposed parameter sets falling in under a minute on a laptop.17 Understanding the Post-Quantum Cryptography World in 5 Minutes - ThunderCore Blog news.thundercore.comThunderCore blog post on post-quantum cryptography, NIST picks, and blockchain migration, because signatures needed a sequel.18 A reminder that PQ migration targets asymmetric crypto first, and AES-128/SHA-256 may still be fine despite the 256-bit cargo cult.19 QUBO Modeling of Module Learning With Errors: Stability and Scaling in Post-Quantum Cryptography arxiv.orgQUBO-encodes small MLWE instances for annealers, then checks noise stability and embedding blowup as dimensions grow.20 Video on the post-quantum shift beyond the EO, mostly the boring part everyone skips: migration details, auth vs encryption, and downgrades.21 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - MDSec mdsec.co.ukFirst char in the clear, the rest XORed with a short key, so Dell BIOS passwords fall out of SPI flash dumps.22 Reason piece on declassified FBI files about David Kahn, the crypto historian first treated like a suspect, because of course.23 Can a Halo2 zkVM prove synthesized hardware is power-side-channel safe without leaking the netlist? Apparently, yes.24 The annoying part: ML-DSA is still the least-bad option, and the shinier PQ signatures aren’t arriving before migration does.25 Post-quantum cryptography is now a federal mandate: Here’s what it means and what your agency should do now yubico.comYet another PQC post, this one is about the federal mandate, inventory, contractor pressure, and CMVP bottlenecks.26 Public keys already on-chain are the problem, and BitGo's new wallet controls mostly amount to quantum risk triage until Bitcoin moves.27 G+D's pitch: PQC isn't just for TLS, it's now a migration problem for IDs, telecom, and eSIMs, with hybrid cards already in demos.28 Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis arxiv.orgPaper on MINIAUTH, a dynamic crawler for mini-program OAuth bugs, with tens of thousands of apps and one delightful Baidu key-bruteforce...29 The Handshake That Can't Keep Its Promise: Why Confidential Computing's Flaw Changes the Data Sovereignty Conversation blogs.groupware.org.ukAttested TLS can be relayed, so confidential computing’s data sovereignty pitch takes a CVE-sized hit.30 Can you trace a poisoned code completion back to the fine-tuning sample that taught it? CodeTracer says yes, mostly.