Anthropic is hailing the results of two cryptographic problems it threw at its Mythos AI security model that found weaknesses in the mathematical problems underpinning the robustness of two algorithms. At the moment, it’s hard to know how much of the company’s reporting is marketing hype, but the findings are still worth paying attention to because they could signal important advances in breaking cryptography that’s crucial to privacy and security.
Before digging into the results, a few caveats.
First, the outcomes are incremental. They don’t break any of the cryptosystems anyone relies on today. Instead, they reveal methods for moderately reducing the work that would be required to defeat the systems.
Second, the cryptosystems tested were weakened versions of the ones defined in their formal specifications. Such “challenge instances” are provided by the specification authors for use in adversarial peer review. It’s standard to use the weakened versions in testing, but the real ones are considerably more robust in production settings.
Third, even with the improvement, the underlying “primitives”—meaning the underlying mathematical problems that form the basic building blocks of cryptosystems—remain safe, at least for now.
Lastly, both of the attacks use methods that would likely be infeasible outside of testing environments.
HAWK is (likely) dead #
Anthropic said its Mythos model—which currently remains available only to a select group of trusted users—was able to advance attacks against two cryptosystems. The first system is HAWK, a digital signature scheme designed to withstand future attacks from quantum computers. HAWK has so far survived two rounds of testing by NIST (the National Institute of Standards and Technology) for evaluating the security of PQC (post-quantum cryptographic) algorithms through widespread testing. HAWK is currently in a third round of testing and remains far from being finalized as a formal standard.