A Mythos attack on a Round 3 PQC algorithm candidate puts him out of commission



Myth helped found a new technique of meeting in the middle based on a Möbius bridgea more sophisticated fingerprinting algorithm used in man-in-the-middle attacks. Using it, Green said, the Mythos code was able to reduce the number of entries required to 289. Anthropic said the savings could reduce the time required for such attacks by a factor of 200 to 800.

The ability to produce large numbers of inputs makes the attack inaccessible outside of the lab. Furthermore, the actual speedup is unknown because the tested attenuated AES algorithm only used 7 rounds. A specification-compliant AES, Green said, uses 10, 12 or 14 rounds, depending on key size.

Anthropic takes care to make most of these warnings clear. Monday’s blog post, however, goes on to argue that the results are still meaningful and could ultimately fundamentally disrupt the cryptanalysis process or adversarial testing of cryptosystems.

“The cyber security community is now grappling with the fact that language models can detect so many bugs that standard human processes (such as vulnerability testing, verification, and remediation) struggle to keep up,” Anthropic wrote. “We predict the same will soon happen in academic cryptography research. As language models increasingly autonomously produce new research results, human researchers may find it difficult to study and validate these results for technical validity, novelty, and utility.”

Anthropic’s report does not mention whether its researchers have used Mythos to attack more tried and tested cryptosystems such as elliptic curve cryptography and RSA. Attack improvements against these systems would be more impressive. It’s not clear how much of an advantage Mythos really has in achieving the most impressive result against an algorithm that’s still in its infancy. There’s no way to know if researchers using traditional cryptanalysis techniques are even close to discovering the same attack.

Ultimately, the lesson from the study is simple. AI-powered cryptanalysis remains untested, and providers of these platforms are keen to exaggerate their benefits. At the same time, there is growing evidence that LLMs can provide significant advantages in finding cryptographic vulnerabilities. It would be a mistake to conclude that LLMs will not one day play an important role in the race between securing and compromising our most vital assets.

The headline and body of this story have been updated to reflect HAWK’s withdrawal.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *