@cryptomancer@fediverse.cryptomancer.de
Post #4171913
2026-07-28 18:10 UTC
Journalists not giving technical details or linking research reports is a PITA.
Not exactly the linked article, but I am currently working through this report, which benchmarks LLMs: »CryptanalysisBench: Can LLMs do Cryptanalysis?«
by Lukas Fluri, Avital Shafran, Nicholas Carlini, Matthew Jagielski, Milad Nasr, Orr Dunkelman, Eyal Ronen and Florian Tramèr
They come to the conclusion that LLMs can find vulnerabilities in the implementation of crypt algorithms, but not yet in the algorithms themselves.
We will get a lot more CVEs in crypt libraries in the near future.
https://arxiv.org/abs/2607.18538
CC: @SteveBellovin@infosec.exchange
Replies (1)
-
@SteveBellovin@infosec.exchange 2026-07-28 19:36
@cryptomancer I follow @CryptoOrrDun@ioc.exchange here… That LLMs should find bugs in crypto libraries is utterly unsurprising at this point. But these results are about the algorithms, which is much more interesting.