#Encryption

Every story tagged Encryption, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

27 stories · open in the command center

  • Security & PrivacyWiredMaddy Varner2m

    DHS Wants Protesters’ Signal Group Chats

    The Department of Homeland Security is seeking access to private Signal group chats used by protesters to organize lawful responses to immigration enforcement activities, raising significant First Amendment concerns and establishing a troubling precedent for government surveillance of encrypted communications. This case highlights the tension between law enforcement access to encrypted platforms and citizens' constitutional rights to associate and organize, with implications for how organizations must protect employee and community communications from government overreach. IT leaders must recognize that encrypted collaboration tools are increasingly becoming targets of legal discovery requests, requiring robust data governance policies, legal preparedness, and transparent communication about data retention and government request procedures.

  • Security & PrivacyThe VergeStevie Bonifield2m

    Now you can securely link multiple phones to one Signal account

    Signal now enables users to securely link multiple phones to a single account with end-to-end encryption, expanding beyond its previous PC/iPad support and addressing the growing need for multi-device workflows in organizations. This enhancement reduces security risks through optional encrypted message transfer and selective device management, making Signal more viable for enterprises managing mobile-first workforces. IT leaders should evaluate whether this capability aligns with their secure communication requirements and BYOD policies, particularly for sensitive communications across distributed teams.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    Apple challenges UK government’s latest demand for iCloud backdoor: report

    Apple is legally challenging the UK government's renewed demand for a backdoor into encrypted iCloud data, marking an escalating conflict over data sovereignty and encryption standards. This precedent-setting case has significant implications for IT organizations globally, as regulatory demands for encryption backdoors could force technology companies to weaken security posture and expose enterprise data to unauthorized access. CIOs must monitor this litigation outcome closely, as an unfavorable ruling could reshape data protection compliance requirements across jurisdictions and compromise the end-to-end encryption standards that underpin modern security architectures.

  • Security & PrivacyTechMemeTim Bradshaw2m

    UK court filing: in July, Apple launched a new legal challenge against the UK government's attempt to create a "backdoor" to access encrypted customer data (Tim Bradshaw/Financial Times)

    Apple has initiated a new legal challenge against UK government proposals to mandate backdoor access to encrypted customer data, escalating the ongoing tension between national security requirements and data privacy protections. This development has significant implications for IT leaders managing data governance and compliance strategies, as regulatory pressure for encryption backdoors could force organizations to choose between government mandates and customer trust. Technology leaders should prepare for potential regulatory shifts that could impact encryption standards, data protection architectures, and international compliance obligations across multiple jurisdictions.

  • Security & Privacy9to5MacZac Hall2m

    Apple launches second legal challenge to UK iCloud backdoor order, per report

    Apple has filed a second legal challenge against the UK government's attempt to mandate encrypted backdoor access to iCloud user data, escalating a dispute that began in early 2025 when the UK secretly ordered Apple to weaken its Advanced Data Protection encryption. This case has significant implications for IT security strategies and regulatory compliance globally, as it establishes a precedent for government overreach into encrypted data systems and threatens the encryption standards that enterprise security models depend upon. CIOs and technology leaders must recognize this as a critical inflection point in the encryption vs. surveillance debate, where regulatory pressure could force fundamental changes to data protection architectures that impact customer trust and security posture across industries.

  • Security & PrivacyVulners1m

    CVE-2026-58061: In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue al... (CVSS 8.7)

    In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

  • Security & PrivacyHacker News3m

    Encryption and Globalization 15 Years Later: E2EE and the "Going Dark" Debate

    End-to-end encryption (E2EE) has become a critical security feature in global communications, creating significant tensions between user privacy protection and law enforcement access needs that IT leaders must navigate. Organizations face mounting pressure from regulatory bodies demanding encryption backdoors while simultaneously needing to meet customer expectations for privacy, requiring CIOs to balance security architecture decisions with evolving compliance obligations across different jurisdictions. Strategic encryption policies directly impact business risk, customer trust, and organizational liability, making this a boardroom-level issue that demands clear governance frameworks and vendor accountability.

  • Security & PrivacyHacker News3m

    Searchable field-level encryption on Supabase with CipherStash

    Supabase now offers field-level encryption through CipherStash integration, enabling organizations to search and query encrypted data without decryption while maintaining exclusive key control—eliminating the traditional trade-off between security and database performance. This Data Level Access Control (DLAC) solution addresses compliance requirements for regulated workloads (HIPAA, GDPR, SOC 2) by enforcing encryption at the application layer with per-value keys managed through zero-knowledge key management, reducing breach surface and audit complexity. The seamless integration requires minimal code changes and works transparently with existing TypeScript ORMs (Drizzle, Prisma) and SQL operations, making it viable for enterprises seeking to maintain searchability without sacrificing data protection.

  • Security & PrivacyHacker News3m

    Codex starts encrypting sub-agent prompts

    Codex's recent encryption of multi-agent sub-agent prompts (v0.137.0+) has created a critical auditability gap—while improving security through encrypted message delivery, it simultaneously removes human-readable task information from audit trails, logs, and debugging tools, making it impossible for IT teams to review what tasks were delegated to sub-agents after deployment. This regression directly impacts compliance, incident investigation, and operational transparency, requiring organizations to either lose auditability or delay encryption implementation pending a fix that preserves readable audit copies alongside encrypted delivery.

  • Security & PrivacyHacker News3m

    Chat Control 1.0 and 2.0 Explained

    The EU is pursuing two parallel legislative tracks to mandate child sexual abuse material detection on digital platforms: Chat Control 1.0 (a temporary law that expired in April 2026 but is being revived through an expedited procedure) and Chat Control 2.0 (a permanent regulation still in negotiations). Both proposals threaten to impose mandatory or coercive scanning of private communications—including end-to-end encrypted messages—creating significant compliance, privacy, and security risks for IT organizations managing European users' data. IT leaders must prepare for potential mandatory content scanning requirements that could conflict with encryption strategies, data protection commitments, and organizational privacy policies.

  • Security & PrivacyHacker News3m

    Since Linux 6.9, LUKS suspend stopped wiping disk-encryption keys from memory

    A critical security vulnerability in Linux 6.9+ has been identified where LUKS disk encryption keys are no longer properly wiped from memory during system suspend operations, potentially exposing sensitive encryption material to unauthorized access. This represents a significant risk for organizations relying on Linux systems with full-disk encryption, particularly in environments where physical device access or memory forensics are possible threats. IT leaders must urgently evaluate their Linux infrastructure deployment versions and develop a patching strategy to mitigate this vulnerability before it can be exploited.

  • Security & PrivacyTechMemeMishal Husain2m

    Q&A with Signal's Meredith Whittaker on why online child safety efforts risk mass surveillance, leaving the markets that demand weakening of encryption, more (Mishal Husain/Bloomberg)

    Signal's leadership warns that well-intentioned child safety initiatives risk enabling mass surveillance through encryption weakening, creating significant security and compliance risks for organizations handling sensitive data. The tension between child protection mandates and privacy preservation presents CIOs with a critical strategic challenge: balancing regulatory pressures in certain markets against the cybersecurity and brand risks of compromised encryption standards. Organizations must prepare for potential regulatory divergence across markets, where some jurisdictions may mandate encryption backdoors while others strengthen privacy protections.

  • Security & PrivacyHacker News3m

    Show HN: Exploiting Slack's video embeds to achieve E2EE communication

    A security researcher demonstrated a method to achieve end-to-end encryption within Slack by exploiting the video embed feature to execute client-side cryptographic operations, revealing a potential gap in Slack's platform security model. This highlights the risk of unintended feature misuse in enterprise communication platforms and raises questions about the security implications of embedded iframe capabilities. IT organizations should assess their Slack deployment configurations and consider whether additional governance controls are needed around third-party app permissions and embedded content handling.

  • Security & PrivacyHacker News3m

    The Quiet Numbers Station: Decoding Nineteen Years of GPS Cryptography

    Researchers have discovered that GPS satellites have been broadcasting encrypted military cryptographic keys to authorized receivers via a public signal for nearly two decades, effectively operating as a global 'numbers station' hidden in plain sight. This Over-the-Air Distribution (OTAD) system, while operationally efficient for the military, creates a significant security risk as the encrypted traffic is accessible to any observer with standard GPS equipment and represents a potential target for cryptanalysis. For IT organizations managing critical infrastructure dependent on GPS timing and positioning, this revelation highlights the importance of understanding hidden dependencies on military systems and assessing vulnerabilities in globally deployed cryptographic networks.

  • Security & PrivacyHacker News3m

    The Empty Field That Wasn't: GPS, OTAD and Two Decades of Encrypted Broadcasts

    Researchers discovered that GPS satellites have been broadcasting encrypted military rekeying messages through a 176-bit field in the public L1 C/A signal for 19 years—effectively operating as covert numbers stations accessible to all receivers. This revelation exposes a significant transparency gap between civil and military GPS infrastructure, with 12.16 million encrypted payloads transmitted daily across the global satellite fleet. IT organizations managing GPS-dependent systems, signal security, or critical infrastructure must reassess their understanding of GPS signal composition and potential security implications of this undocumented military channel.

  • Security & PrivacyHacker News3m

    Parallel Reconstruction of Lawful TLS Wiretapping

    A critical vulnerability (CVE-2023-38198) in acme.sh certificate management software enabled unauthorized TLS certificate issuance through shell command injection in the ACME protocol implementation, creating a pathway for lawful intercept operations to bypass traditional certificate authority safeguards. This attack demonstrates that the entire TLS trust chain—foundational to enterprise security architecture—can be compromised not through cryptographic weakness but through automation tool vulnerabilities in certificate renewal processes. IT organizations must recognize that certificate management automation represents a critical attack surface that directly undermines encryption-based security controls across all encrypted communications.

  • Security & PrivacyHacker News3m

    How Shamir's Secret Sharing Works

    Shamir's Secret Sharing is a cryptographic technique that splits sensitive secrets (like master keys or recovery credentials) into shares where a minimum threshold of shares can reconstruct the secret, but any fewer shares reveal zero information—addressing critical governance and disaster recovery needs without single points of failure. For IT organizations, this mathematical approach enables secure credential management, compliance with multi-person authorization requirements, and resilient backup strategies that prevent both unauthorized access and catastrophic loss. Modern implementations like Ente's Legacy Kit layer this technique with additional server-mediated controls to balance security, recoverability, and revocability—a pattern CIOs should consider for protecting high-value secrets across identity management, privileged access, and business continuity scenarios.

  • Security & PrivacyHacker News3m

    Unknowable Math Can Help Hide Secrets

    Researchers have discovered a breakthrough connection between mathematical logic and cryptography, enabling a new class of zero-knowledge proofs that leverage fundamental mathematical unknowability rather than computational complexity to hide secrets. This advancement overcomes long-standing limitations in cryptographic proof systems and opens new pathways for securing sensitive information without revealing underlying data or reasoning. For IT organizations, this represents a fundamental shift in cryptographic capabilities that could enhance data protection, enable privacy-preserving authentication systems, and strengthen defenses against increasingly sophisticated threats.

  • Security & PrivacyThe VergeJay Peters2m

    Apple brings encrypted RCS chats to iPhone

    Apple has implemented end-to-end encrypted RCS messaging in iOS 26.5, enabling secure cross-platform communication with Android users while preventing Apple and Google from viewing message content. This development represents a significant shift in Apple's interoperability strategy and addresses long-standing security concerns in cross-platform messaging, with encryption enabled by default for new and existing conversations. For IT organizations, this means improved security posture for BYOD environments and reduced liability around unencrypted inter-platform communications, though it requires coordination with carrier support and consideration of potential MDM policy updates.

  • Security & PrivacyWiredReece Rogers2m

    Update Your iPhone Now for Better Encrypted Messaging With Android

    Apple's iOS 26.5 update introduces end-to-end encryption for RCS messaging between iPhones and Android devices, closing a significant security gap in cross-platform communications and reducing organizational vulnerability to message interception. This development has strategic implications for enterprises managing heterogeneous device ecosystems, as it improves security posture for mobile communication without requiring app changes or user behavior modifications. IT leaders should recognize this as a positive shift toward default encryption across platforms, though availability is carrier-dependent and currently in beta.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple pushes back against Canadian bill that could force companies to weaken encryption

    Apple and Meta are opposing Canadian Bill C-22, warning that its broad investigative powers could enable the government to compel companies to weaken encryption or install backdoors—a precedent that threatens the security and privacy capabilities that enterprise users depend on. This marks the continuation of a global pattern of regulatory pressure on encryption, following similar disputes in the UK and echoing the San Bernardino case, which signals an escalating challenge to corporate security infrastructure across jurisdictions. For IT leaders, this legislation portends increasing regulatory fragmentation where different countries may impose conflicting security requirements, forcing organizations to either maintain multiple security postures or accept weakened protections globally.

  • Security & PrivacyHacker News3m

    GnuPG – post-quantum crypto landing in mainline

    GnuPG 2.5.19 introduces post-quantum cryptography support through Kyber (ML-KEM) encryption, marking a critical evolution in cryptographic infrastructure that IT organizations must adopt before the 2.4 series reaches end-of-life in two months. This advancement is essential for protecting sensitive data against future quantum computing threats and establishing compliance with emerging cryptographic standards. For CIOs, this represents both an immediate upgrade obligation and a strategic opportunity to future-proof encryption across email, data protection, and secure communication systems enterprise-wide.

  • Security & PrivacyArs Technica2m

    Contrary to popular superstition, AES 128 is just fine in a post-quantum world

    Cryptography experts have debunked the widespread misconception that quantum computers will render AES-128 encryption obsolete, clarifying that Grover's algorithm cannot effectively parallelize attacks against 128-bit symmetric keys the way classical computers can. The actual security cost of quantum attacks on AES-128 remains around 2^104 operations—well beyond practical threat levels—meaning organizations do not need to prematurely migrate to AES-256, allowing IT teams to focus resources on actual post-quantum cryptography transitions where they are genuinely necessary. This consensus, backed by NIST, German security agencies, and leading cryptographers, provides strategic clarity for enterprise encryption strategies and helps prevent costly and unnecessary security infrastructure overhauls.

  • Security & PrivacyHacker News3m

    Quantum Computers Are Not a Threat to 128-Bit Symmetric Keys

    Despite the urgent need to replace asymmetric cryptography (RSA, ECDSA) vulnerable to quantum attacks, existing symmetric encryption standards like AES-128 and SHA-256 remain secure and require no upgrades for post-quantum readiness. The common belief that quantum computers 'halve' symmetric key security is a misconception based on misunderstanding Grover's algorithm, which cannot efficiently parallelize attacks—breaking AES-128 would require 140 trillion quantum circuits running for a decade. IT organizations can confidently maintain current symmetric encryption deployments while focusing migration efforts exclusively on updating asymmetric cryptography systems.

  • Security & PrivacyArs Technica2m

    "TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database

    Microsoft's Windows 11 Recall feature, which captures user activity via screenshots, has a critical security gap despite improved encryption: a security researcher demonstrated that malware can intercept Recall data through an unprotected system process (AIXHost.exe) once users authenticate, exposing potentially months of sensitive business data. Microsoft has declined to classify this as a vulnerability, stating the behavior is "as designed," leaving enterprise environments at risk. Third-party applications like Signal and Brave are implementing their own protections to exclude themselves from Recall tracking, highlighting the feature's fundamental security concerns for organizations handling sensitive information.

  • Security & PrivacyHacker News2m

    FBI used iPhone notification data to retrieve deleted Signal messages

    The FBI successfully recovered deleted Signal messages from an iPhone by extracting data from Apple's notification storage database, even after the app was removed from the device. This case demonstrates that encrypted messaging apps' security can be bypassed through device-level data retention mechanisms, particularly when users don't enable notification privacy settings. The incident highlights critical gaps between application-level encryption and operating system data caching that can be exploited through forensic tools and device backups.

  • Security & PrivacyHacker News2m

    Veracrypt project update

    VeraCrypt continues to strengthen its position as a critical enterprise encryption solution, with ongoing updates that enhance security posture and compliance capabilities for organizations managing sensitive data. For IT leaders, maintaining VeraCrypt in your data protection strategy ensures alignment with evolving regulatory requirements and protects against emerging threats to encrypted volumes and full-disk encryption implementations. This signals the importance of regularly auditing encryption tools within your infrastructure and planning updates to maintain security standards and operational resilience.

Browse all tags