Insights Topic

Cryptography

Browse Attomus insight related to cryptography, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

5 related insights

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

'Military-Grade Encryption' and Other Phrases That Should Make You Reach for Your Notes

Somewhere in nearly every security product’s marketing sits the phrase “military-grade encryption”. Pause on what that phrase actually tells you. The honest answer is: that the vendor employs a marketing department. There is no military grade. The world’s militaries use, for the most part, the same published algorithms as everyone else – AES is approved for US classified information, and AES is also what encrypts your supermarket loyalty app. The algorithm has never been the differentiator. Everything around it is.

Read article

What Android's Keystore Actually Does with AES Keys (and What It Doesn't)

There is a question that comes up constantly in Android security engineering, usually phrased something along the lines of: “how do I prove to my server that this AES key is hardware-backed?” The common answers to this question are often wrong in that they make you think you have a guarantee that you do not have. The short answer is: you cannot prove an AES key’s hardware provenance to a server directly. The certificate chain mechanism that makes remote attestation possible for asymmetric keys does not exist for symmetric keys. If you are building a system that depends upon being able to remotely attest an AES key’s provenance, you need to redesign the system, not find a better API call.

Read article

When Your Next Customer Is an AI Agent: Trust, Identity, and Provenance on the Agentic Web

A growing share of the traffic arriving at any organisation’s website is no longer human. Some of it is the familiar crawling of search engines. But an increasing fraction is something newer: AI agents acting on behalf of specific people – researching a purchase, evaluating a supplier, summarising a market, shortlisting firms for a piece of professional work. The recommendation that once came from a colleague’s memory or a page of search results now frequently comes from a model’s synthesis of what it read.

Read article

The Wrong Way to Market a Security Product, and What to Do Instead

“Military-grade encryption.” “Zero-knowledge architecture.” “Bank-level security.” “Secure enclave protection.” These phrases appear all over the App Store listings for security products, and most of them are meaningless, misleading, or too vague to be useful. The damage they do reaches well beyond the individual product that deploys them. The argument here is not that the phrases are dishonest, though several are. It is that they are structurally harmful to the security industry, because they train buyers to accept claims instead of demanding evidence. Once buyers have been trained that way, every security product – including the ones with real technical substance behind their claims – has to compete in a market where marketing language is weighed on the same scale as engineering.

Read article

The Verifiable Supply Chain: From 'Trust Your Vendor' to 'Check the Signature'

Every organisation runs on software it did not write, built by people it has never met, assembled from components those people did not write either. The traditional governance answer to this uncomfortable arrangement is the supplier-assurance process: questionnaires, certifications, contractual flow-downs, and an annual review. Anyone who has sat on either side of it knows what it verifies – that somebody was able to fill in the questionnaire. The incidents of the past few years – build systems compromised to ship signed malware to thousands of organisations, popular open-source packages hijacked through maintainer accounts, a backdoor inserted into a compression library over years of patient, socially-engineered contribution – share a common feature. In each case the paperwork was in order. The supply chain failed precisely where assurance is thickest and verification thinnest: in the gap between what suppliers assert and what anyone can check.

Read article