5 related insights
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Browse Attomus insight related to cybersecurity, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Somewhere in nearly every security product’s marketing sits the phrase “military-grade encryption”. Pause on what that phrase actually tells you. The honest answer is: that the vendor employs a marketing department. There is no military grade. The world’s militaries use, for the most part, the same published algorithms as everyone else – AES is approved for US classified information, and AES is also what encrypts your supermarket loyalty app. The algorithm has never been the differentiator. Everything around it is.
Read articleEvery organisation runs on software it did not write, built by people it has never met, assembled from components those people did not write either. The traditional governance answer to this uncomfortable arrangement is the supplier-assurance process: questionnaires, certifications, contractual flow-downs, and an annual review. Anyone who has sat on either side of it knows what it verifies – that somebody was able to fill in the questionnaire. The incidents of the past few years – build systems compromised to ship signed malware to thousands of organisations, popular open-source packages hijacked through maintainer accounts, a backdoor inserted into a compression library over years of patient, socially-engineered contribution – share a common feature. In each case the paperwork was in order. The supply chain failed precisely where assurance is thickest and verification thinnest: in the gap between what suppliers assert and what anyone can check.
Read articleMichael Hayden – the only person to have run both the NSA and the CIA – told a 2014 debate at Johns Hopkins, “We kill people based on metadata.” The line was not a boast about breaking encryption. It was the opposite point: for a great many purposes, nobody needs to. The earlier posts in this series looked at what encryption guarantees, and at who holds the keys. This one concerns everything those guarantees leave exposed: the data about the data. Who communicated with whom. When, how often, in what bursts, from which locations, on which devices, in messages of what size. Content encryption – even flawless, end-to-end, key-custody-correct encryption – conceals none of it.
Read article“Hardware-backed” is among the most widely used and least interrogated phrases in security. At its best it names a specific and valuable protection: a small, deliberately limited piece of hardware that holds cryptographic keys and will not surrender them, even to software that has otherwise taken over the machine. At its worst it is an adjective applied to make a product sound safer than it is. The distance between those two is the subject of this piece.
Read articleThe short answer first: the quantum threat to public-key cryptography is real, it is not imminent, and almost everything needed to deal with it in an orderly fashion already exists. That combination is rare in security. One audience is told the sky is falling and sold “quantum-safe” products of uneven seriousness; another decides the whole business is decades away and files it under someone else’s problem. Both are wrong, and the material needed to see why is all in the public record.
Read article