Kremlin-backed forgery scheme moved $6.9B through global banks
A Kremlin-backed forgery scheme successfully moved $6.9 billion through global banks. The scheme involved illicit financial activities facilitated by forged documents. (ft.com)
Secure messaging that depends on end-to-end encryption protects message content from service operators, but integrating cloud-based AI features undermines that guarantee when devices offload data for processing. Trusted execution environments (TEEs) - used by services such as Apple’s Private Cloud Compute, Google’s Private AI Compute, WhatsApp’s Private Processing, and some chatbots - promise to run code on servers without exposing plaintext to operators. TEEs do improve privacy versus running in the clear, but they are engineering solutions, not math-based encryption: they carry exploitable bugs, side-channel attacks, and the practical difficulty of keeping cryptographic keys isolated on the same hardware. Homomorphic encryption could hide inputs mathematically but remains too slow for typical LLM use, so TEEs are a pragmatic but weaker substitute that can still require physical or sophisticated attacks to breach.
The practical consequence is clear: when an end-to-end encrypted chat sends messages to a cloud TEE for summarization, review, or storage, those messages leave the device and the system ceases to be genuinely end-to-end encrypted. The recommendation is uncompromising: do not design systems that automatically exfiltrate E2EE data to TEEs; give device holders explicit control and pause before any upload. Users should disable automatic data-sending features if present. TEEs still have valid on-device uses (secure enclaves for biometrics, key storage, backups), but cloud TEEs are a downgrade from true end-to-end encryption and must be treated accordingly.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
A Kremlin-backed forgery scheme successfully moved $6.9 billion through global banks. The scheme involved illicit financial activities facilitated by forged documents. (ft.com)
Obscura is a VPN designed to prevent logging of user activity by only seeing IP addresses and not browsing data. It uses end-to-end encryption and a two-party protocol to enhance privacy and bypass internet censorship. (obscura.com)
AI leaders face significant legal and liability challenges as existing laws may not adequately address the risks associated with AI development and deployment. This creates a potential landmine that could impact the future growth and regulation of artificial intelligence technologies. (wsj.com)
Pentagon investigators blamed overreliance on Palantir's AI system, Maven, for a strike that killed 123 Iranian children. The internal review found that outdated data and excessive trust in AI led to a misidentification of the target, resulting in civilian casualties. (gizmodo.com)
ShinyHunters claims to have breached the FBI, stealing sensitive data on thousands of agents and applicants. The hackers say they took terabytes of data from an Oracle server and a government cloud, posing a major counterintelligence threat. (techcrunch.com)
SAML, an XML-based authentication protocol, was developed in 2002 to support single sign-on but is now considered overly complex and insecure. Modern alternatives like OpenID Connect are recommended to replace it due to its design flaws and security vulnerabilities. (blog.trailofbits.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.