-
Why we should INSIST that years are written in full
Two missing digits can change the century and corrupt the record A document I received during the evening of 9 September 2026 has a section headed “History”. Its version table dates version 1.0 as 20.08.26. I presume that means 20 August 2026. The date itself does not establish that. Under a year–month–day convention, the same…
-
CyberSea 2026: Cybersecurity, Community and the Black Sea
Sophie loitering casually by some CyberSea Festival branding in the roasting sunshine. Soare, Mare, Securitate Cibernetică: Sun, Sea, Cybersecurity Reflections from the first two days in Constanța Cybersecurity conferences are often held in anonymous hotel function rooms, apparently designed to ensure that nothing distracts delegates from the PowerPoint slides or the coffee of uncertain legal…
-
Why Your Document Vanishes but Your Secrets Won’t Die
The Asymmetry of Digital Loss & The Tyranny of Tiny Secrets There is a familiar little cruelty in computing: the thing you need is always easy to lose, while the thing you desperately need to delete seems almost impossible to destroy with certainty. The document you were working on yesterday has vanished into some folder,…
-
Resilient Assurance: A Failure-Assumed Approach to Confidence and Control
“Mature assurance is not the pursuit of perfect prevention. It is the disciplined management of inevitable failures” Limits of Classical Assurance Traditional or classical Assurance tends to make assumptions; that controls are implemented, that controls operate correctly, and thus that risk is reduced. In practice, things are not generally so simple. Controls decay. Environments change…
-
Strong Ciphers, Weak Assumptions
The best laid plans of mice and men… A lot of attention has been paid to the design and implementation of messaging apps. Signal usually comes out as being considered the most trustworthy of the bunch by people who worry about detail, but there are other apps with real end-to-end encryption too. Of course, subverting…
-
How will Quantum Vulnerable Encryption (QVE) unravel?
I’ve written a little recently (and less recently!) about Post Quantum Encryption and how action is needed NOW. How the timeline of QVE’s unravelling and collapse will take place is almost impossible to say. But we might usefully draw some lessons from the collapse in confidence of the MD5 hashing algorithm. Let’s look at the…
-
[***NOT REDACTED***]
Or “Redaction Failures”. There have been many high-profile redaction failures over the years[1]. So it may help to briefly classify[2] them into some different types. Application of a black opaque block over the text in a PDF, leaving the original text selectable underneath. A classic of the redaction failure genre. Removal of text, but failing…
