Series
How It Breaks in Real Life
11 parts of 11
-
AES-the-cipher has never been broken in the field -- its deployments have. KRACK, repeated GCM nonces, and cache timing broke the wrapper, never the block.
- Part 2 How the Hash Functions Broke in Real Life: MD5, Flame, SHATTERED, and the Long Death of SHA-1
MD5 and SHA-1 were genuinely, mathematically broken -- yet every real breach still needed a second failure: a deployment still trusting the dead hash.
- Part 3 How RSA Breaks in Real Life: ROCA, Bleichenbacher's Ghosts, FREAK, and the Keys That Shared a Prime
No one has ever factored a strong, deployed RSA key -- yet ROCA, Bleichenbacher's oracle, DROWN, and FREAK broke real RSA anyway. The break was never the factoring.
-
No one has solved the discrete log on a strong curve or a 2048-bit group -- yet PS3, Android wallets, TPMs, CurveBall, and Logjam all fell. Here is exactly how.
-
No quantum computer can break RSA in 2026, yet long-lived secrets encrypted today may already be lost. Harvest now, decrypt later is a deployment failure.
-
ML-KEM shipped with a machine-checked security proof, yet its reference code leaked secret keys through a division instruction. Why every break missed the math.
-
In 2022 two vetted NIST post-quantum candidates fell to classical math -- Rainbow in a weekend, SIKE in ten minutes. That is the process working, not failing.
-
For thirty years cryptographers warned a mandated wiretap is a backdoor. Salt Typhoon proved it: a nation-state walked through CALEA lawful-intercept plumbing.
-
Prompt injection is not a content-safety nuisance. In tool-using AI agents it is a remote-code-execution class -- traced through four disclosed 2025-2026 CVEs.
- Part 10 Ransomware Without the Ransom: How Snowflake and the Extortion-Only Era Rewrote the Playbook
Between 2024 and 2026 the biggest ransomware attacks stopped encrypting. Attackers just logged in or exploited a zero-day, copied the data, and extorted.
- Part 11 How Zero-Knowledge Broke in Real Life: Under-Constrained Circuits and the Bugs That Minted Money
Every time production zero-knowledge has publicly broken, the cryptography held. The real failures are soundness bugs in circuits, verifiers, and transcripts.