Please turn JavaScript on
Attomus icon

Attomus

Welcome to Attomus’s blog - Cybersecurity, Advanced technology and Security discussions from around the globe.

Click on “Follow” and decide if you want to get news from Attomus via RSS, as email newsletter, via mobile or on your personal news page.

Subscription to Attomus comes without risk as you can unsubscribe instantly at any time.

You can also filter the feed to your needs via topics and keywords so that you only receive the news from Attomus which you are really interested in. Click on the blue “Filter” button below to get started.

Title: Attomus

Publisher:  attomus
Message frequency:  0.21 / day

Message History

“Military-grade encryption.” “Zero-knowledge architecture.” “Bank-level security.” “Secure enclave protection.”

These phrases appear all over the App Store listings for security products, and most of them are meaningless, misleading, or too vague to be useful. The damage they do reaches well beyond the individual product that deploys them. The argument here is not that...


Read full story

Every organisation runs on software it did not write, built by people it has never met, assembled from components those people did not write either. The traditional governance answer to this uncomfortable arrangement is the supplier-assurance process: questionnaires, certifications, contractual flow-downs, and an annual review. Anyone who has sat on either side of it knows wh...


Read full story

Threat modelling has a reputation problem. Ask a developer what a threat model is and you tend to get one of two answers. The first: an architectural diagram with threat labels, produced during design and never looked at again. The second: the section of a compliance document everyone writes carefully and nobody reads, including the people who wrote it.

Both of those e...


Read full story

Michael Hayden – the only person to have run both the NSA and the CIA – told a 2014 debate at Johns Hopkins, “We kill people based on metadata.” The line was not a boast about breaking encryption. It was the opposite point: for a great many purposes, nobody needs to.

The earlier posts in this series looked at what encryption guarantees, and at


Read full story

The backup format for an authenticator app looks like a solved problem. Encrypt the secrets with a passphrase. Write the ciphertext to a file. Done.

It is not done. The naive version of this has at least four ways to fail silently, one of which can make your backup permanently undecryptable without any error that would tell you what went wrong. The 28-byte header we en...


Read full story