RSS Amplifier

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Aug 17, 2026

TechLetters ☕️ McEliece post-quantum crypto gets a A PUNCH IN THE FACE? US creates cyber-privateers. Cyber norms face a stress test. French tax office breach exposes 678,000 people.

0
Sign in to vote or save

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique

A major result in post-quantum cryptography. A key security assumption behind Classic McEliece, a public-key encryption system considered to resist quantum computers, has been undermined. Researchers found a provable quasipolynomial-time method for detecting the hidden mathematical structure in its public keys. The attack is still astronomically expensive and cannot yet decrypt messages, but this is a serious weakening of one of the oldest post-quantum cryptosystems. McEliece is not broken practically today, but an important assumption underlying its theoretical security has been broken. For the Classic McEliece parameter sets, the estimated cost of the best known structural distinguisher drops from roughly 2^298-2^691 operations to about 2^114-2^124. That is huge. https://eprint.iacr.org/2026/1630.pdf

USA is building a state-controlled private cyber force. It lets vetted US companies conduct covert access, surveillance and cyberattacks against foreign criminal networks. US companies will be authorised to target industrial control systems and manipulate, disrupt, degrade or destroy cyber-controlled infrastructure, including physical destruction. Operations likely to cause death, serious injury, or amount to a use of force cannot be approved by the normal program directors, (the memo does not say whether higher approval is possible). This does not mean a general license for lethal cyberattacks. But attacks can spill across borders or hit state-linked systems, raising the risk of interstate escalation and conflict. https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/

With US moving to normalise tasking and letting private companies conduct cyber operations, "cyber-privateers and letters of marque", including letting cyber espionage and destructive cyber operations (up to physical destruction of objects), cyber norms finally... may go out of the window! The biggest problem is risk of escalation. In armed conflict, international humanitarian law applies. Contractors directly participating in cyber hostilities may lose civilian protection and become direct partcipants in war. Operations affecting civilian or dual-use systems remain subject to distinction, proportionality and precautions. All of this may turn cyber operations into interstate confrontation, conflict, or war.

Cyberattack on French Tax Office. Data on 678,000 taxpayers/users stolen. The attacker compromised internal systems in late June after obtaining a legitimate identity/access, then gained access via an internal VPN to an internal tax office tool to search records on individuals and businesses. The attacker claims to have automated the extraction until the access was detected and cut off. French authorities have confirmed the intrusion, data access and exfiltration. The exposed information is unusually sensitive: tax IDs, names, dates and places of birth, postal addresses, family status, spouse identifiers, dependants, tax-unit information, reference taxable income, withholding-tax rates, phone numbers, email addresses and records of some previous communications with the tax administration. https://presse.economie.gouv.fr/acces-illegitime-au-systeme-dinformation-de-la-direction-generale-des-finances-publiques/

In case you feel it's worth it to forward this content further:

Subscribed

If you’d like to share:

Share

No posts

Read the original on techletters.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.