Category Archives: Security

AES-256 is the Bell Bottom Pants of Post-Quantum

Newsflash! AES-128 holds up against quantum computers.

Filippo Valsorda took a walk through the math last week. Ok, but we already knew that NIST treats AES-128 as the Category 1 benchmark by definition, and BSI recommends AES-128. Outside CNSA 2.0, no compliance regime requires moving off AES-128, and CNSA 2.0’s AES-256 mandate is for uniform Top Secret protection, not Grover resistance.

Not exactly news after all, I guess. Alas, since I have been probing the Internet for a long while now, I can tell you what’s been really happening with AES key sizes out there related to post-quantum key exchange.

For example, hosts that only negotiate AES-128 adopted PQC come in at a respectable 48%. Compare that with hosts that only negotiate AES-256 and you see PQC drop off a cliff to 6%. The hosts that accept either one sit at 0%. Some of these may be cautious operators waiting for validated implementations, but the TLS 1.2-era cipher pinning pattern is visible in the configs.

I think it’s reasonable to say that we should expect the AES-256 population to be at least comparable, or even better than AES-128. Someone who specified a stronger symmetric cipher might also have taken the trouble to deploy hybrid key exchange. Well, I’m here to tell you the data says otherwise. Clearly the AES-256-only crowd are the worst-prepared for PQ.

It’s detailed on the pqprobe blog. The short version is that AES-128-GCM in a TLS 1.3 suite is mostly a marker of being behind a CDN, and the CDNs are also where ML-KEM has been deployed since 2024. The AES-256-only configs appear to be older server-side preference lists from the TLS 1.2 era that pinned AES-256 alongside classical key exchange and never got revisited.

That’s another way of saying AES-256-only hosts are legacy, and haven’t updated their TLS config in years. They picked AES-256 back when dinosaurs roamed the networks and locked everything else in alongside it: the key exchange, the curve, the signature algorithm. They got the symmetric cipher right and went extinct before Shor said he doesn’t care about the symmetric cipher.

If you have AES-256 pinned somewhere in your stack, that is fine on its own. The question is what else got pinned in the same file. The PQC adoption number I’m probing for that population is barely registering. The hosts falling behind while using AES-256 to be ahead, got there by leaving everything else alone.

Bell bottoms were also forward-looking once. Space age, mod, the future. Then they became the thing you point at to date a photograph.

All the data and methodology are up for your inspection.

No Active Shooter, No Assassin: White House Secret Service Shot Itself at Dinner

Shots fired! Politicians and reporters scrambling! Headlines claim an assassination was averted. Whew! Let’s check in now to review this miraculous security work that stopped a killer.

Record scratch.

Have you seen this hotel security video?

A man walked up to a checkpoint at the Washington Hilton during the White House Correspondents’ Dinner on April 25th. The president, vice president, and most of the cabinet were one floor below. The man was Cole Tomas Allen, a paying guest at the hotel openly carrying a shotgun around the hotel.

The video shows the checkpoint was dysfunctional. A magnetometer was lying flat on the floor. Two TSA agents were crowded around it. Three officers were leaning on the wall near them, idling. Most of the staff in frame did not react to Allen until he had walked right past them. The screening line was broken down while the man it was supposed to protect was still in need of protection.

Source: Washington Post

The video shows Allen had the shotgun pointed at the ground before, during and after he moved through the checkpoint. POINTED AT THE GROUND. The Washington Post emphasizes no muzzle flash came from his weapon at any point in the footage. The shotgun was recovered with a spent shell still in the chamber and no round racked behind it. That is the condition of a pump-action that has not been fired. SHOTS NOT FIRED.

The video reveals the security response to the threat was delayed, reckless and unprofessional. An officer drew his weapon and fired four rounds in a hallway towards at least seven other personnel. The officer does not flinch, stagger, or react like a man who has just taken a round to the vest. Not when Allen comes toward him, or when he passes him. Not before he draws. Not before he fires.

Source: Washington Post

Let’s recap. An open carry environment with a broken-down checkpoint with idling guards not paying attention, a man who walks through with a shotgun pointed at the ground, and a guard who opens fire in the direction of his colleagues.

Now read the deranged spin coming from the White House.

The DOJ affidavit, filed Monday, alleges that when Allen ran through the magnetometer the agents heard a gunshot, Officer V.G. was shot in the chest, and V.G. then fired back. The White House calls this a heroic agent who returned fire after being hit.

Nope. The video contradicts all of this. The White House lied.

The charges include discharging a firearm during a crime of violence and assault on a federal officer. The discharge count requires Allen to have discharged. The video shows no muzzle flash from his shotgun and the weapon was recovered unfired. Nope one. The assault count requires Allen to have assaulted. The video shows no reaction consistent with a vest hit at any point. Nope two.

0 for 2.

The most dangerous person in that hallway was the one who fired four rounds toward his own colleagues at a checkpoint that was already down and practically open.

But let’s go a level deeper. This is a story about what the current Secret Service does when its paper-thin perimeter fails. The agencies that exist to provide accountability apparently run for cover. The FBI signed an affidavit the video plainly contradicts. The acting AG announced charges that are false. The Secret Service director told Congress the perimeter is classified, nothing to see, as if an ostrich is the new national bird.

Open carry, guns in hotels, John Wayne-like thinking as if it’s not supposed to remain fictional. A paying guest carried a shotgun openly through the building and arrived at a checkpoint neglected and torn down. The seven personnel in frame ignore the man with the shotgun. That’s not one officer’s mistake. That smells rotten from the top. Someone authorized the screening line to come down while the people it was protecting were still inside. The failures were in place before Allen walked into the camera view.

The four rounds the officer fired toward his fellow officers tells the real story. An officer who has been shot in the chest by a shotgun and is returning aimed fire does not stand to put rounds across his own colleagues’ line. The shooting pattern on the video is consistent with an officer who was not hit, didn’t block the man’s path, and opened fire as the man ran past him. The perimeter failure made the response failure inevitable. A checkpoint that wasn’t watching produced an officer who fired blind. The DOJ affidavit converts both failures into a heroism narrative.

If Allen never fired, the “loud gunshot” in the affidavit is the officer’s first round. The officer fired first. The legal posture of the entire case inverts. This is not an assassination attempt where an agent heroically returned fire. It’s an armed man approaching a checkpoint, met with reckless discharge by an officer who fired on his colleagues and then claimed credit for stopping the threat he himself created.

Zionist Chug Chaluzi Not What Wikipedia Says It Was

There’s been a German Wikipedia entry about the Chug Chaluzi bothering me for a long time. It claims to document the only German resistance group that acted from Jewish-religious motives. Yeah, uh, no kidding. But that’s not what you think it means, dear post-genocide Germans.

Religious motivation among Jews was NOT a category of honor. In 1943 it was a category of stigma. The framing of a religious resistance group reads to me like someone wants to say there was only one loaf of white bread served at Passover. What are they trying to prove, if you catch my drift?

German-Jewish self-understanding from emancipation through 1933 ran on Bildungsbürgertum, Reform, and liberal Judaism. Orthodoxy was a minority current, looked down upon as problematic for obvious reasons in a society moving away from passive acceptance of fate. Observant practice was coded backward and associated with Ostjuden, the Eastern European Jews whose visible religiosity acculturated German Jews had spent two generations distancing themselves from. It was not subtle, it was visceral.

This history is important and it blows up the Wikipedia page.

You don’t just slap a religious label on Jewish resistance to Nazism and move on like it’s somehow a good thing. Like you can’t just slap kosher on a cheeseburger and say it’s the “only one”. Stop right there.

There needs to be documentation of what stands out as an inherent contradiction in Jewish resistance history. This post may help.

Rosenzweig’s 1913 return to Judaism was rather remarkable as a reversal. The Frankfurt Lehrhaus existed because German Jews had to be reintroduced to Jewish content they no longer carried. They shed it for what are obvious reasons to German Jews, probably invisible to German non-Jews. Christians walk around being Christian without having to do anything or justify anything. Celebrate Christmas, don’t celebrate it, doesn’t change a thing about being Christian. It wasn’t so easy for other religions, because to be Jewish invited scrutiny and judgment, challenges to explain and define traditions and behaviors. You aren’t going to synagogue? How dare you claim to be Jewish then? Expectations of religion among Jews was a form of externally applied control that erased diversity and freedom of self-realized identity. Shedding religion was an act of normalcy in German culture to arrive at the apathetic state of practice Christians enjoyed already.

Inside Zionism this hierarchy ran the exact same direction. Labor Zionism, cultural Zionism, Hashomer Hatzair, the kibbutz movement. Secular, often anti-clerical because religion was correctly seen as too antiquated, conservative and accommodating to the rise of Nazism. Religious leadership in some communities, working under Nazi coercion through Judenrat structures, urged compliance with deportation orders that turned out to be transports to death camps. Mizrachi was a minority stream within an already-minority movement, and the Hechaluz cadres skewed socialist. Jizchak Schwersenz teaching religious content through a Hechaluz-affiliated cell stands out precisely because it cut against the grain of German-Jewish liberalism and mainstream pioneer Zionism at once. It doesn’t make sense at all, which is the seed of why it lacked honor.

The state that emerged from this argument tells you who won it. Israel was founded in 1948 as a secular state by secular Zionists. Ben-Gurion led Mapai, a labor socialist party. The Declaration of Independence invokes “the Rock of Israel” rather than God, a deliberate compromise drafted to satisfy religious signatories without committing the state to religious authority.

The kibbutz movement, the Histadrut, the Palmach, the founding institutions were all secular. Religious Zionism was allowed accommodation through the status quo agreement on Shabbat, kashrut in state institutions, and rabbinical control of personal status law, but the entire architecture of the state was secular by design.

Mizrachi was never more than a coalition partner, and was certainly not a founding ideology. The Jewish state built by Zionists was a Jewish state in the ethnic and national sense, not the religious one. That’s essential history, which Germans clearly aren’t looking at when they try to reframe stories of resistance to fit their own prejudices.

Schwersenz’s religious pedagogy in 1943 Berlin sat completely outside the mainstream, outside the groups that would actually deliver the Zionist goal five years later.

Antisemitism operates by inherently dumbing down such important distinctions and redefining diversity within Jewish history. Nazi racial law, based on German cultural habits of rapid assessment with minimal depth, flattened internal hierarchy to serve outside perspectives. Those who didn’t shed the signal or stigma were sucked into a huge pool ignoring observant or assimilated, Mizrachi or Reform, Berliner or Ostjude. Deportation lists were designed to be highly efficient because they had very low fidelity, as they curated their own distinctions. The status structure that had stigmatized religious observance for sixty years, providing an assimilation path through agnosticism, was very intentionally and cruelly collapsed inside a Nazi decade.

This is the precondition for reading Schwersenz’s pedagogy as resistance.

Without the racial state the same content reads as weirdly provincial traditionalism. He said what? They believed in what? The honorific framing requires the catastrophe that erased the framework that had produced a meaningful stigma (e.g. you wouldn’t want the honor, because of where it comes from). Rare religious motivation usually of discredit became a badge, inverse to its actual meaning, by systemic erasure of the Jewish social structure that had marked it.

Postwar inversion is therefore best described as Wikipedia being exactly backward. The category “religiously motivated Jewish resistance” is like military intelligence. We all know it’s a contradiction while knowing it’s not meant to be one. The real historical contingency has been dropped out, and that shouldn’t be how Wikipedia operates.

The Wikipedia error traces to Barbara Schieb, historian at the Gedenkstätte Deutscher Widerstand, the official German resistance memorial. She puffed up that Chug Chaluzi was the only resistance group inside Germany that acted from Jewish-religious motives. H-Soz-Kult quoted her in the writeup of the 2000 exhibition Juden im Widerstand. Her flawed framing has institutional authorship at the state-funded memorial that re-contextualizes German resistance. The effect is notable, when it is presented as an official German position on who gets remembered and how.

A religious resistance in 1933 would seem completely upside down and backward at that time. This framing however was destroyed by the regime the actual resistance was resisting. The opposite category now is being spread by Germans online because of what it opposed wasn’t stopped soon enough, and the modern accounting drops context.

Take a look at what happened when surviving members gathered in Berlin in 1993. It’s rather enlightening to the question of what context really needs to live on a Wikipedia page. Nathan Schwalb-Dror, then 85, the funder who had moved Hechaluz money to the Berlin underground from 1944, came in from Geneva to speak. When Gad Beck brought up the Existenzkampf the Israeli visitors in the audience (in Berlin under the Senate’s visiting program) pressed for clarification on the February 1945 arrest. Beck’s memoir had attributed it to two Jewish Greifer working with two SS men, connected to the Stella Goldschlag network of Gestapo-run Jewish informers. The actual Zionists from Israel turned up the heat and wanted operational details to walk the actual walk. They wanted names. They wanted to know how the inner religious “resistance” circle had been so penetrated and exactly who was involved in undermining resistance.

Schwalb-Dror would not be moved. He stuck to his prepared report on Hechaluz’s wider rescue operations in Slovakia, Croatia, and Hungary, where the organization helped tens of thousands. Berlin had been a small group among many. Very small. I’ve written about this before, how Berlin even to this day has little accountability and carries a particularly cruel “got away with it” sentiment. Christine Zahn, the moderator, ended the event to keep the dispute from rolling into a public scandal. A scandal that seems essential context for Wikipedia. Only taz reported the breakdown of the resistance narrative.

Nicht ins KZ, sondern in den Widerstand

The Wikipedia effect is to obliterate this real history. It pumps the low-resolution honorific category against high-resolution accountability that Jewish resistance demanded to be counted among the actual honorable. The blurry Wikipedia treatment works only at distance from Jewish history. Up close, with the surviving participants in the room, the truth wanted to come out. Those participants, and perhaps you now too, could see the contradiction and what needs to be recorded instead.

The Jewish memorials to resistance must do better, even if German Wikipedia fiction about Jewish memorials never will.

The Rock That Broke The Nazi Enigma

Her name was Margaret Rock, also known as one of Chief Cryptographer Dilly Knox’s “girls” in Cottage 3 at Bletchley Park, working alongside Mavis Lever.

In August 1940 Knox complained the sexist Civil Service grading system had misclassified Rock as a linguist or clerk rather than a cryptanalyst, which capped her pay regardless of what she actually did. It wasn’t just an advocacy for fair pay, it was also Knox saying the scare quoted “professors” are just fancy titles and grades for men who were not doing any better work than the women. By 1945 75% of the staff of Bletchley Park were women, pioneering codebreaking and computer hardware engineering, with six out of ten in uniform.

The top UK salary allowed Margaret, because of her gender, was £195pa. For context, a male senior cryptanalyst at Bletchley on the higher Civil Service grades would have been earning many times more than her in 1940. Rock was doing fourth or fifth best work on the Enigma staff yet capped far below what the men received. Foreshadowing.

In World War II, Britain invented the electronic computer. By the 1970s, its computing industry had collapsed—thanks to a labor shortage produced by sexism.

Indeed, it was Rock who broke the Abwehr Enigma (variant G) with Lever and Knox on December 8, 1941. Rock and Lever had already cracked the GGG indicator system in October, the precursor stage. Despite the significance of this feeding into the “Double Cross” system and the D-Day deception, and despite being awarded the MBE in 1945, Rock was never graded fairly in her lifetime. She left GCHQ in 1963. The UK Civil Service want you to know this about her:

She remained single throughout her life and lived in her later years with her longtime friend from North Middlesex School, Norah Sheward.

Instead of cracking encryption, I say it should be called rocking it.