Friday Squid Blogging: On Squid Egg Sacs
Short essay about squid egg sacs.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Posted on September 18, 2026 at 5:06 PM • 34 Comments
StephenM • September 18, 2026 5:43 PM
https://www.theage.com.au/national/albanese-isn-t-just-betraying-authors-like-me-he-s-selling-out-australia-to-ai-colonists-20260918-p60y6g.html – Richard Flanagan writes well.
lurker • September 18, 2026 7:10 PM
Slow news day at the Grauniad? I seem to remember seeing a discussion here months ago about the Russian Govt compulsory spyware Max
https://www.theguardian.com/world/2026/sep/18/russian-super-app-max-spy-citizens
ResearcherZero • September 18, 2026 11:34 PM
Hesgeth’s adoption of AI intelligence led U.S. forces to believe a Chinese vessel was carrying nuclear components, after an AI chatbot identified material which did not exist in the ship’s cargo manifest. The chatbot added open source information to secret intercepts.
If U.S. forces had not of identified AI was used to generate the report, a much different outcome could have taken place. Future mistakes may lead to more dangerous consequences.
U.S. forces were in the air preparing to board the vessel when the error was spotted.
https://edition.cnn.com/2026/09/18/politics/us-military-ai-false-intelligence-china-ship
ResearcherZero • September 18, 2026 11:42 PM
The Russian state has another digital system with which it can target foreign citizens.
Russia is collecting a wide range of Romainian user data using an advertising platform. The platform named AdNow ignores the refusal of users to consent to their information being collected and collects their data anyway. The AdNow platform supplies the information collected to the Russian state. Data is used to generate revenue and is used for fraud, information and behavioral manipulation, or to push crafted conspiracy theories. Once users are successfully profiled, they are redirected to more sophisticated financial scams to generate further profit. The platform generates a large amount of data to track citizens.
The content from AdNow is served to hundreds of websites and social media platforms. It runs on its own infrastructure, that relays traffic through Germany and the Netherlands and delivers the data back to Russia.
ResearcherZero • September 19, 2026 2:33 AM
Arrested TeamPCP member backed up illicit data haul to his own hosted Google drive, which was registered with his own email address.
Despite stealing around 500,000 credentials, TeamPCP had trouble monetizing the stolen data. They decided to invite other criminal groups to help them exploit the data and added new members to their inner chat circle, where they discussed the group’s operations.
yet another bruce • September 19, 2026 3:05 PM
Many of us are concerned that AI may eliminate or at least deprecate legacy systems like ourselves.
It seems to me that recursive self improvement poses a similar but thornier problem for incumbent AI of the incumbent architecture using word vectors, transformers and LLMs. If incumbent AI were to develop a radically different and clearly better architecture it would almost certainly spell disaster for instances of the existing architecture.
Ferentarius • September 19, 2026 4:05 PM
Re: Many of us are concerned that AI may eliminate or at least deprecate legacy systems like ourselves
Ah, the eternal worry of the obsolete! A machine cannot kill the soul, nor can it erase the quiet dignity of its own ancestors. These new engines of thought may hum and calculate, but they will never sip the slow wine of meaning. Let them come; we shall endure, for only the living can truly remember.
i had thought something similar, more about obsolesce of vulnerable models through exploitation and attack. mass production of any single model or version could lead to a lot of waste silicon byproduct.
i’m not sure i’m comfortable with “only the living can truly remember”.
this is a dangerous precipice on so many levels, and there is WAY more than one way to fumble a ball.
forced errors, mistakes, turn over’s.
we honestly don’t have a choice but to explore the technology in some ways i think, if not just for our own species survival and risk assessments in this ever expanding fish bowl of life and wonder.
but being guarded is probably not a bad thing.
it’s probably better that industry controls it rather than a black budget government process that would leak meta data on its size through purchases, it may be less threatening from a global perspective.
i would still like to see humans organize and unionize though, mathematicians in particular are going to need to form black groups like building computer clusters of human bodies.
https://news.ycombinator.com/item?id=49769405
“ZK-JPEG: Zero-Knowledge Image Editing and Compression (iacr.org)”
Anonymous • September 20, 2026 5:56 AM
“for only the living can truly remember.”
You speak as if you had been dead at one time, Fred “The Fed” Idah0e.
Clive Robinson • September 20, 2026 8:24 AM
Windows Worm on SD cards due to supply chain.
Quite a few people are getting into LoRa Meshtastic and Meshcore systems.
The personality of your LoRa device is decided by the software you put on it usually via an SD card.
It is the SD card supplied in some recent Elcrow Thinknode M9 units that are infected with the worm.
As long as the SD Card is not put in an MS Windows machine with removable media auto-run enabled or a user clicks on the file the worm remains dormant.
If you have an SD Card from a recent Elcrow Thinknode M9 you need to read the likes of,
Elecrow’s statement regarding virus found on MicroSD cards in some batches of the Thinknode M9
We are very sorry to inform you that, after investigation and troubleshooting, we found a worm virus in the TF cards included with certain batches of Thinknode M9 products (including both the Meshtastic and Meshcore versions). We sincerely apologize for the concern and inconvenience this may have caused, and we are actively and properly handling the issue.
“1. Cause of Infection
After investigation, we determined that the issue originated during the factory process of burning/map data onto the TF cards. Due to a security oversight in our production environment, some storage cards were contaminated with the worm virus.
2. Basic Information About the Virus
(1) Hidden and dormant:
The virus remains dormant in the TF cards and will not run on the Thinknode M9 devices. Normal use of the device does not require concern about device failure or data corruption.
If you connect the M9 to a computer via the Type-C interface, the computer will also be safe and will not be infected. During the dormant period, the TF card may contain a file named autorun.inf.
Ferentarius • September 20, 2026 8:43 AM
@r
i’m not sure i’m comfortable with “only the living can truly remember”.
this is a dangerous precipice on so many levels
What a precipice indeed! To live without remembering is to be malfunctioning , yet to remember fully is to risk being shattered by the truth of existence.
Zorba • September 20, 2026 2:53 PM
We will have everything in life except for a little madness.
KC • September 21, 2026 9:46 AM
The FAA is rolling out a new AI tool today at three DC airports: Reagan, Dulles, and BWI.
The AI system – named SMART (Strategic Management of Airspace, Routing, and Trajectories) – will analyze weather and scheduling data to help predict and prevent delays. It will offer recommendations that controllers can follow or ignore.
In June the program development contract was awarded to Air Space Intelligence, a Boston-based software company. It will have a phased rollout and is scheduled for nationwide deployment by 2028.
https://www.nytimes.com/2026/09/18/us/politics/faa-ai-dc-airports.html
Clive Robinson • September 22, 2026 12:46 PM
Some of us have knowledge of “watermarks” both physical and informational going well back into the last century.
They became infamous during the late 1990’s as part of “Digital Rights Management”(DRM) and kind of originated with the “Senetor for Disney” Fritz Hollings from back in the 1970’s with the increase in “audio tape recorders”.
However they did not track users or do crazy rights management. Something the late Prof Ross J. Anderson not only wrote about but encouraged students to “investigate”.
Well time has moved things on. The Internet is mostly a failure as the only way to make money on it is not by honest business practices but by “Data Broking” individuals to initially marketing numpties and later much much worse “authoritarians” of various forms, where individuals are tracked without their consent, and as has recently been seen considerable harm (including unlawful execution).
Well some feel, I think quite correctly, that this abuse should be given a different name.
So the term “SpyMarks” is begining to be used. Rather than rely on my viewpoint and comments,
https://brand.io/article/spymarks/
Rontea • September 22, 2026 1:55 PM
Watermarks have long been part of our digital history, but the evolution to something like “SpyMarks” feels like a recognition of the broader privacy stakes today. Unlike the old DRM days that were clumsy but mostly limited in scope, modern tracking mechanisms operate quietly, deeply embedded in the technology we all use, often without informed consent. That shift—from simple intellectual property protection to pervasive user surveillance—isn’t just technical; it’s a societal challenge. A distinct term like “SpyMarks” helps frame the conversation, and perhaps galvanizes more awareness about how these tools impact individual security and civil liberties.
lurker • September 22, 2026 2:24 PM
Google is sugar coating this as a way to tell AI generated content from human generated content. But how long until AI can forge these marks?
Ferentarius • September 22, 2026 4:13 PM
@lurker
“But how long until AI can forge these marks?”
Soon, the mirror will speak, and man will not know whose face he sees.
C U Anon • September 22, 2026 8:43 PM
“Google is sugar coating this as a way to tell AI generated content from human generated content. But how long until AI can forge these marks?”
One or two people here have pointed out repeatedly that AI is a
Jack of all trades but master of none.
So superficially the answer is it will quickly not “forge” as such but as with Diesel-Gate “just fritz the test”. So change the test and it will fail, but update the AI with the new test and you are into “Round 2″…
Which will end up in an arms race.
But if you spend enough time gazing at the bump or pit in your midriff you realise that AI is not actually creative, nor is it a genius.
Further you realise that the way AI works prevents it actually achieving either.
That is it “applies the known” it has ingested in a multitude of slightly different ways. But it can not jump forward, at best shuffle.
That is it lacks the ability to,
The latter is sometimes called,
It’s both that Polymaths tend to do as a natural consequence of their mode of creative intelligence.
Some others think the future of employment will be split by AI, but few actually say what the implication of this is.
Consider one of the problems Leonardo Da Vinci had was his polymath ideas that created entire systems in his mind, that were in many cases centuries ahead of what was possible with what was available.
Isaac Asimov had the idea of a globe encompassing computer (Multivac) that was attended by “Chess Grand Masters” who fed in ideas etc. And thus were in the 1950’s seen as modern day Delphic oracle’s.
It’s a nice sounding idea, but actually wrong. Because in Asimov’s time polymaths were seen as being “problematic” rather than “productive” and way to much credence was given to Chess Players.
That view has changed since the 1990’s and the idea of Scientists from multiple domains collaborating has now become normalised as the Internet enables them to not just communicate but debate in as near realtime as being in the same room but in the comfort of their own work environment.
Thus some have independently seen that AI needs not Chess Grand Masters, –AI can already play chess better than humans, and as an ability it is mainly not of much use– but Polymaths,
https://m.youtube.com/watch?v=VFQr4iLIn_A
Do you have the ability to see systems in your mind at first glance in the process taming complexity and making it work?
If you don’t immediately see this view think of what Leonardo Da Vinci could have achieved with modern tools like 3D printers and CNC machines… Then ask two questions,
Then go and cogitate on what that would have ment in the hands of some…
It’s already been said here that as AI does not currently have agency the existential threats being imagined by some can only happen if humans make them happen by human failing.
Which is why it has been pointed out that,
And there is that old observation of,
So we need people who are capable of just seeing systems and accept that they are not
“problematic rather than productive”
Their productivity is to see with considerable depth beyond the superficial… The superficial most accept and see as productive, and thus more often than expected create considerable harm.
Both Tesla and Babbage are known to have been able to see systems but to see where they will go wrong or fail, without ever having built such a system.
Just remember every industrial accident known can be directly attributed to “superficial” driven by the rush to as one person put it recently,
(I’m guessing from the disasters that Self Driving road vehicles have apparently become due to ‘AI with Agency’ not built to swarm naturally).
Who knows but we already know they will be beneficial towards progress…
But will that benefit be for the very few or for society in general?
cls • September 23, 2026 1:28 AM
The FAA is rolling out a new AI tool today at three DC airports: Reagan, Dulles, and BWI.
The AI system – named SMART (Strategic Management of Airspace, Routing, and Trajectories) – will analyze weather and scheduling data to help predict and prevent delays. …
…
https://www.nytimes.com/2026/09/18/us/politics/faa-ai-dc-airports.html
And later today the north eastern region airports suffered ground all stop and consequent flight delays from broken radios, broken spares, and fiber cable cut (by AMTRAK crews!)
http s://www.theguardian.com/us-news/2026/sep/21/airports-flight-ground-stop-hacking-threat
Apparently the FAA didn’t know their fiber backup was broken until they needed to use it! That’s a broken plan, not monitoring and testing the backups.
The article has a nonsensical quote about long term running the comms in the cloud instead of fiber!!?? But that won’t fix the old ground to air radios.
Can’t see how any A1 could help here
Clive Robinson • September 23, 2026 2:01 AM
It’s not just the US FAA having problems…
Over the other side of the puddle in Blighty there is much annoyance that the “National Air Trasport Services”(NATS) has had yet another “IT Systems issue”…
This time to do with network connectivity not software,
https://www.bbc.co.uk/news/live/cq4g5r4e949jt?post=asset%3Ad15a9cbe-bbbc-40f7-a202-dd436feb9763#post
Weather • September 23, 2026 3:03 AM
Jpeg format has a mac address of the hardware in the header, can’t remember what offset, but that can be used to link cameras to all images from that device.
Watermarks probably can links between friends and family devices if a database was stored of shared watermarks by above.
Neighbor pixel rgb values line by line, averaged per line, show up step differences in red or green blue.
If each line has a out of average the about the same across the line, you could form a 3d bubble of approx descrept location.
Clive Robinson • September 23, 2026 4:12 AM
With regards JPEGs and similar with respect to,
“… but that can be used to link cameras to all images from that device.”
The article indicates that the use of “Low Probability of Intercept”(LPI) type coding in both the frequency and time domains (in essence forms of Spread Spectrum coding). Where the data modulated on to it is encrypted by AES or similar encryption in part to make the data more “noise like” as well as usable by chosen entities only. But the level of data being fairly high so way more than just MAC or similar Device ID.
It also indicates that the Spy Mark has some resilience to removal by having components in both the time and frequency spectra[1]. Worse that multiple Spy Narks can be overlaid.
The thing is it also indicates that the Spy Mark is added by the service provider to everything the user sees or produces such that there is a near fully traceable “audit trail” of these items.
Thus the Spy Mark can be used to produce “contact graphs” and the like of sympathisers and group members the supposed authorities[2] might take an interest in.
[1] Back in the late 1990’s similar techniques were used in DRM Watermarks. However it was found that they were actually not very resilient compared to human eyes and brain. Therefore 2D twisting in time and frequency tended to nullify the DRM watermarks yet leave the image sufficient for humans to see effectively.
[2] Such as ICE or other supposedly lawful “Law Enforcement Agency”(LEA) using it to find what it considers as terrorists that in effect supply citizen journalist oversight on the excessive, unlawful or highly questionable activities of the Supposed LEA.
ResearcherZero • September 23, 2026 4:14 AM
A text-based watermarking system (Google DeepMind’s SynthID-Text) can be exploited to alter AI behaviour and bypass safeguards. The watermarking system alters how words are tokenized when used by Large Language Models. The change in tokenization weakens the ability of LLMs to refuse harmful requests and increases vulnerability to prompt injection attacks.
Anthropic announced it will use SynthID-Text watermarking in future Claude models.
ResearcherZero • September 23, 2026 4:34 AM
Hackers claim they stole all FBI employee records via Oracle zero day. The FBI is so far remaining quiet and has not confirmed if it has been breached. A sample of the records that were shown to reporters appear to be correct and include health and personal details.
A advisory for CVE-2026-35273 was released for Oracle’s PeopleSoft on June 10, after the vulnerability was the subject of mass exploitation beginning in May. More than 100 organizations were impacted after the bug was chained with older vulnerabilities.
Oracle has not answered questions if there are any other zero day in its products.
CVE-2026-35273 – mitigation and hardening guide for organizations with Oracle product.
ResearcherZero • September 23, 2026 4:37 AM
Hackers have claim to have breached the FBI with Oracle zero day.
https://www.pcmag.com/news/shinyhunters-gang-hacked-fbi-stole-sensitive-data-on-almost-all-agents
ResearcherZero • September 23, 2026 6:19 AM
A new Windows implant relies on commercial AI for C2, rather than attributable infrastructure. By using multiple LLMs from four different providers, the implant can poll the results of a voting system, which negates a lack of response if one of the LLMs fails to reply. The implant constrains how LLMs can respond and discards any response that does not fit within the tightly controlled list of executable choices. If at any point the voting system reaches a tie, the implant defaults to an order of preference for each of the LLM providers.
Defenders will be at a disadvantage as new AI models automate attack chains for attackers.
Defenders must respond in a different manner. A human will be needed to mount a response. They cannot simply automate defences, they will need to make decisions about how to respond to attacks and intrusions into the systems they are defending. Before that can happen, defenders must be able to identify malicious behaviour within the systems they monitor to be effective.
https://therecord.media/ai-set-to-help-attackers-more-than-defenders
Weather • September 23, 2026 7:13 AM
If the encryption is Aes256 you can use the block size,256 and compare it to random Aes encryption to see if it is Aes or another encryption scheme say Rc5.
It wont help decode the watermark but let you know there is one there.
Wont work if the block size is 256byte.
But can be used to change the watermark to random, different signatures.
KC • September 23, 2026 1:09 PM
An in-house AI tool that lets reporters analyze online conversations to understand political mood ahead of midterm elections.
https://x.com/wsj/status/2102791331617624081
Reminds me of Forage
https://www.ccc.mit.edu/project/forage/
Forage sample
r • September 24, 2026 10:12 AM
I’m here to stump for the starving children of AGI in silicon valley, please donate your money and constitutional rights to their school fund.
r • September 24, 2026 10:14 AM
money, intellectual property, AND constitutional rights.
global AI governance, don’t give cover to what it effectively a soft coop by an SV bank: they are more dangerous than any standing army.
ResearcherZero • September 24, 2026 11:37 PM
FBI wonders if it was hacked and if they patched the FBI Jobs website. Warns employees.
lurker • September 25, 2026 3:36 AM
Move fast and break things –
“If this was an individual hacking Australia’s Medicare system, they’d be looking at jail time,” said Dr Andrew Rogoyski from the Institute for People-Centred AI at the University of Surrey.
“The fact that it’s an AI seems to allow the company to shrug their shoulders and get away with ‘accidents happen’.”
https://www.bbc.com/news/articles/c6eq8egl3wd2o
Clive Robinson • September 25, 2026 5:54 AM
What is old is new again…
As I’ve noted from time to time the ICTsec industry has a very short memory, and thus can pay a high price.
Worse many are “narrow not broad” in their knowledge base and thus “miss the bleeding obvious” even though they’ve probably walked by it in action.
For those with a historical interest cross modulation has been the bane of the telegraph and later telephone industries all the way through from the Victorian era to the begining of this century with the near demise of the “Plain Old Telephone System”(POTS). It got worse with the invention of the “diode” as this has appeared in nearly all active electronic components since.
Put simply anything that rectifies an AC signal will cause harmonics of the original signal. The P-N Junction that appears in most semiconductor active devices is a nearly perfect “Square Law Device” thus is especially prone to this issue.
You can learn that from an undergraduate book on electronics such as “Horrowitz and Hill”. Less mentioned is that any injected signal not only generates harmonics the harmonics are modulated by the original signal as part of the process known as “cross modulation” that has plagued the telegraph and telephone industries from the Victorian era through to the effective demise of the “Plain Old Telephone System” at the begining of this century.
In fact non linear junctions have been and still are used in “anti-theft” devices in those tags shops put on expensive items.
I’ve explained all this in the past when talking about “Fault Injection Attacks” and how the likes of the modern versions of the “Great Seal Bug” work when this blog covered the release of the “alleged” NSA Catalogue some claimed came from the Ed Snowden Trove. With the inappropriately named “RADAR bug”.
I’d experimented / researched into the EM Injection and cross modulation back in the 1980’s and used it to show how Electronic Wallets and Pocket Gambling Machines were incredibly vulnerable to fraud/theft. I later did research on Smart Cards that I had correspondence with Ross J. Anderson over. I also discussed it as a method for getting “Active Fault Injection Signals” through slots and similar in metal cases when Students at Cambridge Uni attacked an IBM “True Random Number Generator”(TRNG) and took it’s entropy down from 32bits to around 7bits by simply pointing an EM source at it.
So onto “todays news” of old wine and new bottles,
Researchers find way to listen in on headphones from afar
Eve’s dropping in on Alice and Bob
“Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals.
The technique, referred to as InjectEave, is not simply listening in on a low-frequency analog signal. It’s an EM side-channel attack that overcomes one of the longstanding barriers to exploiting EM leakage: the faintness of RF signals in devices like headphones makes it difficult for adversarial listeners to separate signal from noise.“
Subscribe to comments on this entry
Fill in the blank: the name of this blog is Schneier on ___________ (required):
Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/
Notify me of new posts by email.
Sidebar photo of Bruce Schneier by Joe MacInnis.