Security

Everything you need to know about security and encryption.

This fight is thirty years old — from the Clipper Chip to Chat Control

Aug 24, 2026

Every attempt to build lawful access into encryption since 1993 has made the same promise and run into the same wall. The mechanisms change. The mathematics doesn't. On 16 April 1993, three months into the Clinton administration, the White House announced a new encryption standard for American telephones. It arrived on a tamper-resistant chip, used a cipher the National Security Agency refused to publish, and had one distinguishing feature: a copy of every key it generated would be held by...

The board is personally on the hook now — how cyber became a directors' duty in Australia

Aug 21, 2026

Picture the standing agenda of a mid-sized Australian company. Finance gets forty minutes and an argument. Cyber gets a slide — usually green, occasionally amber — presented by whoever manages the IT contract, and everyone nods. The working theory is that cyber is a technical matter, technical matters get delegated, and delegation is what good governance looks like. Australia's regulators no longer subscribe to that theory. Across three regimes — corporate law, prudential standards and pri...

Your router is quietly working for someone else — SOHO botnets in 2026

Aug 17, 2026

There is a small plastic box somewhere in your office. Under a desk, on a storeroom shelf, or bolted to the wall near the meter box. Someone installed it years ago. Nobody has logged into it since. It has no screen, no alerts, and it appears on no asset register you have ever seen. It is also, by some distance, one of the most attacked devices you own. The uncomfortable part is not that routers get compromised — that has been true for a decade. It is what compromise looks like from the ...

The internet took the wrong turn - BGP hijacking and route leaks

Aug 13, 2026

The day YouTube vanished On a Sunday afternoon in February 2008, YouTube disappeared. Not slowed down, not glitchy — gone, for most of the planet, for around two hours. There was no army of hackers behind it, no malware, no ransom note. The cause was almost embarrassingly mundane. Pakistan's government had ordered local providers to block YouTube inside the country, so Pakistan Telecom set up a routing rule to send YouTube-bound traffic into a digital black hole. Then it accidentally annou...

The master key: how child safety became the argument for watching everyone

Aug 07, 2026

Australia’s metadata scheme, its encryption laws, the UK Online Safety Act and the EU’s Chat Control were all argued for on the same ground. Here is what happened to each of them afterwards. There is a rhythm to the way sweeping surveillance powers arrive in a democracy. They almost never begin with a plain claim that the state should be able to see inside everyone’s phone. They begin with the worst thing you can imagine happening to a child. Once you notice the pattern, it is difficult...

The silent extra participant — the "ghost" backdoor, explained

Aug 03, 2026

Most attacks on encrypted messaging arrive wearing boots. Ban the apps. Break the maths. Scan every message before it's sealed. The "ghost" proposal arrived wearing slippers — which is exactly why it's worth unpacking. Nobody breaks your encryption. Nobody cracks an algorithm. Law enforcement simply joins your conversation, invisibly, like crocodile clips on the copper phone lines of old. The padlock on your chat stays closed the whole time. It sounds surgical. It's actually a demolition —...

Patch speed is your new security score Surviving the flood of AI-found bugs

Jul 31, 2026

For twenty years, cyber security has been sold as a tidy engineering problem. Scan your systems. Get a list of weaknesses. Work through the list. Watch the number fall. Every audit, every framework and every board report has rested on the same quiet assumption: that exposure is a finite thing you can measure and steadily reduce. Put in enough effort, and the backlog shrinks. In 2026, it doesn't. It grows — and it will keep growing no matter how good your team is. That isn't a failure...

When the lights could go out — nation-state hackers inside critical infrastructure

Jul 24, 2026

When we picture a serious cyber attack, we picture theft. A database of customer records spilled onto a forum, a ransomware note demanding payment, the slow public unravelling of an Optus or a Medibank. That mental model is so dominant it shapes how most Australian businesses think about risk: protect the data, and you’ve protected yourself. But some of the most dangerous intrusions on record steal nothing at all — no records, no ransom note, no money. Their entire purpose is to get inside...

No click required — how zero-click spyware infects a phone that did nothing wrong

Jul 17, 2026

Almost every piece of security advice you have ever absorbed rests on one assumption: that you are the last line of defence. Don’t tap suspicious links. Don’t open attachments from strangers. Think before you click. It is good advice, and against most attacks it works. Then there is the category of attack where it is worthless. A zero-click exploit can plant spyware on a phone through a single incoming message the target never opens — never even sees, in some cases — because the flaw being ex...

What is metadata, really? — and why "it’s just metadata" is misleading

Jul 12, 2026

Whenever a government or a company wants to play down how much it collects about you, the phrase is almost always the same: “Don’t worry — it’s only metadata. We’re not reading your messages.” It sounds modest, even reassuring. It is neither. Metadata — the record of who you contacted, when, from where, for how long, and on what device — can paint a sharper picture of your life than the contents of any single message ever could. And in Australia, the rules governing it are weaker, in one spec...