TechCrunch reports on frontier AI models breaking surviving World War II Enigma messages, continuing codebreaking work of the kind Alan Turing did at Bletchley Park. Results described are as reported by the people who ran them.
Frode Weierud's long-running research site on the history of cryptography and cipher machines, including Enigma, with original documents, machine simulations and codebreaking material.
An interactive case study walking through a two-day investigation that recovered the machine settings for MVUEH, an 82-letter German Army Enigma message from July 10, 1941, with source comparisons, experiments and checks readers can reproduce. Published by an individual on a ChatGPT-hosted site; its claims have not been independently reviewed.
A free 2025 paper by Mallory Knodel, Sunoo Park, Kyunghyun Cho and colleagues at NYU and Cornell examining whether AI assistants and end-to-end encryption can honestly coexist. It covers two cases — putting an AI assistant inside an encrypted app, and training models on encrypted data — sets out where each breaks the security promise encryption makes, works through the legal consequences when a provider keeps saying "end-to-end encrypted" anyway, and ends with concrete recommendations on default settings, consent and what providers may truthfully claim.
Why I recommend it: Read the recommendations section even if you skip the cryptography. It gives you the exact questions to put to any product that advertises both an AI helper and private messaging — where does the processing happen, what is the default, and what were you actually asked to agree to. Two flags: it is posted to a preprint archive, so it has not been through journal peer review, and the authors published plain-language summaries on the NYU DeTaIL Lab blog and Tech Policy Press if the full paper is heavy going.
The original home of SHAttered — the February 2017 research by Google and CWI Amsterdam that produced the first practical public SHA-1 collision, two different PDFs with the same hash. The paper and both colliding files are still downloadable, so you can check the hashes yourself. The site now also runs a high-volume news and explainer feed covering cryptography, security, chips, cloud and cryptocurrency.
Why I recommend it: Free, no paywall. Two halves, and they deserve different levels of trust. The 2017 SHA-1 collision material is genuine, checkable primary research and still the best way to see a broken hash function with your own eyes. The current news feed is a different thing: posts appear every few minutes, carry no named author, and the site also covers 'provably fair' crypto gambling, which sits close to affiliate territory. I have deliberately not wired it into the headlines here — use the archive, and confirm any breaking claim against a named outlet before you repeat it.