spacer C4DT

Dear Reader,

 

The C4DT weekly newsletter brings you a selection of articles or books that interested us.

 

Enjoy reading!

C4DT Team

spacer C4DT
Weekly Picks
spacer C4DT

Inspectors sound the alarm - will the e-ID come later than planned?

blue News — 19/02/2026

Imad's take

"

The Swiss eID audit highlights a trade‑off: release on schedule with fewer security features, or delay to strengthen protection. Christopher Allen, from his work on the TLS protocol, offers three lessons for eID: bugs expected to be fixed in 3–5 years can take 20; the mindset for designing a 20‑year architecture differs from the startup mindset of building a 2‑year product; and once shipped, “good enough” often becomes permanent.

Mark Zuckerberg overruled 18 wellbeing experts to keep beauty filters on Instagram

Financial Times — 18/02/2026

Olivier's take

"

This case is striking in that, while we usually focus on the risks of data theft and profiling from Big Tech, the core threat here is addiction and its devastating long-term impact on the mental health of young people, such as depression, anxiety and body dysmorphia. Internal documents prove that Meta was aware of the harm. Guardrails exist, and countries such as China enforce them; yet Zuckerberg overruled 18 experts. The only logical explanation beyond the rhetoric of 'free expression' is the desire to expand the captive audience and prioritize profit over children's well-being. Just as we had the tobacco industry in the 1980s, now it's big tech's turn.

The Promptware Kill Chain

Schneier on Security — 16/02/2026

Carine's take

"

Since ChatGPT crashed onto the scene in late 2022, attacks involving LLMs have kept pace with the breakneck speed at which they are being integrated into every aspect of our digital lives. This paper is the first that I'm aware of that takes a step back and not only catalogues the attacks by type, but also creates a taxonomy to guide security research into this new world of attacks on and by LLMs. Definitely a must-read for anyone working in security!

Passwortmanager bieten weniger Schutz als versprochen

ETHZ — 16/02/2026

Linus' take

"

Eine Studie über Open-Source Passwort-Managern, die die Passwörter in der Cloud speichern. Da die Programme öffentlich einsehbar sind, hat ein Student von der ETHZ nach Schwachstellen gesucht, und einige gefunden. Alle Fehler waren nur durch einen bösartigen Betreiber ausnutzbar, hatten aber zur Folge, dass Passwörter veränderbar oder sogar einsehbar waren. Die drei Passwort-Manager haben die 90 Tage 'responsible disclosure' genutzt, um die Schwachstellen zu beheben.

TikTok could be forced to change app’s ‘addictive design’ by European Commission

The Guardian — 06/02/2026

Katherine's take

"

Let us celebrate a milestone in digital safety. The European Commission has found TikTok in breach of the EU Digital Services Act for its algorithms designed to hook users. This follows another recent win, with Australia’s social media ban on minors under the age of 16. While the wheels of governance move achingly slow in comparison to the pace of technological change, and we can expect strong pushback from the company, we can at least take comfort in the knowledge that research, dialogue, awareness-raising and advocacy do move the needle.

spacer C4DT
spacer C4DT
spacer C4DT
New Publication
spacer C4DT

C4DT Observer #17, titled “Quantum Demystified: Engineering a Secure Future”

 

Why read?

 

This issue reflects the clear consensus from C4DT’s September 2025 roundtable: quantum computing is neither an imminent catastrophe nor a distant fiction, but a credible threat arriving within 5–15 years that demands action today. It explains why migration to quantum-safe cryptography must start now—by leveraging already-standardized post-quantum algorithms, crypto-agility patterns, hybrid schemes, and CBOM inventories—while addressing the broader organizational challenge of prioritization, vendor coordination, and building broad “quantum literacy” across Switzerland’s ecosystem. Beyond avoiding alarmism or complacency, it frames quantum as a governance and infrastructure opportunity to strengthen security and unlock applications in medicine, sensing, and beyond, rather than just an existential encryption threat.

 

Where to access? Click here

spacer C4DT

EPFL-C4DT
Station 14
CH-1015 Lausanne

c4dt@epfl.ch
https://c4dt.epfl.ch
LinkedIn
Mastodon

Web version