Chrome Is Thinking Quantum - Threat Wire
Quick Overview
Google Chrome is rolling out a three-phase program to make HTTPS certificates quantum-safe using Merkle Tree Certificates (MTCs), collaborating with Cloudflare on Phase 1 feasibility studies ending by early 2028, while OpenAI's newly revealed security tool, Codex Security (formerly Artvark), scans codebases for high-severity vulnerabilities.
Key Points: Google Chrome is initiating a three-phase rollout plan, beginning with Phase 1 in collaboration with Cloudflare, to evaluate the performance and security of quantum-resistant HTTPS using Merkle Tree Certificates (MTCs). The MTC propagation plan is scheduled to conclude with Phase 3 by the start of 2028, aiming to onboard Certificate Authorities to support MTCs. A self-propagating JavaScript worm briefly vandalized Russian Wikipedia pages on March 5, 2026, by injecting malicious code into common.js files, but restoration efforts prevented permanent damage. OpenAI announced Codex Security (formerly Artvark), a security code reviewing tool that identifies complex vulnerabilities and suggests fixes based on project context. Codex Security found 792 critical findings across 12 million code commits from participating open-source groups, including examples like GnuTLS Heap Buffer Overflow (CVE-2026-32900). Research from teams at ETH Zurich, Anthropic, and MATS showed that Large Language Models (LLMs) can unmask pseudonymous users online with surprising accuracy by executing pattern recognition. Motorola phones running GrapheneOS were mentioned positively by viewers as an affordable, secure option, especially for high-risk users.
Context: This episode of Threat Wire covers significant developments in cybersecurity, focusing primarily on Google's efforts to future-proof web security against quantum computing threats and OpenAI's release of an advanced code auditing tool. The segment also reviews a recent, brief Wikipedia vandalism incident caused by a self-propagating JavaScript worm, alongside new research demonstrating the threat LLMs pose to online anonymity.