Blog

News & insights.

Post-quantum security, product updates, and plain-English takes on keeping sensitive files private. From the team building SpaceBox.

10 articles · 2 categories

Harvest now, decrypt later: why your files need post-quantum keys.

Encrypted traffic captured today can be stored and unlocked once large quantum computers arrive. SpaceBox seals every file with ML-KEM-768 (NIST FIPS 203) key exchange and AES-256-GCM, so what you send now stays unreadable then. We break down the threat, the maths, and why we chose these primitives over the alternatives.

Read the article

Ten days, or eight hours

The EU's e-evidence Regulation became applicable on 18 August, letting a judicial authority in one member state order stored data straight from a provider in another, within ten days or eight hours in an emergency. What any order returns is decided long beforehand, by where the keys live.

Read the article

Apple is in court again over encrypted backups

Apple has filed a fresh challenge at the Investigatory Powers Tribunal against a UK notice requiring access to encrypted iCloud data. Eighteen months in, the strongest iCloud encryption is still unavailable to an entire country.

Read the article

Sixty hours to a withdrawn algorithm

An AI model spent about 60 hours on the post-quantum signature candidate HAWK and found a lattice symmetry that halves its security margin. The submission team withdrew the scheme from NIST's process the next day, and nothing already deployed had to change.

Read the article

When the extortion is publication

Attackers reached engineering files on internet-exposed PTC Windchill servers through a CVSS 9.3 deserialization flaw, then emailed hundreds of employees at the affected companies. Nothing was locked, and backups say nothing about who else now holds a copy.

Read the article

The tax documents were in the help desk

Attackers spent two weeks inside a third-party support platform used by Ernst & Young and downloaded documents containing client tax information. Sensitive files accumulate in the systems that are easiest to reach, which are rarely the systems anyone is watching.

Read the article

When hospitals go dark: ransomware and unreachable data

Ransomware shut down hospitals in Dublin, London and Dusseldorf, and networked backups were no help because attackers reach them too. The case for storage that is offline, append-only and impossible to encrypt from afar.

Read the article

One misconfiguration exposed 367,000 files

A European cloud company left a database open to the internet and roughly 367,000 records spilled out, no exploit required. Misconfiguration is the most common way stored data leaks, and it is exactly the case where ciphertext-only storage earns its keep.

Read the article

SpaceBox Lite is out: free, end-to-end encrypted drops

Turn any device into a SpaceBox and receive sealed files from anyone you invite. No account, no card, no email. A tour of what ships in the free beta, and how the two-device model keeps senders anonymous.

Read the article

The problem with cloud backdoors

Providers are legally compelled to hand over your data, and every backdoor becomes a target the moment it exists. What zero-knowledge, non-custodial storage actually changes for the people who need it.

Read the article