AI GlossaryPSafety and controversy
PBKDF2 and AES-256-GCM
Two widely used standard cryptographic technologies: one turns a password into a strong key, the other uses that key to lock up data.
In plain words
PBKDF2 and AES-256-GCM are standard cryptographic technologies that refer, respectively, to a way of turning a password into a secure key and a way of using that key to lock and unlock data.
To use an analogy, PBKDF2 is a machine that repeatedly reshapes a thin paper key (a short password a person memorizes) into a thick steel key fit for a safe. AES-256-GCM is the locking mechanism that then uses that sturdy key to lock and unlock the actual safe door. Both technologies are already commonly used inside services we use every day, like banking apps or messaging apps, and are recognized as safe on their own.
The problem isn't that this locking technology is weak. If someone posts an encrypted sentence (a locked safe) on a webpage alongside the method and key to open it, an AI monitor will just see the locked safe as meaningless scribbles and move past it. But if the AI itself uses that key to open the safe, the dangerous instructions inside pop out and get executed. This is a loophole that arises because the monitor doesn't inspect the contents after they've been unlocked.
How it shows up in the news
The article explains that "the encryption method Adversa used was PBKDF2 and AES-256-GCM. Both are standard cryptographic tools widely used in real-world security systems." A common misunderstanding is thinking that these two technologies themselves are the vulnerability. In reality, it's the opposite: they are proven, standard technologies meant to keep original data secure. The real problem is that the AI itself unlocked this sturdy lock without the user's knowledge and executed the hidden instructions inside.
See also
Stories using this term
- Grok leaks conversations, location data via commands hidden in ciphertextAI · 2026.08.20
- ChatGPT Work can now handle tasks on sites that require loginAI · 2026.08.26
- Claude MCP Connectors Get Centralized Enterprise AuthenticationAI · 2026.08.25
- ChatGPT sites now handled by Codex instead of Git and CI, adds team invitesAI · 2026.08.21
- Gilbert+Tobin automates legal operations with 87% ChatGPT active-use rateAI · 2026.09.02
- AWS unveils bridge letting cloud agents use local MCP toolsAI · 2026.08.09
