Skip to content
TrackPodcasts
newsSep 9, 202612:03

Fylgja CSS Unveils Attr v2 Polyfill, KEM Beats NTRU in Post Quantum, OpenAI Pentagon Clash over Controversial Clause, AI Glasses Spark Privacy Alarm, and more...

Tech News Daily

Get every episode summarized

Each time Tech News Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

120 searchable segments. Every word is indexed and playable.

Fylgja CSS Unveils Attr v2 Polyfill, KEM Beats NTRU in Post Quantum, OpenAI Pentagon Clash over Controversial Clause, AI Glasses Spark Privacy Alarm, and more...

Tech News Daily

0:00
12:03

Full transcript

Tech News DailyFylgja CSS Unveils Attr v2 Polyfill, KEM Beats NTRU in Post Quantum, OpenAI Pentagon Clash over Controversial Clause, AI Glasses Spark Privacy Alarm, and more.... Machine-transcribed; use the interactive transcript above to jump the player to any line.

Good morning. It's September 9th and this is your daily brief in tech. Here's everything you need to know. A new AdderV2 polyfill extension from PhilGISSS is now available to let older browsers fall back to static values generated from modern code, making AdderV2 usable today. The polyfill creates fallback values for browsers that don't yet support AdderV2, enabling developers to start using AdderV2 now. Integrations are provided with VITJS, Lightning CSS and Post CSS, plus an API and CLI for custom setups, with a plan to ship the polyfill as the default in the next PhilGIS utilities release, and to offer availability without a build step via API or CLI. At the moment, PhilGIS utilities does not directly support AttraV2 syntax and relies on experimental imports or external solutions until full support is implemented. Canyus data shows broad AdderV2 support approaching across browsers, including Safari

and Technical Preview, which makes the polyfill a sensible interim solution. The polyfill enables writing CSS utilities with AttraV2 consistently, demonstrated with a sample utility using data, PI, and padding block calculations and the corresponding HTML usage. This approach aims to bridge the gap until full native support arrives and offers a practical path for developers updating legacy sites. The plan to default the polyfill in a future utilities release signals an upcoming standard workflow for teams working with AtraV2 today. In short, the extension provides a practical interim solution that aligns with current browser readiness and existing tooling ecosystems. A standardization shift in post-quantum security is shaping how deployments move from theory to practice. MLKM, built on Kiber, is moving through formal standards like FIPS 203, while NTRU remains a legacy option without standardized code points. In NIST's portfolio, MLKM pairs with MLDSA for signatures, and HQC stays

as a non-lattice backup to hedge future breaks. A detailed comparison shows MLKM versus NTRU-NTRU-prime across standardization status, underlying ideas, and parameter sets, with MLKM offering broader compliance and open source support. A practical migration guide to MLKM outlines auditing key exchanges, assessing library support, and adopting a hybrid with classical algorithms, plus configuration updates such as SSH-Kex algorithms and interoperability testing. Benchmarks from LibboCo's and PQClean indicate strong performance for MLKM in key generation, encapsulation and decapsulation, with Centrupp 761 competitive in SSH context, and hardware accelerated, side channel hardened builds boosting TLS use. The Kiber ransomware incident in 2026 highlights a real world deployment of a standardized MLKM, and the defense considerations amid ongoing harvest now decrypt later risk. NIST chose Kiber over NTRU in 2022 due to better performance, smaller key and ciphertext sizes,

and earlier open source support leading to Kiber's standardization under FIPS 203 in 2024. MLKM's broad deployment footprint, cloud flare, Chrome hybrid TLS, Signal PQ-XDH, Apple PQ-3, AWS services, and open SSH 10.0 drives practitioner adoption and migration momentum while NTRU NTRU prime remains in use for legacy SSH and embedded scenarios without a path to FIPS 1403 compliance. Parameter sets vary in key sizes and ciphertext, with MLKM generally larger, but benefiting from standardization and wider adoption, while NTRU variants are smaller in some cases but lack formal standardization. The standardization status thus emphasizes MLKM's mandatory role in FIPS 203 and the absence of NTRU in the standard, guiding procurement and compliance for federal and enterprise customers. Security foundations contrast module LWE with NTRU lattices, and while neither has a known

quantum break, Grover's algorithm implications and a preference to avoid focusing on a single problem, family led NIST to keep HQC as a backup option. OpenAI and the Pentagon are in a dispute over a clause some say would allow minimal refusal rates in a prototype contract, but both sides say that language appeared only in a draft and not in the final agreement. The intercept is pursuing final contract documents through FOIA litigation to resolve what was actually agreed. The finalized contract does not include the minimal refusal rates language, according to both openAI and the Pentagon, and the released version was a draft. Modification P-00003 covers mid 2025 to mid 2027, increases funding by a nominal amount, and sets an overall ceiling of up to $200 million for the Frontier AI prototype effort with monthly milestones. The released text lists eight prototype tasks, including identifying defense use

cases for Frontier AI, policy prototyping, risk forecasting, industry information sharing, and hands-on prototyping and intelligence, cybersecurity, and autonomous systems, plus deploying a chat GPT-gov app on geni.mil at impact level 5. OpenAI emphasizes three red lines. No mast domestic surveillance, no autonomous weapons without human oversight, and no high stakes automated decisions with the deployment remaining cloud-based and with safety controls. A March 2026 update adds a domestic surveillance restriction, and notes NSA level data would require a new agreement. A leaked defense department modification defines openAI mission models as for national security use cases with minimal refusal rates, applicable to testing under Task 7 of the Frontier AI model prototype effort. The clause appears in an updated P-00003 version tied to a potential $200 million two-year deal expanding openAI's wartime mission

model work for national security purposes. Experts warn that minimal refusal language could signal looser safeguards, raising concerns about private sector influence on warfare policy, and weaker safety constraints for national security use. OpenAI signed a February agreement allowing its services on the DOD's classified networks, though the current contract text is redacted in the latest deployment update. OpenAI says red lines on autonomous killings and spying on Americans were secured, yet contract language may still permit government-approved uses under the current framework. Modification P-00004, effective February 27, 2026, renames the task to testing, evaluation, and refinement of chat GPT mission models, and redacts full details, leaving uncertainty about whether the minimal refusal rates language remains. The dispute sits within broader debates with rivals such as Anthropic, Google, and XAI over safeguards, autonomy, and surveillance implications in military deployments.

Smart glasses powered by AI are raising alarms about privacy and security risks for individuals and enterprises. Experts warn these devices can enable covert surveillance, data theft, and exposure of confidential information. In corporate settings, they urge strict mobile device management integration, updated data loss prevention to flag anomalous Bluetooth activity, and clear policies that designate sensitive zones where wearables are prohibited. Mitigation strategies include enabling multi-factor authentication, timely firmware and app updates, reviewing permissions, encrypting and locking devices, and avoiding linking glasses to unnecessary accounts. Bluetooth and cloud syncing can still expose passwords, location data, audio, contacts, and account tokens that could grant access to VPNs and networks. Relying on visual indicators alone is not enough. There's a call for authenticated indicators and robust device integrity checks to counter tampering and covert recording. Industry voices emphasize governance, policy, and technology controls to mitigate risks.

There is discussion of systemic and regulatory measures, such as hardwired recording indicators, strict hardware registration for optical IoT devices, physical air gapping of sensitive areas, and updated NDAS and acceptable use policies addressing smart glasses. Risks are amplified by excessive app permissions, insecure Bluetooth pairing, weak passwords, unpatched companion apps, and compromised cloud accounts, all increasing data exposure and breach chances. In business settings, these glasses create a new wearable attack surface that could reveal trade secrets, prototypes, production details, client conversations, and other sensitive material if captured and uploaded to personal clouds or external AI services. Astral Beam, a cross-chain bridge built by Make Group, launches on Casper to move tokenized real-world assets across Casper, Robinhood, Chain, Base, Ethereum, and Polygon while carrying

compliance state via the ERC-7786 standard and T-REX ledger. Three key upcoming milestones will determine success. The T-REX mainnet launch, Casper DeFi's development of collateral markets and RWA vaults, and the pace of Apex's pledged asset flow driving regulated volume across connected chains. The system enables transfer eligibility checks against a shared compliance record before settlement, addressing the problem of compliance rules not traveling with tokens across chains. The public test net launches today with mainnet planned later. The T-REX ledger, a sovereign chain for maintaining a reference copy of who may own what and under what conditions is central to the architecture, and mainnet is expected in Q4-2026. Apex Group plans to bring $100 billion in tokenized assets to T-REX by June 2027, illustrating expected scale and the need for multi-chain liquidity across regulated assets.

Robinhood Chain is identified as a critical connector due to its active 24-7 tokenized stocks trading and wide coverage, illustrating the importance of bridging to non-EVM ecosystems with maintained compliance. Astral Beam emphasizes a five-verifier, three-of-five consensus model to mitigate bridge risk, outperforming prior two of five or five of nine schemes, and notes ongoing six-month test net operation, plus a hell-born audit with full report forthcoming. Apex Group's tokeny, Polygon Labs, and the ERC-364-3 association launched the T-REX ledger in March 2026, connecting chains via Aglayer to maintain cross-chain compliance state for ERC-364-3 tokens. Casper is highlighted for its upgradable smart contracts, native ERC-364-3 support, and faster finality, making it a suitable non-EVM partner that can host regulated tokens while

maintaining cross-chain connectivity. This has been your daily brief in tech. To read more about these stories, follow the links in the episode bio. You can also subscribe to these updates via email at www.brief.news. For more daily podcasts about the topics you love, visit brief.news-forward-slash-podcasts. Tune in tomorrow. We'll be back with everything you need to know.

More episodes

More from Tech News Daily

View all episodes →