Security Uses Cryptography in Pieces. WinMagic Says That Gap Is What AI Attacks.

PR Newswire
Today at 12:20pm UTC

Security Uses Cryptography in Pieces. WinMagic Says That Gap Is What AI Attacks.

PR Newswire

As AI-enabled attacks become faster and cheaper to launch, WinMagic CEO Thi Nguyen-Huu says organizations need to reduce the security decisions left to users and connect authentication more closely to the protected session that follows.

TORONTO, Sept. 30, 2026 /PRNewswire/ -- Artificial intelligence has changed the economics of cyberattacks, making convincing lures faster and cheaper to create. IBM reported in July that one in four malicious breaches was AI-enabled, costing organizations an average of about $6 million. Thi Nguyen-Huu, President and CEO of WinMagic, a cybersecurity company focused on endpoint authentication and encryption, points to adversary-in-the-middle (AitM) attacks as a threat he expects to become increasingly significant. In this scenario, the attacker sits between the user and the real service and relays the login as it happens.

“Online, cryptography is the best defense we have. But humans cannot do cryptography, so the endpoint has to do it for us." - Thi Nguyen-Huu, President and CEO of WinMagic

Nguyen-Huu calls it the "mother of all attacks," one that can defeat login methods including passwords, one-time codes, push notifications, and passkeys without breaking them. He says there is nothing to patch or spot because both ends see a login that worked. All it needs is a convincing lure, which AI has made cheaper to create.

According to Proofpoint, almost half of the accounts taken over by attackers had multifactor authentication (MFA) turned on as of December 2024. "You can ask for more, check harder, verify again, none of it helps," Nguyen-Huu said. "Nothing in the exchange is false. The person is real, the device is real, and the answer to every question is correct."

The Rule the Industry Skipped

Nguyen-Huu's answer is one rule: authentication must produce a cryptographic key tied to the party the user is about to communicate with. Nothing in use for online access today does that. Today, a login typically ends with a verdict that the user has been authenticated, while the protected session that follows is established separately.

Machine-to-machine systems have used a version of this model for decades. Through mutual Transport Layer Security (mTLS), two systems can prove their identities while establishing a key protecting their communication. Extending it to people has traditionally required users to manage credentials themselves. Nguyen-Huu argues the endpoint should perform that work instead.

"Online, cryptography is the best defense we have. But humans cannot do cryptography," Nguyen-Huu said. "So the endpoint has to do it for us. You log in to your own device, and after that the device carries you everywhere online, proving a key on every connection. And it comes with something people may like more than the security: no user action at all."

What an Organization Can Deploy Today

WinMagic's MagicEndpoint applies that approach at login, authenticating both the user and device to an organization's existing identity provider. It has been tested with Microsoft Entra ID, Okta, and Ping without requiring changes to the applications users access. Instead of passwords, codes, or prompts, the device proves a hardware-protected key. The goal is to remove login decisions that can be manipulated while allowing the endpoint to handle the cryptographic work.

The next step is to shorten sessions. Most security teams know they should shorten them. Few do, because every extra sign-in lands on the user. With a device-bound key, it doesn't. The session renews silently. The gap between login and session is separate, and nobody has closed it. Short-lived assertions and stricter validation narrow that window, they do not eliminate it. "The login needs nobody else to move. The rest needs the industry to move with us," Nguyen-Huu said.

Closing the Gap Beyond the Login

The next phase will require the industry to take three practical steps:

  • Build the other half. The device proves its key directly to the application, bringing login and session together without a separate token. This approach is called Live Identity in Transaction (LIT).
  • Test it. Work with industry partners on open-source testing and integration with applications already in use.
  • Take it through the standards. WinMagic submitted a formal proposal to the World Wide Web Consortium's WebAppSec group in March 2026, with additional drafts filed at the Internet Engineering Task Force on workload identity and Open Authorization, along with comments submitted to MITRE, a nonprofit research and development organization that works on cybersecurity.

The LIT project on GitHub includes a working reference implementation on Windows, and WinMagic shares additional source code, under agreement, with integration partners. The underlying flaw was published on the company's blog in February 2024, before the current acceleration of AI-enabled threats. Organizations interested in seeing the login implementation, as well as service providers interested in building the application side, can contact research@winmagic.com.

MagicEndpoint removes what a relay can harvest at the login and removes the prompt a relay needs in order to start. Nevertheless, it does not make an already-compromised device trustworthy, and an attacker relaying in real time at the exact moment a session is set up remains a risk that has to be tested, not assumed. Nguyen-Huu does not describe the approach as AI-proof or unphishable.

About WinMagic

WinMagic's mission is to secure the digital world through high standards and strong ethics. For nearly three decades, the organization has led innovation in encryption and endpoint security. Today, WinMagic is advancing a new paradigm for online access—anchoring the endpoint as the foundation of trust. By letting endpoints speak for users, WinMagic turns cumbersome logins into seamless, automated exchanges. What was once user-to-machine communication now becomes a machine-to-machine relationship, governed by policy and anchored in cryptography. This evolution eliminates friction, reduces risk, and lays the groundwork for the Secure Internet—where security is continuous, effortless, and requires no user action. Learn more at https://winmagic.com.

References:

  • IBM. (2026, July 29). IBM study: One in four malicious breaches are AI-enabled, costing companies $6 million on average. IBM Newsroom. newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled%2C-costing-companies-6-million-on-average IBM Newsroom
  • Gardiner, M. (2024, December 30). Why MFA is good but not good enough: The need for defense-in-depth to combat MFA bypass. Proofpoint. proofpoint.com/us/blog/identity-threat-defense/why-mfa-good-not-good-enough-need-defense-depth-combat-mfa-bypass
  • Nguyen-Huu, T. (2024, February 5). WinMagic discovered a flaw in TLS and FIDO. WinMagic.
    winmagic.com/en/blog/winmagic-discovered-a-flaw-in-tls-and-fido
  • Nguyen-Huu, T. (2025, September 23). Did your login pass or fail? WinMagic. winmagic.com/en/blog/did-your-login-pass-or-fail
  • Nguyen-Huu, T. (2026, March 2). Formal proposal: A deterministic (no-token) alternative to DBSC [Electronic mailing list message]. World Wide Web Consortium. lists.w3.org/Archives/Public/public-webappsec/2026Mar/0000.html
  • Nguyen-Huu, T., Nikitin, S., & O'Leary, J. (2026, July 6). Condition-bounded credentials for workload and agent identity: Non-exfiltratable keys and validity by presence [Internet-Draft]. Internet Engineering Task Force. datatracker.ietf.org/doc/draft-winmagic-wimse-condition-bounded-credentials/
  • Nguyen-Huu, T., Nikitin, S., & O'Leary, J. (2026, August 11). Condition-bound keys for mutual-TLS client authentication and DPoP [Internet-Draft]. Internet Engineering Task Force.
    datatracker.ietf.org/doc/draft-winmagic-oauth-condition-bound-keys
  • WinMagic. (n.d.). Live Identity in Transaction (LIT): Reference implementation [Source code]. GitHub. github.com/WinMagic/LIT

Media Inquiries:
Karla Jo Helms
JOTO PR™
727-777-4629
jotopr.com

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/security-uses-cryptography-in-pieces-winmagic-says-that-gap-is-what-ai-attacks-302894388.html

SOURCE WinMagic