Black Lives Matter

5.4K posts

Black Lives Matter banner
Black Lives Matter

Black Lives Matter

@conorgil

he/him. Usable security & privacy engineer🤓 Podcast host🎙Co-creator https://t.co/QA7rVh6azR💡CS PhD student @Berkeley_EECS👨‍🎓Formerly @virtruprivacy 📧

Berkeley, CA Katılım Nisan 2009
1.1K Takip Edilen959 Takipçiler
Black Lives Matter retweetledi
Wei Xu
Wei Xu@cocoweixu·
I am recruiting 1~3 PhD students in CS or ML to join NLP X lab at Georgia Tech. Topics include but not limited to: (1) multilingual multimodal LLM (2) RLHF, text generation models (3) NLP+X (X = privacy, science, etc) Apply by Dec 15: cc.gatech.edu/prospective-gr… (📷Colin Gough)
Wei Xu tweet media
English
10
80
400
143.7K
Michal Špaček
Michal Špaček@spazef0rze·
Something I didn't expect to see in 2023: enter your banking username and password and a code if required so we can automatically log in for you and find your account number. We'll delete it, we promise🤞
Michal Špaček tweet mediaMichal Špaček tweet media
English
3
2
22
3.7K
Black Lives Matter retweetledi
Securing Bits
Securing Bits@securing_bits·
Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps. Today's comic is inspired by a recent paper written by @conorgil, Fuzail Shakir, @Noura_7N, and @v0max. 🧵[1/8] #privacy #cybersecurity
Securing Bits tweet media
English
1
4
10
1.6K
Black Lives Matter retweetledi
Dave Levin
Dave Levin@DistributedDave·
Police auction off many of the items they come into possession of. This includes cellphones. In a study led by @stack__trace we asked: are police wiping phones before they sell them? @briankrebs wrote about our study. In this 🧵, I'll give some highlights. krebsonsecurity.com/2023/05/re-vic…
English
1
16
39
11.8K
Black Lives Matter retweetledi
James Talarico
James Talarico@jamestalarico·
Texas Republicans are trying to force public schools to display the Ten Commandments in every classroom. I told the bill author: “This bill is not only un-constitutional and un-American, it’s deeply un-Christian.” #txlege
English
2.4K
9.6K
40.8K
5.8M
Black Lives Matter retweetledi
J. Alex Halderman
J. Alex Halderman@jhalderm·
Big news from Chrome Security Team! With HTTPS encryption now nearly ubiquitous, they're finally killing off the browser🔒icon, which tends to give users a false sense of security about other threats. blog.chromium.org/2023/05/an-upd… A huge milestone for web security. h/t @dadrian
English
3
31
76
18.3K
Black Lives Matter retweetledi
Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪@mysk_co·
Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on. The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices. We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user. Why is this bad? Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. Also, 2FA QR codes typically contain other information such as account name and the name of the service (e.g. Twitter, Amazon, etc). Since Google can see all this data, it knows which online services you use, and could potentially use this information for personalized ads. Surprisingly, Google data exports do not include the 2FA secrets that are stored in the user's Google Account. We downloaded all the data associated with the Google account we used, and we found no traces of the 2FA secrets. The bottom line: although syncing 2FA secrets across devices is convenient, it comes at the expense of your privacy. Fortunately, Google Authenticator still offers the option to use the app without signing in or syncing secrets. We recommend using the app without the new syncing feature for now. #Privacy #Cybersecurity #InfoSec #2FA #Google #Security
Mysk 🇨🇦🇩🇪 tweet mediaMysk 🇨🇦🇩🇪 tweet mediaMysk 🇨🇦🇩🇪 tweet mediaMysk 🇨🇦🇩🇪 tweet media
English
100
1K
2.5K
942.8K
Filip Gierszewski 💀
Filip Gierszewski 💀@Filip_G_Loco·
@mysk_co 'We recommend using the app without the new syncing feature for now.' How can you do it? There is no option in the settings of the app.
English
1
0
0
398
Adrian Lovell
Adrian Lovell@adrianlovell·
@mysk_co Have you run similar tests on other Authenticators that offer cloud sync?
English
1
0
0
273
Black Lives Matter retweetledi
Ariana Elena Castillo
Ariana Elena Castillo@arianaelena97·
When your institution has a >$50B endowment and accepts an unrestricted $500 million but can’t pay their grad student workers and employees wages that align with cost of living and inflation 💖
English
4
13
151
19.8K
Black Lives Matter retweetledi
Chris Murphy 🟧
Chris Murphy 🟧@ChrisMurphyCT·
If guns made us safer, America would be the safest place in the world. But the opposite is true. Nowhere else do students, concertgoers and bank patrons get slaughtered on a daily basis. Because as it turns out, it's all the guns that make us so unsafe.
English
5.9K
3.9K
18.1K
1.4M
Black Lives Matter retweetledi
Mysk 🇨🇦🇩🇪
Mysk 🇨🇦🇩🇪@mysk_co·
As @PrivacyMatters speculated, Authy sends too much analytics for an authenticator app. It associates analytics with the user's ID, which is tied to phone number and email. The analytics include the issuer name of each scanned QR code. Try to use a different #2FA app. #Privacy
Mysk 🇨🇦🇩🇪 tweet mediaMysk 🇨🇦🇩🇪 tweet mediaMysk 🇨🇦🇩🇪 tweet media
English
21
53
235
51.7K