Greg Dash

392 posts

Greg Dash banner
Greg Dash

Greg Dash

@GregLabour

Higher Education, Skills and Strategy at @UCL Former Labour advisor: Elections, Local Government & Cabinet Office. Fellow of @IWA_Wales.

London, England Katılım Ağustos 2015
2.4K Takip Edilen5.9K Takipçiler
Greg Dash retweetledi
Rhys Williams﮷
Rhys Williams﮷@RhysWilliamsTV·
There is now no Labour Party representative in the Senedd in Wales' eastern valleys. This is where Aneurin Bevan and Michael Foot used to win with 80% of the vote.
English
9
68
302
24.4K
Greg Dash
Greg Dash@GregLabour·
A century of Labour leadership in Wales has come to an end - a record that made us "the most successful political party in the democratic world” according to Cardiff University. Time for reflection - but urgently we need a change in leadership.
English
0
0
0
187
Greg Dash retweetledi
Paul Moore - Security Consultant 
4 days ago, @vonderleyen said "This app will allow users to prove their age when accessing online platforms. Just like shops ask for proof of age for people buying alcoholic beverages" There's a palpable irony there which is only evident when you dive into the architecture of the #EU #AgeVerification framework. When a shopkeeper asks for ID, four things happen simultaneously; the shopkeeper sees the person's face, compares it to the photo on the ID, confirms their date of birth and hands the product to the same person. They're also highly unlikely to keep a copy/disseminate it, but I digress. Verification and consumption are bound together by their physical presence. With the AV app: There's no human shopkeeper. There's no line of sight with the consumer. There's no personal ID to verify. "Proof" of age can come from anywhere and there's absolutely no way for the "shopkeeper" to spot it's not true. For the company desperate to reach compliance, they'll likely consider the checkbox ticked and won't invest in genuinely helpful protection as there's now a strong legal argument that no further investment is necessary. They'll point to the cryptographic, government-backed, hardware-attested, zero-knowledge proof and declare the problem solved. That wouldn't be unreasonable either. @vonderleyen said it herself, "now there's no excuse" - suggesting this, and this alone, is sufficient to reach compliance and represents the gold standard against which other systems should be benchmarked. It's the European Commission effectively telling an industry to stop investing in alternatives; the problem has been solved. So, let's flip the narrative and implement this in the real, physical world. A 10yr child enters an off-license. The shopkeeper can clearly see they're a child, but to make absolutely sure, they present a QR code which the child scans with their phone. Rather than using the AV app, the child installs a free relay which simply sends the challenge to a valid phone. The phone receives the challenge, has no idea where it came from or who initiated it, signs it and sends "proof" back to the shopkeeper. The shopkeeper, utterly confused, has cryptographic proof they are over 18 and hands over the alcohol. The EU #AgeVerification framework has created the digital equivalent of "excuse me mate, can you buy us some alcohol?" - it removes every single element that makes the physical analogy work... then makes the situation worse. It does not & can not protect children in the manner they describe. It creates a legal shield for companies looking for compliance, not necessarily child safety. It's creates a commodity market for bulk-generated, pre-approved assertions that you're "over 18". ... that's just at the architecture level. The implementation goes on to make a mockery of authentication, doesn't cryptographically tie PINs to vaults, stores sensitive biometric data insecurely and breaches #GDPR in the process. I don't think anyone disputes the need to protect children from online harm, but this really isn't the solution.
Paul Moore - Security Consultant @Paul_Reviews

It's not easy to visualize the relay attack against the #EU #AgeVerification app from a user's perspective, so here it is. Even if the app works exactly as designed, the website & verification process is entirely decoupled & 'anonymous' The architecture assumes you'll send the request to your device, which contains your biometric data. But, it can go to any device, anywhere in the world... and because the phone has no way to know who initiated the process, the child still passes age verification. The assertion is the user is over 18. In reality, the app is responding to say the owner of this Android device is over 18. It doesn't know who the user is... how can it know their age? This is the current design, not a bug. They thought the ISO/IEC 18013-7 Annex C/DC API upgrade would protect against this, but CTAP only protects against external attackers, not the user wanting to bypass the system themselves - hence my description that we've replaced "I am over 18" with "someone is over 18" and it's supposedly better. If (more likely when) this is exploited, will company Directors/staff still face fines, legal action or imprisonment for not protecting children? Once you've signed in, websites are highly unlikely to ask for age verification again... so this attack, even if it could be mitigated in some way (I can't see how) only applies to new verifications. The EU #AgeVerification Relay Attack:

English
19
50
174
10.7K
Greg Dash
Greg Dash@GregLabour·
@johnsearby57 Yep, Preston Park. Drop me an email and looking forward to getting involved.
English
0
0
0
11
John Searby
John Searby@johnsearby57·
@GregLabour Hi Greg. Sorry I haven't replied sooner. Are you a member of Preston Park branch? I can email you via Organise, which will be a better way to tell you about forthcoming events, etc.
English
1
0
0
6
Greg Dash
Greg Dash@GregLabour·
@johnsearby57 Hi John, are you deputy at Preston Park branch? Moved into the area and trying to get to meetings.
English
1
0
0
235
Greg Dash
Greg Dash@GregLabour·
Gutted to see that @JimfromOldham has left his role at MHCLG, especially just after the 2nd reading of the Devo Bill. Jim has Local Government running through his veins, and will be a hard act to follow. #Reshuffle
English
0
0
1
373
Greg Dash retweetledi
Abtisam Mohamed
Abtisam Mohamed@Abtisam_Mohamed·
Great news: 9 Gaza students will be evacuated to start their UK scholarships. I’ve led cross-party efforts with 100+ MPs to help over 40 students escape war and study in safety. This must not stop here, we must evacuate the rest. #LetThemLearn theguardian.com/education/2025…
English
0
9
36
2.1K
Greg Dash retweetledi
The Labour Party
The Labour Party@UKLabour·
Happy St David’s Day from the Labour Party. Dydd Gŵyl Dewi Hapus gan y Blaid Lafur.
The Labour Party tweet media
CY
97
142
309
29.7K
Greg Dash retweetledi
stellacreasy
stellacreasy@stellacreasy·
Walthamstow know many people were worried about someone trying to deface or steal our banksy pelicans - thank you to the unsung heroes who have now made sure it’s protected in such a sensitive way and we can enjoy it ( and the chips!) for many years to come.
stellacreasy tweet mediastellacreasy tweet mediastellacreasy tweet media
English
7
7
62
8.6K
Greg Dash retweetledi
UK Year of Service
UK Year of Service@ukyearofservice·
On 16 & 17 July, @NCSTrust hosted our Summer conference. The event saw over 80 members develop their skills, with sessions from @SpeakersTrust and NCS and provided networking opportunities. Thank you to all our members for your engagement and willingness to meet new people.
UK Year of Service tweet mediaUK Year of Service tweet mediaUK Year of Service tweet media
English
0
1
1
224
Greg Dash retweetledi
Roderik Rekker
Roderik Rekker@RoderikRekker·
(1/-) Very excited to share that this paper from my Veni-project has just been published. By analyzing 258 elections studies from 21 countries, I examined to what extent electoral change between 1948 and 2021 has been driven by generational replacement. frontiersin.org/articles/10.33…
English
1
16
33
9.4K
Greg Dash retweetledi
Cllr Andrew Morgan OBE
Cllr Andrew Morgan OBE@AndrewMorganRCT·
It was great to attend and see the stunning Eisteddod chair and crown being unveiled this evening at Llantrisant Guild Hall. 50 days until we welcome the Eisteddfod to RCT 🏴󠁧󠁢󠁷󠁬󠁳󠁿
Cllr Andrew Morgan OBE tweet mediaCllr Andrew Morgan OBE tweet media
English
4
8
51
3.9K
Andrew Fisher
Andrew Fisher@FisherAndrew79·
Politicians, when they're running for the Labour leadership ...
Andrew Fisher tweet mediaAndrew Fisher tweet media
English
14
245
587
30.3K
Greg Dash retweetledi
HOPE not hate
HOPE not hate@hopenothate·
Liz Truss’s alarming descent into far-right territory continues as she appears on the notorious Lotus Eaters show to promote her new book. 🔗 Read our full analysis here: hopenothate.org.uk/2024/05/29/liz…
HOPE not hate tweet media
English
96
40
55
96.9K
Greg Dash
Greg Dash@GregLabour·
@lynbrownmp Really sad to hear Lyn, was a privilege to work alongside you in Parliament.
English
0
0
0
27
Lyn Brown 🌹
Lyn Brown 🌹@lynbrownmp·
I have loved being the MP for West Ham and I love it still. Standing down will be such a huge wrench. But, given the challenges we have in Newham and the health challenges I've faced this year, I think we need new Labour MPs to take us forward with a Labour Government.
Lyn Brown 🌹 tweet media
English
105
36
321
239.9K