Irwin Reyes
157 posts

Irwin Reyes
@irwinreyescom
Security and privacy researcher at @Twosixtech. Previously at @ICSIatBerkeley. @[email protected]
Washington, DC Katılım Eylül 2014
194 Takip Edilen168 Takipçiler

A fantastic end of an important journey: today I passed my #PhD Viva, so yes you can call me Dr. Mazzoli!🤩 A special thanks to my wonderful supervisors @damiantambini @Robin_Mansellx who have supported me throughout!❤️ Big shout-out also to my fellow colleagues from @MediaLSE!

English

Sure looks familiar. So why would someone fall for this? Because invasive accesses are hard to grok, there are no auto-revokes or reminders about existing authorizations, and users trust the platform.
With @dgbalash @wxyowen @milesdoesjump @adamaviv
usenix.org/conference/use…
English

@v0max I suspect it’s designed to look cool at the time of sale. By the time the driver realizes touchscreen interfaces are hot garbage compared to physical controls, they’ve long driven the car off the lot.
English

I’m convinced that the Tesla is a car designed by people who don’t drive.
Yes, having to go through six levels of menus to turn on the headlights is totally safe and reasonable!
I assume self driving mode was mostly added to counteract the distraction of having to use the UI.
Meredith Whittaker@mer__edith
First time in a Tesla (I know, I'm blessed). WHAT?!? It's like an empty shed with a dell laptop on the dashboard. Confusing and overproduced and there's a video games app but I spent 5 minutes trying to figure out how to open the door... I know I'm late but, again, WHAT?!?
English

@ARLnowDOTcom The County needs to be much more aggressive against this. Too many drivers and gig workers use bike lanes for their own selfish convenience.
English

Protected bike lane in Clarendon repeatedly blocked by Starbucks customers, prompting county action arlnow.com/2023/01/20/pro…
English
Irwin Reyes retweetledi

I like how the @espn app says it needs your precise location just for live streaming content. But paid premium ESPN+ films simply won't work until you relent and tell them exactly where you are. So much for "if you're not paying for it, you're the product."


English
Irwin Reyes retweetledi
Irwin Reyes retweetledi

Backup options in many Android #TOTP #2FA apps share personal info w/ 3rd parties, have serious crypto flaws, and/or allow app devs to access TOTP secrets 😱
A 🧵 on our @USENIXSecurity '23 📜 "Security and Privacy Failures in Popular 2FA Apps"
github.com/blues-lab/totp…
#infosec
English
Irwin Reyes retweetledi

Happening now, in Track 1, @USENIXSecurity #usesec2022, David Balash is presenting our work on how users understand Googles 3rd party API access to their accounts.
David is also on the academic job market this year. You should hire him!

English
Irwin Reyes retweetledi
Irwin Reyes retweetledi

My team is looking to hire a research engineer in the Washington DC area. We explore mobile privacy challenges and solutions for the government. If you have a background in mobile software development and an interest in privacy, DM me to learn more. twosixtech.com/job/?gh_jid=45…
English
Irwin Reyes retweetledi

@v0max You're right, you wouldn't be able to use the current webadb implementation as-is because that requires a browser. But you might be able to run those same exact adb commands through the Device Farm API (basically a continuous integration script). docs.aws.amazon.com/devicefarm/lat…
English

@irwinreyescom Though, I'm not entirely sure how we'd use Device Farm, since we need to visit the website from a computer connected to the phone via USB?
English
Irwin Reyes retweetledi

(Please retweet!)
Do you have an Android phone? Please help us with a study!
pages.cpsc.ucalgary.ca/~allan.lyons/w…
English
Irwin Reyes retweetledi

@v0max Got it! I'll toss in a couple points to your data set. Also, if device diversity is a priority, have you guys looked into the AWS Device Farm? I don't know what restrictions they put on adb commands, but there's a decent selection of phones there too.

English

@irwinreyescom Though I should add that diversity of manufacturers/models is most important, because it's the device drivers that tend to log identifiers and location data (which can then be accessed by pre-installed apps/SDKs).
English

@v0max Are you looking mainly at the devices themselves? Or phones that people actually use? I have a couple old Android phones sitting in a drawer if that helps.
English
Irwin Reyes retweetledi








