-

BBC Radio4’s @MoneyBox programme is doing harm to #InformationSecurity & #FraudPrevention, and is providing propaganda for the OnlineSafety bill; with @DamianCollins, @paullewismoney & @kuriouskaf
So a friend who works in big-name consumer fraud mitigation angrily pointed me this week’s episode of Money Box on Radio4: Money Box has fresh revelations about criminal websites on the open internet. Two weeks ago we told you about the websites on which crooks buy and sell your confidential financial information. This week, Money…
-
Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanning | USENIX
End-to-end encryption (E2EE) by messaging platforms enable people to securely and privately communicate with one another. Its widespread adoption however raised concerns that illegal content might now be shared undetected. Following the global pushback against key escrow systems, client-side scanning based on perceptual hashing has been recently proposed by tech companies, governments and researchers to…
-
Researchers show that Apple’s CSAM scanning can be fooled easily
Quelle surprise; the referenced paper is https://www.usenix.org/conference/usenixsecurity22/presentation/jain The research presented at the recent USENIX Security Symposium by British researchers shows that neither Apple’s CSAM nor any system of this type would effectively detect illegal material.As the researchers explain, it’s possible to fool content detection algorithms 99.9% of the time without visually changing the images. The trick is…
-

So: December 16th, I’ve been invited to speak at the venerable HP Colloquium on #InformationSecurity held at @RoyalHolloway. I’ve just submitted the attached abstract. #NoPressure #EndsAllTheWayDown /cc /thanks @martinralbrecht
A title for your talk “Ends” All The Way Down: How we misunderstand Security, Privacy, Identity, and Anonymity. A short blurb/abstract for your talk Diffie says that encryption is possibly the only conceivable way to communicate a secret over distance through an untrusted medium. Less well understood is that end-to-end encryption is similarly perhaps the…
-
A Guide to Starting a Podcast: The Basics
There’s a bit of me which wonders if I should… Looking to start your first podcast? There are a couple of things you’ll need to take into consideration before diving in. Source: A Guide to Starting a Podcast: The Basics
-
An alternative to Poppies …
I’m not a great fan of the Royal British Legion’s “Poppy Drive”; I grew up with it, and I understand it, and my father served in World War 2 so I understand where it comes from and I respect why and that my dad was justifiably a huge supporter of it. But I don’t like…
-

“Mutually Assured Surveillance” (MAS) — what will be the National Security playbook towards platform adoption of End-to-End Encryption for the next 5 years?
There is a lot of end-to-end encrypted messenger tooling available to the general public: iMessage (Q: why does everyone forget iMessage? A: because it’s a fabric.) WhatsApp Signal FB Messenger (parts of) Telegram (parts of) Google (parts of) Wire Threema Matrix … It might be tempting to presume from this that end-to-end encryption is inevitable,…
-

This is a *wonderful* set of TikTok videos which help demonstrate the gulf between the “one size fits all” Internet that some people call for, versus actual diversity of User Experience #UX
featured image: screencap from serafinakarla16’s video, showing filtered “lips” I believe that it will be beneficial for you to watch these videos … So there’s this filter/lens called “Belle” going around on TikTok at the moment; if you’re not at all familiar with this concept you’re probably best-off thinking of it as “digital makeup effects…
-
Two posts on reverse-engineering #PokemonGo
Via Alex Butcher. If I weren’t already so busy I would be using this as an excuse to brush up my advanced Lua… https://www.romainthomas.fr/post/21-11-pgsharp-analysis/ https://www.romainthomas.fr/post/21-07-pokemongo-anti-frida-jailbreak-bypass/
-
Michigan poised to ban most state workers’ use of encrypted messaging | I’ve absolutely no problem with an employer (e.g. The Government) banning employees from conducting work over E2EE …
… not least, it provides business opportunities for all manner of small per-nation escrowed-access startup messengers which can leak sensitive content all over the Web once they are inevitably hacked. The important thing is that the public-at-large need not suffer the same fate: The Michigan State Senate voted unanimously on Tuesday to block state workers…