Ian Miers

@secparam.bsky.social

UMD CS Prof. Security and applied cryptography.

So apparently anyone with a yubikey is currently locked out of Twitter. Which means a bunch of folks on infosec twitter who are still tweeting just got caught with their pants down. ( Or they did have 2fa and actually re-enrolled early and it worked , but that's not as fun). x.com/bax1337/stat...

Nick Bax.eth on X: "@socialwifipaul @nikitabier @X posting on behalf of my friend, who can't log in to X because the 2FA re-enrollment is broken. https://t.co/SxFPDtAp8I" / X

@socialwifipaul @nikitabier @X posting on behalf of my friend, who can't log in to X because the 2FA re-enrollment is broken. https://t.co/SxFPDtAp8I

x.com

There's no such thing as Fully-Homomorphic Decryption. Anytime you see a system using FHE to compute on your sensitive data, remember: someone has the key. If its not you, do you trust them?

I had an interesting convo with @matthewdgreen.bsky.social about Apple's Memory Integrity Enforcement (MIE). It will raise the cost of zero-day exploits, but by how much? MIE stops a huge swath of exploits that target unsafe memory handling. It's impressive and required new hardware features.....

Discord user IDs getting leaked is the entirely predictable consequence of requiring platforms to do age verification. That data never goes away, it spreads. In this case, into appeals in a breached customer support database. And predictably, it can get worse. www.404media.co/the-discord-...

The Discord Hack is Every User’s Worst Nightmare

A hack impacting Discord’s age verification process shows in stark terms the risk of tech companies collecting users’ ID documents. Now the hackers are posting peoples’ IDs and other sensitive informa...

404media.co

The worst part of preparing a tenure portfolio is realizing you actually have to create that 'permanent record' your elementary school teachers threatened you with. And it has pesky formatting requirements.

Interesting anecdote from a friend: quantum computing startups are now raising funds by pitching their ability to break cryptocurrency encryption (n=1 plus VC gossip, but still). Apparently other applications like quantum chemistry don't offer big enough ROI for investors.

Some "AI" on my phone is reading inbound Signal messages. I left predictive typing on, trading a little of my privacy for convenience. Yet something is giving responses using what others wrote in chats with disappearing messages, persisting or sharing them who knows where. Not a good default, Google

Bild

We've crossed a threshold. A paid subscription used to be the ultimate proof of humanity online, now its not enough to allow a single link click inside the NYT cooking app. The next few years are going to be an interesting race to extract more and more invasive proofs of humanity.

Bild

The 2010s internet: Let's mock dissertation-length arguments about weird-ass fanfic tags. The 2025 internet: 'dubcon' is an ancillary part of the financial privacy discourse. The past was a better place.

Post nicht verfügbar.

Making LLM chats private is a good idea. We've accepted too much data harvesting already—this moment lets us reset the norm around who controls our data online. But let's go further: put LLM chats in private compute, so you get technical guarantees you control your data. x.com/sama/status/...

Bild

Friend messaged me: Signal's going mainstream. They've got 150+ active chats. Work life invaded their friend space. Its not just Signal being in the news: people don't trust other apps. Too many places to half-ass privacy: be it backups, ads, or an AI reading over your shoulder.

It's the year 2030. AIs write all our sitcoms now, but they're just endless FRIENDS clones because the underpaid content moderators in offshore offices learned that's the pinnacle of American comedy.

Google announced they will support privacy preserving age verification via zero-knowledge proofs. You prove you have a signed digital copy of a drivers license and it says you are over 18 without revealing anything about you (name, birthdate, etc) blog.google/products/goo...

It’s now easier to prove age and identity with Google Wallet

Learn more about new Google Wallet updates, including new ways to use your digital ID for age and identity verification.

blog.google

The UK is fighting the last war by trying to backdoor encrypted messaging worldwide. The US tried the same trick in the Obama and Bill Barr DoJs. Thankfully, saner minds prevailed. Now the FBI recommends encrypted messaging because it makes us safer from nation state hacking.

Ian Miers@secparam.bsky.social · last yr.

@meredithmeredith.bsky.social points out the real story with Apple disabling encrypted backup (and therefore effectively iMessage encryption) in the UK. The UK is demanding a global backdoor for all data, including Americans. Apple is resisting as best they can.

Easily overlooked threat: The UK is demanding Apple expose your iCloud data, no matter where you live. Apple is fighting for limits, but the demand is world-wide access, not just for UK persons. This is terrible for US sovereignty and national security. wapo.st/4k2AF5Z

U.K. orders Apple to let it spy on users’ encrypted accounts

Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users.

wapo.st

Two sentence horror: Twitter died as a public commons for expert discussion. As bsky turned into a stream of consciousness, and threads into text-o-gram, we were forced to consider desperate alternatives like .... LinkedIn.

When designing computers or, by proxy, society, security is mostly unnecessary. But when, e.g., your 18-year-old needs an abortion or Russian tanks are coming, encryption is essential. Secparam is a pun. A latex macro, short for security parameter, in narrowly technical papers which ignore all this.

terence wiggins@theblacknerd.bsky.social · 3y ago

let's do something fun where did your username come from? I used to be a radio intern when I was 19 and my radio name was "Terence The Black Nerd" and it stuck