I'm extremely happy to announce I'll be doing ambitious and experimental AI security work with Anthropic this summer. Proud to be doing my part to help AI go well!
Jade
@jade.packet.science
they/she PhD Student @cs.umass.edu Privacy-Enhancing Technologies && Internet Censorship Website: https://packet.science Opinions expressed here do not reflect anyone but myself (and I change my mind often...)
red.anthropic.com/2026/attack-... Reading over Anthropic's list of threat actor techniques.
Woman Laughing: Hahaha I Do That
ALT: Woman Laughing: Hahaha I Do That
static.klipy.com
Big changes to Android and Chrome VRP: - focus on high-impact, reproducible bugs with low/no reward for lower impact - big prizes for full chains with some annual limits - PoCs required It’s the end of an era, but the start of a new one. bughunters.google.com/blog/evolvin...
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
bughunters.google.com
Happy to report my team's project "Syscon" co-won the LinuxArena track of the 2026 Apart AI Control Hackathon!
If your adversary is the FBI you should probably not be using your regular payment information with Protonmail, because even if they protect email at rest (and in transit given specific conditions), they are obligated to comply with Swiss LE.
A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.
Senators Wyden and Brown are requesting an investigation into side-channel and TEMPEST attacks. www.wired.com/story/how-vu...
How Vulnerable Are Computers to an 80-Year-Old Spy Technique? Congress Wants Answers
A pair of US lawmakers are calling for an investigation into how easily spies can steal information based on devices’ electromagnetic and acoustic leaks—a spying trick the NSA once codenamed TEMPEST.
wired.com
At what point is this stuff just advertisement for a particular mediocre ChatGPT wrapper with canvas integration. The bleak reality is that students at all levels are using regular models to cheat, and whether they have to click 4 or 5 times to submit an assignment doesn't really change anything.
In response to critics who say an AI tool that does your homework for you misses the entire point of education, the creator of Einstein says it's just how cars replaced horses 🐴 @evystadium.bsky.social has more. Story by @mjgault.bsky.social: www.404media.co/whats-the-po...
What did you think --dangerously-skip-permissions meant, vibes? Essays?
Meta’s director of AI safety, the person at the company who is working to make sure that AI tools don’t go rogue, had to scramble to stop an AI agent from deleting her inbox. @evystadium.bsky.social has more. Story by @emanuelmaiberg.bsky.social : www.404media.co/meta-directo...
Re: model distillation theft, Anthropic could do the funniest thing right now. www.anthropic.com/research/sma... www.anthropic.com/news/golden-...
Golden Gate Claude
When we turn up the strength of the “Golden Gate Bridge” feature, Claude’s responses begin to focus on the Golden Gate Bridge. For a short time, we’re making this model available for everyone to inter...
anthropic.com
I presented our work: "Geedge Cases: Censorship Measurement Insights from the Geedge Networks Leak" to FOCI 26 (winter, online) today, detailing our pipeline for finding domain censorship rules in the Geedge Networks leak.
Do PRC security researchers give foreign threat actors^W^W security researchers cool codenames? Asking for a friend.
My team and I are happy to accept "Best Circumvention Tool" at Jump The Wall at DistrictCon 1! More details to come!
Giving a talk to 39c3 today on our work "Wallbleed: A Memory Disclosure Vulnerability in the Great Firewall of China" and more! fahrplan.events.ccc.de/congress/202... Come say hi :3
[39c3] A Tale of Two Leaks: How Hackers Breached the Great Firewall of China
While probing the Great Firewall’s DNS injection system in 2021, we noticed something strange: Sometimes the injected responses contained weird garbage. After some investigation, we realized we’d stum...
fahrplan.events.ccc.de
Why are experts warning against the development of superintelligence? In a new video we partnered with SciShow on, Hank Green explains the concerning trends we see in AI. SciShow has over 8M subscribers. It's great to see so many people learn about this problem! [link below]
Great article about how TEEs are providing much less security than folks believe they will. arstechnica.com/security/202...
New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel
On-chip TEEs withstand rooted OSes but fall instantly to cheap physical attacks.
arstechnica.com
Politics over who gets the good offices/cubicles are honestly kinda fun. I sort of wish those were the only politics I had to worry about.
I've been spending a lot of time with the Geedge Networks leak, and I can't shake the idea that the name is vaguely Dutch. Vergeef mij, Fang Binxing, want ik heb geedged!
Can we have a law called the "if you vote no on this bill you love kicking puppies act" that bans congresspeople from picking these ridiculous and deceptive names?
#SaveSpeech the 'STOP CSAM Act of 2025' [S.1829] is currently estimated to be 56% likely to pass according to Govtrack This bill will undermine services offering end-to-end encryption and force internet companies to take down lawful user content tell reps to OPPOSE www.congress.gov/members/find...
The torrent has reportedly been sort of slow to download. If you, like me, are a security researcher doing fun things with this data, you should use your fancy university/company servers to help seed :)
One of the things that amazes me about scientific research is how much work goes into it. It’s just crazy. I mean all things require work, but it’s just so far above anything else (writing, software development.) I understand all the complaints about replication, what’s missing is the labor.
As instructors we must deal with this before it's too late. "Don't use AI" isn't really a sufficient guardrail. x-post from x.com/GarrettPeter...
Citizen Lab director warns cyber industry about US authoritarian descent techcrunch.com/2025/08/06/c...
Citizen Lab director warns cyber industry about US authoritarian descent | TechCrunch
Ron Deibert, the head of the prominent digital human rights groups Citizen Lab, sounds the alarm at the Black Hat security conference about the "dramatic descent into authoritarianism," but one that t...
techcrunch.com
Tom Scott making good stuff as always (11 years ago) youtu.be/RIuf1V1FhpY
Oversight: Thank you for volunteering, citizen.
YouTube video by Tom Scott
youtu.be
Getting into big security conferences may be difficult, but I'm grateful to have never seen anything as bad as "who is adam"
GWU was very welcoming of @pet-symposium.bsky.social attendees. The nearby whole foods, not so much.