
Neal Poole
@nealpoole
Interested in web application security. Security Engineer at Facebook. My tweets do not reflect the opinions or views of my employer.
ID: 46830209
https://nealpoole.com 13-06-2009 04:58:56
2,2K Tweet
3,3K Followers
311 Following




matt blaze Vote for Pedro! Check out Pedro Canahuati (Pedro Canahuati): x.com/mepedroc?s=09

What annoys me most about the The New York Times #Facebook "Private Messages" story launched & everyone is copying, is that once cooler heads look into it, it will be seen as a storm in a teacup, newspapers will rage at regulators for contradicting them, & civil society will look stupid.

At first sight this sounds like a terrible idea, but in fact there's peer reviewed research on measuring the security-usability tradeoff in correcting password typos, and it turns out it makes a lot of sense to do this. cs.cornell.edu/~rahul/papers/… Screenshot HT Andrew Munchbach









Several coworkers and I put up a proposal / demo on privacy preserving reporting on third parties using blind signatures github.com/siyengar/priva…. There are a surprising number of fun sub-problems to solve along the way. We'd love feedback Erik Taubeneck Andrew Knox Sean Bedford.

I just learned about "to-do list debt" and it's blowing my mind, so I want to share it with you. To-do list debt is when you've built up a backlog of overdue tasks. Just like real debt, if you pay off your debts first and ignore today's expenses, you just stay in debt. [thread]



At #realworldcrypto, Jon Millican just announced definitively that @Facebook will ship end-to-end encryption in Messenger. Bold. No timeline was provided, however.

