
Serge Egelman (@v0max.bsky.social)
@v0max
Does his own research. Dir. of Usable Security & Privacy @ICSIatBerkeley. Founder, @AppCensusInc. All opinions are those of his employer(s), and not his own.
ID: 18670940
http://www.guanotronic.com/~serge/ 06-01-2009 11:43:26
6,6K Tweet
2,2K Takipçi
1,1K Takip Edilen


Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps. Today's comic is inspired by a recent paper written by Black Lives Matter, Fuzail Shakir, Noura N. Alomar, and Serge Egelman (@v0max.bsky.social). 🧵[1/8] #privacy #cybersecurity
![Securing Bits (@securing_bits) on Twitter photo Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps.
Today's comic is inspired by a recent paper written by <a href="/conorgil/">Black Lives Matter</a>, Fuzail Shakir, <a href="/Noura_7N/">Noura N. Alomar</a>, and <a href="/v0max/">Serge Egelman (@v0max.bsky.social)</a>. 🧵[1/8]
#privacy #cybersecurity Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps.
Today's comic is inspired by a recent paper written by <a href="/conorgil/">Black Lives Matter</a>, Fuzail Shakir, <a href="/Noura_7N/">Noura N. Alomar</a>, and <a href="/v0max/">Serge Egelman (@v0max.bsky.social)</a>. 🧵[1/8]
#privacy #cybersecurity](https://pbs.twimg.com/media/F0Q8bqYaEAALot0.jpg)


Thanks Serge Egelman (@v0max.bsky.social) for a distinction about the audiences of privacy policies. Ostensibly they’re for end users, but the actual audience is different: regulators, lawyers, and researchers. #pets23







Great presentation by Allan right now USENIX Security on our recent work about logging of sensitive information in Android. #usesec23 Paper + slides (and soon the talk) here: usenix.org/conference/use… /cc Serge Egelman (@v0max.bsky.social) Narseo Vallina @jgamba_






The regulation also says that these keys cant be removed without the authorization of the issuing member state‼️ This means that checks from the community like this awesome work by Serge Egelman (@v0max.bsky.social) and Joel Reardon would be useless if states want to keep their keys: washingtonpost.com/technology/202…