Serge Egelman (@v0max.bsky.social) (@v0max) 's Twitter Profile
Serge Egelman (@v0max.bsky.social)

@v0max

Does his own research. Dir. of Usable Security & Privacy @ICSIatBerkeley. Founder, @AppCensusInc. All opinions are those of his employer(s), and not his own.

ID: 18670940

linkhttp://www.guanotronic.com/~serge/ calendar_today06-01-2009 11:43:26

6,6K Tweet

2,2K Takipçi

1,1K Takip Edilen

Serge Egelman (@v0max.bsky.social) (@v0max) 's Twitter Profile Photo

👇This. If you’re doing something interesting that requires deep expertise, you don’t need to worry *too* much about randos with money outcompeting you.

Securing Bits (@securing_bits) 's Twitter Profile Photo

Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps. Today's comic is inspired by a recent paper written by Black Lives Matter, Fuzail Shakir, Noura N. Alomar, and Serge Egelman (@v0max.bsky.social). 🧵[1/8] #privacy #cybersecurity

Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps.

Today's comic is inspired by a recent paper written by <a href="/conorgil/">Black Lives Matter</a>, Fuzail Shakir, <a href="/Noura_7N/">Noura N. Alomar</a>, and <a href="/v0max/">Serge Egelman (@v0max.bsky.social)</a>. 🧵[1/8]

#privacy #cybersecurity
Alvaro Bedoya (@bedoyaftc) 's Twitter Profile Photo

Our Chicago and Atlanta FTC offices are hiring new attorneys. These are among of our most dynamic shops. I urge you to consider applying: usajobs.gov/job/735035000

Shomir Wilson (@shomirwilson) 's Twitter Profile Photo

Thanks Serge Egelman (@v0max.bsky.social) for a distinction about the audiences of privacy policies. Ostensibly they’re for end users, but the actual audience is different: regulators, lawyers, and researchers. #pets23

Maximilian Hils (@maximilianhils) 's Twitter Profile Photo

No, it was not a joke. "Our paying customers need X, when will you fix it?" may not be the best way to introduce yourself to an open source project. #TodayInOpenSource

No, it was not a joke. "Our paying customers need X, when will you fix it?" may not be the best way to introduce yourself to an open source project.

#TodayInOpenSource
Robert Bateman (@robertjbateman) 's Twitter Profile Photo

Police used the Meta Pixel tracker to share interactions with a form for witnesses and victims with Facebook. Also told Meta when someone clicked a link to "securely and confidentially report rape or sexual assault". It is utterly bonkers that this is so unsurprising. Just WHY

Police used the Meta Pixel tracker to share interactions with a form for witnesses and victims with Facebook.

Also told Meta when someone clicked a link to "securely and confidentially report rape or sexual assault".

It is utterly bonkers that this is so unsurprising.

Just WHY
Serge Egelman (@v0max.bsky.social) (@v0max) 's Twitter Profile Photo

I’m no marketing wizard, but it seems to me that you might want to make your email pitches a bit more distinguishable from recall notices…

I’m no marketing wizard, but it seems to me that you might want to make your email pitches a bit more distinguishable from recall notices…
CYBERGEM 💎✨ (@ultraterm) 's Twitter Profile Photo

🚨 "We may manually review DMs..." 🚨 This window randomly popped up for me stating that employees will read our DMs for various reasons, including if a government requests access. I already assumed this was the case, but it's nice to know for sure that we have no privacy here.

🚨 "We may manually review DMs..." 🚨

This window randomly popped up for me stating that employees will read our DMs for various reasons, including if a government requests access.

I already assumed this was the case, but it's nice to know for sure that we have no privacy here.
Serge Egelman (@v0max.bsky.social) (@v0max) 's Twitter Profile Photo

Pro tip: in CA they’re required to allow you to cancel online (Cal. Bus. & Prof. Code § 17602). Comcast violates this, and so when it happened to me, I documented it and then disputed the credit card charge. They immediately canceled when Amex notified them of the dispute.

Pro tip: in CA they’re required to allow you to cancel online (Cal. Bus. &amp; Prof. Code § 17602).

Comcast violates this, and so when it happened to me, I documented it and then disputed the credit card charge. They immediately canceled when Amex notified them of the dispute.
Juan Tapiador (@0xjet) 's Twitter Profile Photo

Great presentation by Allan right now USENIX Security on our recent work about logging of sensitive information in Android. #usesec23 Paper + slides (and soon the talk) here: usenix.org/conference/use… /cc Serge Egelman (@v0max.bsky.social) Narseo Vallina @jgamba_

Great presentation by <a href="/Allan__Lyons/">Allan</a> right now <a href="/USENIXSecurity/">USENIX Security</a> on our recent work about logging of sensitive information in Android. #usesec23

Paper + slides (and soon the talk) here:
usenix.org/conference/use…

/cc <a href="/v0max/">Serge Egelman (@v0max.bsky.social)</a> <a href="/narseo/">Narseo Vallina</a> @jgamba_
Socially Distant Ryan 🇺🇦 (@ryan_hassett) 's Twitter Profile Photo

It's still incredible to me that Uber set up what were obviously illegal taxi operations, called it something else and eventually got virtually every city in North America to roll over, say "okay!" and either tear down taxi regulations or set up two parallel regulatory regimes.

Chris Hoofnagle (@hoofnagle) 's Twitter Profile Photo

In my various travels, I hear Max Schrems' name invoked as much as the FTC's. Schrems will someday be recognized as one of the most consequential people in privacy. Even if you disagree with him, Schrems shows how a young, entrepreneurial lawyer can change the world

Daniel Woods (@ieltop) 's Twitter Profile Photo

#weis2024 is on an accelerated timeline this year. The Submission deadline is 30 November 2023 Details: weis.utdallas.edu/call-for-contr…

#weis2024 is on an accelerated timeline this year.

The Submission deadline is 30 November 2023

Details: weis.utdallas.edu/call-for-contr…
Carmela Troncoso (@carmelatroncoso) 's Twitter Profile Photo

The regulation also says that these keys cant be removed without the authorization of the issuing member state‼️ This means that checks from the community like this awesome work by Serge Egelman (@v0max.bsky.social) and Joel Reardon would be useless if states want to keep their keys: washingtonpost.com/technology/202…