Today we published WeWorm, our zero-click worm that spreads across iOS and Android.
All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack.
We reported the bug to Tencent, and it's now mitigated for all users.
We hope this sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them.
AI gives us a chance to find and fix these bugs faster than ever. We should work together to make the world safer for everyone.
Our story and demos: https://t.co/YsoYFduv60
We've been crowdsourcing a list of "fancy cryptography" used at scale in production. For two reasons: first it's amazing to see how much this is actually in use today. More importantly, most of it is not post-quantum, and this gives researchers a great resource for future work!
We're crowdsourcing a list of mainstream uses of "fancy" cryptography such as OPRFs, blind signatures, SNARKs and ZKP. Basically cryptography beyond symmetric ciphers, hashes, signatures, and KEM/PKE.
https://t.co/HnBYEpMV8a
I was reading the "Intro to ProgCrypto" book by @0xPARC. To understand the examples and algos better, I translated them line-by-line to Jupyter notebooks.
I plan to add exercises and use it as a base to learn advanced topics for each chapter
https://t.co/Hjf1InQgdN
⬇️
A lot of people are now in Bangkok for Devcon, an Ethereum conference, and a lot of them are stuck in Bangkok traffic for hours
I lived there for 10+ years on and off and there's a specific workflow we digital nomads developed to get around Bangkok FAST:
- book your hotel near the BTS (the skytrain)
- bring a hoodie (more on that later)
- look for the orange jacket moto guys, they're everywhere, or install Grab app and book a moto there, check what price should be, it's normal to negotiate and you'll need cash probably
- yes going on the back of a moto isn't safe but here's the point you all miss: you DO NOT drive a moto for your MAIN journey on big roads: you use a moto to get from your hotel to the BTS skytrain station
- then hop on the BTS, buy a Rabbit card (easy) for easy check in
- take the airconditioned BTS skytrain and you might need your hoodie cause it's so cold
- arrive near your spot, if it's a mall you can probably walk into it from the BTS
- if a cafe or restaurant, get out of the station, again look for orange jacket moto drivers or book a Grab moto, drive to your destination
Other things:
- malls are different here than in the West, malls are a universe here, you can spend all day there, not shopping even but just walking around, drinking coffee, eating great food, bowling, cinema, endless activities, and you'll skip the outside heat and air pollution cause air inside is cold and filtered
- try massages, my fav is foot massage
- my fav area is around Lumphini very upscale
- Bangkok is great cause it has a range from supercheap to super luxury expensive, it works with everyone's budget, you probably have stereotypes about Thailand like everyone but there's like 30 different types of Bangkok depending which area you're in, I've had street food sushi for $1 and Japanese Michelin chef private sushi for $700! Can do both
- if you have time, fly to some of the islands, they're nice to explore, Ko Pha Ngan in particular is a great spot kinda like Bali but not so busy and very hippie
Enjoy Bangkok and Thailand!
The free Kindle version of the fourth edition of my book Linear Algebra Done Right is now available at https://t.co/TwoHBIxr2a.
The free pdf version of the book is available at https://t.co/fAxuAOpdHg. The free translation into Chinese is also available as a pdf file at https://t.co/fAxuAOpdHg.
#linearalgebra
Happening a week from today! Great to see the level of interest so far. Register for Zoom link.
Here's the info if you want to share it on your company Slack or in your networks.
Website: https://t.co/4ASEoWIApR
Registration: https://t.co/vPG2FvVawx
Poster:
New essay: ML seems to promise discovery without understanding, but this is fool's gold that has led to a reproducibility crisis in ML-based science. https://t.co/UrHbAsdSz0 (with @sayashk).
In 2021 we compiled evidence that an error called leakage is pervasive in ML models across scientific fields. In our most recent survey the number of affected fields has climbed to 30. https://t.co/mjy8TfKA4U
Leakage is only one of many reasons for reproducibility failures. There are widespread shortcomings in every step of ML-based science, from data collection to preprocessing and reporting results. https://t.co/hFhvM1rSHl
Root causes
The reasons for pre-ML replication crises, such as publication bias, also apply to ML. But a new and important reason for the poor quality of ML-based science is pervasive hype, resulting in the lack of a skeptical mindset among researchers, which is a cornerstone of good scientific practice.
We’ve observed that when researchers have overoptimistic expectations, and their ML model performs poorly, they assume that they did something wrong and tweak the model, when in fact they should strongly consider the possibility that they have run up against inherent limits to predictability. Conversely, they tend to be credulous when their model performs well, when in fact they should be on high alert for leakage or other flaws. And if the model performs better than expected, they assume that it has discovered patterns in the data that no human could have thought of, and the myth of AI as an alien intelligence makes this explanation seem readily plausible.
This is a feedback loop. Overoptimism fuels flawed research which further misleads other researchers in the field about what they should and shouldn’t expect AI to be able to do. https://t.co/UrHbAsdSz0
Glimmers of hope
Researchers should in principle be able to download a paper’s code and data, review it, and check whether they can reproduce the reported results. And the vast majority of errors can be avoided if the researchers know what to look out for. So we think that the problem can be greatly mitigated by a culture change where researchers systematically exercise more care in their work and reproducibility studies are incentivized.
We have led a few efforts to change this. First, our leakage paper has had an impact. Many researchers have used it to avoid leakage in their own work and to check previously published work. https://t.co/u2eJayGky9
Beyond leakage, we led a group of 19 researchers across computer science, data science, social sciences, mathematics, and biomedical research to develop the REFORMS checklist for ML-based science. It is a 32-item checklist that can help researchers catch eight kinds of common pitfalls in ML-based science. It was recently published in Science Advances. Of course, checklists by themselves won’t help if there isn’t a culture change, but based on the reception so far, we are cautiously optimistic. https://t.co/SWu8E6O4am
A tool, not a revolution
Of course, AI can be a useful tool for scientists. The key word is tool. AI is not a revolution. It is not a replacement for human understanding — to think so is to miss the point of science. AI does not offer a shortcut to the hard work and frustration inherent to research. AI is not an oracle and cannot see the future.
We are at an interesting moment in the history of science. Look at these graphs showing the adoption of AI in various fields (by Duede et al. https://t.co/pKhvCfzNnp):
These hockey stick graphs are not good news. They should be terrifying. Adopting AI requires changes to scientific epistemology. No scientific field has the capacity to accomplish this on a timescale of a couple of years. This is not what happens when a tool or method is adopted organically. It happens when scientists jump on a trend to get funding.
Given the level of hype, scientists don’t need additional incentives to adopt AI. That means AI-for-science funding programs are probably making things worse. We doubt the avalanche of flawed research can be stopped, but if at least a fraction of AI-for-science funding were diverted to better training, critical inquiry, meta-science, reproducibility, and other quality-control efforts, the havoc can be minimized.
https://t.co/UrHbAsdSz0
P. S. Our book AI Snake Oil is all about how to separate real AI advances from hype. It's now available to preorder (and we're told preordering makes a big difference to the book's success).
https://t.co/foQpEhRfhs
https://t.co/fHa32jM5Es
Job opening for assistant professor at @TUe_MCS in the group of Andreas Hülsing (@cr_yp_to ) We are especially looking for great candidates with a passion for cryptographic implementations and for formal verification of security properties. https://t.co/ltizYZ2a0l @TUeindhoven
The lecture notes of "Cryptographic Computing", the master level course I teach together with @schollster, are available at https://t.co/YxKl2EL1bd #aarhuskrypto
CATS deadline is in two weeks (on September 1st)! In other words, there's still plenty of time to get a talk submission ready! :) Details here: https://t.co/syvz0ZyH2Y