We (cc @blueminimal) are soliciting web security students & postdocs for junior PC members for #SecWeb '24 (co-located with IEEE S&P). We have a mentoring program in place to help guide the junior PC members. If interested, please fill out the form: https://t.co/fvYTafsyMA
We are just days away from the RAID conference on October 16-18! We have an amazing program with a lot of great papers. Curious? Check out the program here: https://t.co/rxjXOr9BGD
Χωρίς αυτούς τους ανθρώπους δε θα μπορούσαμε να πάμε στη Θεσσαλία.
Ευχαριστούμε και τους 25 απίθανους ανθρώπους που προσφέρθηκαν εθελοντικά να κάνουν τζι-τζι τους πάνω από 1100100 φορητούς υπολογιστές! Για περισσότερες από 6 ώρες έδωσαν τον καλύτερο τους εαυτό!
Επίσης, μαζί μας
If you are a strong programmer, security-minded, and love operating systems, I'm looking for PhD students and interns to join me at @IMDEA_Software to work on Systems and Security related projects . More info at https://t.co/D0B9w6lvW6
Encrypted Client Hello (ECH) is a great improvement for online privacy. However, it’s important to stress that this ISN'T the last puzzle piece to privacy as stated by the article's title.
ECH safeguards plaintext domain names (previously exposed via the SNI field in TLS handshake) from passive eavesdropping, but the IP address is still there, potentially carrying a lot of information about the website visited. This is especially true for many websites that are single-hosted (i.e., having a 1-to-1 domain-IP mapping with the hosting address).
More details are from these research papers:
AsiaCCS '20: https://t.co/yovtyzbOVH
PoPETS '21: https://t.co/1K16IHWNuh
The original Citizen Lab report correctly mentions that this required an *on-path* capability—a MitM (in-path) attack is not strictly necessary for this. Man-on-the-Side (on-path) is easier. https://t.co/xgNcZd0JLp
Periodic reminder why plain HTTP (non-encrypted) traffic is a vulnerability: "...if the target went to any ‘http’ site, the attackers injected traffic to silently redirect them to an Intellexa site, c.betly[.]me." https://t.co/qvPlynux2j
Introducing the ai-cli library, a command-line copilot. It attaches to programs that offer interactive command-line editing and modifies their interface so you can obtain generative AI suggestions with a single keystroke. https:/www.spinellis.gr/l/ai-cli-lib?tw230914
No, these aren't screenshots of Apple's website. These are 1970s @LEGO_Group booklets that I've collected. They were doing bento box layouts set in a bold sans-serif 50 years ago.
Exciting news! #FOCI2023, the Workshop on Free and Open Communications on the Internet, is happening in person alongside the @PET_Symposium this year!
Join us for cutting-edge discussions on censorship, circumvention and more.
To register, 👉https://t.co/wdmZ8OuPqh
Before going to the beach and having your laptop off for a few weeks (I wish...), consider submitting your latest work at ISC this summer! The conference will be held in the Netherlands and we have keynotes from the best -- we will reveal, soon. :)
Joint statement from more than 300 scientists from 32 countries warning against the EU proposal for regulation to detect Child Sexual Abuse Material https://t.co/Z2yi3gMgrK…
The technologies it puts forward are inadequate to solve the problem and bring huge societal risks
🧵