My Dad unexpectedly passed away last Thursday at the age of 84, peacefully, calmly, in the house I grew up in. He was an inventor, a radio operator, a pilot, an entrepreneur, an amazing father and pop-pop. He never let a loving thought go unsaid. Love you, pop.
On @Cloudflare Radar, you can now track various forms of traffic tampering around the world! This is the result of our collaboration between @UofMaryland and Cloudflare to develop passive ways of detecting when third parties tamper with user traffic. Stay tuned for a blog post!
I bought this shirt ~15 years ago and waited for the right opportunity to wear it. Today was that day, as I performed a science experiment with my kid's class. Thank you @PHDcomics for helping introduce a love for data to a new generation!
We found many instances of identity theft, including victims' social social security numbers, credit card numbers, bank account information, passports and other forms of identification—the literal definitions of "personally identifiable information".
First, there were all the things you might expect: text messages, photos (including nudity, drugs, weapons), browsing histories, cookies, usernames, passwords,...
That was not the only time a phone's credentials were included in the auction. Here is another PropertyRoom auction from Jan 2020 that has what appears to be a swipe pattern on it (we did not purchase this phone or confirm).
The police appear to have cracked one phone's PIN using @GrayshiftLLC's GrayKey. Here's the picture from PropertyRoom. This phone arrived with a sticky-note on the back; we confirmed the number was the PIN. This was not one of the most common PINs; we would not have guessed it.
Of the 228 we purchased, we got full access to 49 of them JUST BY TURNING THEM ON. They had no passcode; they arrived completely unlocked. We tried the 100 most common PINs/patterns ("1234", etc.) and that got us access to another 11 phones.
Whatever the group needs to collectively achieve their goals, in terms of both productivity and happiness. Sometimes that'll mean a non-coding manager, sometimes a coding manager. Blanket rules never work.
At the time, ~15% of South America reassigned within 12 hours. We found in a paper a few years ago that Brazil had more Hajime bots than any other country, by far. That said, CARDCount will still be useful for you when you want to count bots over longer periods of time!
Paper, code, and data to come. Stay tuned! But if you have a dataset of IP addresses and want to count them, or if you just want to understand a botnet better, reach out!
Congrats again to @_LeonBock and fellow authors @rameses888@chr_doerr and Max Mühlhäuser!
We call it CARDCount: Considering Address Reassignment Durations when counting. where is other techniques only let you count, bots in small, sub our snap shots, CARDCount gives accurate estimates over weeks.
The high-level idea is to learn how long ISPs assign IP addresses then use that to determine if two IP addresses are likely from the same host. If an ISP reassigns every 24 hours and you see 4 IPs over 4 days, it’s probably one bot. Sounds simple, but the devil’s in the details!
We all know that IP addresses are poor long-term identifiers, because they’re not permanently assigned. But what if you want to accurately count the bots in a botnet and all you have is IP addresses? Thanks to @_LeonBock’s first @NDSSSymposium paper we have a solution! 🧵
Senator Booker thinks that because this is a “nonviolent” crime so her punishment should be “fair and proportionate” (i.e., shortened). I would much rather be the victim of a violent crime than terminate a pregnancy that Theranos knowingly incorrectly said was not viable.
Recorded a podcast as a guest on the @packetpushers! We covered it all: research, open access publications, AI, and the competitive world of tuba auditions. The episode should drop late this month — stay tuned!
Made it to school in time to introduce @LeoLambro to the CS Honors students, so he can tell them all about his research finding bugs through fuzzing!
Taking advantage of the nice weather to run to @UofMaryland from my home in the heart of @washingtondc. Apply to UMD, and enjoy being so close to the nation’s capital.
The papers I linked above describe half a dozen server-side strategies that evade censorship in Iran. Some might work for you; if they do, let us know! If you want to try, let us know! And if you want to learn more, check out censorship.ai
ALT I Would Very Much Like To Hear Your Thoughts Captain Jean Luc Picard GIF
Two years ago, Iran turned on their protocol filter: an extra layer of censorship that permits only a limited set of protocols. Within about an hour, Geneva found server-side strategies to evade the filter and its traditional censorship infrastructure.
cs.umd.edu/~dml/papers/iran_…
Geneva discovered the first server-side censorship evasion strategies that work with totally unmodified clients. The server does all the work for the client; this helps people who didn’t even know they were being censored in the first place.
cs.umd.edu/~dml/papers/genev…
This tool, Geneva, trains directly against live censors to discover new sequences of packets that evade censorship without adversely affecting the service the client is trying to reach. Training against real censors, it takes advantage both of design flaws and bugs.
Is your website being censored in Iran? We might be able to help. We have developed an AI-based tool that automatically learned how to evade censorship without requiring clients inside Iran to download any extra software whatsoever 🧵
It appears to be a bit more nuanced with SC retailers. But what’s especially weird to me is that this is an example of the exception that proves the rule: by saying they can’t sell to under-21s 7pm-9am they are implying that they CAN sell to them at the other times of day 🤔
I.. never thought of that. Usually by the time I’m at camera ready stage I’m just thinking about addressing the comments in the reviews, but this.. dang this makes sense.
ALT How Did I Never Think Of It Before Its So Obvious GIF