dear peter, welcome back! by the time you read this, i will probably be long gone. we thought you were too once upon a time, but our dear friends managed to get your brain cryogenically-preserved at the last possible hour. it is so amazing that the scientists of my future have figured out how to bring you back, and i wish i were there to hear all about it. was it like being asleep? did they have…
This is a quick blog post about a security vulnerability (now fixed) that allowed me to make anyone like or message a profile on okcupid.com simply by getting them to click a link on my website. In doing so, I used one of the most boring web application security issues (CSRF) combined with a somewhat interesting JSON type confusion. Proof that it worked on a friend who agreed to help me with…
about a year ago, i moved to a hillier neighborhood in San Francisco. my beat-up vintage road bike, a beloved and steadfast companion on thousands of commutes across SoMA, suddenly became way less practical and more importantly, way less fun. as months of quarantine dragged on, i started either taking Lyft rental e-bikes out of sheer laziness or just staying in flat regions (a technique i call…
prologue: on laziness lately i have been doing some lazy baking whilst in quarantine, where lazy is defined as: no need for fancy equipment like stand mixers with dough hooks no need for hard-to-find ingredients like lye NO STARTERS (like the kind you need for making sourdough) less than one hour of work total can be made by someone with minimal baking experience can skip/improvise/fuckup 1-2…
Recently I’ve been really interested in what goes on in Ableton Live under the hood, since it’s a widely-used piece of proprietary software for making bangers. It turns out you can get pretty far knowing just a small amount of Python scripting! For instance, I found that .als files (and .adv’s, and .adg’s, and probably more) are just gzipped XML and so therefore you can do…
My friend Aviv was recently the subject of a popular Buzzfeed article about the possibility of an impending “information apocalypse”. tl;dr: Aviv extrapolates from the fake news crisis that started in 2016 to a world in which anyone can create AI-assisted misinformation campaigns indistinguishable from reality to the average observer. From there, a series of possible dystopian…
1. A perfect game-theoretic analysis machine Imagine that you had a magic machine. You tell the machine what your goals are. The machine tells you, in any situation, the optimal statement to say in order to achieve your goals, and who to say it to. The statement may or may not be true. Under which circumstances, if any, would you follow the machine’s instructions? Example 1: Bob tells the…
[Update (12/14/16): Reuters has specified that the rootkit was implemented as a Linux kernel module. Wow.] Yesterday morning, Reuters dropped a news story revealing that Yahoo installed a backdoor on their own infrastructure in 2015 in compliance with a secret order from either the FBI or the NSA. While we all know that the US government routinely asks tech companies for surveillance help, a…
While migrating my blog from WordPress to Hugo + GitHub Pages, I found two old diary entries from last autumn, a period of life when I rode buses a lot. They are copied below. oct 28, 2015 they told me not to, so i’m taking the bus from downtown LA to LAX. on my right, a man is asking everyone except me for 50 cents. everyone except me is a black guy. the bus stops for the zillionth time and…
The second and last time that I visit Chelsea Manning, we speak and move with a sense of urgency, as if a natural disaster is imminent. By now, the Ft Leavenworth prison visit procedure feels strangely familiar, like a movie you once watched in a dream. I check in with the uniformed officer at the Disciplinary Barracks front desk, wait uselessly while he misgenders Chelsea and figures out if I’m…
On the day that I am scheduled to see my friend Chelsea for the first time in six years, I wake up at 4:51pm to a shrieking fire alarm in my hotel room. Semi-conscious and disoriented, I leap out of bed and spin around wildly grabbing at all the things I care about my phone and passport, the precious slip of paper that will allow me entrance to Fort Leavenworth prison, the bag of quarters that…
i turn 25 in an hour. this seems strange and unbelievable. surely 25 years of existence is enough to become acquainted with the monotonicity of time. but instead the seconds pass and disbelief stares back, unmoving. a quarter-century is a long time. with sadness, i realize how much of it i have forgotten already. imagine that we could live forever. would we still talk about wasting time if time…
Dear Chelsea, You probably don’t remember me, but we met in September 2009. This was before everyone knew your name and before many people knew mine. I was at home, helping my friend cut her hair. Out of the corner of my eye, I saw you walk into the living room. You were taking photos of our mural-covered walls, seemingly happy to be in such a bizarre and interesting house of MIT students. Someone…
Every so often, I get sick of basically everything. Walls become suffocating, routine is insufferable, and the city I live in wraps itself against the sky like a cage. So inevitably I duck away and find something to chase (warm faces, the light in autumn, half-formed schemes, etc.), run until I’m dizzy and lost and can’t remember whose couch I’m waking up on or why I crashed there. Weeks later,…
you know things are getting better when you walk away from the hotel where you just gave two presentations wearing your best pretense of holding-it-togetherness while inside you felt shakey, hungover, and insane. remember how long you stood there, smiling and rationing weak handshakes while pretending you believed that you had a future? promise yourself you’re never doing that again. you walk away…
In addition to unforgettable life experiences and personal growth, one thing I got out of DEF CON 23 was a copy of POC||GTFO 0x08 from Travis Goodspeed. The coolest article I’ve read so far in it is “Deniable Backdoors Using Compiler Bugs,” in which the authors abused a pre-existing bug in CLANG to create a backdoored version of sudo that allowed any user to gain root access. This is very sneaky,…
FYI: this post is an artifact of the Dark Ages when my blog was self-hosted WordPress. Let us not speak of that time. Having recently given some talks about Content Security Policy (CSP), I decided just now to enable it on my own blog to prevent cross-site scripting. This lil’ blog is hosted by the MIT Student Information Processing Board and runs on a fairly-uncustomized WordPress 4.x…
Greetings from the beautiful museum district of Berlin, where I’ve been trapped in a small conference room all week for the quarterly meeting of the W3C Technical Architecture group. So far we’ve produced two documents this week that I think are pretty good: no encryption backdoors no non-consensual web tracking I just realized I have a few more things to say about the latter, based on my…
The combination of my roommate starting a Rust podcast and a long, animated conversation with a (drunk) storyteller last night caused me to become suddenly enamored with the idea of starting my own lil’ podcast. Lately I keep thinking about how many spontaneous, insightful conversations are never remembered, much less entombed in a publicly-accessible server for posterity. So a podcast seemed like…
i’ve finally recovered enough from a multi-week bout of sickness to say some things and put up some photos. lately i’ve felt exhausted and lethargic and unproductive to be honest. being sick probably had something to do with it; i sure hope next week gets better. yesterday, someone told me they had a theory that everyone who sleeps at night (with rare exceptions) can only manage ~3 significant…
Yesterday TechCrunch reported that Twitter now seems to be requiring SMS validation from new accounts registered over Tor. Though this might be effective for rate-limiting registration of abusive/spammy accounts, sometimes actual people use Twitter over Tor because anonymity is a prerequisite to free speech and circumventing information barriers imposed by oppressive governments. These users might…
that could have been us , 2015 Oil pastels, lipstick, eyeliner, cold medicine, and ballpoint pen on canvas. i painted this while standing in my bathroom on valentine’s day’s night, unable to sleep and grotesquely feeling the weight of the oncoming dawn. it was my first time drawing on canvas. as i worked, i kept thinking about all these people passing to and from doomed relationships, that feeling…
I remember quite clearly sitting in Scott Aaronson’s computability and complexity theory course at MIT in 2011. I was a 19 year-old physics major back then, so Scott’s class was mostly new and fascinating. One spring day, Scott was at the chalkboard delightedly introducing the concept of time complexity classes to us, with the same delight he used when introducing most abstract constructs. He said…
Yesterday the W3C Technical Architecture Group published a new finding titled, “ The Web and Encryption .” In it, they conclude: “. . . the Web platform should be designed to actively prefer secure origins — typically, by encouraging use of HTTPS URLs instead of HTTP ones. Furthermore, the end-to-end nature of TLS encryption must not be compromised on the Web, in order to preserve this trust.” To…
Yesterday, Prof. Matthew Green wrote a nice blog post about why PGP must die. Ignoring the UX design problem for now, his four main points were: (1) the keys themselves are too unwieldy, (2) key management is hard, (3) the protocol lacks forward secrecy, and (4) the crypto is archaic/non-sane by default. Happily, (1) and (4) can be solved straightforwardly using more modern crypto primitives like…
4 years ago, I went to HOPE for the first time on a last-minute press pass from my college newspaper . Some relevant facts about the trip: I was 19 and had never been to a hacker con before. I didn’t identify as a hacker (or an activist). I was too shy to talk to anyone the entire time. Combined with the fact that I knew only a few people there, I was mostly off by myself. HOPE that year was the…
Say that you want to “securely” acquire an app called EncryptedYo for “securely” communicating with your friends. You go to the developer’s web site, which is HTTPS-only, and download a binary executable. Done! Perhaps if you’re paranoid, you fetch the developer’s GPG key, make sure that there’s a valid trust path to it from your own key, verify the detached signature that they’ve posted for the…
This was my favorite part of my interview with The Setup: What would be your dream setup? Let’s start with the easy ones. I would like (1) an e-book reader that has the portability and battery life of a Kindle, runs free software out-of-the-box, and doesn’t support DRM; (2) an open-source maps application for Android /CyanogenMod that can provide biking and public transit directions for any city…
Every week, answer “yes” to one question that you would instinctively say no to. Don’t spend money or sleep in a real bed for as long as possible. Buy a pound of the ugliest paint that you can find. Keep a journal of thoughts you avoid. Block port 80 for a day. Be kind at random.
Hi there. Have a funny picture: Today, I was briefly worried by the observation that mainstream media takes 24-36 hours to start freaking out about over half of web encryption being fundamentally broken , compared to 2-3 hours for an XSS bug in a Twitter client that causes self-retweeting tweets and unexpected rickrolls and such. Then I remembered that most Americans watch TV for like 4+ hours per…
It’s always unnerving to realize that your happiness is highly correlated with some particular event, object, person, substance, or thought pattern. Various components of pop culture have led us to believe that happiness is {a warm gun | two kinds of ice cream | high serotonin levels | coca-cola} and so forth, but nobody ever says that happiness is a volatile multidimensional product of…
Update (5/28/14): Regrettably, most of the stories covering this blog post have been all “OMG EVERYTHING IS BROKEN” rather than “Here’s how to make things better til WordPress rolls out a fix” (which I humbly believe will take a while to *fully* fix, given that their SSL support is so patchy). So, given that most people reading this are probably coming from one of those articles, I think it’s…
Mashable just put out a nice-looking chart showing “ Passwords You Need to Change Right Now ” change in light of the recent Heartbleed carnage. However, it has some serious caveats that I wanted to mention: It’s probably better to be suspicious of companies whose statements are in present-tense (ex: “We have multiple protections” or even “We were not using OpenSSL”). The vulnerability existed…
The other day, I overheard Seth Schoen ask the question, “What is the smallest change you can make to a piece of software to create a serious vulnerability?” We agreed that one bit is generally sufficient ; for instance, in x86 assembly, the operations JL and JLE (corresponding to “jump if less than” and “jump if less than or equal to”) differ by one bit, and the difference between the two could…
In the year 2014, a startup in San Francisco builds an iPhone app that successfully cures people of heartbreak, but it requires access to every permission allowed on the operating system, including some that no app has ever requested before. It only costs $2.99 though. The app becomes hugely popular. The heartbroken protagonist of our story logs into the Apple iStore to download it, but because…
On the plane ride from Baltimore to SFO, I started thinking about a naming dilemma described by Zooko . Namely (pun intended): it’s difficult to architect name assignment systems that are simultaneously secure, decentralized, and human meaningful. Wikipedia defines these properties as: Secure : The quality that there is one, unique and specific entity to which the name maps. For instance, domain…
My co-worker Peter and I were riding the Caltrain from Mozilla to San Francisco a few days ago. A stranger sat down next to us and started talking. When I mentioned that we worked at EFF, his eyes lit up and he said, “Oh! But you guys have won, right?” Confused, I asked what he meant by that. He said, “You defeated SOPA and PIPA a couple years ago. So you’ve won.” We laughed and explained that it…
I lost four friends and relatives of friends to suicide this past year. I’d prefer it if 2014 were different, and I’ve been trying to think about how to make that happen. The least I could do is offer myself to anyone who feels alone otherwise: so, if you’re at that point where you’re thinking about hurting yourself, please please please call or write to me. I’d really like that, even if you don’t…
Was great. Lots of tea and monitors. Then I went home and cooked a surprisingly-phenomenal dinner with my housemates, the first time I’ve cooked in this house. Rhodey made potatoes with oranges, Mark contributed some wild rice, and I spun up yellow lentil daal with kale. We sang some Neutral Milk Hotel songs afterward, and the future looked bright.
One year ago, I started writing again out of panic. Humans are very adept at forgetting the feeling of panic, so the act of crystallizing it in sentences can be cathartic if you write slowly enough. Last November was a weird and difficult time for me. I remember spending the night of the twenty-third in a friend’s childhood bedroom overlooking the idyllic frost-laced meadows of suburban…
**Disclaimer** : This post was published before I started working at EFF, hence some stylistic mistakes (calling it “the EFF” rather than just “EFF”) are excusable and left uncorrected. 🙂 Two days ago, the EFF published a report tiled, “ Encrypt the Web Report: Who’s Doing What .” The report included a chart that rated several large web companies on how well they were protecting user privacy via…
The following is a phenomenal story for illustrating how real-life cybersecurity disasters come from a combination of technical and social failures. In this case, both were necessary for making things as catastrophic as they were. A couple days ago, it was announced that 130 million Adobe account credentials were compromised by a cyberattack. (If you are an Adobe customer, please make sure you’ve…
This is a post about fear. It’s easy to write about things that everyone says they are afraid of, but less so about nightmares that you suspect might just be your own. The latter is much more distressing and also easier to push out of the way. I’ll try to elaborate on something that has been in the back of my mind. Last night, I went to a talk by my friend Andy titled, “ Cypherpunks 2.0 .” Andy…
Tonight I found a collection of stupendously precocious (lolol) poems I wrote on a trip to Memphis at age 13. Here they are, untouched, in all their prematurely cynical glory: I’m going to Hell I mean Memphis, in two hours Do not raid my house. If I don’t return Do not mope like Charlie Brown You’re not in my will. I gave my pet bird To some short college student With lots of birdseed. My root…
I wrote a Firefox addon one afternoon in France called TabStash. It’s quite simple: you click a button to close all your tabs except the current one. You click it again to open all of them. (Chrome has a popular extension called OneTab that does this, but at the time there wasn’t a Firefox version.) A couple nights ago, I finally got around to sending it to the Mozilla addon store. It came out…
I flew back to MIT recently for the GNU 30th Anniversary Celebration and Hackathon, thanks to a generous travel scholarship from the Free Software Foundation. All I had to do was never, ever run any proprietary javascript in my browser and something something something about firstborns. Seemed like a net win. The hackathon itself was fun. I spent most of it teaching people about privacy-enhancing…
Below is an amalgamation of some posts that I made recently on a popular microblogging platform: ======== I’ve been reading a lot today about what I believe is a super-likely NSA backdoor into modern cryptosystems. There are these things called elliptic curves that are getting used more and more for key generation in cryptography, especially in forward-secrecy-enabled SSL (which is the…
Working on HTTPS Everywhere, an open source project with dozens of contributors, has sharpened my git vocabulary immensely. I figured I’d list a few lesser-known commands that I like: git log _ -pretty=oneline -n –abbrev-commit -G _: This shows the latest commits in oneline format with shortened commit hashes that added or removed lines matching . The git pickaxe options (-S, -G) are super useful…
Quick update to mention that a new version of the browser extension I’ve been helping with this summer has just been released! This release was spurred by the impending arrival of Firefox 23, which notably has Mixed Active Content Blocking enabled by default . In summary, this means that scripts loaded via HTTP on an otherwise-HTTPS site will be blocked automatically for security reasons. Although…