A number of countries are currently trying to pass laws that will coerce development teams to destroy the security of their systems and build in backdoors. This is a terrible idea, so here are a few ways that we may be able to design around it.
What if we could build secure systems that didn't depend on central servers or even Internet access to let people collaborate? What would a system like this mean for political organizing, disaster relief, or even civic infrastructure? The Briar app and the Bramble framework are an attempt to find out. Briar has been in the works for a number of years now, but we haven't properly explained our…
The 21st century will be defined by sociotechnical infrastructural systems, and our toolkit for understanding them is incomplete. In this piece, I lay the foundations for what I see as one of the big missing parts of that toolkit the tools we need to diagnose and embody affect and social scripts. Long-time readers will be unsurprised to hear that I think Nordic larp has some of the answers. This…
Building secure software is hard, especially if you don't know where to start. This is the final part of my four-part Patreon-supported series intended to provide an overview of the process of secure application development. It won't tell you how to do the work, but it should leave you with a good understanding of how the pieces fit together so you know what you need to learn. While I've had NGOs…
Building secure software is hard, especially if you don't know where to start. This is the third part of my four-part Patreon-supported series intended to provide an overview of the process of secure application development. It won't tell you how to do the work, but it should leave you with a good understanding of how the pieces fit together so you know what you need to learn. While I've had NGOs…
Building secure software is hard, especially if you don't know where to start. This is the second part of my four-part Patreon-supported series intended to provide an overview of the process of secure application development. It won't tell you how to do the work, but it should leave you with a good understanding of how the pieces fit together so you know what you need to learn. While I've had NGOs…
Building secure software is hard, especially if you don't know where to start. This is the first part of a four-part Patreon-supported series intended to provide an overview of the process of secure application development. It won't tell you how to do the work, but it should leave you with a good understanding of how the pieces fit together so you know what you need to learn. While I've had NGOs…
We have enough secure messaging tools (kind of), but we need so much else. This is my first Patreon-supported essay, which went out a week early to my $10 and up subscribers. In it, I talk about the gaps I've seen in tools intended to support high-risk users and what solutions to fill them might look like. I also outline the set of properties that I think new secure messaging tools should support.…
What kinds of stories do the lives of high-risk users actually tell? One of the most difficult things for a security engineer or a designer to understand is the life of someone living under very different circumstances, and high-risk, specifically targeted users (whether targeted by a big adversary or a small one) often have needs that are both the hardest and most critical to understand. I'm…
There is significant confusion as to the reach of the Wassenaar Arrangement. This was written just after the 2014 language became publicly discussed to try to explain what it actually covered and why.
I gave a talk on surveillance, ethics, economics, the balance of power, and our responses to all this at OHM (Observe Hack Make), the 2013 Dutch Hacker camp. A number of political issues came up during the run-up to the camp around several of the sponsors who sold or supported government surveillance, and also around the responses of the organizing committee to public censure there. Originally, my…