RSSAmplifier

Blog

Mildly-Aggrieved (not mad!) Scientist

Recent content on Mildly-Aggrieved (not mad!) Scientist

stuartschechter.orgRSS feed ↗13 posts

Latest posts

Difficult Truths for our Harsh Times — Have security & privacy research, and the students we have trained, actually made the world a better place?

Not everyone will miss Ross Anderson. Ross was not afraid to speak truths that made people uncomfortable. His ideas and arguments threatened the beliefs, status, power, ego, and bank balances of others — often those with power. His writings and talks undermined proponents of hardware attestation, chip-and-pin authentication, and surveillance, to name just a few. Many of those threatened by what…

How some of the world's most brilliant computer scientists got password policies so wrong

The US government’s latest recommendations acknowledge that password composition and reset rules are not just annoying, but counterproductive. The story of why password rules were recommended and enforced without scientific evidence since their invention in 1979 is a story of brilliant people, at the very top of their field, whose well-intentioned recommendations led to decades of ignorance.…

Name Tags & Gender-Inclusive Events

Getting people’s pronouns right is a struggle when attending large events, even when those running and attending the events care about gender inclusivity. When I watch others struggle with pronouns at these events, it’s both a relief that I’m not alone and a disappointment that we are all so bad at this. Even in 2023, most events I attend don’t even have pronouns on name…

Introducing Embed-a-Toot

Mastodon’s current option for embedding posts (“toots”) on other websites is inefficient, inflexible, and insecure.1 It embeds posts via an iframe element which loads over a megabyte of content and scripts from the Mastodon server. That iframe gives those scripts full control over your webpage.2 You, the embedder, get no control over how the content is rendered on your page.…

The Safety Tips Dating Apps Omit

Before creating that dating profile… Consider that you might be travel outed (or trouted) The makers of dating apps mostly present ‘safety’ as a matter of managing the risks of interacting with matches online and in person, and not the risks of trusting an app to facilitate this process. Whether it’s safety guidance of Tinder 📄, Bumble 📄, Hinge 📄, Grindr 📄, or Feeld, the…

How You Can Help Fix Peer Review

Reviewing other’s work for the purpose of scoring it does not advance science. Scoring work does not help authors improve it. Scoring does not help a work’s audience understand the work, identify its limitations, or evaluate its credibility. Scoring does, however, undermine our objectivity as peer reviewers because scoring activates our biases. We are predisposed to like works that are…

Introducing Fediverse-Comments

I’ve started self-hosting all my blog posts to wean myself away from commercial platforms. I wanted to support discussion, but didn’t want all the code infrastructure to support them. My blog is a static website. I wanted to keep it simple. But, I did want people reading my blog to feel invited to discuss articles and to see others’ discussing them. What I realized I really…

Collecting Commissions Corrupts Product Coverage

Would you try a new medication recommended in an article titled ‘Why You Need an Antidepressant’ that earns its publisher a commission each time someone clicks on a link to purchase the recommended product? I’d hope not. Yet, much of the news media openly collects commissions for recommending less-regulated products with surprising potential hazards. Consider password managers. The New York…

Before You Use a Password Manager

I cringe when I hear self-proclaimed experts implore everyone to “use a password manager for all your passwords” and “turn on two-factor authentication for every site that offers it.” As most of us who perform user research in security quickly learn, advice that may protect one individual may harm another. Each person uses technology differently, has a unique set of skills, and faces different…

Before You Turn On Two-Factor Authentication…

Many online accounts allow you to supplement your password with a second form of identification, which can prevent some prevalent attacks. The second factors you can use to identify yourself include authenticator apps on your phone, which generate codes that change every 30 seconds, and security keys, small pieces of hardware similar in size and shape to USB drives. Since innovations that can…

Creating a Research Ethics Policy for your Conference or Journal

Conference and journals have a unique opportunity to influence research ethics, as researchers’ careers depend on their ability to understand and meet the requirements for having their research accepted for publication. In the past few years, a number of Computer Science conferences have added research ethics policies to their calls for papers. Good reasons for creating such a policy may include…

On transparency in peer review

Publicity is justly commended as a remedy for social and industrial diseases. Sunlight is said to be the best of disinfectants; electric light the most efficient policeman. Louis D. Brandeis, United States Supreme Court Associate Justice from 1916 to 1939, in “Other People’s Money and How the Bankers Use It” (1914), Chapter 5 Two years ago I started a personal experiment in transparency; I began…

Papers

A record of my academic addiction and occasional relapses David Ng, Jacky Ho, Christian Hercules, Cristian Bravo-Lillo, and Stuart Schechter. Do Password Managers Improve Password Hygiene?, Harvard University Tech Report, 2022 Stuart Schechter and Cormac Herley, The Binomial Ladder Frequency Filter and its Application to Shared Secrets., 2018 Yuan Tian, Cormac Herley, and Stuart Schechter, Using…