conorgil Profile Banner
Black Lives Matter Profile
Black Lives Matter

@conorgil

Followers
970
Following
11K
Media
209
Statuses
5K

he/him. Usable security & privacy engineer🤓 Podcast host🎙Co-creator https://t.co/QA7rVh6azR💡CS PhD student @Berkeley_EECS👨‍🎓Formerly @virtruprivacy 📧

Berkeley, CA
Joined April 2009
Don't wanna be here? Send us removal request.
@conorgil
Black Lives Matter
3 years
Backup options in many Android #TOTP #2FA apps share personal info w/ 3rd parties, have serious crypto flaws, and/or allow app devs to access TOTP secrets 😱 A 🧵 on our @USENIXSecurity '23 📜 "Security and Privacy Failures in Popular 2FA Apps" https://t.co/KehOVknjut #infosec
Tweet card summary image
github.com
Security and Privacy Failures in Popular 2FA Apps. Contribute to blues-lab/totp-app-analysis-public development by creating an account on GitHub.
1
14
22
@yixinzouu
Yixin Zou
1 year
Come join us!
@chritcu
Catalin Hritcu
1 year
The Max Planck Institutes in Computer Science invite applications for tenure-track faculty by Dec 1, 2024. We are considering all areas of CS, including security and privacy, and expect to fill several positions:
0
3
19
@cocoweixu
Wei Xu
2 years
I am recruiting 1~3 PhD students in CS or ML to join NLP X lab at Georgia Tech. Topics include but not limited to: (1) multilingual multimodal LLM (2) RLHF, text generation models (3) NLP+X (X = privacy, science, etc) Apply by Dec 15: https://t.co/ae62WD6BSj (📷Colin Gough)
10
81
405
@securing_bits
Securing Bits
2 years
Are you implementing 2FA for your mobile or web app? You need to understand the privacy and security risks associated with various 2FA apps. Today's comic is inspired by a recent paper written by @conorgil, Fuzail Shakir, @Noura_7N, and @v0max. 🧵[1/8] #privacy #cybersecurity
1
4
10
@DistributedDave
Dave Levin
3 years
Police auction off many of the items they come into possession of. This includes cellphones. In a study led by @stack__trace we asked: are police wiping phones before they sell them? @briankrebs wrote about our study. In this 🧵, I'll give some highlights.
Tweet card summary image
krebsonsecurity.com
Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without first having the data on them erased, a practice that can lead to...
1
16
40
@engineering_bae
Taylor Poindexter
3 years
I went to book a hotel thru Amex’s travel site to get the extra points and perks, but I noticed the price I’d pay through them was significantly higher than booking thru the hotel directly. To the point that the Amex points were pointless. Has anyone else experienced this?
101
18
578
@jamestalarico
James Talarico
3 years
Texas Republicans are trying to force public schools to display the Ten Commandments in every classroom. I told the bill author: “This bill is not only un-constitutional and un-American, it’s deeply un-Christian.” #txlege
2K
10K
41K
@jhalderm
J. Alex Halderman
3 years
Big news from Chrome Security Team! With HTTPS encryption now nearly ubiquitous, they're finally killing off the browser🔒icon, which tends to give users a false sense of security about other threats. https://t.co/oU5jQulwjb A huge milestone for web security. h/t @davidcadrian
Tweet card summary image
blog.chromium.org
Editor’s note: based on industry research (from Chrome and others), and the ubiquity of HTTPS, we will be replacing the lock icon in Chrome’...
3
31
77
@KhoaVuUmn
Khoa Vu
3 years
"You can do this in R, and R is free!" R: https://t.co/1gXfMU52xn
145
994
8K
@mysk_co
Mysk 🇨🇦🇩🇪
3 years
Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on. The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
101
1K
3K
@christiaanbrand
Christiaan Brand
3 years
Good things come to those who wait. New and improved @Google Authenticator. (Feels like an appropriate start to @RSAConference week). https://t.co/AaBqP3B2Gh
39
56
296
@arianaelena97
Ariana Elena Castillo
3 years
When your institution has a >$50B endowment and accepts an unrestricted $500 million but can’t pay their grad student workers and employees wages that align with cost of living and inflation 💖
4
13
155
@ChrisMurphyCT
Chris Murphy 🟧
3 years
If guns made us safer, America would be the safest place in the world. But the opposite is true. Nowhere else do students, concertgoers and bank patrons get slaughtered on a daily basis. Because as it turns out, it's all the guns that make us so unsafe.
6K
4K
18K
@pklosti
Philip Klostermeyer
3 years
Happy to be part of the @SOUPSConference poster session - You can submit until May 25, 2023 🙂 https://t.co/UVTQSr78lg #UsableSecurity #soups2023
0
3
6
@mysk_co
Mysk 🇨🇦🇩🇪
3 years
As @PrivacyMatters speculated, Authy sends too much analytics for an authenticator app. It associates analytics with the user's ID, which is tied to phone number and email. The analytics include the issuer name of each scanned QR code. Try to use a different #2FA app. #Privacy
22
53
238
@jenheemstra
Jen Heemstra
3 years
Being a good researcher does not necessarily make you a good leader.
@MrJoeMilliano
Joe Milliano
3 years
Which of your STEM education related opinions would get you in this position?
16
105
1K
@NevarezBrewster
Melissa Nevarez-Brewster (she/her/ella)
3 years
The room was filled, but not by quantity but by quality 🥹 to the one person who I didn't recognize and stayed for the whole thing and asked a question and kept nodding and smiling during my presentation, you made it all worth it - thank you so much! ♥️ #SRCD2023
75
155
6K
@traecrowder
Trae Crowder
3 years
ON TENNESSEE BANNING DRAG SHOWS
979
6K
20K
@academic_exit
Academic Exit
3 years
I don't know who needs to hear this, but if you're in a toxic workplace, it's ok for you to leave. You have the strength to heal from the damage done by this workplace & find something new. Commenters, back me up: raise your hand if you have walked away from a toxic workplace.
61
47
646