Nadim Kobeissi

1.8K Followers
265 Following
508 Posts
Cryptography, security & privacy, puzzle games, and running! tfr
Websitehttps://nadim.computer
Companyhttps://symbolic.software
Podcasthttps://cryptography.fm

The Belgian presidency has drafted yet another tweaked #chatcontrol proposal. In summary, the proposal remains completely unacceptable.

TLDR: All the problems pointed our in our earlier open letters are still there
https://nce.mpi-sp.org/index.php/s/eqjiKaAw9yYQF87
https://docs.google.com/document/d/13Aeex72MtFBjKhExRTooVMWN9TC-pbH-5LEaAbMF91Y/

a) the risk of abuse of the solution for other applications (including political purposes)
b) the huge number of false positives (no waiting for 2 alerts does not work)
c) the fact that the real targets will use other technologies (e.g. sharing links to encrypted files).
d) chilling effect on teenagers.

Summary of latest proposal:
1) Detection of known CSAM and of new CSAM using AI (2 hits before you are reported) remain fully unacceptable because it just does not work for technical reasons pointed out earlier.
2) Grooming detection in text and audio is abandoned; information is pseudonymized before it is reported (presumably identity of the user is known)
3) User has to give consent before the client side scanning; details are not known but it is unclear what happens if consent is not given – is the message not sent? Why do policy makes believe that popups solve problems (cookies anyone)?

Source (in German):
https://netzpolitik.org/2024/internes-protokoll-belgien-will-nutzer-verpflichten-chatkontrolle-zuzustimmen/

Open Letter CSA v2.pdf

Nextcloud - a safe home for all your data

Nextcloud

We've got this cheap egg cooker that plays the loudest, most terrifying alarm you've ever heard when it's done cooking. My wife requested that I make it "less aggressive" so I hacked it into the most gentle egg cooker of ALL TIME

(warning: probably loud)

Yesterday, I predicted that the unwarranted outcry by certain privacy experts towards Google's new local LLM that scans calls for scams would result in misleading press articles. Today, we have one such press article over at TechCrunch.

I wrote a critique of it here: https://nadim.computer/posts/2024-05-16-googlellm.html

Critique of the TechCrunch Article on Google's Call-Scanning AI

Yesterday, I predicted that the unwarranted outcry by certain privacy experts towards Google's new local LLM that scans calls for scams would result in misleading press articles. Today, we have one such press article over at TechCrunch.

Nadim Kobeissi

Announcing the Real World Cryptography Paris meetups!

➡️First meetup: June 12!

➡️Call for talks deadline: June 3!

Our goal is to bring together enthusiasts, professionals, and academics to discuss the latest advancements in cryptography. Whether you're an experienced cryptographer, a software engineer, or someone with a keen interest in the field, our meetups offer a platform to learn, share, and network.

Register and submit your talks!!! https://cryptography.paris

Real World Cryptography Paris (RWC Paris) Meetups

RWC Paris aims to bring together enthusiasts, professionals, and academics to discuss the latest advancements in cryptography. Whether you're an experienced cryptographer, a software engineer, or someone with a keen interest in the field, our meetups offer a platform to learn, share, and network.

Why would Apple's brand be at risk? Their products are manufactured in China, chips designed in Israel. They keep breaking laws and bullying their partners, tell us that developers leech off their success. They monopolize the market, nanny their users. They kicked the leading game engine developer off their platforms over a dispute over an (illegal) clause in their contracts. Their prices keep going up in a cost of living crisis. And they tell us it's for our own good.

I see no problems here? 😜

Throwaway idea for a novel #CSRF defence: use an encrypted session cookie, but with a random key that then becomes the anti-csrf token. Now you are guaranteed that the session cookie cannot be used without the csrf token.

Stack Overflow joins Twitter and Reddit in demonstrating control-freak contempt for the people who made the platform what it is.

https://www.tomshardware.com/tech-industry/artificial-intelligence/stack-overflow-bans-users-en-masse-for-rebelling-against-openai-partnership-users-banned-for-deleting-answers-to-prevent-them-being-used-to-train-chatgpt

The company will probably get away with it, because people seem unable to fight back in effective ways, at least in numbers that make a difference.

Stack Overflow bans users en masse for rebelling against OpenAI partnership — users banned for deleting answers to prevent them being used to train ChatGPT

Stack Overflow is overflowing with salt.

Tom's Hardware
In Seattle!

So there's a lot of kvetching, from myself included, about how the modern internet has gotten worse, usually due to a combination of SEO, social media gone evil, and the prevalence of money as more and more of a guiding factor in tech.

But of course the old internet had the problem of being fairly boring. The interesting question is how to get a third way. I've heard a few proposals:

This may sound cheesy but the broadway play Wicked is so good that I didn’t even think theatre could be this good