Available at https://whynotlog.com and promo code HACKERNEWS gives access to the pro plan for six months.
110 karma · joined October 23, 2013
Available at https://whynotlog.com and promo code HACKERNEWS gives access to the pro plan for six months.
Location: Chicago, IL
Remote: Yes
Willing to relocate: Yes
Technologies: Go, Python, JavaScript, React, PostgreSQL, Docker, k8s
Résumé/CV: https://files.nymity.ch/resume.pdf
Email: identityfunction@gmail.com
I'm a seasoned software engineer and research scientist solving problems in computer networking, privacy, and security.Brave is on a mission to protect the human right to privacy online. We’ve built a free web browser that blocks creepy ads and trackers by default, a private search engine with a truly independent index, a browser-native crypto wallet, and a private ad network (opt-in!) that directly rewards you for your attention. And we’re just getting started. Already 50 million people have switched to Brave for a faster, more private web.
Brave is looking for an experienced security/privacy researcher to join Brave’s research team to develop new ambitious security and privacy research products and work alongside our engineering teams to implement the results of research into our products. This job involves working side-by-side with researchers, research engineers, engineers, and product managers across multiple departments so Brave’s research findings can benefit millions of daily active users around the world. The Researcher will be responsible for a wide range of privacy and security research areas, including privacy-preserving analytics, trusted computing, and detecting and fighting fraud. They should have a passion for helping protect users’ privacy and security.
https://brave.com/careers/?gh_jid=4761953
Feel free to reach out if you have questions. My email address is in my profile.
It's 95% done. Most of the (unedited) content is available for open review: https://nymity.ch/book/
Brave is on a mission to protect the human right to privacy online. We’ve built a free web browser that blocks creepy ads and trackers by default, a private search engine with a truly independent index, a browser-native cryptocurrency wallet, and a private ad network (opt-in!) that directly rewards you for your attention. And we’re just getting started. Already 50 million people have switched to Brave for a faster, more private web.
Brave is looking for a Security Researcher to join Brave’s research team to help with both developing new ambitious research ideas and in transferring advanced research prototypes into Brave products. This job involves working collaboratively with both researchers and developers to design, develop, and implement new systems for preserving user security and privacy. Learn more about the Brave Research team here.
For more information: https://brave.com/careers/?gh_jid=4091909
IEEE is just the publishing organisation and doesn't review research. That's handled by the program committee that each IEEE conference has. These committees consist of several dozen researchers from various institutions that review each paper submission. A typical paper is reviewed by 2-5 people and the idea is that these reviewers can catch ethical problems. As you may expect, there's wide variance in how well this works.
While problematic research still slips through the cracks, the field as a whole is getting more sensitive to ethical issues. Part of the problem is that we don't yet have well-defined processes and expectations for how to deal with these issues. People often expect IRBs to make a judgement call on ethics but many (if not most) IRBs don't have computer scientists that are able to understand the nuances of a given research projects and are therefore ill-equipped to reason about the implications.
All three types are generally referred to as "professor" but they differ in their seniority.
Figure 10 shows that most users (52%) use bookmarks, followed by locally-saved text files (37%), and referral to trusted web pages (35%).
Also, lots of people find themselves unable to determine an onion service's legitimacy (Figure 12), which is why phishing attacks are successful. We document one such attack in Section 5.1 of another research paper: https://nymity.ch/sybilhunting/pdf/sybilhunting-sec16.pdf
We found that several thousand relays that shared prime factors (most part of a research project), ten relays shared moduli, and 122 relays used a non-standard RSA exponent, presumably in an attempt to manipulate the Tor network's distributed hash table, which powers onion services.
Obviously, people can lie in their reverse DNS record but active measurements from distributed vantage points (e.g., by using the RIPE Atlas network) could expose that.
My understanding is that CS publishers tolerate researchers hosting their own papers, but I'm very interested in evidence suggesting otherwise.
Also, onion domains are Base32-encoded, which means that they aren't case sensitive and they don't use the digits 0, 1, 8, and 9.
By "hijacking" we mean that an entity in the network is "borrowing" IP addresses meant for Internet users for ~20 minutes of probing activity. That's not the same as IP spoofing, i.e., simply sending IP packets with a spoofed source address.
I was actually objecting to stuff like this: ExitNodes {us}. By interfering with your path selection algorithm in such a strong way, you make it easier for attackers to narrow down your path over time (which gives them an idea of which exit relays to monitor) and intersection attacks also become easier. Then again, you might have good reasons to do exactly that. It depends on your threat model, of course.
Finally, we published our scanner for a good reason: to crowd-source the hunt for more malicious relays :)