Steven Murdoch's Avatar

Steven Murdoch

@steven.murdoch.is

Professor of Security Engineering; Head of UCL Information Security Research Group @sec.cs.ucl.ac.uk; Director Open Rights Group. ๐Ÿ˜ย https://mastodon.social/@sjmurdoch ๐Ÿฆย @sjmurdoch ๐ŸŒย https://murdoch.is/

1,146 Followers  |  219 Following  |  91 Posts  |  Joined: 10.10.2023  |  2.1722

Latest posts by steven.murdoch.is on Bluesky

Actual actual reality: nobody cares about his secrets. (Also, I would be hard-pressed to find that wrench for $5.)

Actual actual reality: nobody cares about his secrets. (Also, I would be hard-pressed to find that wrench for $5.)

โ€œ$5 Wrench Attacks: When Cryptocurrency Crime Get Physicalโ€, a post on Benthamโ€™s Gaze by Marilyne Ordekian discussing when XKCD comics become reality โ€“ www.benthamsgaze.org/2025/07/22/5...

22.07.2025 17:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I am recruiting mental-health experts (clinical psychologists and psychiatrists) for an in-person workshop in London to discuss a mobile app for mental health care. Participants will receive ยฃ500+expenses for their time. If you might be interested please email s.murdoch@ucl.ac.uk

06.06.2025 13:42 โ€” ๐Ÿ‘ 1    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A Privacy Framework for Research Using Social Media Data Social media data enables researchers to understand current events and human behavior with unprecedented ease and scale. Yet, researchers often violate user privacy when they access, process, and stor...

On our new paper published at IEEE Security and Privacy โ€“ โ€œA Privacy Framework for Research Using Social Media Dataโ€, a summary by Kyle Beadle. www.benthamsgaze.org/2025/05/15/a...

15.05.2025 14:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

If it needs to interoperate with Signal I would think it would be easier to modify Signal to include the new audit-friendly protocol than add audit to Signal. A lot of what Signal includes (P2P key verification, PFS, post-compromise security, deniable) are contrary to the goal of universal logging.

05.05.2025 17:26 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

The major selling points of these companies is self-hosting the key management server, and sometimes even more of the infrastructure. This would need to be part of the product offering too.

05.05.2025 13:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I can see the idea but thatโ€™s a hard market to get into. Youโ€™d need a security cleared technical sales team, FIPS certifications, etc. it would be a major departure for the company culture. These companies also often value having ex- military/intelligence staff. I can see conflicts there.

05.05.2025 11:50 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
โ€ŽArmour Mobile โ€ŽArmour Mobile provides secure voice calls, video calls, 1-1 and group messaging, voice and video conference calls, file attachments, message burn and sent/ received/read message status. Protecting bu...

In terms of UX I think thatโ€™s achievable, e.g. the UK app in this space looks pretty much like WhatsApp. For ecosystem, indeed thatโ€™s a problem because government requirements are anti-requirements for pretty much everyone else. apps.apple.com/gb/app/armou...

05.05.2025 11:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Itโ€™s just a bizarre situation. When I was looking into MIKEY-SAKKE I found a whole ecosystem of government messengers with NATO security certifications and clearances. The protocol is (for better or worse) very amenable to centralised logging. And yet they picked a hacked-up Signal.

05.05.2025 09:19 โ€” ๐Ÿ‘ 10    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Scam Checker Service | Nationwide As a mutual, we want to do everything we can to keep our members safe from scammers. Read more about our Scam Checker Service, designed to keep you safe.

Nationwide offers the only service Iโ€™m aware of that backs up their advice with a guarantee. I donโ€™t know how it works but I suspect that if AI is involved, thereโ€™s human verification of decisions. www.nationwide.co.uk/help/fraud-a...

14.04.2025 14:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
13.7.             The AI-generated content and information is provided for general information purposes only and is not intended to constitute or substitute legal or other professional advice of any kind whatsoever. The AI-generated content and information is not intended or implied to be a substitute for professional advice.
13.8.             You are encouraged to confirm any information obtained from or through Silver with other sources and review all information provided. Please do not disregard professional advice or delay seeking advice because of something you have read on our website or in the AI-generated content and information.
13.9.             We make no representations about the suitability, reliability, timeliness, comprehensiveness, and accuracy of the AI-generated content and information, and other content produced by Silver.

13.7. The AI-generated content and information is provided for general information purposes only and is not intended to constitute or substitute legal or other professional advice of any kind whatsoever. The AI-generated content and information is not intended or implied to be a substitute for professional advice. 13.8. You are encouraged to confirm any information obtained from or through Silver with other sources and review all information provided. Please do not disregard professional advice or delay seeking advice because of something you have read on our website or in the AI-generated content and information. 13.9. We make no representations about the suitability, reliability, timeliness, comprehensiveness, and accuracy of the AI-generated content and information, and other content produced by Silver.

AI-based scam checkers are gaining popularity but I would be cautious in following their advice unless the company is willing to stand behind it. For example, Metro Bank makes bold claims but the fine print absolves them of any responsibility for errors. www.metrobankonline.co.uk/ways-to-bank...

14.04.2025 14:04 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I have an open PhD position at @sec.cs.ucl.ac.uk on applying traffic-analysis resistance techniques to protect industrial control systems. Full funding is available for home-fee status students (deadline 15 April). www.ucl.ac.uk/security-cri...

07.04.2025 20:11 โ€” ๐Ÿ‘ 6    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

And Iโ€™d add that Telegramโ€™s janky cryptography doesnโ€™t achieve anything normal encryption canโ€™t provide. Signal uses some interesting constructions but did so to offer better security (and largely succeeded).

30.03.2025 15:48 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

I'd view the consultation as an opportunity to revisit how electronic evidence should be handled, and disclosure is obviously a critical part of that. Flipping the presumption is just a mechanism to impose disclosure requirements on a party that is reluctant to do so.

27.03.2025 10:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

You raise a good point. In my experience, the presumption is rarely explicitly mentioned in disputes. And it's not entirely clear whether PACE s69 would worked out better (the Post Office included PACE s69 statements even when they were not needed).

27.03.2025 10:28 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
Secret London tribunal to hear appeal in Apple vs government battle over encryption | Computer Weekly The decision by home secretary Yvette Cooper to issue a Technical Capability Notice requiring Apple to give UK law enforcement and intelligence services โ€œbackdoorโ€ access to data stored by Appleโ€™s cus...

Whisper it, the showdown over Apple encryption is THIS WEEK โฑ๏ธ

๐Ÿค A secret tribunal will hear the appeal against the governmentโ€™s order to carve a backdoor into Appleโ€™s encrypted services.

๐Ÿ›‘ Our cybersecurity and privacy shouldnโ€™t be decided in the shadows.

www.computerweekly.com/news/3666203...

11.03.2025 16:57 โ€” ๐Ÿ‘ 12    ๐Ÿ” 18    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Container ship SOLONG collision with anchored Oil Tanker STENA IMMACULATE off the UK coast
YouTube video by VesselFinder Container ship SOLONG collision with anchored Oil Tanker STENA IMMACULATE off the UK coast

I found this video showing the tracking information. The Solong was heading directly towards the tanker for hours before the collision. Iโ€™ve no idea what could have caused such a failure. youtu.be/Ex6OpRiuflA?...

11.03.2025 15:17 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Until now, the UK government recommended that individuals at high risk, like legal professionals, enable Apple Advanced Data Protection (ADP). Apple disabled ADP following government pressure, and now the NCSC quietly deleted their guidance recommending ADP.

06.03.2025 16:10 โ€” ๐Ÿ‘ 22    ๐Ÿ” 12    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Thanks, that looks like it. The IPT web page makes no mention of that, but maybe they are focused on what members of the public could bring to them.

04.03.2025 21:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The article refers to the Investigatory Powers Tribunal, but I canโ€™t see any description of how this falls into the type of complaints the IPT handles. Can anyone more qualified work out whatโ€™s actually going on?

04.03.2025 20:29 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I remember hearing similar objections when Signal implemented disappearing messages. Iโ€™m glad the pragmatists won, correctly (IMO) arguing that the feature is to encourage good hygiene rather than enforce security against a malicious communication partner.

02.03.2025 12:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Dear Apple: add โ€œDisappearing Messagesโ€ to iMessage right now This is a cryptography blog and I always feel the need to apologize for any post that isnโ€™t โ€œstraight cryptography.โ€ Iโ€™m actually getting a little tired of apologizing for iโ€ฆ

So hereโ€™s a simple request to Apple. Apple iMessage needs to enable โ€œdisappearing messages.โ€ And they need to do it soon. blog.cryptographyengineering.com/2025/03/01/d...

01.03.2025 17:02 โ€” ๐Ÿ‘ 80    ๐Ÿ” 31    ๐Ÿ’ฌ 4    ๐Ÿ“Œ 2

This could be followed up by a judicial review, for example arguing that there was a violation of human rights. The existence of this would be public knowledge but not necessarily all the evidence presented.

23.02.2025 19:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Investigatory Powers (Amendment) Bill: Strengthening the Notice Review Process

In case you are curious about the legal route, it is described here. It would not necessarily be public, so I canโ€™t say whether it has happened. www.gov.uk/government/p...

23.02.2025 19:13 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Apple pulls data protection tool after UK government security row Customers' photos and documents stored online will no longer be protected by end to end encryption.

๐Ÿšจ APPLE WITHDRAWS ENCRYPTION TECH FROM UK ๐Ÿšจ

The Home Officeโ€™s actions have deprived millions of Britons from accessing a security feature.

UK citizens will be at higher risk of their personal data and family photos falling into the hands of criminals and predators โ€ผ๏ธ

www.bbc.co.uk/news/article...

21.02.2025 16:23 โ€” ๐Ÿ‘ 38    ๐Ÿ” 41    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 5
Preview
Keep our Apple data encrypted It is reported that the Home Office has ordered Apple to build a backdoor into its encrypted services so that they can get hold of content that any Apple user has upload to the cloud. Encryption keeps...

Encryption IS online safety ๐Ÿ’ก

Keeping data secure is key when hackers are skilled at unpicking accounts.

So why does the UK government want to make us unsafe by ordering a backdoor to Apple encrypted services?

โœ๏ธ Sign to save encryption this #SaferInternetDay.

you.38degrees.org.uk/petitions/ke...

11.02.2025 13:22 โ€” ๐Ÿ‘ 13    ๐Ÿ” 10    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
We are looking to appoint to one or more posts in IP/IT Law, as Associate Professor or Lecturer in Law. Applications from colleagues who can also teach in other subject areas, including French Law, are most welcome.

The closing date for applications is 28 February 2025. Interviews will likely take place in the week(s) commencing 05 and 12 May 2025.

About you

Successful candidates will be expected to engage in world leading research, and to contribute to the Facultyโ€™s development and advancement of both intellectual property and information technology law and policy, and other areas of law falling within their subject matter expertise. It is also expected that the post-holders will contribute to all aspects of the academic life of the Faculty and University.

The Faculty has a particular interest in recruiting scholars with research interests in copyright law, platform regulation, enforcement with and through technology, and the intersection of emerging technologies with other IP rights such as designs. UCL Laws faces growing demand for teaching and engagement on IP and IT issues from other parts of the university, as well as in executive education, and we particularly welcome applicants with interest and experience of teaching contested legal topics to technologists, creatives and other non-lawyers.

Reflecting the broad strength of the Faculty, we welcome scholars from a wide array of approaches to these issues โ€” socio-legal, comparative, doctrinal, empirical, historical and/or theoretical and interdisciplinary approaches. Applicants should, however, pay particular attention to how their work illustrates their capacity for depth and rigour in a fast-moving field prone to superficial analysis.

We are looking to appoint to one or more posts in IP/IT Law, as Associate Professor or Lecturer in Law. Applications from colleagues who can also teach in other subject areas, including French Law, are most welcome. The closing date for applications is 28 February 2025. Interviews will likely take place in the week(s) commencing 05 and 12 May 2025. About you Successful candidates will be expected to engage in world leading research, and to contribute to the Facultyโ€™s development and advancement of both intellectual property and information technology law and policy, and other areas of law falling within their subject matter expertise. It is also expected that the post-holders will contribute to all aspects of the academic life of the Faculty and University. The Faculty has a particular interest in recruiting scholars with research interests in copyright law, platform regulation, enforcement with and through technology, and the intersection of emerging technologies with other IP rights such as designs. UCL Laws faces growing demand for teaching and engagement on IP and IT issues from other parts of the university, as well as in executive education, and we particularly welcome applicants with interest and experience of teaching contested legal topics to technologists, creatives and other non-lawyers. Reflecting the broad strength of the Faculty, we welcome scholars from a wide array of approaches to these issues โ€” socio-legal, comparative, doctrinal, empirical, historical and/or theoretical and interdisciplinary approaches. Applicants should, however, pay particular attention to how their work illustrates their capacity for depth and rigour in a fast-moving field prone to superficial analysis.

Now hiring in law & tech @ucllaws.bsky.social!
Lecturer/Assoc Prof in IP & IT law: intersection of platform reg, emerging tech, copyright/designs.

Join me @bernardkeenan.bsky.social Orla Lynskey @alinatrapova.bsky.social Ilanah Fhima, Matt Fisher, Robin Jacob & friends
www.ucl.ac.uk/work-at-ucl/...

10.02.2025 13:25 โ€” ๐Ÿ‘ 26    ๐Ÿ” 24    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 4

That doesnโ€™t seem unreasonable to handle, but as with spell checkers it doesnโ€™t need to be 100% accurate to be useful. There would still be a feature where you could say โ€œacceptโ€ and ignore the supposed error.

05.02.2025 18:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Why is it still possible to write a date where the day of the week doesnโ€™t match the day of the month? This doesnโ€™t need AI; a regular expression would do. I want a big red underline if I ever write โ€œThursday 5 Februaryโ€. Has someone patented this and spoiled it for everyone?

05.02.2025 17:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Cover of Electronic Civil Disobedience and Other Unpopular Ideas by Critical Art Ensemble.

Cover of Electronic Civil Disobedience and Other Unpopular Ideas by Critical Art Ensemble.

Thinking about this classic recently, which is available free here:

monoskop.org/images/d/df/...

04.02.2025 09:19 โ€” ๐Ÿ‘ 359    ๐Ÿ” 92    ๐Ÿ’ฌ 10    ๐Ÿ“Œ 6

We had a good discussion on what might characterise legitimate protest and touched on what the law might say. Despite what politicans sometimes claim, what is illegal in the physical world is illegal online. However the electronic equivalent to legal protest is often illegal, and thatโ€™s a problem.

04.02.2025 13:57 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@steven.murdoch.is is following 20 prominent accounts