Episodes

10 total
Sep 23, 2024Blog » The magic of software; or, what makes a good engineer also makes a good engineering organizationThe people who create software generally refer to themselves as software engineers, and yet if they graduate from university, it is typically with a degree in computer science. That has always felt a little strange to me, because science and engineering are two pretty different disciplines – yet we for the most part seem to take such an obvious contradiction for granted. However, I think there is something uniquely magical about software, and part of that magic might stem from this tension in how we define it.17:18Nov 13, 2023Blog » California’s biggest flexI think the crummy shape of California’s symbols is the clearest sign of its strength. This may seem like a contradiction, but over time I’ve come to think of it as the greatest possible flex.05:39Jan 7, 2022Blog » My first impressions of web3Despite considering myself a cryptographer, I have not found myself particularly drawn to “crypto.” I don’t think I’ve ever actually said the words “get off my lawn,” but I’m much more likely to click on Pepperidge Farm Remembers flavored memes about how “crypto” used to mean “cryptography” than I am the latest NFT drop.24:18Feb 24, 2015Blog » GPG And MeI receive a fair amount of email from strangers. My email address is public, which doesn’t seem to be a popular choice these days, but I’ve received enough inspiring correspondence over the years to leave it be.05:08Jun 12, 2013Blog » We Should All Have Something To HideSuddenly, it feels like 2000 again. Back then, surveillance programs like Carnivore, Echelon, and Total Information Awareness helped spark a surge in electronic privacy awareness. Now a decade later, the recent discovery of programs like PRISM, Boundless Informant, and FISA orders are catalyzing renewed concern.09:59May 13, 2013Blog » A Saudi Arabia Telecom’s Surveillance PitchLast week I was contacted by an agent of Mobily, one of two telecoms operating in Saudi Arabia, about a surveillance project that they’re working on in that country. Having published two reasonably popular MITM tools, it’s not uncommon for me to get emails requesting that I help people with their interception projects. I typically don’t respond, but this one (an email titled “Solution for monitoring encrypted data on telecom”) caught my eye.09:37Jan 7, 2013Blog » Career AdviceTo my great surprise, young people now somewhat frequently contact me in order to solicit career advice. They are usually in college or highschool, and want to know what the best next steps are for a career in security or software development.11:22Nov 27, 2012Blog » The WorstI don’t really know who Dustin Curtis is, but he blogs a lot, and those blog entries often end up on Hacker News. Not too long ago, he wrote a blog post titled “The Best,” in which he explains that he has nice stuff. That in fact, everything he owns is actually the very best of its kind.07:39Dec 13, 2011Blog » The Cryptographic Doom PrincipleWhen it comes to designing secure protocols, I have a principle that goes like this: if you have to perform any cryptographic operation before verifying the MAC on a message you’ve received, it will somehow inevitably lead to doom.06:56Dec 5, 2011Blog » Your app shouldn’t suffer SSL’s problemsIn recent months, Comodo has been hacked repeatedly, DigiNotar was compromised, and the security of CAs as a whole has been found to be not altogether inspiring. The consensus finally seems to be shifting from the notion that CAs are merely a ripoff, to the notion that they are a ripoff, a security problem, and that we want them dead as immediately as possible. The only question that remains is how to replace them.08:30