Live as if today's yesterday was the day after yesterday's tomorrow.

Joined March 2009
54 Photos and videos
David Oswald retweeted
We have a PhD position opening over at the University of Birmingham! If you are interested in embedded systems, low-level hacking, telco security or trusted execution environments, feel free to reach out. Happy to discuss. Current Application deadline: Dec 5th.
11
21
3,117
David Oswald retweeted
This is concerning… being a science superpower takes more than words. I very much hope these “fears” turn out to be unfounded.
BREAKING: Fears budget squeeze may stop UKRI awarding new grants in 2025 - free to read researchprofessionalnews.com…
3
10
41
9,372
David Oswald retweeted
7 Sep 2024
Although it’s forgotten it, Birmingham was once the cycle capital of the world. After all, the modern machine was invented in the West Midlands. My latest piece for @brumdispatch. birminghamdispatch.co.uk/p/b…
2
12
33
3,694
David Oswald retweeted
What’s a #BlackStart? Well it’s NOT an outage, power cut, loss of supply, localised fault, blown fuse, shutdown, trip, fault. It’s a TOTAL shutdown of the power system, with the desynchronisation of all power stations. It’s DEAD 😵 We have NEVER had one. So relax folks ☺️ [1/20]
29
86
336
64,573
David Oswald retweeted
Our paper "SIMurai: Slicing Through the Complexity of SIM Card Security Research" just went public! In this paper, we explore the question: What kind of attacks could a hostile SIM launch against your phone? Surprisingly, a lot.
2
96
257
33,498
David Oswald retweeted
People of Birmingham! On 23rd October I'll be in conversation with @AadVanMoorsel at @unibirmingham asking whether we ought to be worried about AI - tied to my book. Make sure to get your ticket now! birmingham.ac.uk/events/the-…

3
4
725
David Oswald retweeted
Dangerous driving in our area has become a huge safety concern. I've been campaigning on this since 2021 with little progress made due to funding cuts. Pooling resources is vital. I've written to @SimonFosterPCC and @CllrMajid calling for action to improve road safety.
32
33
163
27,495
David Oswald retweeted
We fundamentally don't understand how dogs work inside thus we should be scared of dogs causing an extinction level event in about 5 to 10 yrs. All governments should allocate 10% of their respective budgets to safe guard against an uprising of super-dogs.
10 Jul 2024
Ex-OpenAI safety researcher William Saunders: — We fundamentally don't know how AI works inside — A lot of people in OpenAI think we could be 3 years away from something dangerous — GPT-5 could be the Titanic
17
60
274
30,718
David Oswald retweeted
On the one hand Signal had some bad bugs that are now fixed. On the other hand when a bad guy is running code on your computer, your messenger apps are not going to be able to protect your comms.
TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment: - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app) - I ran the script in the Terminal and got a copy of my Signal data on my Mac - I booted a fresh macOS installation in a virtual machine - I transferred the copy of Signal's data to the VM and placed it where Signal expects it: ~/Library/Application\ Support/Signal - I installed Signal and started it - Signal started and restored my session with all the chat histories 😳 - I exchanged a couple messages with a contact from the VM and it worked 😳 - Then, I started Signal on the Mac - I got three sessions running in unison: Mac, iPhone, and VM 😳 Messages were either delivered to the Mac or to the VM. The iPhone received all messages. All of the three sessions were live and valid. Signal didn't warn me of the existence of the third session [that I cloned]. Moreover, Signal on the iPhone still shows one linked device. This is particularly dangerous because any malicious script can do the same to seize a session. Perhaps this flaw is what makes some users think that Signal has a "backdoor" as it is easy for sophisticated attackers to target a victim who's using the Mac app and see their chats. (The same may be also true for the Windows app) #privacy #security
7
30
149
33,144
David Oswald retweeted
*Must read* for anyone interested in ML security, by Nicholas Carlini. Attacks are the only way we know whether or not a purportedly secure system actually is. Moreover, I consider personal attacks like this unacceptable in my research communities. nicholas.carlini.com/writing…
1
44
269
63,997
David Oswald retweeted
The 1st picture is the latest victim of road violence, Mayar Bahia RIP The 2nd picture is of the scene. The 3rd tells you what you can do. The 4th doesn’t exist yet, but statistically, another person will die due to road violence in B’ham next week. @for_birmingham
10
17
2,889
David Oswald retweeted
Lattice methods still safe ... eprint.iacr.org/2024/555 "Update on April 18: Step 9 of the algorithm contains a bug, which I don’t know how to fix. See Section 3.5.9 (Page 37) for details. I sincerely thank Hongxun Wu and (independently) Thomas Vidick for finding the bug today.
7
21
1,302
David Oswald retweeted
Replying to @crypto_carsten
The author at least seems to think that it's not immediately fatal.
2
1
13
4,649
David Oswald retweeted
This looks serious. Damn serious. Some lattice expert can say something about it? eprint.iacr.org/2024/555

9
39
150
53,005
David Oswald retweeted
Gosh, this sounds terrible. Imagine losing 70% of your customers overnight……. 🤔 Or do we think someone might be being slightly economical with the truth? Let’s dig in! 🧵 1/12
433
2,820
13,047
3,702,168
theguardian.com/uk-news/2024… If you had a license for a shotgun which you used to maim someone YOU WOULD NEVER GET IT BACK! This man will drive again in < 5 years. Where's the justice for his victim, and all who will have to share the roads with him? #SafeStreetsNow #PeaceSpaceJustice
1
11
49
3,012
David Oswald retweeted
WebGPU allows websites to use your GPU for general-purpose computations without asking for permission in the browser. To understand which attack vectors are possible using this interface, see our @ASIACCS2024 paper and try the PoC in your browser.
Our new paper "Generic and Automated Drive-by GPU Cache Attacks from the Browser" has been accepted at @ASIACCS2024! 🎉 We show basic cache attack primitives on NVIDIA&AMD, and more complex attacks on NVIDIA. You can read it and try a tiny POC here ginerlukas.com/gpuattacks/.
2
6
30
5,136
David Oswald retweeted
Interested in low-level hacking, embedded systems, and trusted execution environments? We currently have a PhD opening, feel free to reach out for more information! Application deadline: April 1st 2024.
1
18
24
7,068
David Oswald retweeted
Excited to announce the CFP for #systex24 co-located with @IEEEEUROSP in Vienna. A great place to meet and discuss work (in progress) and ideas on system software attacks/defenses for trusted execution! Submission deadline March 14, 2024. 🧑‍🔬🌍👇 systex24.github.io/
4
8
2,627