Posts

Summary of My Past Research

Image
When doing reappointment and promotion packages for faculty, you're expected to submit a summary of your research and accomplishments. Since I'm a full professor, I'm not required to do this anymore, but I thought it would still be a useful exercise, partly to help me reflect on my work but also to share with the world what I felt were some of my key accomplishments. So here are some highlights of my research and teaching over the past twenty years. ____________________ Pioneered research on protecting people from phishing scams . This research combined ideas from machine learning, decision sciences, learning science, and game design, and greatly expanded the field of usable privacy and security in its early days. The browser warnings in Microsoft Internet Explorer 8 were re-designed based on our research, and key ideas from our work are still present in all web browser warnings today. Our work detecting phishing web pages is one of the earliest and perhaps most cited pap...

Questions for Privacy Risk Modeling

In 2004, my colleagues and I published a paper called  Privacy risk models for designing privacy-sensitive ubiquitous computing systems . This paper posed a series of questions about user interface design, system design, and organizational issues that one should consider with respect to privacy when designing new ubicomp systems. In a recently published chapter in the book  Mobile Sensing in Psychology: Methods and Applications , I offer an updated version of these questions, shared below. Design Issues  • What kinds of personal information are sensed or gathered (e.g., name, email)? • How sensitive is the data? If leaked, can the data be easily linked to a specific individual? • Is there a clear value proposition for end users for sharing their personal data? Is this value proposition clear to end users? • Does this data collection match people’s expectations about the app? For example, it makes sense for a sleep monitor to use a microphone but perhaps not for a f...

SCGSSM 2023 Commencement Address

I had the honor of being the 2023 commencement speaker for my old high school, the South Carolina Governor's School for Science and Math . It was especially good timing, since it's been 30 years since I graduated high school, so my friends and I organized a 30 year reunion at the same time.  Here's a link to a video of my speech . Here's a link to my speaking notes . I used a table with alternating colors to make it easier to follow where I was. I had several students thank me for the speech, especially the parts about handling failure and about not always listening to your parents. Yeah, I know that second one is going to bite me in the future, but now is now and I'll enjoy time with my kids in the meanwhile. --------- Thank you for the kind introduction. As you just heard, I'm a professor of computer science at Carnegie Mellon University. Now, inviting a professor to speak is a dangerous proposition, because as you may know, we professors have been trained t...

Caret Browsing for Chrome

My young children have been fascinated by computers, and have a tendency to mash the keyboard. While this hasn't caused too many problems, it did lead to a strange case where the home, end, and arrow keys didn't work as usual in the Chrome browser. That is, instead of the down arrow key scrolling the page down, it would instead go to the next link on the page. Similarly, the end key wouldn't go to the bottom of the page, but would instead move the cursor to the end of the current line. After about an hour debugging, it turns out that this is a feature in Chrome known as Caret mode. It's an accessibility feature to help people navigate. To turn it on or off, hit F7. 

Fake Malware Warning on NYTimes web site

Image
I just got a fake malware warning while reading an article on the New York Times web site. It also locked up my web browser too. I'm copying and pasting the text here, to help any folks who do a search on the text. There was a dangerous try to get an access to your personal logins & bank information. Luckily, your Firewall managed to block this suspicious connection. We recommend you to freeze your accounts until some measures will be taken. There is a great threat of leaking of your personal data. So you need to respond swiftly! Trojan Virus may have already hurt your hard disk and its data. That is why we are checking and verifying your system security. Do not waste your tie and consult one of our service centers or call us. Contact Microsoft Support: +1 (866) 273-6507 (TOLL-FREE). Your urgent response is needed. To deal with this problem, contact our network administrator. How can we tell this is fake?  First, I'm using the Chrome web browser, and folks from the...

What are the least secure connected devices?

A journalist was asking my thoughts about the least secure connected devices out there today. Here's my response: ---------- What's insecure? Almost all of the cheaper consumer electronics available on the market today, including toys, light bulbs, weight scales, bread makers, web cams, and more. There are two major reasons. The first is that most of these are made by hardware manufacturers who have little background in software engineering best practices, let alone security. The result is common security problems, such as default passwords, no support for software updates, little or no encryption, or poor management of cloud servers. The other reason is economics. We consumers don't make purchasing decisions based on whether a device is secure or not, since we can't easily gauge the quality of security. One result is that manufacturers don't put a lot of effort into security. I research IoT security, and I basically try to avoid having any of these device...

Future of Education and Training in a World of Automation

A journalist was asking me about the future of automation, especially in terms of how we (society) should change in regards to training and education of workers. Below are my responses. 1) Do you consider your courses at CMU to be training a workforce for an increasingly automated world? We don't explicitly gear our courses at CMU for training workforces. Generally, our courses are more about teaching high level concepts, methods, and skills. It's the same difference as learning how to program in Java and learning computer science with Java. The former focuses only on skills, while the latter focuses on bigger picture issues as well as the fundamentals. 2) Is the best way to train for "future jobs" truly in learning the mechanics of the machines that we rely on? Or is it perhaps better to train for truly complementary roles, human skills that a machines are far away from replicating?  (i.e. communications, design). I would say that it's mostly for comple...

Thoughts on the Future of Technology and Well-Being

I just filled out a survey by Pew Internet and Elon College about the future of Internet technologies on well-being. Here are my responses: Our question: Over the next decade, how will changes in digital life impact people’s overall well-being, physically and mentally? Many years ago, the famed Nobel laureate Herb Simon pointed out that "[I]nformation consumes the attention of its recipients. Hence a wealth of information creates a poverty of attention." Simon presciently pointed this out in 1971. However, back then, the challenge was information overload. Today, we now also have organizations that are actively vying for our attention, distracting us with smartphone notifications, highly personalized news, addictive games, Buzzfeed-style headlines, and fake news. These organizations also have a strong incentive to optimize their interaction loops, drawing on techniques from psychology and mass A/B testing to draw us in. Most of the time it's to increase clickthrough...

My Commencement Speech for SCGSSM 2017

I was recently honored with Alumni of the Year award from my high school alma mater, the South Carolina Governor's School for Science and Math . For this award, I was also offered some time to give a short speech at this year's commencement ceremonies. Note that the main speaker was Mick Mulvaney , who is Trump's budget director at the Office of Management and Budget. As you might know, Mulvaney is in charge of putting together the proposed US government budget, which essentially cuts... well, pretty much everything except the military . Given that I am a scientist myself, and am an alum of a school for science and math, and would be speaking after someone who is proposing massive cuts to the National Science Foundation, EPA, National Institutes for Health, ARPA-E, Centers for Disease Control, NASA, and more , I felt I had to make a strong case for why science really matters, and to still encourage the graduating seniors that there is hope for the future. And yes, I d...

Cybersecurity under the Trump Administration

A journalist asked me about cybersecurity under the Trump administration, whether anything will change. Here are my thoughts. Note that this is just my opinion and does not represent my employers or any of my funders. -------------- I don't expect much to change. President Obama already  made cybersecurity one of his top 10 priorities, and as a result, a lot of the heavy lifting has already started. However, there are still some opportunities for the  next administration . For example: A lot more research funds for longer-term thinking and solutions to big problems. Security today is dominated by the latest data breach, and there isn't enough funding for problems 5-10 years down the road, in particular Internet of Things. Another area that needs longer-term thinking and solutions is foreign countries interfering with elections . It's unclear how much happened this year, but it's only going to get worse. There are a lot of concerns that foreign countries are...

Some Tips on Protecting Yourself from Ransomware

I've been asked by more and more journalists to offer some insights into various aspects of cybersecurity. I figured that since I'm already writing these up, I might as well share them with the public. This one is on ransomware. ------------------ Ransomware is a kind of malware that holds your data hostage. The malware scrambles your data and makes it so that you can't access it, unless you pay a ransom, typically in Bitcoin. It's not really clear if you can recover your data or not. Some people have been able to by paying the ransom, while others have not. Instead, the best thing you can do is to prevent being infected in the first place. Here are some tips for protecting yourself: Don't install any software you weren't expecting to install. A lot of malware and ransomware are designed to trick you into installing them. They might pretend to be anti-virus, or say that you need to update your browser. Don't do it! Be especially careful of email ...

Android Smartphone Settings for Privacy

I was just asked to write up some tips for managing privacy on smartphones. I figured this would be generally useful to share with folks on the Internet. 1. Many Android phones track a person's location history. You can check if Google has your location history by logging into your Google account and going to:     https://www.google.com/maps/timeline If you want to turn this feature off, on your smartphone, go to:   Google Settings (app) -> Location -> Location History Or go to:   Settings -> Location -> Google Location History ----------------- 2. You can also choose to opt out of personalized ads. Android phones can share an advertising ID with sites, and this ID can be used to build up a profile of interests. These advertising IDs are just like web browser cookies. If you want to turn this feature off, go to:   Google Settings (app) -> Ads Or go to:   Settings -> Accounts -> Google -> Personal Info & Privacy...

Toward a Safe and Secure Internet of Things

Image
I wrote up a white paper about the cybersecurity issues that we will face as the Internet of Things becomes more common. I discuss issues like physical security, scale, lack of experience by manufacturers, and lack of tools and best practices. One idea I also advance is this pyramid of IoT Devices. At the top tier we will all have a few devices that have a lot of computational horsepower, such as laptops, smartphones, and glasses. In the middle tier we will have dozens of devices that have moderate computational capabilities, but also only require a little bit of our attention. These include TVs, refrigerators, and smart toys. At the bottom tier are hundreds of cheap devices or ones that we are barely aware of. These include RFIDs, smart toilets, digital picture frames, electronic locks, smart meters, cheap environmental sensors, and more. The bottom two tiers are the ones we need to worry about the most. The top tier already has major tech manufacturers wor...

Chase Fraud Alert from SMS 28107

I got a fraud alert on my phone this morning from SMS short code 28107. Is this legitimate? The short story, from what I can tell, is yes. The alert I got was: FREE MSG: Chase Fraud-Did you use card ending xxxx for $xx.xx at INGLES MARKETS on 07/13? If YES reply 1, NO reply 2 In cybersecurity, getting these kinds of alerts is a pretty common kind of scam. Attackers will send out lots of these kinds of SMS and email and try to get you to verify your account, essentially tricking you into sharing sensitive information. If you ever get one of these kinds of alerts, you should try to verify it independently. So I logged into my credit card account and saw that there were several purchases that morning. Looking up the name of the store, it appears to be a chain of grocery stores in North Carolina. Ok so definitely fraud. So I responded with a "1" to the SMS message, and it said that Chase would call when a specialist is available, or call the number on the card. There...

Should companies be allowed to "hack back" against thieves?

Here are my comments on New America responding to the question of whether companies should be allowed to hack back against thieves . Companies should absolutely not hack back against cyber thieves. One major concern is attribution, namely knowing that you have identified the right parties. Intruders typically use other people’s computers and servers, so odds are high that a company would simply be attacking an innocent party. Furthermore, if a company does take down an attacking server, they might take down many other innocent third-party web sites and services, which would make the company potentially liable for damages. Companies also have varying levels of talent and resources. While a very large tech company might be able to mount a proportional countermeasure, the vast majority of companies can’t. It would only be a matter of time before one of these other companies oversteps its bounds and inadvertently causes collateral damage and a great deal of embarrassment. Lastly, ...

My Article in Slate on Human Weaknesses in Cybersecurity

I published an article on Slate about human aspects of cybersecurity . A great deal of metadata and surrounding context can still be inferred from unclassified emails. These inferences might include the social connections between people, the names of projects a person is working on, how emails are formatted, and what jargon a person uses. On the surface, this kind of information might seem innocuous. However, in the hands of a skilled and patient adversary, this information can be used to exploit human weaknesses in cybersecurity.

World Economic Forum IdeasLab talk on Smartphones and Healthcare

Image
Here is a YouTube video of my talk at the World Economic Forum on Smartphones, Personal Data, and Healthcare.

Article in Quartz Magazine about Usability and Cybersecurity

I recently wrote up an article on Quartz looking at why public officials are using personal email accounts for business, looking at it from a usability and security perspective . Why are so many politicians turning to personal email in the first place? This trend may justifiably raise concerns about transparency and legality. But why are so many politicians turning to personal email in the first place? It could be that usability issues are driving our public officials and their subordinates to use personal accounts.

Conflict Management and Negotiation

One thing we do in our Master's of Human-Computer Interaction program is to have our students participate in workshops about conflict management. Conflict is inevitable, but how you deal with it is not. This year, we also sent our students some web resources about negotiation strategies. These are, for the most part, very positive ways of looking at negotiation, rather than making it something purely adversarial. How to Negotiate Nicely Without Being a Pushover , Harvard Business Review Episode 425: An FBI Hostage Negotiator Buys A Car , Planet Money, NPR (audio only) What A Former FBI Hostage Negotiator Can Teach Us About The Fiscal Cliff , Planet Money, NPR (audio + transcript)

Computer Science, Internet of Things, Privacy, and Advice for Students

I wrote up an article for my old high school's alumni magazine , about my work and advice for the students. Here's the article below. ------------- In the near future, our smart homes, smart cars, and smartphones will essentially know everything about us. In many ways, this will be a good thing, as these devices can help us in terms of healthcare, sustainability, safety, and more. At the same time, these same systems pose many new kinds of privacy challenges. What kind of data is being sensed and collected? How is it used? How can we help people feel like they are in control? How can we create a connected world that we would all want to live in? After graduating from SCGSSM in 1993, I majored in both computer science and mathematics at Georgia Tech, and then got my PhD at University of California at Berkeley. Since 2004, I’ve been a professor at Carnegie Mellon University, one of the top schools in the world in computer science. It’s a very fun place, with brilliant p...