@LukaszOlejnik@mastodon.social
@LukaszOlejnik@mastodon.social avatar

LukaszOlejnik

@LukaszOlejnik@mastodon.social

Security & Privacy. Data protection. Research. Engineering. Strategy, communication. Analyst. Technology Policy. W3C standardisation. PhD (CS/privacy), LL.M (Information Technology Law). Consultant (perhaps happy to do interesting work for you?). Reading & writing (scientific articles, sometimes op-eds, analyses, reports, a book). Seems that I like it?
email: me (at) lukaszolejnik.com.
Book: https://lukaszolejnik.com/book-philosophy-cybersecurity
Twitter: @lukOlejnik

This profile is from a federated server and may be incomplete. Browse more on the original instance.

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

"The theft-prevention system installed in Seattle rental cars by a car-sharing company was designed to prevent cars being towed away by thieves. It disabled the cars remotely if they were detected to be moving with the engine off. Renters taking the boat ferry found themselves unable to restart their cars when the ferry docked. An anti-theft system in a car caused major delays to a regional ferry system" https://www.ft.com/content/178ab808-21ff-4ac2-a81f-f831326c22d4

LukaszOlejnik, to ai
@LukaszOlejnik@mastodon.social avatar

Just a few months after the launch of ChatGPT, copywriters and graphic designers (freelancers) have been affected by a significant drop in the number of contracts received, and in those that have received them - a drop in earnings. being more skilled was no shield against loss of work or earnings. Being more skilled was no shield against loss of work or earnings
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4527336

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Still the best predictor for fraud prosecutors and money laundering investigatora. Bery high efficiency.

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

The US military tracked Putin's movements. How? His comrades (advisers, drivers, etc.) had smartphones and were browsing the internet, using apps. Ads were displayed to them. And data traces from advertising networks revealed everything. https://www.wired.com/story/how-pentagon-learned-targeted-ads-to-find-targets-and-vladimir-putin/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Authentication provider 1Password breached. Due to other authentication provider, Octa, breached. THAT IS how fragile is technology. Hand-wave policy report/advice on "supply-chain" security but at the end of the day, random npm package 0wns stuff. https://blog.1password.com/okta-incident/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar
LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Are your systems safe from cat cyberattacks? "four-hour system interruption in September ... while a technician was reviewing the configuration of a server cluster, their cat jumped on the keyboard and deleted it" https://www.theregister.com/2023/10/05/hospital_cat_incident/

image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Significant GPS outage over Poland, Denmark, Sweden. Source unknown. https://gpsjam.org/?lat=53.67154&lon=17.62490&z=4.8&date=2023-12-26

LukaszOlejnik, (edited ) to random
@LukaszOlejnik@mastodon.social avatar

If that's the security reality of LLMs, we're going to redo the basics of security again. Prior to that, we did so for: web, mobiles, IoT, blockchain (...). And now, LLMs.

LukaszOlejnik, to poland
@LukaszOlejnik@mastodon.social avatar

My comment in @wired about sabotage disrupting railways in Poland. Radio emission brings trains to a halt in several places. Who's behind unclear. Executing this sabotage is technically simple (I explain), though requires proximity. Solution: move to GSM-R.

https://www.wired.com/story/poland-train-radio-stop-attack/

image/png
image/png
image/png

LukaszOlejnik, to privacy
@LukaszOlejnik@mastodon.social avatar

Issues of data protection and human dignity of generative AI processing and creations are an important one. My complaint about OpenAI's data processing. It concerns input and output, access to information, and technology design.
Context/writeup: https://blog.lukaszolejnik.com/ai-llms-gdpr-complaint-and-human-dignity/

The fullcomplaint is here: https://lukaszolejnik.com/stuff/OpenAI_GDPR_Complaint_LO.pdf?ref=mastodon
The supplement is here https://lukaszolejnik.com/stuff/OpenAI_GDPR_Complaint_supplement.pdf?ref=mastodon

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Scientists "cut out" everything possible from the bacterial genome to obtain a minimal cell genome. Half of the genome removed. Cells were alive and then... Even if you reduce the genome to the bare minimum, evolution means mutations. It can’t be stopped! 300 days of evolution (~40k humans years) enough for a cell to gain everything that was removed. Natural selection outweighed deleterious effects of genomic disruption. Life always finds a way. https://www.nature.com/articles/s41586-023-06288-x

image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Longer description of the train hacking (controller software reverse engineering) story. Amazing story which considers cybersecurity, train security, competition issues. One of the best hacking examples in 2023. https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Google changed its privacy policy: "we may collect information that’s publicly available online or from other public sources to help train Google’s AI models and build products and features, like Translate, Bard and Cloud AI capabilities".

LukaszOlejnik, to books
@LukaszOlejnik@mastodon.social avatar

My book Philosophy of Cybersecurity tackles a broad domain from systems cybersecurity, user's aspects, healthcare, critical infrastructure security, to policy and politics matters, international law, and cyberwarfare.

Carefully written, with examples, scenarios.

It was a lot of careful work, requiring knowledge and experience. I put all that in the book. Enjoy, happy readings! https://blog.lukaszolejnik.com/my-cybersecurity-book-philosophy-of-cybersecurity/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

On Thursday and Friday, two Finnair flights from Helsinki to the Estonian city of Tartu were forced by the GPS jamming to turn around and return to Finland as they were unable to navigate safely to their planned destination. https://www.ft.com/content/37776b16-0b92-4a23-9f90-199d45d955c3

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

My life story, or life with a disability. I have a hearing impairment. I am a person with a disability. I explain what it is about. Why did I write this? Because I hope it will be useful to at least one person. https://blog.lukaszolejnik.com/invisible-disability-in-the-world-of-technology/

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

My Complaint regarding OpenAI's data processing and designs in LLM/AI deployments has been significantly extended. Description of the original one: https://techcrunch.com/2023/09/21/poland-chatgpt-gdpr-complaint-probe/?guccounter=1

LukaszOlejnik, to Cybersecurity
@LukaszOlejnik@mastodon.social avatar

Data leak from LLM usage. "Vulnerability that allows recovery of data from GPU local memory created by another process on Apple, Qualcomm, AMD, and Imagination GPUs". Security/privacy leak of data from AI/LLM systems. Among the affected devices are iPhones. Where is your "AI" now? https://blog.trailofbits.com/2024/01/16/leftoverlocals-listening-to-llm-responses-through-leaked-gpu-local-memory/

image/png
image/jpeg

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Every macOS/iPhone (2020+) susceptible to information leak, for example GMail password theft. By visiting a website from Safari/Firefox. CPU architecture attack. Great research! https://ileakage.com/files/ileakage.pdf

image/png
image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Security vulnerability in... qsort. Yes, the glibc's sort algorithm. It's all over the place on systems running the Internet. "All versions from at least September 1992 are affected". That makes it a more 32 years old bug. https://www.openwall.com/lists/oss-security/2024/01/30/7

image/png
image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Australian supermarket chain Pak'nSave introduced a chatbot suggesting recipes for budget-conscious shoppers with leftover ingredients. Unfortunately, the bit suggested a recipe that, if followed, would have resulted in the creation of a toxic chloramine gas. https://www.sbs.com.au/news/article/supermarket-chatbot-suggests-recipes-for-toxic-gas-and-poisonous-jelly/u4cw51rtw

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

€345,000,000 fine for TikTok. Violation of data protection rules. The details are SHOCKING. https://edpb.europa.eu/system/files/2023-09/final_decision_tiktok_in-21-9-1_-_redacted_8_september_2023.pdf

image/png
image/png
image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

iPhone apps are collecting quite some A LOT OF user private data. Extremely verbose, allowing to fingerprint, perhaps even track users.

Context from my works. About privacy risks of light data: https://blog.lukaszolejnik.com/ambient-light-sensor-privacy-constraints-gdpr-data-protection-by-design-gdpr-state-of-the-art/
Risks of battery information: https://blog.lukaszolejnik.com/battery-status-not-included-assessing-privacy-in-w3c-web-standards/

Data source: https://twitter.com/mysk_co/status/1753960043450356137

image/png
image/png
image/png

LukaszOlejnik, to random
@LukaszOlejnik@mastodon.social avatar

Attention. The European Parliament passed a law on sharing health data with external entities. Allegedly only "pseudonymised" (anonymisation impossible), unclear how. Caution advised. Unfortunately data shared without consent. Opt-out is manual. https://www.europarl.europa.eu/doceo/document/TA-9-2024-0331_EN.pdf

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • rosin
  • thenastyranch
  • GTA5RPClips
  • tester
  • InstantRegret
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • mdbf
  • slotface
  • kavyap
  • JUstTest
  • cisconetworking
  • khanakhh
  • normalnudes
  • osvaldo12
  • cubers
  • tacticalgear
  • Durango
  • ethstaker
  • modclub
  • anitta
  • provamag3
  • Leos
  • lostlight
  • All magazines