Sean O'Brien Profile picture
🛡️ Prof Diggity @IvyCyberEd 🤖 Founder @YalePrivacyLab at @YaleISP 🔆 Secure Apps at @GetPrivacySafe 🎙️ Subscribe 👉 https://t.co/USDYgbwYf5
Mar 5 7 tweets 3 min read
Think your old password is safe? Think again. With AI scraping the web, #malware harvesting logins, and hackers recording keystrokes, digital #security is an arms race — and you might already be losing. 🧵👇
psafe.ly/EKNysD 🚨 A new report found that the Common Crawl dataset, used to train AI like #ChatGPT, contains thousands of leaked credentials. Researchers uncovered nearly 12,000 live API keys, passwords, and sensitive secrets... and some granting access to critical services. Image
Mar 2 7 tweets 3 min read
Had your account #hacked because your password was "qwerty1993"? 🤦

Our @GetPrivacySafe team released a small, simple tool to help you generate strong passwords & memorable passphrases — right in your web browser, wherever you are. 🌍
psafe.ly/mnnyWH Your secrets are created entirely on your device & generated on-the-fly. No data is copied, transmitted, or stored on any server:


Unlike "the cloud", #PrivacySafe Bot helps you create quick, customizable passwords without worrying about a #databreach. privacysafe.botImage
Feb 22 5 tweets 1 min read
😳 Your Face Is Not The Problem, Virtual Meetings Are

After nearly a decade of #remotework across multiple roles, I know how virtual meetings can drain energy. It's not just all the screen time. There’s another layer that doesn’t get talked about... How we see ourselves on cam A new study confirms what many of us have felt: #Zoom video calls don’t just lead to fatigue, they also impact confidence. The more dissatisfied someone is w/ their looks, the more exhausting meetings feel. We talk about it in the latest @BitsOnTape - bitsontape.com/hack-baby-zoom…
Jan 28 11 tweets 7 min read
Before I begin: I believe US users should have access to apps made by Chinese companies and vice versa.
Network analysis of @deepseek_ai app has approx 30% of traffic talking to servers in mainland China. More traffic is routed through servers in Germany owned by retailer Taobao Image The #DeepSeek Android app has com.bytedance.applog.collector.Collector as receiver. I need to dig more re: what info is sent. Ofc basic network + device profile is sent to #ByteDance & intermediaries like fengkongcloud.com owned by Shumei Technology ishumei.com Image
Jan 11, 2022 18 tweets 13 min read
Just received a response from @GETTRofficial to our @tl_eng report. Their Global Communications Director @ebonybowden has emailed and asked us to publish a series of comments from their CEO @JasonMillerinDC. So we are. 1/ This thread will address Miller’s rebuttals point-by-point. In the images attached to these tweets, when GETTR quotes our article the text appears in quotation marks. GETTR responses appear in bold type.

Read our original @tl_eng report here: 2/ talkliberation.substack.com/p/gettr-app-re…
Jan 2, 2022 8 tweets 4 min read
In addition to the issues @Suzi3D points out, it's important to highlight a few differences that separate the arch + design of Panquake.com from networks like GETTER and Parler. Short thread. First, we're taking #decentralization seriously. Panquake.com conversations are committed to a blockchain record which will be shared around the world. Users on the network will communicate and verify each other using peer-to-peer methods and strong encryption.
Feb 5, 2020 21 tweets 20 min read
I spent an hour last night analyzing the #IowaCaucasDisaster app that VICE reported on. There's nothing outwardly terrible from a privacy and security standpoint at first glance, but it may be worth digging more. Thread. 1/
vice.com/en_us/article/… The app is seemingly clean from malware and tracker SDKs, although there is some Google and Facebook code when I disassemble the classes.dex file. Exodus Scan output below (I had to use the CLI because the app is not in Google Play). 2/