Privacy

Biometrics & Security: Privacy, Deepfakes, & Cyber Threats

Biometrics & Security: Privacy, Deepfakes, & Cyber Threats

An in-depth analysis of biometric authentication, exploring how the technology works, its applications in security, and the significant privacy risks involved. The summary covers biometric templates, threats like deepfakes, and mitigation strategies such as cancellable biometrics and multi-factor authentication.

Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated Approach

Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated Approach

Qinge Xie from Georgia Tech presents a large-scale evaluation of modern website privacy policies using a novel LLM-based framework. The research systematizes privacy practices from 10 major US and EU regulations into 34 clauses and analyzes over 100,000 websites to reveal current trends in data collection, sharing, and consumer rights disclosure.

Encrypted Access Logging for Online Accounts: Device Attributions without Device Tracking

Encrypted Access Logging for Online Accounts: Device Attributions without Device Tracking

Client-Side Encrypted Access Logging (CSAL) is a proposed protocol that uses OS-level cryptography and FIDO2-style attestations to create trustworthy, privacy-preserving account activity logs, resolving the tension between preventing user tracking and accurately detecting account compromise.

How to scam an AI agent, DDoS attack trends and busting cybersecurity myths

How to scam an AI agent, DDoS attack trends and busting cybersecurity myths

A discussion on novel methods for hijacking AI agents through social engineering, the evolution of DDoS attacks, the legacy of Zero Trust, and the glaring security flaws in AI training data apps.

zk-promises: Anonymous Moderation, Reputation, & Blocking from Anonymous Credentials with Callbacks

zk-promises: Anonymous Moderation, Reputation, & Blocking from Anonymous Credentials with Callbacks

A novel framework called zk-promises is introduced, enabling stateful anonymous credentials with Turing-complete state machines and asynchronous callbacks. This allows for robust moderation, such as banning or reputation updates, for anonymous users without compromising their privacy, using zk-objects and zero-knowledge proofs to ensure state integrity.

Encrypted Computation: What if Decryption Wasn’t Needed? • Katharine Jarmul • GOTO 2024

Encrypted Computation: What if Decryption Wasn’t Needed? • Katharine Jarmul • GOTO 2024

An exploration of encrypted computation, detailing how techniques like homomorphic encryption and multi-party computation can enable machine learning on encrypted data. The summary covers the core mathematical principles, real-world use cases, and open-source libraries to build more private and trustworthy AI systems.