|
Sarah Jamie Lewis
@
SarahJamieLewis
Unceded territories of the xwməθkwəy̓əm (Musqueam), Skwxwú7mesh (Squamish), Stó:lō and Səl̓ílwətaʔ/Selilwitulh (Tsleil- Waututh) People
|
|
Executive Director @OpenPriv.
Enforcing Consent & Resisting Surveillance with Cryptography. Vegan Lesbian, Queer Anarchist.
Donate: openprivacy.ca/donate
|
|
|
17.879
Tweet
|
490
Takip ediliyor
|
24.498
Takipçi
|
| Tweet |
|
Sarah Jamie Lewis
@SarahJamieLewis
|
7 sa. |
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
7 sa. |
|
"Security researcher resembles witch" is my new favorite evoting take.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
7 sa. |
|
Wait...seriously?! twitter.com/priordice/stat…
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
10 sa. |
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
10 sa. |
|
Over the last few years I've had some pretty good quotes in media, the start of this article might take place as my second favorite ever.
letemps.ch/economie/syste…
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
(This question isn't theoretical)
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
Now I ask: Excluding of all the existential issues with e-voting. Who has the authority to accept security risks identified as part of public voting infrastructure? Because it certainly shouldn't be the people who operate it, or the people who gain power through it.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
That is not security engineering, it is a publicity stunt, and it's really concerning that projects are starting to see it as a way to market themselves as "secure".
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
One of the reasons I dislike public intrusion testing stunts, is that the limited scope results in perverse outcomes:
* If no exploitable issues are found, the project will wave that flag around
* If exploitable issues are found, the project will claim it's battle hardened.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
As such, I've seen projects postponed because both mitigating the risk AND acceptance are too expensive/timely/difficult.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
In work I've done, the someone with enough authority has been anyone from a line manager to a director, to a VP.
The higher up the chain you go to get a risk assessment the more difficult and costly it becomes.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
On such an occasion you have 2 possibilities:
1) Change the goal to something that can be secured.
2) Someone with enough authority accepts the risk.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
11 sa. |
|
When I was a security engineer I always went into projects with the goal of shipping the product, securely. My job was to work out how to achieve something securely.
On occasion though, it turns out that goal is not possible.
|
||
|
|
||
| Sarah Jamie Lewis retweetledi | ||
|
Open Privacy
@OpenPriv
|
12 sa. |
|
Board Member Spotlight: Today, as part of our 2019 fund raising drive, we hear from @NormanShamas on why they are involved in @OpenPriv, and their thoughts and hopes going forward. openprivacy.ca/blog/2019/02/1…
|
||
|
|
||
| Sarah Jamie Lewis retweetledi | ||
|
p≡p foundation
@pEpFoundation
|
21 Şub |
|
The work @openpriv is doing seems promising -- concretely decentralized frameworks like #cwtch!
twitter.com/OpenPriv/statu…
So we donated 142 mBTC to have this and other work continued!
Many greets & 🖤 to Vancouver, Canada!
Check out: openprivacy.ca/work/cwtch/ 🤩
#Privacy #P2P
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
25 Şub |
|
Liking the scare quotes around "expert" too. I forgot that my sexuality nullifies my years as a computer scientist for the UK gov, and as a security engineer for Amazon, and all the experience around in between.
Fucking girls and plants, draining my expertise.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
25 Şub |
|
Anyway, the really funny thing is this vegan lesbian knows things about your voting system that you don't.
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
25 Şub |
|
Shelved awaiting a maintainer with the time to develop it further: twitter.com/SarahJamieLewi…
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
25 Şub |
|
LOL. Of course there is a sexist satire about me and the evoting thing. pic.twitter.com/VkGsezxcll
|
||
|
|
||
|
Sarah Jamie Lewis
@SarahJamieLewis
|
24 Şub |
|
Thanks for the offer :) I'd like to direct any donations to @OpenPriv - Without them I wouldn't have been able to spend all the time I did on this!
openprivacy.ca/donate/ (For bitcoin, click on "donate once" and then the bitcoin logo).
|
||
|
|
||