Profile avatar
zappala.bsky.social
human-centered security research at BYU
31 posts 193 followers 162 following
Regular Contributor
Active Commenter

I received one of the 232 NIH grant "terminations" sent to scientists at Columbia last night. My research focuses on improving maternal and child health in the US. Also affected: ongoing clinical trials, research training programs, and research centers that aim to improve the health of Americans.

Excellent statement from Nature’s editorial board. The last section on “How to respond” is the most important. www.nature.com/articles/d41...

Firings are happening right now at the National Science Foundation. Essential staff are being cut. This isn’t about the budget. If it was, they’d be going after the military (17%) or state appropriations (38%). NSF is 0.7% of the federal budget. All federal employees make up only 4% of the budget.

🚨BREAKING. From a program officer at the National Science Foundation, a list of keywords that can cause a grant to be pulled. I will be sharing screenshots of these keywords along with a decision tree. Please share widely. This is a crisis for academic freedom & science.

In this new pre-print, my student @yuxuanli1225.bsky.social outlines how language agents making shockingly biased decisions, even when their words seem "unbiased". Also, the latest models are better at hiding bias, but it still drives what they do. It's also his FIRST Ph.D. paper! Please boost :)

Submissions are OPEN for the Enigma track at USENIX Security 2025; submit your killer talk by 7 March 2025! https://sec25enigma.usenix.hotcrp.com/ (CFP: https://www.usenix.org/conference/usenixsecurity25/enigma-cfp )

I presented our (@michaelzimmer.bsky.social @profprof.bsky.social @sarahagilbert.bsky.social Naiyan Jones) paper on Reddit research ethics at the ACM GROUP conference. It won an award! dl.acm.org/doi/10.1145/... Here is a chunk of our discussion section in three videos. 1. Don't rely on IRBs.

Absolutely fantastic article.

I would love to see providers (regardless of authentication method) have a “Get Help With My Account” flow. Sends a time-limited access token to the email of your choosing. You approve access, can revoke at any time or automatically after a preconfigured time. RBAC is a useful concept.

Maybe we should mandate that every Supreme Court decision be sent to the National Archives with a digital collection of all references.

I am recruiting 2 PhD students and 2-3 masters students to join my group at UAlberta in Fall 2025! PhD: I'm looking for people who are either, (1) Background in HCI and interest in privacy research (2) Background in cryptography or systems security Application FAQ bkacsmar.github.io//advising/

hello! i am recruiting for my dissertation survey. if you've ever played tabletop roleplaying games (TTRPGs) like d&d, i would appreciate if you participated! #ttrpg #academicsky #phdsky

So about ten years ago I found a small network of bots on Reddit dedicated to spreading hate. The thing about it is that these weren't even responding to political topics - they were just responding to random keywords with insults and hate. The same bots are now here. You should understand why. 🧵

The problem with Bluesky verification as domains is that they have confused the Registration Authority with the Certificate Authority. This is an extremely common issue and not entirely their fault. But verification needs the RA.

Now out in @science.org: misinformation exploits outrage to spread online. www.science.org/doi/10.1126/... Doing this work was way harder than it had to be, thanks to Big Tech. I want to highlight our lead analyst @killianmcloughlin.bsky.social for his heroic perseverance to bring you this paper 🧵

In academia, made it here, and already following me (or someone who reposted this)? Great, then you should consider applying to CISPA's tenure-track positions (deadline December 2 AoE) including *three* PhD positions from day 1. Check out career.cispa.de/faculty.html for all the details.

I wrote a very timely introduction to digital security for journalists for @gijn.org, this guidance may also apply to activists, lawyers, and anyone else doing at-risk work these days. gijn.org/resource/int...

A tour-de-force of scholarship and detective work: Fara Dabhoiwala reveals that a portrait of an 18th-century Black scientist, long dismissed as a caricature, is in fact a record of the man's mastery of Newtonian physics—and the only painting made in 1759 of the return of Halley's comet.

When we first released ZMap, we drafted best practices for minimizing harm when conducting large active Internet measurements. 10 years later, with more experience and shifted norms, we have updated our recommendations for researchers in Section 6 of our recent ZMap retrospective.

Really interesting experiment. Shows how dangerous social media algorithms can be, how companies can do better, and reminds us to be aware that an algorithm can manipulate us.

I am looking for PhD students and masters students to start in Fall 2025 to work with me at university of Alberta. If you don't know, the Canadian style thesis-based master's is like a mini-PhD.

Our Polarization Lab at Duke hopes to hire another post-doc this year-- apply below and/or please share with people who might be interested: academicjobsonline.org/ajo/jobs/29305

CMU is hiring tenure-track faculty who'd like to do fun and exciting research in computer security and privacy. Please consider applying! www.cylab.cmu.edu/about/hiring...

Attention PhD students interested in digital safety: applications are now open for the Security, Trust, and Safety Fellowships at Cornell Tech! Eligible projects must focus on adversarial threats to security, privacy and user safety on digital infrastructures. 🚡🚡🚡 mailchi.mp/tech/applica... 🚡🚡🚡