Sign in

Stefan Savage

@docsavage.bsky.social
192 followers 276 following 50 posts
PostsRepliesMedia
Stefan Savage @docsavage.bsky.social · 21/09/2026
Oh, I agree. It just seems like the courts have decided pretty clearly that the don’t consider manual review at the border to be unreasonable. Riley did not get them there and even when there was a framework to think that way (aka Cano) they didn’t take it.
110
Stefan Savage @docsavage.bsky.social · 20/09/2026
I suspect that if your luggage held your diary, all your bank statements and your trade secret documents that they wouldn’t blink an eye.
110
Stefan Savage @docsavage.bsky.social · 20/09/2026
Even the 9th, which probably has the strongest protections against _forensic) border search (RS of contraband, via Cano) goes the same way, " "...we conclude that manual cell phone may be conducted by border officials without reasonable suspicion" Cano, 934 F.3d at 1015-1016.
001
Stefan Savage @docsavage.bsky.social · 20/09/2026
Doesn't this strike you as unsurprising though? I don't think there is any circuit with a warrant, or even RS, requirement for manual phone search and every circuit that has ruled on this (1st, 2nd, 4th, 5th, 7th, 9th, 11th) has gone the same way.
210
Stefan Savage @docsavage.bsky.social · 17/09/2026
UC San Diego's Computer Science and Engineering dept is hiring: apol-recruit.ucsd.edu/JPF04649
apol-recruit.ucsd.edu
Assistant Professor - CSE
University of California, San Diego is hiring. Apply now!
012
Reposted by Stefan Savage
Alisha Ukani @alishaukani.bsky.social · 11/08/2026
By law, the US government can request your information (like your emails, photos, and search history) from companies and they have to comply. But how do we protect against hackers creating fake search warrants to access that same sensitive data? My new USENIX Security paper addresses this issue 🧵
alishaukani.com
151
Stefan Savage @docsavage.bsky.social · 22/07/2026
But there's no requirement for a provider to search for CSAM, because if there were then the provider would become an agent of the government and the 4th amendment would apply. That's why 18 USC 2258A is written the way it is (report it if you find it)
130
Stefan Savage @docsavage.bsky.social · 22/07/2026
Also, worth reminding your readers that this is a civil case (class action alleging product liability, negligence and intentional infliction of emotional distress). Their 2252/2252A claims were throw out earlier. Section 230 does NOTHING to block a criminal prosecution.
120
Stefan Savage @docsavage.bsky.social · 22/07/2026
Remember for the purpose of 230, the requirement is that Apple's iCloud is an "interactive computer service" and thus cannot be treated as a publisher wrt content provider by another party.
120
Stefan Savage @docsavage.bsky.social · 21/07/2026
Context: dealers+insurers install these devices to protect cars on the lot and then an alarm "upsell". If buyer says they don't want it, it doesn't get removed - its wired deeply into the guts - it just gets "disabled". Disabled doesn't mean what you'd like and, now anyone can now open your car.
010
Stefan Savage @docsavage.bsky.social · 21/07/2026
What's particularly insidious about this one is that its an aftermarket device (i.e., your OEM isn't in a position to fix it), the car owner didn't install it and may not know it exists, and there may be no notification path to the owner. It will likely stay unpatched a long time...
110
Stefan Savage @docsavage.bsky.social · 21/07/2026
Nice Wired story about some work my colleague Aaron Schulman and his great students did looking at vehicular security. www.wired.com/story/a-devi...
wired.com
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
131
Stefan Savage @docsavage.bsky.social · 22/03/2026
I just wondered if anyone had tried to push this in practice because a) some of the agencies who have opposed such changes are those who only have subpoena power and b) if ever there was a time for crazy admin subpoenas now would be that time.
010
Stefan Savage @docsavage.bsky.social · 22/03/2026
Dear god yes. Norms, expectations and policies have all been thoroughly devalued as impediments to adventurism.
100
Stefan Savage @docsavage.bsky.social · 21/03/2026
Ooops... I meant Warshak (but roughly the same time frame)
100
Stefan Savage @docsavage.bsky.social · 21/03/2026
The 180day thing always seemed nuts. However, I’m curious if you’re aware of agencies actually availing themselves of this power post-Theofel. My sense is that the big providers won’t honor it, and DoJ hasn’t tried, but I’d love to know if that’s wrong (esp agencies that only have subpoena power)
201
Stefan Savage @docsavage.bsky.social · 31/01/2026
Perhaps another is a conspiracy charge no? As I recall you get to date the clock on conspiracy from the last overt act and I don’t think a warrant for evidence of an overt act needs to include the conspiracy charge.
000
Stefan Savage @docsavage.bsky.social · 30/01/2026
FWIW, the docket remains sealed in PACER -- and hence the application and its affidavit. I assume the copy of the warrant out there is via service.
000
Stefan Savage @docsavage.bsky.social · 30/01/2026
Note that in general, gand runs criminal process as mc case types (i.e., not as mj) and they generally stay sealed unless they are explicitly unsealed via litigation.
000
Stefan Savage @docsavage.bsky.social · 30/01/2026
www.documentcloud.org/documents/26...
documentcloud.org
1-28-26 Fulton Warrant
100
Stefan Savage @docsavage.bsky.social · 27/01/2026
I'd also note that, on the off chance it were true, it would create problems for Meta beyond this particular tort claim... as Meta has represented to the US that it is not able to provide such information under court order (presumably pursuant to the explicit exception in CALEA around encryption).
030
Stefan Savage @docsavage.bsky.social · 27/01/2026
So for me the interesting bit is the lawyers. Keller Postman is a std plaintiffs firm. Barrett is an individual practice guy from Oklahoma. and QE is lead counsel... an interesting mix.
020
Stefan Savage @docsavage.bsky.social · 27/01/2026
Actually, this doesn't look that weird to me for an initial complaint (its not uncommon in such cases for the complaint to be amended). They allege that there are specific whistleblowers who claim that "WhatsApp and Meta store and have unlimited access to WhatsApp encrypted communications..."
010
Stefan Savage @docsavage.bsky.social · 04/12/2025
The pardon text is for those “convicted of offenses related to events that occurred at or near the United States Capitol on January 6, 2021;”. The bomb was planted on Jan 5. I foresee some litigating on “related to”
000
Stefan Savage @docsavage.bsky.social · 02/12/2025
Correct. But once you insert a policy like this for one set of topics it’s not clear why you can’t extend it to other domains in the future…
110
Stefan Savage @docsavage.bsky.social · 07/11/2025
Google scholar is an illusion, kinda like magenta. It only exists in your mind.
010
Stefan Savage @docsavage.bsky.social · 14/10/2025
I think the other difference is the tremendous amount of manual work to figure out what the traffic was, who it belonged to and who to disclose to... which has been non-stop detective work for them over the last year.
000
Stefan Savage @docsavage.bsky.social · 14/10/2025
The difference is one of scale (a dozen transponders vs > 400, decoding a a single standard protocol vs building a system to decode an array of proprietary protocols)
120
Stefan Savage @docsavage.bsky.social · 14/10/2025
Amazing story about the work of my amazing colleagues: www.wired.com/story/satell...
wired.com
Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypte...
072
Stefan Savage @docsavage.bsky.social · 05/10/2025
An interesting question is what the other warrants were for... In my experience, attachment A and B generally only get numbered when they're part of a larger group.
000
Stefan Savage @docsavage.bsky.social · 04/10/2025
Next time “the Meg”
010
Stefan Savage @docsavage.bsky.social · 06/09/2025
Yeah, no idea on that one. After all YOU did not register the copyright.
110
Stefan Savage @docsavage.bsky.social · 06/09/2025
The open questions seem to be about a) whether "book" is limiting and b) if there is some kind of pro-rata thing for what fraction of a work was pirated.
000
Stefan Savage @docsavage.bsky.social · 06/09/2025
I will point out that ACM Proceedings do have ISBN numbers and apparently ACM registered the copyrights. They look like class members to me... ditto IEEE.
200
Stefan Savage @docsavage.bsky.social · 06/09/2025
I also wonder if the term book is not salient. It has to have an Asin/isbn number. So perhaps a whole proceedings might be much a thing?
100
Stefan Savage @docsavage.bsky.social · 03/09/2025
In this respect I’m skeptical about the “it’s just a tool” analogy. That’s great when it’s interchangeable (ie purely labor saving). The advent of calculators made our arithmetic muscles atrophy, but so what? Generative AI text threatens to make our thinking muscles atrophy — different I think.
010
Stefan Savage @docsavage.bsky.social · 03/09/2025
I think, from a student standpoint, writing is the most problematic case. Writing is the mechanism we have for thinking through problems, making them crisp and concrete. When we allow AI to do drafts of writing we are outsourcing our thinking and we don’t develop our own abilities.
110
Reposted by Stefan Savage
Andy Greenberg @agreenberg.bsky.social · 19/07/2025
On the one-year anniversary of CrowdStrike's disastrous crashes that took down millions of computers worldwide, a new study finds 750-plus hospital networks in the US were disrupted, and 200-plus appear to have had outages of patient medical services. www.wired.com/story/at-lea...
wired.com
At Least 750 US Hospitals Faced Disruptions During Last Year’s CrowdStrike Outage, Study Finds
Of those, more than 200 appear to have had outages of services related to patient care following CrowdStrike’s disastrous crash, researchers have revealed.
16416
Stefan Savage @docsavage.bsky.social · 06/06/2025
Don’t you think Google’s change in how location history is stored is going to make this practically (albeit not legally) moot? Did anyone else offer geofence? Tower dumps maybe will be the next front here.
100
Stefan Savage @docsavage.bsky.social · 01/06/2025
Tracy was also the founding drummer in UWs legendary “Anna’s All Girl Band” — an interdisciplinary systems/theory musical experience. Clearly he had it in his blood.
010
Stefan Savage @docsavage.bsky.social · 20/05/2025
The argument is that maybe a big part of the goal here is for students to learn at the beginning that they should be doing AEAD. We don’t teach miasma and leeches and then “work up” to medicine that works after all. I think bottom up leads people to believe they can be clever.
150
Stefan Savage @docsavage.bsky.social · 20/05/2025
Every single one of your commenters seems to suggest bottom up. Arguing, rightly I suspect, that it’s pedagogically better to start with simpler things and compose them. I’ll play devils advocate and suggest the reverse.
120
Stefan Savage @docsavage.bsky.social · 09/05/2025
Ok, folks here the question I’ve seen no one else ask yet. Since the current Pope is a US citizen, does this mean no more US SIGINT collection directly against the pope without a FISA warrant?
010
Stefan Savage @docsavage.bsky.social · 27/04/2025
On the other hand, some models come with deep indemnification pockets: blogs.microsoft.com/on-the-issue...
blogs.microsoft.com
Microsoft announces new Copilot Copyright Commitment for customers - Microsoft On the Issues
With customers ask whether they can use Microsoft’s Copilot services without worrying about copyright claims, we are providing a straightforward answer: yes, you can, and if you are challenged on copy...
010
Stefan Savage @docsavage.bsky.social · 27/04/2025
With a secondary risk that there might be ownership interests from third parties whose code was used to train the model — something we very much don’t have clarity on in the US and perhaps even less so in the EU (courtesy Recital 105 of the AI act). Cross-border rules even less clear.
120
Stefan Savage @docsavage.bsky.social · 24/04/2025
“AFRAID--A Frequently Redundant Array of Independent Disks” www.usenix.org/conference/u... We came up with the acronym first, months later I did a summer internship to figure out what it might mean, then paper, then patent. Names have power…
usenix.org
AFRAID--A Frequently Redundant Array of Independent Disks | USENIXusenix_logo_notag_white
090
Stefan Savage @docsavage.bsky.social · 31/12/2024
Those of us whose musical input has languished since we stopped living near you request a Spotify channel to follow :)
110
Stefan Savage @docsavage.bsky.social · 15/12/2024
Whale, don’t whale if you can’t get in. The application process is a killer and can feel cruwhale. But whether you can get in, Orcant, you’re all great and have a porpoise.
010
Stefan Savage @docsavage.bsky.social · 15/12/2024
So many seally puns, bordering on sealf-indulgent…
100
Stefan Savage @docsavage.bsky.social · 09/12/2024
Your comment that culture is peer-dynamics completely resonates with me. I think any time you create situations for positive-minded faculty to do things together -- and even better in public -- you create some social gravity that spills over.
110