Sign in

Nicolas Christin

@nc2y.bsky.social
531 followers 221 following 129 posts

Prof. at Carnegie Mellon University. Computer security, online crime, and assorted online seediness. Reformed(?) hacker. Economic migrant. 📍 Pittsburgh, PA, mostly 🕸️ www.andrew.cmu.edu/user/nicolasc

PostsRepliesMedia
Reposted by Nicolas Christin
Dan York @danyork.bsky.social · 20/04/2026
Very interesting and useful paper on a critically important topic ... what happens to all our digital assets when we die? How are we setting up our estate plans / wills to ensure our heirs can access our info? Something I don't think we collectively pay enough attention to... #Death #Internet
121
Nicolas Christin @nc2y.bsky.social · 14/04/2026
Anyway, I digress. Read Jenny's paper. It's illuminating. Older people are far from being digitally illiterate, and we are not serving their needs well at the moment. And we have to fix this, sooner rather than later. (5/5)
010
Nicolas Christin @nc2y.bsky.social · 14/04/2026
A lot of us have completely moved all asset management online. I haven't been to my bank since 2005. Yet, a lot of estate planning does not account for, or even reflect that new reality. (4/5)
100
Nicolas Christin @nc2y.bsky.social · 14/04/2026
There is a growing need for estate planners with digital literacy. Shockingly, this is more often than not an afterthought. With GenXers/Xennials starting to get gray, there is -- in my opinion -- a real need here. (3/5)
100
Nicolas Christin @nc2y.bsky.social · 14/04/2026
Grossly simplifying: key finding is that older individual don't really care about their purely digital assets (pictures, etc). They do care about digital artifacts (e.g., email, etc) that could make it harder for their heirs to manage estate transmission. (2/5)
100
Nicolas Christin @nc2y.bsky.social · 14/04/2026
My student Jenny Tang just presented our work at #chi26. We have been interested in post-mortem management of online accounts (1/5) andrew.cmu.edu/user/nicolas...
andrew.cmu.edu
232
Reposted by Nicolas Christin
Joseph Lorenzo Hall, PhD @josephhall.org · 28/10/2025
HTTPS by default security.googleblog.com/2025/10/http...
security.googleblog.com
HTTPS by default
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secu...
051
Nicolas Christin @nc2y.bsky.social · 20/10/2025
Last week my student Ally Nisenoff published "Exploiting the Shared Storage API" at @acm_ccs: www.andrew.cmu.edu/user/nicolas... 3 days later, Google announced they're abandoning Shared Storage: privacysandbox.com/news/update-... (Correlation doesn't imply causation. Interesting, though.)
andrew.cmu.edu
020
Nicolas Christin @nc2y.bsky.social · 11/09/2025
We're hosting the 7th intl' conf. on Advances in Financial Technologies (AFT'25) at Carnegie Mellon on Oct. 8-10. Join us to hear about the latest exciting developments in crypto research. Registration closes on Sept 16! advfintech.org/aft25/attend... (Program: advfintech.org/aft25/progra...)
advfintech.org
Advances in Financial Technologies
021
Nicolas Christin @nc2y.bsky.social · 03/09/2025
This is concerning, it seems like lower fees on Ethereum are facilitating address poisoning attacks… x.com/toxin_tagger...
x.com
Toxin Tagger (T-T) on X: "🚨Warning🚨: There was a surge in the number of poisoning attacks on Ethereum, potentially due to the lower transaction fees. Figures: Daily number of poisoning transfers in August 2025 for Ethereum and BSC. https://t.co/jorxvN3hv3" / X
🚨Warning🚨: There was a surge in the number of poisoning attacks on Ethereum, potentially due to the lower transaction fees. Figures: Daily number of poisoning transfers in August 2025 for Ethereum and BSC. https://t.co/jorxvN3hv3
011
Nicolas Christin @nc2y.bsky.social · 15/08/2025
That’s a wrap for me at #usesec25 Conferences should really consider reusing the tag holders, the amount of wasted plastic is staggering
000
Nicolas Christin @nc2y.bsky.social · 15/08/2025
“Canadian pharmacist helps run notorious deepfake porn site.” The online crime jokes write themselves.
110
Nicolas Christin @nc2y.bsky.social · 14/08/2025
Ah true but I should try again today then
000
Reposted by Nicolas Christin
Wentao Guo @wentaoguo.bsky.social · 13/08/2025
I'm presenting my USENIX paper "How Researchers De-Identify Data in Practice" at 9am this Thursday. Kudos to my co-authors Paige Pepitone, @adamaviv.bsky.social, and @mmazurek.bsky.social. Come say hi—I am on the academic job market! Here's the paper: www.usenix.org/conference/u... #usesec25
Poster for our paper "How Researchers De-Identify Data in Practice"
062
Nicolas Christin @nc2y.bsky.social · 13/08/2025
Taro just presented this at #usesec25, and will be manning the poster shortly. If you are around we would love to hear from you.
021
Nicolas Christin @nc2y.bsky.social · 13/08/2025
I’m not sure there is a more clichéed Seattle experience than having a latte at a local coffee shop with some salmon on toast while they’re blaring Soundgarden’s “Outshined.”
130
Nicolas Christin @nc2y.bsky.social · 12/08/2025
My student Jenny Tang (coadvised with @lujobauer.bsky.social) is making friends at SOUPS with our paper on looking at 10 years of SOUPS papers and reviewing how solid the stats were. Basically: not great, not great at all. (And that includes my own work.) Paper: www.andrew.cmu.edu/user/nicolas...
andrew.cmu.edu
021
Nicolas Christin @nc2y.bsky.social · 21/07/2025
TLDR: Address poisoning is a thing. Paper: arxiv.org/abs/2501.16681 Real-time website: cryptotrade.cylab.cmu.edu/poisoning/ Real-time twitter bot: x.com/toxin_tagger (no BlueSky bot yet, sorry, soon I hope) (7/7 end)
arxiv.org
Blockchain Address Poisoning
In many blockchains, e.g., Ethereum, Binance Smart Chain (BSC), the primary representation used for wallet addresses is a hardly memorable 40-digit hexadecimal string. As a result, users often select ...
000
Nicolas Christin @nc2y.bsky.social · 21/07/2025
We simulated the lookalike address generation process across various software- and hardware-based implementations. One large attacker group appears to use GPUs for this attack! The paper also discusses some defenses. (6/7)
100
Nicolas Christin @nc2y.bsky.social · 21/07/2025
We discovered a few large attack entities using clustering techniques. Larger groups are vastly profitable and win against smaller attack groups. We uncovered some attack strategies, such as populations they target, success conditions, and cross-chain attacks. (5/7)
100
Nicolas Christin @nc2y.bsky.social · 21/07/2025
We developed a detection system and performed measurements on two years of ETH and BSC. We identified 13x the number of attack attempts reported previously—in all, 270M on-chain attacks targeting 17M victims. 6,633 incidents have caused at least 83.8M USD in losses. (4/7)
110
Nicolas Christin @nc2y.bsky.social · 21/07/2025
The attacker generates “lookalike” addresses that resemble the victim’s recipient’s address, engages with the victim to “poison” the transaction history, and fools the victim into sending their assets to the attacker by mistake. (3/7)
100
Nicolas Christin @nc2y.bsky.social · 21/07/2025
Background: Crypto wallet addresses are usually impossible to memorize. As a result, users often select addresses from their recent transaction history, which facilitates phishing-like attacks: blockchain address poisoning. (2/7)
110
Nicolas Christin @nc2y.bsky.social · 21/07/2025
New research alert 🚨 from my group, “Blockchain Address Poisoning” (Tsuchiya et al.), to appear at USENIX Security 2025 (arxiv.org/abs/2501.16681)! As a follow-up, we also developed a real-time detection system: cryptotrade.cylab.cmu.edu/poisoning/ and x.com/toxin_tagger (1/7)
arxiv.org
Blockchain Address Poisoning
In many blockchains, e.g., Ethereum, Binance Smart Chain (BSC), the primary representation used for wallet addresses is a hardly memorable 40-digit hexadecimal string. As a result, users often select ...
142
Reposted by Nicolas Christin
CMU Software & Societal Systems (S3D) @cmus3d.bsky.social · 19/06/2025
CMU S3D’s “Tartan Federer” swept all 4 MIDST tracks, revealing privacy gaps in diffusion models. Its loss-feature attack was the only entry to beat random guessing in the white-box multi-table test. Details: s3d.cmu.edu/news/2025/0501-midst.html #AIPrivacy #CMU #AI #ML!
s3d.cmu.edu
CMU's "Tartan Federer" Team Sweeps All Four Tracks at International AI Privacy Challenge - Software and Societal Systems Department - School of Computer Science - Carnegie Mellon University
Carnegie Mellon University's "Tartan Federer" team, led by S3D’s Zhiwei Steven Wu, achieved a clean sweep at the 2025 Vector Institute MIDST Challenge, winning all four competition tracks. Their innov...
011
Reposted by Nicolas Christin
Mike Wiser @drmikewiser.bsky.social · 17/06/2025
Just because your prof didn't file an academic dishonesty report does not mean that they don't know you cheated. Knowing you did it and proving it to the hearing board are two different thresholds.
1314
Nicolas Christin @nc2y.bsky.social · 16/06/2025
Details: it's likely that there are some symbol mismatches between some homebrew libraries linked against old OpenGL libs and the new OpenGL shipping with Sequoia. This drove me nuts. So I'm posting this here in hopes people don't waste their time. Oh, and don't ask an LLM, they're clueless.
000
Nicolas Christin @nc2y.bsky.social · 16/06/2025
PSA: If you're using homebrew, and discovered that MAME crashes w/ a Bus Error upon startup after upgrading to Sequoia, 1) update mame.ini so that the line containing gl_lib points to /System/Library/Frameworks/OpenGL.framework/Libraries/libGLVMPlugin.dylib 2) launch w/ DYLD_LIBRARY_PATH="" mame
100
Nicolas Christin @nc2y.bsky.social · 09/06/2025
🧵 about a new paper by my amazing students and collaborators. To appear this week at SIGMETRICS. 👇
010
Reposted by Nicolas Christin
Carnegie Mellon University @cmu.edu · 06/06/2025
CMU researchers are using personalized models to decode how cancer behaves in individual patients, one of medicine's toughest challenges. Through individualized data and insights, their work revealed hidden #cancer subtypes that could inform treatment and improve survival predictions. #Research
cmu.edu
CMU Researchers Build Personalized Models To Advance Precision Cancer Care
Researchers from Carnegie Mellon University’s School of Computer Science developed a new approach to bridge this gap between available data and actionable insight, creating personalized models to help...
084
Nicolas Christin @nc2y.bsky.social · 28/05/2025
Looking for a home for your great scientific result in fintech that is almost all written up and ready to go? The AFT deadline is in less than 24 hours… aftconf.github.io/aft25/index....
aftconf.github.io
Advances in Financial Technologies
000
Nicolas Christin @nc2y.bsky.social · 25/05/2025
Jokes aside yeah it seems like this could work.
000
Nicolas Christin @nc2y.bsky.social · 25/05/2025
Do you live in England, by any chance?
110
Nicolas Christin @nc2y.bsky.social · 25/05/2025
Possible? Yes. Putting the contents of a can of sardines in a yoghurt is also possible, from a physics standpoint.
110
Reposted by Nicolas Christin
Serge Egelman @v0max.bsky.social · 25/05/2025
Pasta sauce cookie is something you should only attempt after you’ve gotten your second Michelin star. Like, David Chang, I’d eat his pasta sauce cookie no questions. Doing it myself because the teevee told me to, yeah, no.
0267
Reposted by Nicolas Christin
Eileen Clancy 🧿 @clancyny.bsky.social · 24/05/2025
In NYC, a man was tortured for two weeks for Bitcoin. He escaped. Alice Hutchings @message4bob.bsky.social and colleagues tell us it's happening around the world. Conference paper: "Investigating Wrench Attacks: Physical Attacks: Targeting Cryptocurrency Users" drops.dagstuhl.de/storage/00li...
Investigating Wrench Attacks: Physical Attacks
Targeting Cryptocurrency Users

Marilyne Ordekian #
Department of Computer Science, University College London, UK

Gilberto Atondo-Siu #
Department of Computer Science, University of Cambridge, UK

Alice Hutchings #
Department of Computer Science, University of Cambridge, UK

Marie Vasek #
Department of Computer Science, University College London, UK

Abstract

Cryptocurrency wrench attacks are physical attacks targeting cryptocurrency users in the real world to illegally obtain cryptocurrencies. These attacks significantly undermine the efficacy of existing digital security norms when confronted with real-world threats. We present the first comprehensive
study on wrench attacks. We propose a theoretical approach to defining wrench attacks per criminal law norms, and an interdisciplinary empirical approach to measure their incidence. Leveraging three data sources, we perform crime script analysis, detecting incidents globally across 10 interviews with victims and experts, 146 news articles, and 37 online forums. Our findings reveal diverse groups
1125
Reposted by Nicolas Christin
Ben Waber @bwaber.bsky.social · 06/05/2025
Next was an intriguing talk by McKenna McCall on the need to combine formal methods and usable security approaches at @cmus3d.bsky.social www.youtube.com/watch?v=qbnq... (5/7)
youtube.com
Current Topics in Privacy-January 21st 2025-McKenna McCall
YouTube video by Carnegie Mellon Software and Societal Systems Dept
112
Reposted by Nicolas Christin
Patrick Park @patpark.bsky.social · 18/05/2025
These talented young musicians teamed up to bring the joy of music to young children in the community. Please support their cause. 6pm (CT) tonight at Nichols Hall, Evanston. Please join us in person or through the live stream. youtube.com/live/MxXwBr_...
011
Reposted by Nicolas Christin
Pittsburgh Scanner @pgh-scanner.com · 11/05/2025
Lawrenceville. 44th Street. If you accidentally left your rooster in your locked car, PD is about to break your window.
1922029
Reposted by Nicolas Christin
Rua M. Williams @fractalecho.bsky.social · 03/05/2025
If you're a grad student or an undergrad interested in research I need to you listen to me very carefully. You cannot learn to write good research papers if you do not read good research papers. Stop asking LLMs to summarize papers for you.
232118567
Nicolas Christin @nc2y.bsky.social · 02/05/2025
You misspelled “fridge.”
120
Reposted by Nicolas Christin
Michael Hilton @michaelhilton.bsky.social · 02/05/2025
Posted slides for my CSEE&T keynote here conf.researchr.org/details/icse...
conf.researchr.org
The Promise and Peril of SE Education in the Age of AI (CSEE&T 2025 - IEEE Conference on Software Engineering Education and Training (CSEE&T)) - ICSE 2025
In 2025, the IEEE Conference on Software Engineering Education and Training (CSEE&T) will replace ICSE’s traditional education track (SEET). CSEE&T 2025 will be co-located with ICSE 2025 on Monday 28 ...
032
Reposted by Nicolas Christin
Steve Rathje @steverathje.bsky.social · 10/04/2025
I'm thrilled to announce that I'll be joining Carnegie Mellon as an Assistant Professor of Human-Computer Interaction (with a courtesy joint appointment in Social and Decision Sciences) in 2026!
Steve Rathje wearing a Carnegie Mellon sweatshirt
141306
Reposted by Nicolas Christin
CyLab @cylab.bsky.social · 07/04/2025
In a @darkreading.bsky.social article, Professor Lorrie Cranor (@lorriecranor.bsky.social), CyLab Director, explains to Becky Bracken (@beckybracken.bsky.social) why, regardless of #encryption protections, #Gmail user devices and accounts still need to be secured.
darkreading.com
Gmail Is Not a Secure Way to Send Sensitive Comms
New end-to-end Gmail encryption alone isn't secure enough for an enterprise's most sensitive and prized data, experts say.
012
Nicolas Christin @nc2y.bsky.social · 05/04/2025
Does that mean the dog is also graduating? This will not stand.
110
Nicolas Christin @nc2y.bsky.social · 31/03/2025
French for cipher is “chiffre” (which also means digit). James Bond fans know this from Casino Royale’s main antagonist’s name.
121
Reposted by Nicolas Christin
Frederic Jacobs @fredericjacobs.com · 21/03/2025
🔐✌️ Victory for Privacy and Security in France 🇫🇷 End-to-end encryption will continue to be available in France, as the assembly overwhelmingly voted against an amendment to legislation fighting drug trafficking which required backdoors in encrypted messengers. www.lemonde.fr/societe/arti...
lemonde.fr
L’Assemblée nationale vote pour le maintien de la confidentialité des messageries cryptées, lors d’une nuit agitée
Malgré une panne du système de vote, les députés ont repoussé, jeudi, la mesure défendue par le ministre de l’intérieur, Bruno Retailleau, qui aurait permis aux services de renseignement d’accéder aux...
15524
Nicolas Christin @nc2y.bsky.social · 19/03/2025
Cool hack!
010
Reposted by Nicolas Christin
Steve Syfuhs @syfuhs.net · 18/03/2025
What, no? I mean, probably not. Well, it shouldn't. Look, I'm not going to find out, but yes probably. Amusingly, I think it was written by one of our VPs who just retired.
131
Reposted by Nicolas Christin
Steve Syfuhs @syfuhs.net · 17/03/2025
Q: Why is the code doing this thing? A: oh...oh no
New for Win95, allows a caller to determine what...
921615