Sign in

Steven Murdoch

@steven.murdoch.is
1.3K followers 221 following 123 posts

Professor of Security Engineering; Head of UCL Information Security Research Group @sec.cs.ucl.ac.uk; Director Open Rights Group. 🐘 mastodon.social/@sjmurdoch 🐦 @sjmurdoch 🌍 murdoch.is

PostsRepliesMedia
Steven Murdoch @steven.murdoch.is · 08/09/2026
It’s #NationalCodingWeek next week, so I've published a resource on using the BBC @microbit.org to play a game that explores how radio waves travel, get blocked by/reflected off obstacles, and the challenges of measuring strong signals that can overload sensors.
BBC micro:bit
111
Steven Murdoch @steven.murdoch.is · 31/08/2026
Graph showing temperature curve of cooking two steaks.
100
Steven Murdoch @steven.murdoch.is · 18/08/2026
I spoke to The Guardian about Claude’s content watermarking. As long as it only modifies how the existing random number generator works, it should have no measurable effect on quality. www.theguardian.com/technology/2...
However, LLMs already do not make the best choices. “There’s already randomness involved in any of these large language models,” said Murdoch. “It’s pretty essential to how they work. If it wasn’t for this randomness, then they’d get stuck in loops and start repeating the same thing over and over again.”

In other words, a chatbot does not necessarily decide to call running water a “stream” as opposed to a “brook” because the latter might have a more old-fashioned register. The model does not contemplate these choices: it makes them by chance.
141
Steven Murdoch @steven.murdoch.is · 11/08/2026
A prompt that’s been very helpful at getting Claude to improve a user-facing app with minimal interaction from me has been to ask it to do a cognitive walkthrough with a given persona. It’s not great at coming up with good personas (IME) but if you give it one it can run with it.
Take on the persona of [INSERT PERSONA DEFINITION HERE].

Perform a cognitive walkthough. Update the app so that at each stage:

The user will try to achieve the right result
The user will notice that the correct action is available
The user will associate the correct action with the result they're trying to achieve
After the action is performed, the user will see that progress is made toward the goal
This persona is only one of several that will use the app, so take care not to compromise existing qualities of the app without good reason.

Add a summary of each cognitive walkthrough performed to COGNITIVE-WALKTHROUGHS.md, including the persona, issues identified, and changes made.
010
Steven Murdoch @steven.murdoch.is · 28/07/2026
And a demo of what the dataset makes possible: an interactive chronology of 347 dated events, plotting UCL’s decisions against national restrictions and its own case curve, each with a verbatim quote from the source it came from. sjmurdoch.github.io/uclcovid-tim...
Screenshot of the interactive UCL COVID-19 response visualisation showing case statistics for UCL and Camden in the context of national and local lock-downs, annotated with announcements and other important events.
000
Steven Murdoch @steven.murdoch.is · 24/07/2026
I spoke to @smaurizi.bsky.social for a @computerweekly.bsky.social article on smartphone security, particularly how @grapheneos.org can protect journalists’ data. www.computerweekly.com/feature/Jour...
Graphene is good, but not impossible to crack

What does Murdoch think about GrapheneOS? 

“I would not go as far as to say the hardware is impossible to crack, but experience has shown that even some of the best forensic software currently is incapable of obtaining data from GrapheneOS devices without knowledge of the passcode, particularly if the device has been freshly rebooted,” says Murdoch.

“GrapheneOS offers enhanced security compared to Android because Google doesn’t consider these features worth the resulting inconvenience to users, performance loss, or development effort,” he adds.

Additionally, GrapheneOS disables user-tracking features that Google wants to retain to support its business and that of its partners. “The users of GrapheneOS prioritise security, so are willing to make sacrifices in other aspects, and its business model does not depend on user tracking,” he says.
133
Steven Murdoch @steven.murdoch.is · 05/06/2026
I spoke to The Guardian about Anthropic’s call for mechanisms to slow the development of frontier AI capabilities. www.theguardian.com/technology/2...
If calling for a worldwide conversation on AI risk is in contradiction with supporting a US spy agency to – potentially – attack Iran and China with cyberweapons, neither development is “surprising” given the AI company’s past actions, said Steven Murdoch, a professor at University College London.

“Anthropic might give the impression of being warm and fuzzy, but their definition of AI safety is narrow. Supporting US authorities in the development of offensive capabilities has never been something they have spoken against,” he said.

Murdoch said that Anthropic’s post did not offer evidence of any step changes in the progress of AI capabilities.

“It is true that there’s some evidence that AI capabilities have increased and continue to increase with no limits becoming immediately clear,” he said, but he added: “I don’t think anything has fundamentally changed today that has caused Anthropic to publish this article.”
030
Steven Murdoch @steven.murdoch.is · 16/04/2026
Claude Opus 4.7 is out, and I’ve been interfacing it with the National Rail Live Departure Boards API. I leave you with a poem inspired by the current departures from St Pancras station.
⏺ At St Pancras, a Quarter Past Nine
  after John Betjeman

  The gothic clock of Scott's red brick
      Regards the concourse, vast and pale,
  Where escalators, sorely sick,
      On platform A have ceased to sail;
  The up-bound stair from platform B
  Is likewise fixed in lethargy.

  The eight-and-forty for St Albans
      Has hung her head these thirty-seven —
  She creeps at last, her carriages ailing,
      Toward a Hertfordshire half-heaven
  Where Knebworth lawns and Harpenden
  Receive the late commuting men.

  Platform A: the Brighton flyer,
      Two small minutes out of true,
  Breathes past Farringdon, and higher
      Gothic vaults of Blackfriars' view —
  Where, soon behind, the Rainham train
  Tilts eastward through the Kentish rain.

  O litany of riverside stops!
      Greenwich, Maze Hill, Westcombe Park,
  Charlton's terraces, corner shops,
      Woolwich Dockyard after dark;
  Plumstead, Belvedere, Erith's gleam,
  Slade Green sidings under steam;

  Then Dartford, Stone Crossing, Greenhithe
      (For Bluewater's consumer shrine),
  Swanscombe chalk-pits, Northfleet, blithe
      Gravesend where the marshes shine —
  Higham, Strood, and Rochester's keep,
  Chatham, Gillingham, Rainham's sleep.

  But spare a thought, at twelve-past-nine,
      For Sutton, London SM1 —
  Her train is cancelled on the line,
      Her passengers, their evening done,
  Shall shuffle to the Northern Line
  And dream of semis, trim and fine.

  Beyond, a gentler warning comes:
      Through Stevenage, ten minutes late;
  From Streatham down where Wimbledon hums,
      A twenty-minute verdict's weight.
  So stand beneath the station's span
  And pity the commuting man.
000
Steven Murdoch @steven.murdoch.is · 14/04/2025
AI-based scam checkers are gaining popularity but I would be cautious in following their advice unless the company is willing to stand behind it. For example, Metro Bank makes bold claims but the fine print absolves them of any responsibility for errors. www.metrobankonline.co.uk/ways-to-bank...
13.7.             The AI-generated content and information is provided for general information purposes only and is not intended to constitute or substitute legal or other professional advice of any kind whatsoever. The AI-generated content and information is not intended or implied to be a substitute for professional advice.
13.8.             You are encouraged to confirm any information obtained from or through Silver with other sources and review all information provided. Please do not disregard professional advice or delay seeking advice because of something you have read on our website or in the AI-generated content and information.
13.9.             We make no representations about the suitability, reliability, timeliness, comprehensiveness, and accuracy of the AI-generated content and information, and other content produced by Silver.
141
Steven Murdoch @steven.murdoch.is · 07/10/2024
Along with Sir Peter Fraser, I'll be speaking at the Inner Temple on the reliability of electronic evidence. The event is open to the public, so if you're interested in the topic, you can join in person or online. www.innertemple.org.uk/events/?id=E...
The Use of Electronic Evidence in the Law
021
Steven Murdoch @steven.murdoch.is · 11/09/2024
Interestingly, the EU proposal introduces liability for “electronic communications service providers”. The banking industry has been lobbying for years to get (primarily) Facebook to cover the cost of reimbursements. There’s no UK proposal for this (so far).
Where informed by a payment service provider of the occurrence of the type of fraud as referred to in paragraph 1, electronic communications services providers shall cooperate closely with payment service providers and act swiftly to ensure that appropriate organizational and technical measures are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address. If the electronic communications service providers do not remove the fraudulent or illegal content, after being informed of its occurence, they shall refund the payment service provider the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without any delay, reported the fraud to the police and notified its payment service provider.
000
Steven Murdoch @steven.murdoch.is · 11/09/2024
Previously the EU reimbursement only applied when the criminal impersonates the bank, but now it’s been expanded to any type of impersonation.
Where a payment services user who is a consumer was manipulated by a third party pretending to be an employee of the consumer’s payment service provider or any other relevant entity of a public or private nature using the name or e-mail address or telephone number of that entity unlawfully and that manipulation gave rise to subsequent fraudulent authorised payment transactions, the payment service provider shall refund the consumer the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without any delay, reported the fraud to the police and notified its payment service provider.
100
Steven Murdoch @steven.murdoch.is · 28/08/2024
If you want to take the direct route to your gates and avoid the crowded shopping area, you’ll be charged £10 per person for the privilege.
FastTrack plus charge, allowing passengers to avoid the shops.Map of Stansted Airport showing path forcing passengers through the shops before getting to the gates.
010
Steven Murdoch @steven.murdoch.is · 28/08/2024
At Stansted Airport, notorious for an unpleasant experience (long queues, too few seats, routes forcing passengers through shops, …) someone decided that the real problem is the signs saying “Wait for gate” and should instead be “Relax”.
Stansted Airport departures showing “Relax” by flights for which gate information is unavailable.
120
Steven Murdoch @steven.murdoch.is · 16/08/2024
I’m pleased the article managed to include one of the more subtle points – better security features aren’t always better for fraud victims.
Sometimes, members of the public contact Prof Murdoch when they are having trouble proving to their bank that they have been the victim of fraud.

“If the transaction was done by magstripe, then it’s a very easy argument to say someone copied it,” says Prof Murdoch as he points out the irony. “But if the transaction was one of the more secure methods - then it’s much harder.”
020
Steven Murdoch @steven.murdoch.is · 31/10/2023
Personally, I'm pleased to see this development. Competition and consumer choice is a powerful mechanism for change, when it is informed by good data. By the way, what’s going on with Dzing Finance – 19% of payments received are fraudulent! /ends
Volume of APP fraud received per million transactions (non-directed PSPs). Largest value is Dzing Finance with 187,695 fraudulent transactions per million.
100
Steven Murdoch @steven.murdoch.is · 31/10/2023
Statistics on authorized push payment from the PSR are interesting in their own right but also breaks new ground in that they differentiate between banks’ security. The banking industry has published good aggregate statistics but pushed hard against separating it per bank. 🧵 1/3
Chart showing the percentage of reported APP fraud losses refunded by value.
100