Sign in

Steven Murdoch

@steven.murdoch.is
1.3K followers 221 following 123 posts

Professor of Security Engineering; Head of UCL Information Security Research Group @sec.cs.ucl.ac.uk; Director Open Rights Group. 🐘 mastodon.social/@sjmurdoch 🐦 @sjmurdoch 🌍 murdoch.is

PostsRepliesMedia
Steven Murdoch @steven.murdoch.is · 18/09/2026
Does anyone know what happened to Thistle Technologies? They seemed to be doing some interesting things, but now their website (thistle.tech) has been down for a while.
thistle.tech
000
Steven Murdoch @steven.murdoch.is · 08/09/2026
The game is a treasure hunt for a hidden radio transmitter, using a signal-strength meter. The only requirements are a browser and a few micro:bits. It includes a lesson plan and worksheet for in-depth exploration, plus a quick start to just play the game. www.benthamsgaze.org/2026/09/08/a...
benthamsgaze.org
A radio treasure hunt for National Coding Week – Bentham’s Gaze
020
Steven Murdoch @steven.murdoch.is · 08/09/2026
It’s #NationalCodingWeek next week, so I've published a resource on using the BBC @microbit.org to play a game that explores how radio waves travel, get blocked by/reflected off obstacles, and the challenges of measuring strong signals that can overload sensors.
BBC micro:bit
101
Steven Murdoch @steven.murdoch.is · 31/08/2026
It even has a @quint-lang.org model of the UI. This found one UI flow bug and one in Apalache. Again this is overkill for a trivial application but makes for an interesting case study in a low steaks environment. github.com/apalache-mc/...
github.com
[BUG] Unhandled NoSuchElementException in SetInRule when a fold's lambda tests membership in a singleton set literal · Issue #3479 · apalache-mc/apalache
Impact Not blocking: there is a one-line workaround (below). But the failure is an unhandled Scala exception rather than a diagnostic, and the trigger is very hard to see from the spec — the same s...
010
Steven Murdoch @steven.murdoch.is · 31/08/2026
The tool is at sjmurdoch.github.io/reverse-sear/ with source at github.com/sjmurdoch/re.... It is 100% Claude Code generated so take any claim with a pinch of salt (but the first steaks it helped cook were delicious). For the science behind reverse-searing, see www.seriouseats.com/reverse-sear...
sjmurdoch.github.io
Reverse Sear Pilot
Fits a physical heating model to probe readings and says when to next open the oven.
100
Steven Murdoch @steven.murdoch.is · 31/08/2026
Graph showing temperature curve of cooking two steaks.
100
Steven Murdoch @steven.murdoch.is · 31/08/2026
With the availability of LLMs we can now apply ridiculous levels of polish to trivial problems. In this vein, here’s a tool to optimise the reverse-sear of a steak when your thermometer can’t be left in the oven by fitting a three-parameter physical model to measurements.
210
Steven Murdoch @steven.murdoch.is · 18/08/2026
Incidentally my first academic paper was on watermarking, as applied to game bots. The covert communication allowed a team to coordinate a better outcome than any individual player could achieve. murdoch.is/papers/ih04c...
000
Steven Murdoch @steven.murdoch.is · 18/08/2026
I spoke to The Guardian about Claude’s content watermarking. As long as it only modifies how the existing random number generator works, it should have no measurable effect on quality. www.theguardian.com/technology/2...
However, LLMs already do not make the best choices. “There’s already randomness involved in any of these large language models,” said Murdoch. “It’s pretty essential to how they work. If it wasn’t for this randomness, then they’d get stuck in loops and start repeating the same thing over and over again.”

In other words, a chatbot does not necessarily decide to call running water a “stream” as opposed to a “brook” because the latter might have a more old-fashioned register. The model does not contemplate these choices: it makes them by chance.
141
Steven Murdoch @steven.murdoch.is · 11/08/2026
A prompt that’s been very helpful at getting Claude to improve a user-facing app with minimal interaction from me has been to ask it to do a cognitive walkthrough with a given persona. It’s not great at coming up with good personas (IME) but if you give it one it can run with it.
Take on the persona of [INSERT PERSONA DEFINITION HERE].

Perform a cognitive walkthough. Update the app so that at each stage:

The user will try to achieve the right result
The user will notice that the correct action is available
The user will associate the correct action with the result they're trying to achieve
After the action is performed, the user will see that progress is made toward the goal
This persona is only one of several that will use the app, so take care not to compromise existing qualities of the app without good reason.

Add a summary of each cognitive walkthrough performed to COGNITIVE-WALKTHROUGHS.md, including the persona, issues identified, and changes made.
010
Steven Murdoch @steven.murdoch.is · 28/07/2026
And a demo of what the dataset makes possible: an interactive chronology of 347 dated events, plotting UCL’s decisions against national restrictions and its own case curve, each with a verbatim quote from the source it came from. sjmurdoch.github.io/uclcovid-tim...
Screenshot of the interactive UCL COVID-19 response visualisation showing case statistics for UCL and Camden in the context of national and local lock-downs, annotated with announcements and other important events.
000
Steven Murdoch @steven.murdoch.is · 28/07/2026
National COVID-19 figures couldn’t tell a department whether to hold a seminar next week. So from 2020 to 2022 I collected UCL’s daily case counts and turned them into an early-warning chart. I’ve now archived all of it plus 168 newsletters for context. www.benthamsgaze.org/2026/07/26/u...
benthamsgaze.org
UCL’s response to the COVID-19 pandemic: a historical archive – Bentham’s Gaze
101
Steven Murdoch @steven.murdoch.is · 24/07/2026
I spoke to @smaurizi.bsky.social for a @computerweekly.bsky.social article on smartphone security, particularly how @grapheneos.org can protect journalists’ data. www.computerweekly.com/feature/Jour...
Graphene is good, but not impossible to crack

What does Murdoch think about GrapheneOS? 

“I would not go as far as to say the hardware is impossible to crack, but experience has shown that even some of the best forensic software currently is incapable of obtaining data from GrapheneOS devices without knowledge of the passcode, particularly if the device has been freshly rebooted,” says Murdoch.

“GrapheneOS offers enhanced security compared to Android because Google doesn’t consider these features worth the resulting inconvenience to users, performance loss, or development effort,” he adds.

Additionally, GrapheneOS disables user-tracking features that Google wants to retain to support its business and that of its partners. “The users of GrapheneOS prioritise security, so are willing to make sacrifices in other aspects, and its business model does not depend on user tracking,” he says.
133
Steven Murdoch @steven.murdoch.is · 17/07/2026
I was interviewed for Computerphile on my analysis of hidden messages within the GPS signals and what message they might carry (and to whom). youtu.be/2Q6OvYjOJi0
youtu.be
GPS Hidden Messages - Computerphile
YouTube video by Computerphile
020
Reposted by Steven Murdoch
Steven Murdoch @steven.murdoch.is · 24/06/2026
The corrected and expanded article on my exploration of GPS special messages is available at sjmurdoch.github.io/gps-special-.... Additionally, this is now mobile-friendly and accompanied by detailed footnotes, allowing results to be verified against the published dataset. 5/
sjmurdoch.github.io
The Empty Field That Wasn't: GPS, OTAD and Two Decades of Encrypted Broadcasts
What 24 million GPS special messages reveal about military rekeying on a public channel.
142
Steven Murdoch @steven.murdoch.is · 24/06/2026
My pet peeve is when universities fall to Conway's law and ship their org chart as a website. It’s a well-known failure, and yet it keeps happening. assets.publishing.service.gov.uk/media/57a08d...
assets.publishing.service.gov.uk
020
Steven Murdoch @steven.murdoch.is · 24/06/2026
Finally, there is one message which, on first inspection, appears to be a plaintext leak: “+81H DAYS”. However, analysis suggests that it is more likely just a coincidence. The discussion forum is open, and I’d welcome comments on this or other findings. github.com/sjmurdoch/gp... 6/6
github.com
Is “+81H DAYS” a plaintext leak? · sjmurdoch gps-special-messages · Discussion #5
One payload in the corpus ends in a legible English word. PRN 6 transmitted it twice on 18 July 2019, at 00:10:48 and 00:23:18 UTC: +'X1D8A°PTA9F+81H DAYS It is a genuine broadcast. Both observatio...
100
Steven Murdoch @steven.murdoch.is · 24/06/2026
The corrected and expanded article on my exploration of GPS special messages is available at sjmurdoch.github.io/gps-special-.... Additionally, this is now mobile-friendly and accompanied by detailed footnotes, allowing results to be verified against the published dataset. 5/
sjmurdoch.github.io
The Empty Field That Wasn't: GPS, OTAD and Two Decades of Encrypted Broadcasts
What 24 million GPS special messages reveal about military rekeying on a public channel.
142
Steven Murdoch @steven.murdoch.is · 24/06/2026
On my side, I found that some special messages were missed because the decoder did not handle bit-flipped messages properly. After fixing the issue, I’ve re-done the analysis. The substantive conclusions remain unchanged, but some numbers have been updated. 4/
110
Steven Murdoch @steven.murdoch.is · 24/06/2026
Also, @neetintel.bsky.social looked for correlations between the GPS special messages and Emergency Action Messages (EAMs). The correlation result was negative, but still interesting work and worth reading, particularly the discussion around the different systems. github.com/sjmurdoch/gp... 3/
github.com
Informational: Relationship between HFGCS EAMs and GPS Subframe 4, Page 17 data? (none found) · sjmurdoch gps-special-messages · Discussion #4
For the last few years I have worked at a 'professional hobbyist' level on transcribing and analyzing Emergency Action Messages (EAMs) broadcast over the US military's High Frequency Global Communi...
100
Steven Murdoch @steven.murdoch.is · 24/06/2026
Dominik Bay replicated my results and extended the analysis subsequent to my cut-off date (2026-01-23). He found that the message rotation rate has increased again, back to that of the assumed OTAD/OTAR operational period. github.com/sjmurdoch/gp... 2/
111
Steven Murdoch @steven.murdoch.is · 24/06/2026
Since the original publication of my Inside GNSS article on hidden messages within the GPS signal (The Empty Field That Wasn’t: GPS, OTAD and Two Decades of Encrypted Broadcasts), there have been a few developments and updates. 🧵 1/
122
Steven Murdoch @steven.murdoch.is · 08/06/2026
It was also covered in the @wired.com Security Newsletter www.wired.com/story/securi... and discussed on Hacker News news.ycombinator.com/item?id=4841...
wired.com
Crypto-Funded Chinese Peptide Labs Are Booming
Plus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more.
000
Steven Murdoch @steven.murdoch.is · 08/06/2026
My article on hidden messages within GPS signals was featured on @404media.co. www.404media.co/the-u-s-mili...
404media.co
The U.S. Military Quietly Turned GPS Into a Global ‘Numbers Station,’ Evidence Suggests
A random sequence in an innocuous GPS message field is likely encrypted traffic from the U.S. military's system for remotely updating cryptographic keys around the world.
100
Steven Murdoch @steven.murdoch.is · 05/06/2026
I spoke to The Guardian about Anthropic’s call for mechanisms to slow the development of frontier AI capabilities. www.theguardian.com/technology/2...
If calling for a worldwide conversation on AI risk is in contradiction with supporting a US spy agency to – potentially – attack Iran and China with cyberweapons, neither development is “surprising” given the AI company’s past actions, said Steven Murdoch, a professor at University College London.

“Anthropic might give the impression of being warm and fuzzy, but their definition of AI safety is narrow. Supporting US authorities in the development of offensive capabilities has never been something they have spoken against,” he said.

Murdoch said that Anthropic’s post did not offer evidence of any step changes in the progress of AI capabilities.

“It is true that there’s some evidence that AI capabilities have increased and continue to increase with no limits becoming immediately clear,” he said, but he added: “I don’t think anything has fundamentally changed today that has caused Anthropic to publish this article.”
030
Steven Murdoch @steven.murdoch.is · 04/06/2026
For the tl;dr, I wrote a summary of my analysis of the GPS Special Message “number station”, including entropy measurement, duplicated strings, a mysterious new “TEXT” prefix, and the system’s relationship with military key distribution. www.benthamsgaze.org/2026/06/02/t...
051
Steven Murdoch @steven.murdoch.is · 03/06/2026
The source code is available on GitHub, and the data is on Zenodo. I’d welcome follow-up analysis. github.com/sjmurdoch/gp...
github.com
GitHub - sjmurdoch/gps-special-messages: Analysis of the GPS Special Message field
Analysis of the GPS Special Message field. Contribute to sjmurdoch/gps-special-messages development by creating an account on GitHub.
020
Steven Murdoch @steven.murdoch.is · 03/06/2026
Try the PDF cdn.coverstand.com/61061/865273...
cdn.coverstand.com
120
Steven Murdoch @steven.murdoch.is · 02/06/2026
For 19 years, GPS satellites have secretly broadcast a “numbers station” in their signals. We decoded 12M messages: a 2011 flash where 31 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. lsc-pagepro.mydigitalpublication.com/publication/...
lsc-pagepro.mydigitalpublication.com
Inside GNSS Media & Research • May/June 2026 • 62
621985
Steven Murdoch @steven.murdoch.is · 16/04/2026
Claude Opus 4.7 is out, and I’ve been interfacing it with the National Rail Live Departure Boards API. I leave you with a poem inspired by the current departures from St Pancras station.
⏺ At St Pancras, a Quarter Past Nine
  after John Betjeman

  The gothic clock of Scott's red brick
      Regards the concourse, vast and pale,
  Where escalators, sorely sick,
      On platform A have ceased to sail;
  The up-bound stair from platform B
  Is likewise fixed in lethargy.

  The eight-and-forty for St Albans
      Has hung her head these thirty-seven —
  She creeps at last, her carriages ailing,
      Toward a Hertfordshire half-heaven
  Where Knebworth lawns and Harpenden
  Receive the late commuting men.

  Platform A: the Brighton flyer,
      Two small minutes out of true,
  Breathes past Farringdon, and higher
      Gothic vaults of Blackfriars' view —
  Where, soon behind, the Rainham train
  Tilts eastward through the Kentish rain.

  O litany of riverside stops!
      Greenwich, Maze Hill, Westcombe Park,
  Charlton's terraces, corner shops,
      Woolwich Dockyard after dark;
  Plumstead, Belvedere, Erith's gleam,
  Slade Green sidings under steam;

  Then Dartford, Stone Crossing, Greenhithe
      (For Bluewater's consumer shrine),
  Swanscombe chalk-pits, Northfleet, blithe
      Gravesend where the marshes shine —
  Higham, Strood, and Rochester's keep,
  Chatham, Gillingham, Rainham's sleep.

  But spare a thought, at twelve-past-nine,
      For Sutton, London SM1 —
  Her train is cancelled on the line,
      Her passengers, their evening done,
  Shall shuffle to the Northern Line
  And dream of semis, trim and fine.

  Beyond, a gentler warning comes:
      Through Stevenage, ten minutes late;
  From Streatham down where Wimbledon hums,
      A twenty-minute verdict's weight.
  So stand beneath the station's span
  And pity the commuting man.
000
Steven Murdoch @steven.murdoch.is · 16/04/2026
MCP gives AI tools access to powerful capabilities but is notorious for heavy token use. AXI is a promising token-efficient alternative, but it relies on predicting typical tool usage. I've proposed a modification where tools self-tune through an OODA loop. github.com/kunchenguid/...
github.com
Add §11: Usage-driven improvement via OODA loop by sjmurdoch · Pull Request #29 · kunchenguid/axi
Motivation AXI §1–10 tell you what to optimize for, but not how to know whether you got it right. Every AXI tool ships with best-guess defaults — 3-4 default fields, a row limit, a truncation thres...
010
Steven Murdoch @steven.murdoch.is · 01/12/2025
Reuters were accused of acting illegally in guessing the URL of an unreleased report in 2002. I didn’t hear anything after the initial reports so presume it was quietly dropped or settled. blog.citp.princeton.edu/2002/10/31/i...
blog.citp.princeton.edu
Intentia vs. Reuters: A (Slightly) Contrarian View - CITP Blog
The recent dispute between Intentia and Reuters has gotten lots of online attention, most of it scornful of Intentia's position. I think Intentia is wrong, but it's a closer call than most online comm...
011
Steven Murdoch @steven.murdoch.is · 12/08/2025
UCL Computer Science are hiring Section Managers to support the development and delivery of teaching, research, and strategy within their section. I’ll be leading the Foundational Computer Science section, where the InfoSec group is based. www.ucl.ac.uk/work-at-ucl/...
041
Reposted by Steven Murdoch
UCL InfoSec @sec.cs.ucl.ac.uk · 22/07/2025
“$5 Wrench Attacks: When Cryptocurrency Crime Get Physical”, a post on Bentham’s Gaze by Marilyne Ordekian discussing when XKCD comics become reality – www.benthamsgaze.org/2025/07/22/5...
Actual actual reality: nobody cares about his secrets. (Also, I would be hard-pressed to find that wrench for $5.)
131
Steven Murdoch @steven.murdoch.is · 06/06/2025
I am recruiting mental-health experts (clinical psychologists and psychiatrists) for an in-person workshop in London to discuss a mobile app for mental health care. Participants will receive £500+expenses for their time. If you might be interested please email s.murdoch@ucl.ac.uk
023
Reposted by Steven Murdoch
UCL InfoSec @sec.cs.ucl.ac.uk · 15/05/2025
On our new paper published at IEEE Security and Privacy – “A Privacy Framework for Research Using Social Media Data”, a summary by Kyle Beadle. www.benthamsgaze.org/2025/05/15/a...
benthamsgaze.org
A Privacy Framework for Research Using Social Media Data
Social media data enables researchers to understand current events and human behavior with unprecedented ease and scale. Yet, researchers often violate user privacy when they access, process, and stor...
022
Steven Murdoch @steven.murdoch.is · 05/05/2025
If it needs to interoperate with Signal I would think it would be easier to modify Signal to include the new audit-friendly protocol than add audit to Signal. A lot of what Signal includes (P2P key verification, PFS, post-compromise security, deniable) are contrary to the goal of universal logging.
120
Steven Murdoch @steven.murdoch.is · 05/05/2025
The major selling points of these companies is self-hosting the key management server, and sometimes even more of the infrastructure. This would need to be part of the product offering too.
000
Steven Murdoch @steven.murdoch.is · 05/05/2025
I can see the idea but that’s a hard market to get into. You’d need a security cleared technical sales team, FIPS certifications, etc. it would be a major departure for the company culture. These companies also often value having ex- military/intelligence staff. I can see conflicts there.
120
Steven Murdoch @steven.murdoch.is · 05/05/2025
In terms of UX I think that’s achievable, e.g. the UK app in this space looks pretty much like WhatsApp. For ecosystem, indeed that’s a problem because government requirements are anti-requirements for pretty much everyone else. apps.apple.com/gb/app/armou...
apps.apple.com
‎Armour Mobile
‎Armour Mobile provides secure voice calls, video calls, 1-1 and group messaging, voice and video conference calls, file attachments, message burn and sent/ received/read message status. Protecting bu...
010
Steven Murdoch @steven.murdoch.is · 05/05/2025
It’s just a bizarre situation. When I was looking into MIKEY-SAKKE I found a whole ecosystem of government messengers with NATO security certifications and clearances. The protocol is (for better or worse) very amenable to centralised logging. And yet they picked a hacked-up Signal.
0103
Steven Murdoch @steven.murdoch.is · 14/04/2025
Nationwide offers the only service I’m aware of that backs up their advice with a guarantee. I don’t know how it works but I suspect that if AI is involved, there’s human verification of decisions. www.nationwide.co.uk/help/fraud-a...
nationwide.co.uk
Scam Checker Service | Nationwide
As a mutual, we want to do everything we can to keep our members safe from scammers. Read more about our Scam Checker Service, designed to keep you safe.
021
Steven Murdoch @steven.murdoch.is · 14/04/2025
AI-based scam checkers are gaining popularity but I would be cautious in following their advice unless the company is willing to stand behind it. For example, Metro Bank makes bold claims but the fine print absolves them of any responsibility for errors. www.metrobankonline.co.uk/ways-to-bank...
13.7.             The AI-generated content and information is provided for general information purposes only and is not intended to constitute or substitute legal or other professional advice of any kind whatsoever. The AI-generated content and information is not intended or implied to be a substitute for professional advice.
13.8.             You are encouraged to confirm any information obtained from or through Silver with other sources and review all information provided. Please do not disregard professional advice or delay seeking advice because of something you have read on our website or in the AI-generated content and information.
13.9.             We make no representations about the suitability, reliability, timeliness, comprehensiveness, and accuracy of the AI-generated content and information, and other content produced by Silver.
141
Steven Murdoch @steven.murdoch.is · 07/04/2025
I have an open PhD position at @sec.cs.ucl.ac.uk on applying traffic-analysis resistance techniques to protect industrial control systems. Full funding is available for home-fee status students (deadline 15 April). www.ucl.ac.uk/security-cri...
078
Steven Murdoch @steven.murdoch.is · 30/03/2025
And I’d add that Telegram’s janky cryptography doesn’t achieve anything normal encryption can’t provide. Signal uses some interesting constructions but did so to offer better security (and largely succeeded).
231
Steven Murdoch @steven.murdoch.is · 27/03/2025
I'd view the consultation as an opportunity to revisit how electronic evidence should be handled, and disclosure is obviously a critical part of that. Flipping the presumption is just a mechanism to impose disclosure requirements on a party that is reluctant to do so.
200
Steven Murdoch @steven.murdoch.is · 27/03/2025
You raise a good point. In my experience, the presumption is rarely explicitly mentioned in disputes. And it's not entirely clear whether PACE s69 would worked out better (the Post Office included PACE s69 statements even when they were not needed).
210
Reposted by Steven Murdoch
Open Rights Group @openrightsgroup.org · 11/03/2025
Whisper it, the showdown over Apple encryption is THIS WEEK ⏱️ 🤐 A secret tribunal will hear the appeal against the government’s order to carve a backdoor into Apple’s encrypted services. 🛑 Our cybersecurity and privacy shouldn’t be decided in the shadows. www.computerweekly.com/news/3666203...
computerweekly.com
Secret London tribunal to hear appeal in Apple vs government battle over encryption | Computer Weekly
The decision by home secretary Yvette Cooper to issue a Technical Capability Notice requiring Apple to give UK law enforcement and intelligence services “backdoor” access to data stored by Apple’s cus...
11218
Steven Murdoch @steven.murdoch.is · 11/03/2025
I found this video showing the tracking information. The Solong was heading directly towards the tanker for hours before the collision. I’ve no idea what could have caused such a failure. youtu.be/Ex6OpRiuflA?...
youtu.be
Container ship SOLONG collision with anchored Oil Tanker STENA IMMACULATE off the UK coast
YouTube video by VesselFinder
110
Steven Murdoch @steven.murdoch.is · 06/03/2025
Until now, the UK government recommended that individuals at high risk, like legal professionals, enable Apple Advanced Data Protection (ADP). Apple disabled ADP following government pressure, and now the NCSC quietly deleted their guidance recommending ADP.
02211