Nicolas Christin
@nc2y.bsky.social
500 followers 220 following 120 posts
Prof. at Carnegie Mellon University. Computer security, online crime, and assorted online seediness. Reformed(?) hacker. Economic migrant. 📍 Pittsburgh, PA, mostly 🕸️ https://www.andrew.cmu.edu/user/nicolasc
Posts Media Videos Starter Packs
nc2y.bsky.social
We're hosting the 7th intl' conf. on Advances in Financial Technologies (AFT'25) at Carnegie Mellon on Oct. 8-10. Join us to hear about the latest exciting developments in crypto research. Registration closes on Sept 16!
advfintech.org/aft25/attend...
(Program: advfintech.org/aft25/progra...)
Advances in Financial Technologies
advfintech.org
nc2y.bsky.social
That’s a wrap for me at #usesec25
Conferences should really consider reusing the tag holders, the amount of wasted plastic is staggering
nc2y.bsky.social
“Canadian pharmacist helps run notorious deepfake porn site.”

The online crime jokes write themselves.
nc2y.bsky.social
Ah true but I should try again today then
Reposted by Nicolas Christin
wentaoguo.bsky.social
I'm presenting my USENIX paper "How Researchers De-Identify Data in Practice" at 9am this Thursday. Kudos to my co-authors Paige Pepitone, @adamaviv.bsky.social, and @mmazurek.bsky.social. Come say hi—I am on the academic job market!

Here's the paper: www.usenix.org/conference/u...
#usesec25
Poster for our paper "How Researchers De-Identify Data in Practice"
nc2y.bsky.social
Taro just presented this at #usesec25, and will be manning the poster shortly. If you are around we would love to hear from you.
nc2y.bsky.social
I’m not sure there is a more clichéed Seattle experience than having a latte at a local coffee shop with some salmon on toast while they’re blaring Soundgarden’s “Outshined.”
nc2y.bsky.social
My student Jenny Tang (coadvised with @lujobauer.bsky.social) is making friends at SOUPS with our paper on looking at 10 years of SOUPS papers and reviewing how solid the stats were. Basically: not great, not great at all. (And that includes my own work.)
Paper: www.andrew.cmu.edu/user/nicolas...
www.andrew.cmu.edu
nc2y.bsky.social
We simulated the lookalike address generation process across various software- and hardware-based implementations. One large attacker group appears to use GPUs for this attack! The paper also discusses some defenses. (6/7)
nc2y.bsky.social
We discovered a few large attack entities using clustering techniques. Larger groups are vastly profitable and win against smaller attack groups. We uncovered some attack strategies, such as populations they target, success conditions, and cross-chain attacks. (5/7)
nc2y.bsky.social
We developed a detection system and performed measurements on two years of ETH and BSC. We identified 13x the number of attack attempts reported previously—in all, 270M on-chain attacks targeting 17M victims. 6,633 incidents have caused at least 83.8M USD in losses. (4/7)
nc2y.bsky.social
The attacker generates “lookalike” addresses that resemble the victim’s recipient’s address, engages with the victim to “poison” the transaction history, and fools the victim into sending their assets to the attacker by mistake. (3/7)
nc2y.bsky.social
Background: Crypto wallet addresses are usually impossible to memorize. As a result, users often select addresses from their recent transaction history, which facilitates phishing-like attacks: blockchain address poisoning. (2/7)
Reposted by Nicolas Christin
drmikewiser.bsky.social
Just because your prof didn't file an academic dishonesty report does not mean that they don't know you cheated.

Knowing you did it and proving it to the hearing board are two different thresholds.
mikefeigin.bsky.social
What is common knowledge in your field, but shocks outsiders?

Scientists and governments aren’t colluding to hide the cure for cancer.
aaronsofaer.bsky.social
What is common knowledge in your field, but shocks outsiders?

Almost all of the bugs and problems and breakage in the software you use is known to the engineers, we just aren't allowed to fix it. Gotta ship new features.
nc2y.bsky.social
Details: it's likely that there are some symbol mismatches between some homebrew libraries linked against old OpenGL libs and the new OpenGL shipping with Sequoia. This drove me nuts. So I'm posting this here in hopes people don't waste their time. Oh, and don't ask an LLM, they're clueless.
nc2y.bsky.social
PSA: If you're using homebrew, and discovered that MAME crashes w/ a Bus Error upon startup after upgrading to Sequoia, 1) update mame.ini so that the line containing gl_lib points to /System/Library/Frameworks/OpenGL.framework/Libraries/libGLVMPlugin.dylib 2) launch w/ DYLD_LIBRARY_PATH="" mame
nc2y.bsky.social
🧵 about a new paper by my amazing students and collaborators. To appear this week at SIGMETRICS. 👇
Reposted by Nicolas Christin
cmu.edu
CMU researchers are using personalized models to decode how cancer behaves in individual patients, one of medicine's toughest challenges.

Through individualized data and insights, their work revealed hidden #cancer subtypes that could inform treatment and improve survival predictions.

#Research
CMU Researchers Build Personalized Models To Advance Precision Cancer Care
Researchers from Carnegie Mellon University’s School of Computer Science developed a new approach to bridge this gap between available data and actionable insight, creating personalized models to help...
www.cmu.edu
nc2y.bsky.social
Looking for a home for your great scientific result in fintech that is almost all written up and ready to go? The AFT deadline is in less than 24 hours…

aftconf.github.io/aft25/index....
Advances in Financial Technologies
aftconf.github.io
nc2y.bsky.social
Jokes aside yeah it seems like this could work.
nc2y.bsky.social
Do you live in England, by any chance?