
Principal Scientist, PARC; founder of RavenWhite; collaborator at www.SecurityCartoon.com
San Francisco Bay Area

Principal Scientist, PARC; founder of RavenWhite; collaborator at www.SecurityCartoon.com
San Francisco Bay Area
Using adversarial modeling from the field of cryptography, combined with related modeling of human behavior, I analyse the security of real-life applications and design improved security protocols. The efforts are often aimed at gaining a better understanding of and preventing phishing, pharming, malware spread and click-fraud. My students and I do consulting for the financial industry, allowing us to translate academic insights into better consumer products. My background also involves cryptographic protocol design, theoretical aspects of cryptography, incentive structures, lightweight cryptography and wireless security.
phishing and countermeasures, combined social and technical threats, protocol design, privacy, click-fraud, user interfaces, voting.
(Public Company; 501-1000 employees; Computer & Network Security industry)
October 2007 — Present (8 months)
I am Principal Scientist at PARC, and a member of the security group. I am spending much time on password reset -- see Blue Moon Authentication http://I-forgot-my-password.com.
(Privately Held; 1-10 employees; Computer & Network Security industry)
2005 — Present (3 years)
We believe that phishing is best fought using server-side measures, thereby avoiding educational requirements, support calls, and fears of spoofed requests to "update" software. My role in RavenWhite involves developing the vision of where the threats are headed; coordination of product development; and client contacts.
(Educational Institution; Computer & Network Security industry)
August 2004 — Present (3 years 10 months)
IUB has made a major effort in building a strong security group (see http://security.informatics.indiana.edu/), with support from the Center for Applied Cybersecurity Research (http://cacr.iu.edu/) and various funding agencies. We are successfully building relationships with other universities, government agencies, corporate entities and trade groups. Given that most faculty members of the group joined in 2004, we have an unusually low student-to-faculty ratio, which translates into a very dynamic and personal feel.
(Public Company; rsas; Computer & Network Security industry)
May 2000 — August 2004 (4 years 4 months)
My research was focused on finding the next threats and applications; I made efforts to steer the RSA research towards wireless research, RFID research, and phishing research. Although these directions were not immediately embraced, they are now part of the central research foci of RSA Labs.
(Public Company; LU; Computer & Network Security industry)
June 1997 — May 2000 (3 years)
(Privately Held; 1-10 employees; Computer Software industry)
1985 — 1992 (7 years)
Ran a small software company producing educational software for the Swedish market. Did pretty well until imported software killed us.
PhD, computer science, 1993 — 1997
MSc (civilingenjor), computer engineering (datateknik), 1987 — 1992
Visiting Research Scholar of Anti-Phishing Working Group; member of Internatonal Association for Cryptologic Research and International Identity Theft Technology Council; founding member of eFraudNetwork forum.