Junade Ali | |
---|---|
Born | 1996 (age 27–28) [1] |
Nationality | British |
Citizenship | United Kingdom |
Known for | Cybersecurity research |
Scientific career | |
Thesis | Cryptographic Hash-Based Anonymisation of Wireless Unique Identifiers (2022) |
Doctoral advisor | Vladimir Dyo |
Junade Ali CEng FIET is a British computer scientist known for research in cybersecurity. [2] [1] [3] [4] [5] [6] [7]
Ali studied for a Master of Science degree aged 17, was awarded Chartered Engineer status at 23 and became the youngest ever Fellow of the IET at 27. [2] [8] [9] [10] [11] He holds a PhD in cryptography. [12] [13]
He started his research career working on the UK's Motorway Incident Detection and Automatic Signalling network and working on the maximum coverage problem in road traffic sensor placement. [14] [15] [16] [17]
Ali later worked for cybersecurity firm Cloudflare as an engineering manager where he worked on developing network diagnostic tooling, a security operations center and safety-engineered natural language processing. [18] [19] [20] [21] [22]
In February 2018, Ali created the first Compromised Credential Checking protocol (using k-anonymity and cryptographic hashing) to anonymously verify whether a password was in a data breach without fully disclosing the searched password. [23] [24] This protocol was implemented as a public API and is now consumed by multiple websites and services, including password managers [25] [26] and browser extensions. [27] [28] This approach was later replicated by Google's Password Checkup feature and by Apple iOS. [29] [30] [31] [32] Ali worked with academics at Cornell University to develop new versions of the protocol known as Frequency Smoothing Bucketization (FSB) and Identifier-Based Bucketization (IDB). [33] In March 2020, cryptographic padding was added to the protocol. [34] Ali's research was praised in Canadian cryptographer Carlisle Adams book, Introduction to Privacy Enhancing Technologies. [35]
Ali conducts cybersecurity research on North Korea and provides expert commentary to journalists at NK News. [36] [37] [38] [39]
In January 2022, Ali told journalists at NK News and Reuters that he had observed North Korea's internet being taken offline in a second major outage that month following a missile test, Ali told journalists that data he collected was consistent with a DDoS attack. [40] [41] [42] [43] [44] South Korean Government officials responded by saying "we are monitoring the situation under coordination with relevant government agencies," without elaborating further. [45] Wired journalist, Andy Greenberg, later confirmed the downtime resulted from an attack and reported that a single American hacker by the pseudonym P4x had shared evidence of his responsibility. [46] In November 2022, news outlets reported that Ali had said that North Korea's internet was hit by the largest outages in months amid increased missile launches and other military activity, with Ali saying he'd "be surprised if this wasn’t an attack". [47] [48] In 2023, Ali told reporters at NK News that North Korea faced another 'total internet outage' in advance of the reported Malligyong-1 satellite launch. [49]
Ali's consultancy clients have included cybersecurity firm Risk Ledger and engineering productivity company Haystack Analytics. [8] [50] In July 2021, Ali commissioned a study by Survation for Haystack Analytics which found that 83% of software developers were suffering from burnout. [51] [52] [53] The poll also found 57% of software engineers agreed "to a great extent" or "to a moderate extent" with the phrase "Software reliability at my workplace concerns me". [54] [55] Ali claimed this was "the first time representative opinion polling was used to understand software engineers." [56]
In November 2023, Ali served as principal investigator for an investigation by the software auditing firm Engprax, which identified that 53% of software engineers in the UK have suspected wrongdoing at work with 75% reporting they faced retaliation the last time they reported wrongdoing to their employers. [57] [58] The research also found that Worldpay had used a gagging clause banned by the Financial Conduct Authority and shed new light on gagging clauses by Post Office Limited during the British Post Office scandal. [59] [60] [61] [62] The research also found that "industry-standard" DORA metrics used for evaluating the DevOps performance of engineering teams were solely measuring factors that both software engineers and the wider public thought were least important when using computer systems. [63]
During the COVID-19 pandemic, Ali worked on security improvements to the (Google/Apple) Exposure Notification system used to create public health contact tracing apps. [64] [7]
Junade Ali | |
---|---|
Born | 1996 (age 27–28) [1] |
Nationality | British |
Citizenship | United Kingdom |
Known for | Cybersecurity research |
Scientific career | |
Thesis | Cryptographic Hash-Based Anonymisation of Wireless Unique Identifiers (2022) |
Doctoral advisor | Vladimir Dyo |
Junade Ali CEng FIET is a British computer scientist known for research in cybersecurity. [2] [1] [3] [4] [5] [6] [7]
Ali studied for a Master of Science degree aged 17, was awarded Chartered Engineer status at 23 and became the youngest ever Fellow of the IET at 27. [2] [8] [9] [10] [11] He holds a PhD in cryptography. [12] [13]
He started his research career working on the UK's Motorway Incident Detection and Automatic Signalling network and working on the maximum coverage problem in road traffic sensor placement. [14] [15] [16] [17]
Ali later worked for cybersecurity firm Cloudflare as an engineering manager where he worked on developing network diagnostic tooling, a security operations center and safety-engineered natural language processing. [18] [19] [20] [21] [22]
In February 2018, Ali created the first Compromised Credential Checking protocol (using k-anonymity and cryptographic hashing) to anonymously verify whether a password was in a data breach without fully disclosing the searched password. [23] [24] This protocol was implemented as a public API and is now consumed by multiple websites and services, including password managers [25] [26] and browser extensions. [27] [28] This approach was later replicated by Google's Password Checkup feature and by Apple iOS. [29] [30] [31] [32] Ali worked with academics at Cornell University to develop new versions of the protocol known as Frequency Smoothing Bucketization (FSB) and Identifier-Based Bucketization (IDB). [33] In March 2020, cryptographic padding was added to the protocol. [34] Ali's research was praised in Canadian cryptographer Carlisle Adams book, Introduction to Privacy Enhancing Technologies. [35]
Ali conducts cybersecurity research on North Korea and provides expert commentary to journalists at NK News. [36] [37] [38] [39]
In January 2022, Ali told journalists at NK News and Reuters that he had observed North Korea's internet being taken offline in a second major outage that month following a missile test, Ali told journalists that data he collected was consistent with a DDoS attack. [40] [41] [42] [43] [44] South Korean Government officials responded by saying "we are monitoring the situation under coordination with relevant government agencies," without elaborating further. [45] Wired journalist, Andy Greenberg, later confirmed the downtime resulted from an attack and reported that a single American hacker by the pseudonym P4x had shared evidence of his responsibility. [46] In November 2022, news outlets reported that Ali had said that North Korea's internet was hit by the largest outages in months amid increased missile launches and other military activity, with Ali saying he'd "be surprised if this wasn’t an attack". [47] [48] In 2023, Ali told reporters at NK News that North Korea faced another 'total internet outage' in advance of the reported Malligyong-1 satellite launch. [49]
Ali's consultancy clients have included cybersecurity firm Risk Ledger and engineering productivity company Haystack Analytics. [8] [50] In July 2021, Ali commissioned a study by Survation for Haystack Analytics which found that 83% of software developers were suffering from burnout. [51] [52] [53] The poll also found 57% of software engineers agreed "to a great extent" or "to a moderate extent" with the phrase "Software reliability at my workplace concerns me". [54] [55] Ali claimed this was "the first time representative opinion polling was used to understand software engineers." [56]
In November 2023, Ali served as principal investigator for an investigation by the software auditing firm Engprax, which identified that 53% of software engineers in the UK have suspected wrongdoing at work with 75% reporting they faced retaliation the last time they reported wrongdoing to their employers. [57] [58] The research also found that Worldpay had used a gagging clause banned by the Financial Conduct Authority and shed new light on gagging clauses by Post Office Limited during the British Post Office scandal. [59] [60] [61] [62] The research also found that "industry-standard" DORA metrics used for evaluating the DevOps performance of engineering teams were solely measuring factors that both software engineers and the wider public thought were least important when using computer systems. [63]
During the COVID-19 pandemic, Ali worked on security improvements to the (Google/Apple) Exposure Notification system used to create public health contact tracing apps. [64] [7]