Erik Rye joins the Johns Hopkins University as an assistant professor of computer science and a member of the Johns Hopkins Information Security Institute (ISI) and the Institute for Assured Autonomy. Rye received his PhD in computer science from the University of Maryland.
Tell us a little bit about your research, particularly as it relates to information security.
I work on empirical network security and privacy problems. I look for threats that affect real people on the internet, try to measure or quantify those threats, and hopefully help mitigate them. Sometimes that means working with device manufacturers or operating system developers to try to remediate vulnerabilities. Other times that might mean making network operators aware of a problem. Often, I need to develop new tools to collect the kinds of data that I’m interested in, which I find to be a lot of fun.
Tell us about a project you are excited about.
Lately I’ve been really interested in where network security and privacy intersect with the physical world. Location data—where a person or their network devices are—is often some of the most sensitive information possible about an individual. If an attacker can figure out where a network device physically is, that can have really serious consequences for the owner of that device.
Over the last couple of years, I’ve been interested in positioning systems that operating system vendors use to help geolocate devices in their ecosystems—think mobile phones and laptops. In addition to GPS, most mobile operating systems also use the locations of nearby Wi-Fi access points to help self-geolocate. After figuring out how to extract the locations of billions of Wi-Fi access points from these systems, I’ve been using these datapoints to infer other things about the physical world. For instance, colleagues and I geolocated Starlink routers used by the Ukrainian military in their war with Russia, tracked widespread power outages and natural disasters, and in some cases pinned down where the buyers and sellers in eBay auctions were located.
There’s a ton of cool downstream work that I’m doing in this space with some awesome students and collaborators.
Why this? What drives your passion for your field?
Phil Rogaway, a cryptographer at UC Davis, wrote an essay in 2015 called “The Moral Character of Cryptographic Work.” In it, he implores his fellow cryptographers to consider the broader implications of their work rather than as fun, innocuous math puzzles to solve. Because it can be used, for instance, to conceal secrets and validate people’s identities, cryptography is inherently about power and we must think about its application in moral terms.
I think the critique extends beyond cryptography. There is incredible power in computer security and privacy. Being able to co-opt someone else’s computer is a form of power. Being able to track someone’s location is a form of power. Being in control of the data that we’re constantly generating is a form of power. There are a lot of people, companies, and governments that have tremendous interest in gaining and maintaining that power, or reducing other people’s, companies’, and governments’ power. So we need to think and talk about computer security and privacy in moral terms, too.
I find security and privacy work so compelling and urgent precisely because of this power dynamic. We’ve structured our lives and our society around networked devices, which means the systems we all depend on are also the systems through which we can be surveilled, tracked, or exploited. Most of my own work is about making that concrete: taking systems people assume are private or secure and demonstrating where they are not. Understanding the power dynamic is the first step in being able to do something about it.
What classes are you teaching?
This fall I’m teaching Network Security, and will be teaching Computer Networks in the spring. I’m really looking forward to both courses. As a ’90s kid, I distinctly remember a time before the internet and watched firsthand how profoundly widespread commercial internet access went on to change our lives and our society. I try to harness some of that early excitement I felt about the internet in working with students who, for the most part, have grown up in a world where internet access is as ubiquitous as electricity.
Why are you excited to be joining the Johns Hopkins University Information Security Institute?
I couldn’t be more excited to be joining Johns Hopkins and its ISI. Johns Hopkins’ reputation is built on a century and a half of doing groundbreaking research; when the public sees the Hopkins name—whether it’s on medical, artificial intelligence, or security research—they expect it to be important and unassailably correct. I’m thrilled to have an amazing set of colleagues in the Department of Computer Science and the ISI, and the students here are top-notch.
Besides your work, what are some of your other hobbies and passions?
Like most security people I know, the line between what counts as work versus a hobby is pretty porous and indistinct for me; I’ve always got some project I’m hacking on. I oscillate between running a lot and not running at all, which is usually a function of the weather. My wife and I have two young kids, so my free time is often well spent attending lacrosse practice or dance recitals.

