Lukasz Olejnik

Cybersecurity, technology research

Independent researcher and consultant working on cybersecurity and technology. My work combines technical research and development with security and privacy analysis, standardisation, and technology policy.

Want to work with me? I take on consulting and advisory work, commissioned research, and independent technical reviews.

Email: me(at)lukaszolejnik.com.

Follow my work on X, Mastodon, or the blog.

Selected work

A selection of my work.

  • Technical research and development. Experimental systems, prototypes, technical investigations, and implementation work across cybersecurity and emerging technologies. This includes security engineering, system and application analysis, and the development and evaluation of research systems.
  • Security and privacy engineering. Research on browser information leaks, browsing history, fingerprinting, sensors, and other security and privacy properties of deployed technologies. Some of this work contributed to changes in browser implementations and technical specifications, including altered or removed functionality. I have also researched the security and privacy of Real-Time Bidding systems and technologies used for targeted communication.
  • Technology standards and architecture. I am a W3C Invited Expert and a former member of the W3C Technical Architecture Group. My work includes security and privacy analysis of Web technologies and standards, and co-authoring and editing the W3C security and privacy self-review questionnaire.
  • Cybersecurity, technology policy, and cyber operations. I was a cyberwarfare advisor at the International Committee of the Red Cross, including work on the potential human consequences of cyber operations. I have advised on the ePrivacy Regulation, worked with the European Data Protection Supervisor, and contributed to policy work concerning security research, privacy, and technology.
  • Research and public analysis. Scientific and interdisciplinary research, technical and policy reports, books, public speaking, and commentary on cybersecurity and technology.