VLDB 2026 Research / reviewers in the wild / expert
Tom van Goethem
dblp:147/2244
· DBLP profile ↗
28ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0001-6846-9081ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 7 first-author · 12 since 2021Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing Attacks
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
NDSS | 2 |
| 2026 | The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 EcosystemabstractCryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. In this paper, we identify and formalize five privacy threats that arise directly from wallets interacting with the network and the web browser. Using large-scale dynamic measurements of 85 of the most popular Chrome Web Store browser-extension wallets (representing 35.16 million users), we observe that routine remote procedure call (RPC) operations leak structural links between a user's addresses; that the majority of Ethereum wallets implement permission revocation inconsistently and continue to expose previously revoked addresses across sessions; and that many wallets inject their provider interfaces into cross-origin iframes, enabling passive cross-site tracking beyond dApps and potentially real-world identity deanonymization without user interaction. Taken together, our results show that these wallet behaviors leak sensitive information that can be used to link multiple addresses to the same user, track wallet users across sessions and sites, and connect their browsing activity to their on-chain wealth. We discuss practical mitigations and show that many of these threats can be substantially reduced through improved wallet implementation, stronger privacy considerations in ecosystem standards, and stricter controls over provider exposure. Our results highlight the need for standardized, privacy-preserving wallet architectures and provide actionable guidance for strengthening user privacy in the emerging Web3 ecosystem. Yana Dimova, Victor Vansteenkiste, Tom van Goethem, Tom Van Cutsem |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Shiny Shells, Rusty Cores: A Crowdsourced Security Evaluation of Integrated Web Browsers
Gertjan Franken, Pieter Claeys, Tom van Goethem, Lieven Desmet |
SOUPS | 3 |
| 2023 | Time Will Tell: Exploiting Timing Leaks Using HTTP Response Headers
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
ESORICS (2) | 2 |
| 2023 | A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy Bugs
Gertjan Franken, Tom van Goethem, Lieven Desmet, Wouter Joosen |
USENIX Security Symposium | 2 |
| 2023 | Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the webabstractThe management of many different login credentials can be tricky for the average web user. OAuth eases this process by invoking identity providers (IdPs) as intermediaries, which identify the users and access their data on behalf of the website, without sharing their credentials. However, the information that IdPs share with websites is not always limited to basic data. Our work observes and documents that IdPs make a variety of resources (scopes) available to be requested by websites, most of which are not necessary for user identification (e.g., location, interests). By performing a large-scale analysis on OAuth-based login on the web, we show that 18.53% of websites using OAuth request at least one non-minimal scope. Additionally, our findings show that at least part of the requested information is redundant since websites provide alternative login methods that require less information from the user. Moreover, through a manual analysis we observe that revoking access to these scopes seems not to hinder the functionality of the website. Finally, when comparing OAuth-based login with registering a new account, we find that OAuth is often the more privacy-friendly option in terms of the amount of personal data being shared with the website. Yana Dimova, Tom van Goethem, Wouter Joosen |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | SoK: Exploring Current and Future Research Directions on XS-Leaks through an Extended Formal ModelabstractA web visit typically consists of the browser rendering a dynamically generated response that is specifically tailored to the user. This generation of responses based on the currently authenticated user, whose authentication credentials are automatically included via cookies in all (including cross-site) requests, have led to a multitude of issues. Through cross-site leaks (XS-Leaks), an adversary can try to circumvent the same-origin policy and extract information about responses, which in turn can reveal potentially sensitive information about the user. As research on this class of vulnerabilities only recently gained traction, and the attacks affect many different components of the web platform, the intrinsic characteristics and underlying causes remain largely unexplored. Tom van Goethem, Gertjan Franken, Iskander Sánchez-Rola, David Dworken, Wouter Joosen |
AsiaCCS | 1 |
| 2022 | Helping hands: Measuring the impact of a large threat intelligence sharing community
Xander Bouwman, Victor Le Pochat, Pawel Foremski, Tom van Goethem, Carlos Gañán, Giovane Cesar Moreira Moura, Samaneh Tajalizadehkhoob, Wouter Joosen, Michel van Eeten |
USENIX Security Symposium | 4 |
| 2022 | An Audit of Facebook's Political Ad Policy Enforcement
Victor Le Pochat, Laura Edelson, Tom van Goethem, Wouter Joosen, Damon McCoy, Tobias Lauinger |
USENIX Security Symposium | 3 |
| 2022 | Trace Oddity: Methodologies for Data-Driven Traffic Analysis on TorabstractTraffic analysis attacks against encrypted web traffic are a persisting problem. However, there is a large gap between the scientific estimate of attack threats and the real-world situation. As traffic analysis attacks depend on very specific metadata information, they are sensitive to artificial changes in the transmission characteristics. While the advent of deep learning greatly improves the performance rates of traffic analysis attacks on Tor in research settings, deep neural networks are known for being implicitly vulnerable to artifacts in data. Removing artifacts from our experimental setups is essential to minimizing the risk of evaluation bias. In this work, we study a state-of-the-art end-to-end traffic correlation attack on Tor and propose a novel data collection setup. Our design addresses the key constraint of prior work: instead of using a single proxy node for collecting exit traffic, we deploy multiple proxies. Our extensive analysis shows that in the multi-proxy design (i) end-to-end round-trip times are more realistic than in the original design, and that (ii) traffic correlation attack performance degrades significantly on realistic timings. For a reliable and informative evaluation, we develop a general scientific methodology for replication and comparison of machine and deep-learning attacks on Tor. Our evaluation indicates high relevance of the multi-proxy data collection setup and the novel dataset. Vera Rimmer, Theodor Schnitzler, Tom van Goethem, Abel Rodríguez Romero, Wouter Joosen, Katharina Kohls |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Reading Between the Lines: An Extensive Evaluation of the Security and Privacy Implications of EPUB Reading SystemsabstractIn recent years, e-books have proven to be a very appealing alternative to physical books; nowadays, almost every written book is published in an electronic format next to its physical copy. In an attempt to promote consensus and to offer an alternative to emerging proprietary e-book formats, the Open eBook format was introduced, now known as the EPUB format. Building on existing web functionalities, this open format relies primarily on XHTML and CSS to construct e-books. As such, browser engines are often employed to render the contents of EPUBs. However, this implies that reading systems may face similar vulnerabilities as web browsers.In this paper, we report on a semi-automated evaluation of the security and privacy aspects of EPUB reading systems. This evaluation, which was performed on 97 EPUB reading systems covering seven platforms and five physical reading devices, revealed that almost none of the JavaScript-supporting reading systems sufficiently adhere to the EPUB specification’s security recommendations. Furthermore, our results indicate that 16 reading systems even allow an EPUB to leak information about the user’s file system, and in eight cases extract file contents. In addition to the semi-automated evaluation, we demonstrate that an attacker can launch even more potent attacks that may lead to a full compromise of a user’s system, by exploiting aspects specific to the implementation of reading systems used by millions of users. Finally, we investigate the root cause of the identified security and privacy issues, uncovering several flaws in both the implementation of EPUB reading system, as well as shortcomings of the EPUB specification. Gertjan Franken, Tom van Goethem, Wouter Joosen |
SP | 2 |
| 2021 | The CNAME of the Game: Large-scale Analysis of DNS-based Tracking EvasionabstractAbstract Online tracking is a whack-a-mole game between trackers who build and monetize behavioral user profiles through intrusive data collection, and anti-tracking mechanisms that are deployed as browser extensions, DNS resolvers, or built-in to the browser. As a response to pervasive and opaque online tracking, more and more users adopt anti-tracking measures to preserve their privacy. Consequently, as the information that trackers can gather on users is being curbed, some trackers are looking for ways to evade these protections. In this paper we report on a large-scale longitudinal evaluation of an anti-tracking evasion scheme that leverages CNAME records to include tracker resources in a same-site context, which effectively bypasses anti-tracking measures that rely on fixed hostname-based block lists. Using historical HTTP Archive data we find that this tracking scheme is rapidly gaining traction, especially among high-traffic websites. Furthermore, we report on several privacy and security issues inherent to the technical setup of CNAME-based tracking that we detected through a combination of automated and manual analyses. We find that some trackers are using the technique against the Safari browser, which is known to include strict anti-tracking configurations. Our findings show that websites using CNAME trackers must take extra precautions to avoid leaking sensitive information to third parties. Yana Dimova, Gunes Acar, Lukasz Olejnik, Wouter Joosen, Tom van Goethem |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | A Practical Approach for Taking Down Avalanche Botnets Under Real-World Constraints
Victor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem, Davy Preuveneers, Andrzej Duda, Wouter Joosen, Maciej Korczynski |
NDSS | 4 |
| 2020 | Timeless Timing Attacks: Exploiting Concurrency to Leak Secrets over Remote Connections
Tom van Goethem, Christina Pöpper, Wouter Joosen, Mathy Vanhoef |
USENIX Security Symposium | 1 |
| 2019 | Purchased Fame: Exploring the Ecosystem of Private Blog NetworksabstractFor many, a browsing session starts by entering relevant keywords in a popular search engine. The websites that users thereafter land on are often determined by their position in the search results. Although little is known about the proprietary ranking algorithms employed by popular search engines, it is strongly suspected that the incoming links have a significant influence on the outcome. This has lead to the inception of various black-hat SEO techniques that aim to deceive search engines to promote a specific website. In this paper, we present the first extensive study on the ecosystem of a novel type of black-hat SEO, namely the trade of artificially created backlinks through private blog networks (PBNs). Our study is three-pronged: first, we perform an exploratory analysis, through which we capture intrinsic information of the ecosystem and measure the effectiveness of backlinks. Next, we develop and present an ML-driven methodology that detects PBN sites with an accuracy of 98.7% by leveraging various content-based and linking-based features intrinsic to the operation of the ecosystem. Finally, in a large-scale experiment involving more than 50,000 websites, we expose large networks of backlink operations, finding thousands of websites engaged in PBNs. Tom van Goethem, Najmehalsadat Miramirkhani, Wouter Joosen, Nick Nikiforakis |
AsiaCCS | 1 |
| 2019 | Mobile Friendly or Attacker Friendly?: A Large-scale Security Evaluation of Mobile-first WebsitesabstractIn the last few years, traffic generated by mobile devices has surpassed desktop visits. In order to provide users with the best browsing experience, many website owners specifically tailor their site to mobile devices. While some websites make use of reactive designs, many others opt to create an entirely new "mobile-first" website, typically hosted on a subdomain of the desktop site. These mobile-first sites provide a unique viewpoint on how organizations handle security: the mobile version of a site is typically developed several years after the desktop site by the same organization. Through a large-scale security analysis on 10,222 domains with both a desktop and mobile-first version, we find several strong indicators that security is generally applied consistently across the different parts of an organization's web estate. Overall, we find relatively few differences between the desktop and mobile versions of a website, both on the adoption and the implementation of security features, indicating that these are applied reactively rather than proactively during the design phase. Tom van Goethem, Victor Le Pochat, Wouter Joosen |
AsiaCCS | 1 |
| 2019 | Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation
Victor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski, Wouter Joosen |
NDSS | 2 |
| 2019 | Funny Accents: Exploring Genuine Interest in Internationalized Domain Names
Victor Le Pochat, Tom van Goethem, Wouter Joosen |
PAM | 2 |
| 2019 | Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies
Gertjan Franken, Tom van Goethem, Wouter Joosen |
USENIX ATC | 2 |
| 2018 | Automated Website Fingerprinting through Deep Learning
Vera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem, Wouter Joosen |
NDSS | 4 |
| 2018 | Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie Policies
Gertjan Franken, Tom van Goethem, Wouter Joosen |
USENIX Security Symposium | 2 |
| 2017 | Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingabstractHosting providers play a key role in fighting web compromise, but their ability to prevent abuse is constrained by the security practices of their own customers. Shared hosting, offers a unique perspective since customers operate under restricted privileges and providers retain more control over configurations. We present the first empirical analysis of the distribution of web security features and software patching practices in shared hosting providers, the influence of providers on these security practices, and their impact on web compromise rates. We construct provider-level features on the global market for shared hosting -- containing 1,259 providers -- by gathering indicators from 442,684 domains. Exploratory factor analysis of 15 indicators identifies four main latent factors that capture security efforts: content security, webmaster security, web infrastructure security and web application security. We confirm, via a fixed-effect regression model, that providers exert significant influence over the latter two factors, which are both related to the software stack in their hosting environment. Finally, by means of GLM regression analysis of these factors on phishing and malware abuse, we show that the four security and software patching factors explain between 10% and 19% of the variance in abuse at providers, after controlling for size. For web-application security for instance, we found that when a provider moves from the bottom 10% to the best-performing 10%, it would experience 4 times fewer phishing incidents. We show that providers have influence over patch levels--even higher in the stack, where CMSes can run as client-side software--and that this influence is tied to a substantial reduction in abuse levels. Samaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian, Rainer Böhme, Tyler Moore 0001, Wouter Joosen, Michel van Eeten |
CCS | 2 |
| 2017 | The Wolf of Name Street: Hijacking Domains Through Their NameserversabstractThe functionality and security of all domain names are contingent upon their nameservers. When these nameservers, or requests to them, are compromised, all domains that rely on them are affected. In this paper, we study the exploitation of configuration issues (typosquatting and outdated WHOIS records) and hardware errors (bitsquatting) to seize control over nameservers' requests to hijack domains. We perform a large-scale analysis of 10,000 popular nameserver domains, in which we map out existing abuse and vulnerable entities. We confirm the capabilities of these attacks through real-world measurements. Overall, we find that over 12,000 domains are susceptible to near-immediate compromise, while 52.8M domains are being targeted by nameserver bitsquatters that respond with rogue IP addresses. Additionally, we determine that 1.28M domains are at risk of a denial-of-service attack by relying on an outdated nameserver. Thomas Vissers, Timothy Barron, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
CCS | 3 |
| 2016 | It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming Services
M. Zubair Rafique, Tom van Goethem, Wouter Joosen, Christophe Huygens, Nick Nikiforakis |
NDSS | 2 |
| 2016 | Request and Conquer: Exposing Cross-Origin Resource Size
Tom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter Joosen |
USENIX Security Symposium | 1 |
| 2015 | The Clock is Still Ticking: Timing Attacks in the Modern WebabstractWeb-based timing attacks have been known for over a decade, and it has been shown that, under optimal network conditions, an adversary can use such an attack to obtain information on the state of a user in a cross-origin website. In recent years, desktop computers have given way to laptops and mobile devices, which are mostly connected over a wireless or mobile network. These connections often do not meet the optimal conditions that are required to reliably perform cross-site timing attacks. In this paper, we show that modern browsers expose new side-channels that can be used to acquire accurate timing measurements, regardless of network conditions. Using several real-world examples, we introduce four novel web-based timing attacks against modern browsers and describe how an attacker can use them to obtain personal information based on a user's state on a cross-origin website. We evaluate our proposed attacks and demonstrate that they significantly outperform current attacks in terms of speed, reliability, and accuracy. Furthermore, we show that the nature of our attacks renders traditional defenses, i.e., those based on randomly delaying responses, moot and discuss possible server-side defense mechanisms. Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
CCS | 1 |
| 2015 | Maneuvering Around Clouds: Bypassing Cloud-based Security ProvidersabstractThe increase of Distributed Denial-of-Service (DDoS) attacks in volume, frequency, and complexity, combined with the constant required alertness for mitigating web application threats, has caused many website owners to turn to Cloud-based Security Providers (CBSPs) to protect their infrastructure. These solutions typically involve the rerouting of traffic from the original website through the CBSP's network, where malicious traffic can be detected and absorbed before it ever reaches the servers of the protected website. The most popular Cloud-based Security Providers do not require the purchase of dedicated traffic-rerouting hardware, but rely solely on changing the DNS settings of a domain name to reroute a website's traffic through their security infrastructure. Consequently, this rerouting mechanism can be completely circumvented by directly attacking the website's hosting IP address. Therefore, it is crucial for the security and availability of these websites that their real IP address remains hidden from potential attackers. In this paper, we discuss existing, as well as novel "origin-exposing" attack vectors which attackers can leverage to discover the IP address of the server where a website protected by a CBSP is hosted. To assess the impact of the discussed origin-exposing vectors on the security of CBSP-protected websites, we consolidate all vectors into CloudPiercer, an automated origin-exposing tool, which we then use to conduct the first large-scale analysis of the effectiveness of the origin-exposing vectors. Our results show that the problem is severe: 71.5% of the 17,877 CBSP-protected websites that we tested, expose their real IP address through at least one of the evaluated vectors. The results of our study categorically demonstrate that a comprehensive adoption of CBSPs is harder than just changing DNS records. Our findings can steer CBSPs and site administrators towards effective countermeasures, such as proactively scanning for origin exposure and using appropriate network configurations that can greatly reduce the threat. Thomas Vissers, Tom van Goethem, Wouter Joosen, Nick Nikiforakis |
CCS | 2 |
| 2014 | Clubbing Seals: Exploring the Ecosystem of Third-party Security SealsabstractIn the current web of distrust, malware, and server compromises, convincing an online consumer that a website is secure, can make the difference between a visitor and a buyer. Third-party security seals position themselves as a solution to this problem, where a trusted external company vouches for the security of a website, and communicates it to visitors through a security seal which the certified website can embed in its pages. In this paper, we explore the ecosystem of third-party security seals focusing on their security claims, in an attempt to quantify the difference between the advertised guarantees of security seals, and reality. Through a series of automated and manual experiments, we discover a real lack of thoroughness from the side of the seal providers, which results in obviously insecure websites being certified as secure. Next to the incomplete protection, we demonstrate how malware can trivially evade detection by seal providers and detail a series of attacks that are actually facilitated by seal providers. Among other things, we show how seals can give more credence to phishing attacks, and how the current architecture of third-party security seals can be used as a completely passive vulnerability oracle, allowing attackers to focus their energy on websites with known vulnerabilities. Tom van Goethem, Frank Piessens, Wouter Joosen, Nick Nikiforakis |
CCS | 1 |