Daniele Lain

dblp:172/6530 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-6101-7306ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 3 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Interactive Cybersecurity Education for Upper Secondary School
abstract
We introduce CyberQuest, an interactive learning platform for teaching cybersecurity to upper secondary school students. It is fully web-based, does not require additional software besides a browser, and provides an entry barrier that is as low as possible for novices. Two main components form the platform: the lesson center and the ''target applications.'' The lesson center holds the theoretical lessons, questions, exercise tasks that require an interaction with the target applications, as well as progress tracking and classroom management for teachers. The target applications are sandbox environments that mimic common real-world apps that are interesting for educational purposes.
Sven Grübel, Daniele Lain, Dennis Komm
ITiCSE (1)2
2025 Breaking Bad: How Compilers Break Constant-Time Implementations
Moritz Schneider 0001, Daniele Lain, Ivan Puddu, Nicolas Dutly, Srdjan Capkun
AsiaCCS2
2025 CyberQuest: An Interactive Web-Based Cybersecurity Platform
abstract
We introduce a learning platform to teach cybersecurity topics in an interactive way to a K--12 audience. The platform targets cybersecurity novices and is entirely browser-based, making using it in class as simple as possible. It consists of two main components: a lesson center and a small mock social media network. The lesson center introduces students to basic concepts such as HTTP status codes and cookies, and asks them to carry out simple tasks within the social media network. Furthermore, students can look behind the curtains to see what kind of data is generated through interactions with the network. The ultimate goal is to ''hack'' into the social media network and impersonate a different user.
Sven Grübel, Daniele Lain, Dennis Komm
ITiCSE (2)2
2025 Phishing Attacks against Password Manager Browser Extensions
Claudio Anliker, Daniele Lain, Srdjan Capkun
USENIX Security Symposium2
2025 URL Inspection Tasks: Helping Users Detect Phishing Links in Emails
Daniele Lain, Yoshimichi Nakatsuka, Kari Kostiainen, Gene Tsudik, Srdjan Capkun
USENIX Security Symposium1
2024 Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training
abstract
A common form of phishing training in organizations is the use of simulated phishing emails to test employees' susceptibility to phishing attacks, and the immediate delivery of training material to those who fail the test. This widespread practice is dubbed embedded training; however, its effectiveness in decreasing the likelihood of employees falling for phishing again in the future is questioned by the contradictory findings of several recent field studies.
Daniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen, Srdjan Capkun
CCS1
2024 On (the Lack of) Code Confidentiality in Trusted Execution Environments
abstract
Trusted Execution Environments (TEEs) have been proposed as a solution to protect code confidentiality in scenarios where computation is outsourced to an untrusted operator. We study the resilience of such solutions to side-channel attacks in two commonly deployed scenarios: when the confidential code is a native binary that is shipped and executed within a TEE and when the confidential code is an intermediate representation (IR) executed on top of a runtime within a TEE. We show that executing IR code such as WASM bytecode on a runtime executing in a TEE leaks most IR instructions with high accuracy and therefore reveals the confidential code. Contrary to IR execution, native execution is much less susceptible to leakage and largely resists even the most powerful side-channel attacks. We evaluate native execution leakage in Intel SGX and AMD SEV and experimentally demonstrate end-to-end instruction extraction on Intel SGX, with WASM bytecode as IR executed within two popular WASM runtimes: WAMR and wasmi. Our experiments show that IR code leakage from such systems is practical and therefore question the security claims of several commercial solutions which rely on TEEs+WASM for code confidentiality.
Ivan Puddu, Moritz Schneider 0001, Daniele Lain, Stefano Boschetto, Srdjan Capkun
SP3
2022 Phishing in Organizations: Findings from a Large-Scale and Long-Term Study
abstract
In this paper, we present findings from a largescale and long-term phishing experiment that we conducted in collaboration with a partner company. Our experiment ran for 15 months during which time more than 14,000 study participants (employees of the company) received different simulated phishing emails in their normal working context. We also deployed a reporting button to the company’s email client which allowed the participants to report suspicious emails they received. We measured click rates for phishing emails, dangerous actions such as submitting credentials, and reported suspicious emails. The results of our experiment provide three types of contributions. First, some of our findings support previous literature with improved ecological validity. One example of such results is good effectiveness of warnings on emails. Second, some of our results contradict prior literature and common industry practices. Surprisingly, we find that embedded training during simulated phishing exercises, as commonly deployed in the industry today, does not make employees more resilient to phishing, but instead it can have unexpected side effects that can make employees even more susceptible to phishing. And third, we report new findings. In particular, we are the first to demonstrate that using the employees as a collective phishing detection mechanism is practical in large organizations. Our results show that such crowd-sourcing allows fast detection of new phishing campaigns, the operational load for the organization is acceptable, and the employees remain active over long periods of time.
Daniele Lain, Kari Kostiainen, Srdjan Capkun
SP1
2019 2FA-PP: 2nd factor phishing prevention
abstract
Two factor authentication (2FA) schemes provide strong user authentication guarantees and increase the security of a wide range of web services. However, 2FA schemes still largely remain vulnerable to phishing attacks in which attackers also phish users' second factor (e.g., their OTP tokens). We propose 2FA-PP, a phishing detection scheme that protects users' 2nd authentication factor from phishing attacks. 2FA-PP uses novel browser APIs that support direct communication between browsers and external devices (e.g., mobile phones) and enables the user's phone to check the domain to which the user is connected. The second factor is then only made available to the user if he is accessing the correct domain. 2FA-PP can be combined with different 2FA schemes, both interactive, based on OTP, QR codes and non-interactive, based on device pairing or proximity.
Enis Ulqinaku, Daniele Lain, Srdjan Capkun
WiSec2
2019 PILOT: Password and PIN information leakage from obfuscated typing videos
abstract
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters (∗ or ∙) that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos ( PILOT ). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work (In European Symposium on Research in Computer Security ( 2018 ) 263–280 Springer). In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.
Kiran S. Balagani, Matteo Cardaioli, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
J. Comput. Secur.7
2019 Skype & Type: Keyboard Eavesdropping in Voice-over-IP
abstract
Voice-over-IP (VoIP) software are among the most widely spread and pervasive software, counting millions of monthly users. However, we argue that people ignore the drawbacks of transmitting information along with their voice, such as keystroke sounds—as such sound can reveal what someone is typing on a keyboard. In this article, we present and assess a new keyboard acoustic eavesdropping attack that involves VoIP, called Skype & Type ( S&T ). Unlike previous attacks, S&T assumes a weak adversary model that is very practical in many real-world settings. Indeed, S&T is very feasible, as it does not require (i) the attacker to be physically close to the victim (either in person or with a recording device) and (ii) precise profiling of the victim’s typing style and keyboard; moreover, it can work with a very small amount of leaked keystrokes. We observe that leakage of keystrokes during a VoIP call is likely, as people often “multi-task” during such calls. As expected, VoIP software acquires and faithfully transmits all sounds, including emanations of pressed keystrokes, which can include passwords and other sensitive information. We show that one very popular VoIP software (Skype) conveys enough audio information to reconstruct the victim’s input—keystrokes typed on the remote keyboard. Our results demonstrate that, given some knowledge on the victim’s typing style and keyboard model, the attacker attains top-5 accuracy of 91.7% in guessing a random key pressed by the victim. This work extends previous results on S&T , demonstrating that our attack is effective with many different recording devices (such as laptop microphones, headset microphones, and smartphones located in proximity of the target keyboard), diverse typing styles and speed, and is particularly threatening when the victim is typing in a known language.
Stefano Cecconello, Alberto Compagno, Mauro Conti, Daniele Lain, Gene Tsudik
ACM Trans. Priv. Secur.4
2018 SILK-TV: Secret Information Leakage from Keystroke Timing Videos
Kiran S. Balagani, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
ESORICS (1)6
2018 Back To The Epilogue: Evading Control Flow Guard via Unaligned Targets
Andrea Biondo, Mauro Conti, Daniele Lain
NDSS3
2017 Don't Skype & Type!: Acoustic Eavesdropping in Voice-Over-IP
abstract
Acoustic emanations of computer keyboards represent a serious privacy issue. As demonstrated in prior work, physical properties of keystroke sounds might reveal what a user is typing. However, previous attacks assumed relatively strong adversary models that are not very practical in many real-world settings. Such strong models assume: (i) adversary's physical proximity to the victim, (ii) precise profiling of the victim's typing style and keyboard, and/or (iii) significant amount of victim's typed information (and its corresponding sounds) available to the adversary.
Alberto Compagno, Mauro Conti, Daniele Lain, Gene Tsudik
AsiaCCS3
2017 A roaming-based denial of service attack on LTE networks: poster
abstract
During the last ten years, mobile communications greatly evolved. Along this process, the main goal was to satisfy users' needs such as coverage, communication speed, and availability. However, less attention has been posed to prevent attacks such as Denial of Service (DoS), which aim to render the mobile network unserviceable.
Moreno Ambrosin, Stefano Cecconello, Mauro Conti, Daniele Lain
WISEC4