Kostas Solomos

dblp:232/2988-1 · also Konstantinos Solomos 0001 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-3474-0635ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 6 since 2021
YearPublicationVenuePosition
2026 Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop Environments
Andrea Infantino, Mir Masood Ali, Kostas Solomos, Iasonas Polakis
NDSS3
2025 Lost in Translation: Exploring the Risks of Web-to-Cross-platform Application Migration
abstract
The cross-platform application-development paradigm alleviates a major challenge of native application development, namely the need to re-implement the codebase for each target platform, and streamlines the deployment of applications to different platforms. Essentially, cross-platform application development relies on migrating web application code and repackaging it as a native application. In other words, code that was designed and developed to execute within the confines of a browser, with all the security checks and safeguards that that entails, is now deployed within a completely different execution environment. In this paper, we explore the inherent security and privacy risks that arise from this migration, due to the fundamental differences between these two execution environments, which we refer to as security lacunae. To that end, we establish a differential analysis workflow and develop a set of customized tests designed to uncover divergent behaviors of web code executed within a browser and as an Electron cross-platform application. Guided by the findings from our empirical exploration, we retrofit part of the Web Platform Tests (WPTs) testing suite so as to apply to the Electron framework, and systematically assess mechanisms that relate to isolation and access control, and critical security policies and headers. Our research uncovers semantic gaps that exist between the two execution environments, which affect the enforcement of critical security mechanisms, thus exposing users to severe risks. This can lead to privacy issues such as the exposure of sensitive data over unencrypted connections or unregulated third-party access to the local filesystem, and security issues such as the incorrect enforcement of CSP script execution directives. We demonstrate that directly migrating web application code to a cross-platform application, without refactoring the code and implementing additional safeguards to address the conceptual and behavioral mismatches between the two execution environments, can significantly affect the application's security and privacy posture.
Claudio Paloscia, Kostas Solomos, Mir Masood Ali, Iasonas Polakis
Proc. Priv. Enhancing Technol.2
2024 Harnessing Multiplicity: Granular Browser Extension Fingerprinting through User Configurations
abstract
Browser extension fingerprinting poses a dual privacy threat to users, as it can be used for both tracking (e.g., as part of browser fingerprinting systems) and directly inferring sensitive user data (e.g., religion, medical issues). In this work, we conduct a novel study that expands the view held by all prior extension-fingerprinting studies, which were limited to detecting whether an extension is installed or not, and show that extensions can exhibit diverse behaviors and features when personalized by users. We introduce the concept of multi-fingerprinting, which aims to harness extensions that exhibit diverse behaviors due to such personalization. Accordingly, we develop Hecate, a system that employs multiple techniques, including static analysis and fuzzing, for generating diverse extension configurations and capturing the corresponding be-havioral signatures. We conduct an extensive experimental evaluation of Hecate, and find that it triggers diverse behaviors by uncovering and fuzzing configuration options in extensions installed by millions of users. Additionally, we analyze the real-world impact of multi-fingerprinting through a pilot user study, in which 25% of the users can be uniquely identified through multi-fingerprinting. Our study demonstrates the impact of extension personalization on the fingerprintability of extensions, while also highlighting the significant real-world privacy risk posed by multi-fingerprinting.
Kostas Solomos, Nick Nikiforakis, Iasonas Polakis
ACSAC1
2022 Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral Modifications
abstract
Browser fingerprinting continues to proliferate across the web. Critically, popular fingerprinting libraries have started incorporating extension-fingerprinting capabilities, thus exacerbating the privacy loss they can induce. In this paper we propose continuous fingerprinting, a novel extension fingerprinting technique that captures a critical dimension of extensions' functionality that allowed them to elude all prior behavior-based techniques. Specifically, we find that ephemeral modifications are prevalent in the extension ecosystem, effectively rendering such extensions invisible to prior approaches that are confined to analyzing snapshots that capture a single moment in time. Accordingly, we develop Chronos, a system that captures the modifications that occur throughout an extension's life cycle, enabling it to fingerprint extensions that make transient modifications that leave no visible traces at the end of execution. Specifically, our system creates behavioral signatures that capture nodes being added to or removed from the DOM, as well as changes being made to node attributes. Our extensive experimental evaluation highlights the inherent limits of prior snapshot-based approaches, as Chronos is able to identify 11,219 unique extensions, increasing coverage by 66.9% over the state of the art. Additionally, we find that our system captures a unique modification event (i.e., mutation) for 94% of the extensions, while also being able to resolve 97% of the signature collisions across extensions that affect existing snapshot-based approaches. Our study more accurately captures the extent of the privacy threat presented by extension fingerprinting, which warrants more attention by privacy-oriented browser vendors that, up to this point, have focused on deploying countermeasures against other browser fingerprinting vectors.
Kostas Solomos, Panagiotis Ilia, Nick Nikiforakis, Iasonas Polakis
CCS1
2022 The Dangers of Human Touch: Fingerprinting Browser Extensions through User Actions
Kostas Solomos, Panagiotis Ilia, Soroush Karami, Nick Nikiforakis, Iasonas Polakis
USENIX Security Symposium1
2021 Tales of Favicons and Caches: Persistent Tracking in Modern Browsers
Kostas Solomos, John Kristoff, Chris Kanich, Iasonas Polakis
NDSS1
2020 Carnus: Exploring the Privacy Threats of Browser Extension Fingerprinting
Soroush Karami, Panagiotis Ilia, Kostas Solomos, Iasonas Polakis
NDSS3
2019 TALON: An Automated Framework for Cross-Device Tracking Detection
Kostas Solomos, Panagiotis Ilia, Sotiris Ioannidis, Nicolas Kourtellis
RAID1