VLDB 2026 Research / reviewers in the wild / expert
Alastair R. Beresford
dblp:29/361
· DBLP profile ↗
39ranked-venue papers
0as first author
17since 2021 · last 2026
0000-0003-0818-6535ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 15 since 2021Human-computer interaction and ubiquitous computing · 7 · 1 since 2021Systems, architecture and hardware · 5 · 1 since 2021Software engineering, systems software and programming languages · 4Applied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 3Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | iOSModZoo: A Large-Scale Study of Third-Party iOS App Markets
Luis Adan Saavedra, Hridoy Sankar Dutta, Alastair R. Beresford, Alice Hutchings |
WISEC | 3 |
| 2026 | KeyDroid: A Large-Scale Analysis of Secure Key Storage in Android AppsabstractMost contemporary mobile devices offer hardware-backed storage for cryptographic keys, user data, and other sensitive credentials. Such hardware is capable of protecting credentials from extraction by an adversary who has compromised the main operating system, such as a malicious third-party app. Since 2011, Android app developers can access trusted hardware via the Android Keystore API, making hardware-backed key storage a widely accessible PET. In this work, we conduct the first comprehensive survey of hardware-backed key storage in Android devices. We analyze 490,119 Android apps, collecting data on how trusted hardware is used by app developers (if at all) and cross-referencing our findings with sensitive user data collected by each app, as self-reported by developers via the Play Store’s data safety labels. We find that despite industry-wide initiatives to encourage adoption, 56% of apps self-reporting as processing sensitive user data do not use Android’s trusted hardware capabilities at all, while just 5% of apps collecting some form of sensitive data use the strongest form of trusted hardware, a secure element distinct from the main processor. To better understand the potential downsides of using secure hardware, we conduct the first empirical analysis of trusted hardware performance in mobile devices, measuring the runtime of common cryptographic operations across both software- and hardware-backed keystores and providing the first empirical analysis to date of the performance of secure elements in mobile devices. We find that while hardware-backed key storage using a coprocessor is viable for most common cryptographic operations, secure elements capable of preventing more advanced attacks make performance infeasible for symmetric encryption with non-negligible payloads. Jenny Blessing, Ross J. Anderson, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | App-solutely Modded: Surveying Modded App Market Operators and Original App DevelopersabstractApp-solutely Modded: Surveying Modded App Market Operators and Original App Developers Luis Adan Saavedra, Hridoy Sankar Dutta, Alastair R. Beresford, Alice Hutchings |
AsiaCCS | 3 |
| 2025 | Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution EnvironmentsabstractIn this paper we present attestable builds, a new paradigm to provide strong source-to-binary correspondence in software artifacts. We tackle the challenge of opaque build pipelines that disconnect the trust between source code, which can be understood and audited, and the final binary artifact which is difficult to inspect. Our system uses modern trusted execution environments (TEEs) and sandboxed build containers to provide strong guarantees that a given artifact was correctly built from a specific source code snapshot. As such it complements existing approaches like reproducible builds which typically require time-intensive modifications to existing build configurations and dependencies, and require independent parties to continuously build and verify artifacts. In comparison, an attestable build requires only minimal changes to an existing project, and offers nearly instantaneous verification of the correspondence between a given binary and the source code and build pipeline used to construct it. We evaluate it by building open-source software libraries - focusing on projects which are important to the trust chain and have proven difficult to be built deterministically. The overhead (42 seconds start-up latency and 14% increase in build duration) is small in comparison to the overall build time. Importantly, our prototype can build complex projects such as LLVM Clang without requiring any modifications to their source code and build scripts. Finally, we formally model and verify the attestable build design to demonstrate its security against well-resourced adversaries. Daniel Hugenroth, Mario Lins, René Mayrhofer, Alastair R. Beresford |
CCS | 4 |
| 2025 | SoK: Web Authentication and Recovery in the Age of End-to-End EncryptionabstractThe advent of end-to-end encryption (E2EE) has brought new challenges for usable authentication and recovery. Compared to regular web services, the nature of E2EE requires that the provider cannot recover data for users who have forgotten passwords or lost devices. More robust recovery schemes are therefore required, leading to a plethora of solutions ranging from randomly-generated recovery codes to social authentication. These implications have spread to new forms of authentication and legacy web services: passwordless authentication (``passkeys'') has become a promising candidate to replace passwords altogether, but is inherently device-bound. However, users expect that they can login from multiple devices and recover their passwords in case of device loss---prompting providers to sync credentials to cloud storage using E2EE and making contemporary authentication for even non-E2EE services dependent on E2EE. Hence, E2EE authentication quickly becomes relevant not only for a niche group of dedicated E2EE enthusiasts but for the general public using the passwordless authentication techniques promoted by their device vendors. In this paper we systematize existing research literature and industry practice relating to security, privacy, usability, and recoverability of both end-user authentication to E2EE services and the use of E2EE in securing backend credential databases. We investigate authentication and recovery schemes in all widely-used E2EE web services, analyze syncing protocols for E2EE credential managers, and survey passwordless authentication deployment in the top-300 most popular websites. Finally, we present concrete research directions based on observed gaps between industry deployment and academic literature. Jenny Blessing, Daniel Hugenroth, Ross J. Anderson, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Pudding: Private User Discovery in Anonymity NetworksabstractAnonymity networks allow messaging with metadata privacy, providing better privacy than popular encrypted messaging applications. However, contacting a user on an anonymity network currently requires knowing their public key or similar high-entropy information, as these systems lack a privacy-preserving mechanism for contacting a user via a short, human-readable username. Previous research suggests that this is a barrier to widespread adoption.In this paper we propose Pudding, a novel private user discovery protocol that allows a user to be contacted on an anonymity network knowing only their email address. Our protocol hides contact relationships between users, prevents impersonation, and conceals which usernames are registered on the network. Pudding is Byzantine fault tolerant, remaining available and secure as long as less than one third of servers are crashed, unavailable, or malicious. It can be deployed on Loopix and Nym without changes to the underlying anonymity network protocol, and it supports mobile devices with intermittent network connectivity. We demonstrate the practicality of Pudding with a prototype using the Nym anonymity network. We also formally define the security and privacy goals of our protocol and conduct a thorough analysis to assess its compliance with these definitions. Ceren Kocaogullar, Daniel Hugenroth, Martin Kleppmann, Alastair R. Beresford |
SP | 4 |
| 2024 | Sloth: Key Stretching and Deniable Encryption using Secure Elements on SmartphonesabstractPrivacy enhancing technologies must not only protect sensitive data in-transit, but also locally at-rest. For example, anonymity networks hide the sender and/or recipient of a message from network adversaries. However, if a participating device is physically captured, its owner can be pressured to give access to the stored conversations. Therefore, client software should allow the user to plausibly deny the existence of meaningful data. Since biometrics can be collected without consent and server-based authentication leaks metadata, implementations typically rely on memorable passwords for local authentication. Traditional password-based key stretching lacks a strict time guarantee due to the ease of parallelized password guessing by attackers. This paper introduces Sloth, a key stretching method leveraging the Secure Element (SE) commonly found in modern smartphones to provide a strict rate limit on password guessing. While this would be straightforward with full access to the SE, Android and iOS only provide a very limited API. Sloth utilizes the existing developer SE API and novel cryptographic constructions to build an effective rate-limit for password guessing on recent Android and iOS devices. Our approach ensures robust security even for short, randomly-generated, six-character alpha-numeric passwords against adversaries with virtually unlimited computing resources. Our solution is compatible with approximately 96% of iPhones and 45% of Android phones and Sloth seamlessly integrates without device or OS modifications, making it immediately usable by app developers today. We formally define the security of Sloth and evaluate its performance on various devices. Finally, we present HiddenSloth, a plausibly-deniable encryption scheme leveraging Sloth. It provides multi-snapshot resistance against adversaries who can covertly capture its on-disk content multiple times. Daniel Hugenroth, Alberto Sonnino, Sam Cutler, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Powering Privacy: On the Energy Demand and Feasibility of Anonymity Networks on Smartphones
Daniel Hugenroth, Alastair R. Beresford |
USENIX Security Symposium | 2 |
| 2023 | SoK: Managing risks of linkage attacks on data privacyabstractNovel attacks on dataset privacy are usually met with the same range of responses: surprise that a route to information gain exists from information previously thought to be safe; disputes around the viability or validity of the attack in real-world contexts; and, in the case of the computer science community, a drive to produce techniques that provably protect against the new class of attack. The result is a disjointed landscape with no shared approach to modelling threats to dataset privacy, and a toolbox of technically complex systems whose guarantees come with narrow assumptions and whose application in real-world contexts is hard to achieve. In this paper we aim to understand these issues by charting the history of dataset privacy attacks and systematising breaches through the lens of data linkage. We show how identification or information gain on a dataset's subjects can be expressed as data linkage, and use this to present a taxonomy of threat models which we apply to ninety-four attacks from across the literature. Our work demonstrates that dataset privacy must be approached first as a risk management problem, rather than one of strict guarantees, an approach which aligns well with law and practice. Our taxonomy of attacker intents provides a coherent language for expressing the wide variety of threat models in dataset privacy, and a framework for understanding how risks identified under one model can be understood within another. We also present insights around the factors that affect the feasibility and severity of attacks, and proposals for practical techniques that can be used for risk appraisal and management by practitioners, researchers, and regulators alike. Jovan Powar, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | ACDC: Anonymous Crowdsourcing Using Digital Cash
Luis Adan Saavedra, Alastair R. Beresford |
CANS | 2 |
| 2022 | Enhancing User Privacy in Mobile Devices Through Prediction of Privacy Preferences
Ricardo Mendes, Mariana Cunha, João P. Vilela, Alastair R. Beresford |
ESORICS (1) | 4 |
| 2022 | Effect of User Expectation on Mobile App Privacy: A Field StudyabstractRuntime permission managers for mobile devices allow requests to be performed at the time in which permissions are required, thus enabling the user to grant/deny requests in context according to their expectations. However, in order to avoid cognitive overload, second and subsequent requests are usually automatically granted without user intervention/awareness. This paper explores whether these automated decisions fit user expectations. We performed a field study with 93 participants to collect their privacy decisions, the surrounding context and whether each request was expected. The collected 65261 permission decisions revealed a strong misalignment between apps’ practices and expectation as almost half of requests are unexpected by users. This ratio strongly varies with the requested permission, the category and visibility of the requesting application and the user itself; that is, expectation is subjective to each individual. Moreover, privacy decisions are most strongly correlated with user expectation, but such correlation is also highly personal. Finally, Android’s default permission manager would have violated the privacy of our participants 15% of the time. Ricardo Mendes, André Brandão, João P. Vilela, Alastair R. Beresford |
PerCom | 4 |
| 2022 | CoverDrop: Blowing the Whistle Through A News AppabstractAbstract Whistleblowing is hazardous in a world of pervasive surveillance, yet many leading newspapers expect sources to contact them with methods that are either insecure or barely usable. In an attempt to do better, we conducted two workshops with British news organisations and surveyed whistleblowing options and guidelines at major media outlets. We concluded that the soft spot is a system for initial contact and trust establishment between sources and reporters. CoverDrop is a two-way, secure system to do this. We support secure messaging within a news app, so that all its other users provide cover traffic, which we channel through a threshold mix instantiated in a Trusted Execution Environment within the news organisation. CoverDrop is designed to resist a powerful global adversary with the ability to issue warrants against infrastructure providers, yet it can easily be integrated into existing infrastructure. We present the results from our workshops, describe CoverDrop’s design and demonstrate its security and performance. Mansoor Ahmed-Rengers, Diana A. Vasile, Daniel Hugenroth, Alastair R. Beresford, Ross J. Anderson |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | A Highly-Available Move Operation for Replicated TreesabstractReplicated tree data structures are a fundamental building block of distributed filesystems, such as Google Drive and Dropbox, and collaborative applications with a JSON or XML data model. These systems need to support amoveoperation that allows a subtree to be moved to a new location within the tree. However, such a move operation is difficult to implement correctly if different replicas can concurrently perform arbitrary move operations, and we demonstrate bugs in Google Drive and Dropbox that arise with concurrent moves. In this article we present a CRDT algorithm that handles arbitrary concurrent modifications on trees, while ensuring that the tree structure remains valid (in particular, no cycles are introduced), and guaranteeing that all replicas converge towards the same consistent state. Our algorithm requires no synchronous coordination between replicas, making it highly available in the face of network partitions. We formally prove the correctness of our algorithm using the Isabelle/HOL proof assistant, and evaluate the performance of our formally verified implementation in a geo-replicated setting. Martin Kleppmann, Dominic P. Mulligan, Victor B. F. Gomes, Alastair R. Beresford |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Key Agreement for Decentralized Secure Group Messaging with Strong Security GuaranteesabstractSecure group messaging protocols, providing end-to-end encryption for group communication, need to handle mobile devices frequently being offline, group members being added or removed, and the possibility of device compromises during long-lived chat sessions. Existing work targets a centralized network model in which all messages are routed through a single server, which is trusted to provide a consistent total order on updates to the group state. In this paper we adapt secure group messaging for decentralized networks that have no central authority. Servers may still optionally be used, but they are trusted less. We define decentralized continuous group key agreement (DCGKA), a new cryptographic primitive encompassing the core of a decentralized secure group messaging protocol; we give a practical construction of a DCGKA protocol and prove its security; and we describe how to construct a full messaging protocol from DCGKA. In the face of device compromise our protocol achieves forward secrecy and post-compromise security. We evaluate the performance of a prototype implementation, and demonstrate that our protocol has practical efficiency. Matthew Weidner, Martin Kleppmann, Daniel Hugenroth, Alastair R. Beresford |
CCS | 4 |
| 2021 | Rollercoaster: An Efficient Group-Multicast Scheme for Mix Networks
Daniel Hugenroth, Martin Kleppmann, Alastair R. Beresford |
USENIX Security Symposium | 3 |
| 2021 | Factory Calibration Fingerprinting of SensorsabstractDevice fingerprinting aims to generate a distinctive signature, or fingerprint, that uniquely identifies individual computing devices. Fingerprints may be a privacy concern since apps and websites can use them to track user activity online. To protect user privacy, both Android and iOS have included a variety of measures to prevent such tracking. In this paper we present a new type of fingerprinting, factory calibration fingerprinting, that bypasses existing tracking protection. Our attack recovers embedded per-device factory calibration data from the accelerometer, gyroscope, and magnetometer sensors that are pervasive in modern smartphones by careful analysis of the sensor output alone. We discuss the factory calibration behaviour of each sensor and show that the calibration fingerprint is fast to generate, does not change over time or after a factory reset, and can be used to track users across apps and websites without any special permission from the user. We find the calibration fingerprint is very likely to be globally unique for iOS devices, with an estimated 67 bits of entropy for the iPhone 6S. In addition, we have analysed 146 Android device models from 11 vendors and found the attack also works on recent Google Pixel devices. For Pixel 4/4 XL, we estimate the calibration fingerprint provides about 57 bits of entropy. Following our disclosures, Apple deployed a mitigation in iOS 12.2 and Google in Android 11. We analyse Apple's fix and show that the mitigation is imperfect although it is likely to be sufficient in most threat models. Jiexin Zhang 0001, Alastair R. Beresford, Ian Sheret |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | LibID: reliable identification of obfuscated third-party Android librariesabstractThird-party libraries are vital components of Android apps, yet they can also introduce serious security threats and impede the accuracy and reliability of app analysis tasks, such as app clone detection. Several library detection approaches have been proposed to address these problems. However, we show these techniques are not robust against popular code obfuscators, such as ProGuard, which is now used in nearly half of all apps. We then present LibID, a library detection tool that is more resilient to code shrinking and package modification than state-of-the-art tools. We show that the library identification problem can be formulated using binary integer programming models. LibID is able to identify specific versions of third-party libraries in candidate apps through static analysis of app binaries coupled with a database of third-party libraries. We propose a novel approach to generate synthetic apps to tune the detection thresholds. Then, we use F-Droid apps as the ground truth to evaluate LibID under different obfuscation settings, which shows that LibID is more robust to code obfuscators than state-of-the-art tools. Finally, we demonstrate the utility of LibID by detecting the use of a vulnerable version of the OkHttp library in nearly 10% of 3,958 most popular apps on the Google Play Store. Jiexin Zhang 0001, Alastair R. Beresford, Stephan A. Kollmann |
ISSTA | 2 |
| 2019 | Inequality: multi-modal equation entry on the webabstractOnline learning in STEM subjects requires an easy way to enter and automatically mark mathematical equations. Existing solutions did not meet our requirements, and therefore we developed Inequality, a new open-source system which works across all major browsers, supports both mouse and touch-based entry, and is usable by high school children and teachers. Inequality has been in use for over 2 years by about 20000 students and nearly 900 teachers as part of the Isaac online learning platform. In this paper we evaluate Inequality as an entry method, assess the flexibility of our approach, and the effect the system has on student behaviour. We prepared 343 questions which could be answered using either Inequality or a traditional method. Looking across over 472000 question attempts, we found that students were equally proficient at answering questions correctly with both entry methods. Moreover, students using Inequality required fewer attempts to arrive at the correct answer 73% of the time. In a detailed analysis of equation construction, we found that Inequality provides significant flexibility in the construction of mathematical expressions, accommodating different working styles. We expected students who first worked on paper before entering their answers would require fewer attempts than those who did not, however this was not the case (p = 0.0109). While our system is clearly usable, a user survey highlighted a number of issues which we have addressed in a subsequent update. Andrea Franceschini, James P. Sharkey, Alastair R. Beresford |
L@S | 3 |
| 2019 | SensorID: Sensor Calibration Fingerprinting for SmartphonesabstractSensors are an essential component of many computer systems today. Mobile devices are a good example, containing a vast array of sensors from accelerometers and GPS units, to cameras and microphones. Data from these sensors are accessible to application programmers who can use this data to build context-aware applications. Good sensor accuracy is often crucial, and therefore manufacturers often use per-device factory calibration to compensate for systematic errors introduced during manufacture. In this paper we explore a new type of fingerprinting attack on sensor data: calibration fingerprinting. A calibration fingerprinting attack infers the per-device factory calibration data from a device by careful analysis of the sensor output alone. Such an attack does not require direct access to any calibration parameters since these are often embedded inside the firmware of the device and are not directly accessible by application developers. We demonstrate the potential of this new class of attack by performing calibration fingerprinting attacks on the inertial measurement unit sensors found in iOS and Android devices. These sensors are good candidates because access to these sensors does not require any special permissions, and the data can be accessed via both a native app installed on a device and also by JavaScript when visiting a website on an iOS and Android device. We find we are able to perform a very effective calibration fingerprinting attack: our approach requires fewer than 100 samples of sensor data and takes less than one second to collect and process into a device fingerprint that does not change over time or after factory reset. We demonstrate that our approach is very likely to produce globally unique fingerprints for iOS devices, with an estimated 67 bits of entropy in the fingerprint for iPhone 6S devices. In addition, we find that the accelerometer of Google Pixel 2 and Pixel 3 devices can also be fingerprinted by our approach. Jiexin Zhang 0001, Alastair R. Beresford, Ian Sheret |
IEEE Symposium on Security and Privacy | 2 |
| 2019 | Snapdoc: Authenticated snapshots with history privacy in peer-to-peer collaborative editingabstractAbstract Document collaboration applications, such as Google Docs or Microsoft Office Online, need to ensure that all collaborators have a consistent view of the shared document, and usually achieve this by relying on a trusted server. Other existing approaches that do not rely on a trusted third party assume that all collaborating devices are trusted. In particular, when inviting a new collaborator to a group, one needs to choose between a) keeping past edits private and sending only the latest state (a snapshot) of the document; or b) allowing the new collaborator to verify her view of the document is consistent with other honest devices by sending the full history of (signed) edits. We present a new protocol which allows an authenticated snapshot to be sent to new collaborators while both hiding the past editing history, and allowing them to verify consistency. We evaluate the costs of the protocol by emulating the editing history of 270 Wikipedia pages; 99% of insert operations were processed within 11.0 ms; 64.9 ms for delete operations. An additional benefit of authenticated snapshots is a median 84% reduction in the amount of data sent to a new collaborator compared to a basic protocol that transfers a full edit history. Stephan A. Kollmann, Martin Kleppmann, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | Quantifying Privacy Loss of Human Mobility Graph TopologyabstractAbstract Human mobility is often represented as a mobility network, or graph, with nodes representing places of significance which an individual visits, such as their home, work, places of social amenity, etc., and edge weights corresponding to probability estimates of movements between these places. Previous research has shown that individuals can be identified by a small number of geolocated nodes in their mobility network, rendering mobility trace anonymization a hard task. In this paper we build on prior work and demonstrate that even when all location and timestamp information is removed from nodes, the graph topology of an individual mobility network itself is often uniquely identifying. Further, we observe that a mobility network is often unique, even when only a small number of the most popular nodes and edges are considered. We evaluate our approach using a large dataset of cell-tower location traces from 1 500 smartphone handsets with a mean duration of 430 days. We process the data to derive the top−N places visited by the device in the trace, and find that 93% of traces have a unique top−10 mobility network, and all traces are unique when considering top−15 mobility networks. Since mobility patterns, and therefore mobility networks for an individual, vary over time, we use graph kernel distance functions, to determine whether two mobility networks, taken at different points in time, represent the same individual. We then show that our distance metrics, while imperfect predictors, perform significantly better than a random strategy and therefore our approach represents a significant loss in privacy. Dionysis Manousakas, Cecilia Mascolo, Alastair R. Beresford, Dennis Chan |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Demand Around the Clock: Time Use and Data Demand of Mobile Devices in Everyday LifeabstractMotivated by mobile devices' growing demand for connectivity, and concern in HCI with the energy intensity and sustainability of networked services, in this paper we reveal the impact of applications on smartphones and tablets in terms of network demand and time use. Using a detailed mixed methods study with eight participants, we first provide an account of how data demand has meaning and utility in our participants' social practices, and the timing and relative impacts of these. We then assess the scale of this demand by drawing comparison between our fine-grained observations and a more representative dataset of 398 devices from the Device Analyzer corpus. Our results highlight the significant categories of data demanding practice, and the identification of where changes in app time and duration of use might reduce or shift demand to reduce services' impacts. Kelly Widdicks, Oliver Bates, Mike Hazas, Adrian Friday, Alastair R. Beresford |
CHI | 5 |
| 2017 | Ethical issues in research using datasets of illicit originabstractWe evaluate the use of data obtained by illicit means against a broad set of ethical and legal issues. Our analysis covers both the direct collection, and secondary uses of, data obtained via illicit means such as exploiting a vulnerability, or unauthorized disclosure. We extract ethical principles from existing advice and guidance and analyse how they have been applied within more than 20 recent peer reviewed papers that deal with illicitly obtained datasets. We find that existing advice and guidance does not address all of the problems that researchers have faced and explain how the papers tackle ethical issues inconsistently, and sometimes not at all. Our analysis reveals not only a lack of application of safeguards but also that legitimate ethical justifications for research are being overlooked. In many cases positive benefits, as well as potential harms, remain entirely unidentified. Few papers record explicit Research Ethics Board (REB) approval for the activity that is described and the justifications given for exemption suggest deficiencies in the REB process. Daniel R. Thomas, Sergio Pastrana, Alice Hutchings, Richard Clayton 0001, Alastair R. Beresford |
Internet Measurement Conference | 5 |
| 2017 | There are many apps for that: quantifying the availability of privacy-preserving appsabstractThe adage "there's an app for that" holds true in modern app stores. Indeed, app stores usually go further and provide multiple apps with very similar functionality; examples range from flashlight apps to alarm clocks. We call these functionally-similar apps. When searching for these apps, users are often presented with a vast array of choices, but no distinction is made in the user interface to highlight the relative privacy risks inherent in choosing one app over another. Yet the availability of many functionally-similar apps raises the question of whether some apps are significantly less invasive than others. In this paper, we take several steps toward answering this question. We begin by enumerating 2 500 groups of functionally-similar apps in the Google Play Store. Within groups of apps, we use static analysis to understand the real-world risks coming from apps with aggressive permission usage. By leveraging an established ranking system, and combining it with real-world data from over 28 000 Android devices, we quantify the improvements that can be made if users installed apps with privacy in mind. We observe that at least 25.6% of apps contain libraries that gratuitously exploit available permissions and find that 43.5% of apps could be swapped for comparable alternatives that require fewer permissions. Permissions saved may deliver important privacy and security improvements, including preventing access to the calendar (in 24% of cases), sending text messages (12%) and recording audio (8%). This is particularly important for apps which embed third-party libraries, since library code executes with the same permissions as the app itself. Vincent F. Taylor, Alastair R. Beresford, Ivan Martinovic |
WISEC | 2 |
| 2017 | Verifying strong eventual consistency in distributed systemsabstractData replication is used in distributed systems to maintain up-to-date copies of shared data across multiple computers in a network. However, despite decades of research, algorithms for achieving consistency in replicated systems are still poorly understood. Indeed, many published algorithms have later been shown to be incorrect, even some that were accompanied by supposed mechanised proofs of correctness. In this work, we focus on the correctness of Conflict-free Replicated Data Types (CRDTs), a class of algorithm that provides strong eventual consistency guarantees for replicated data. We develop a modular and reusable framework in the Isabelle/HOL interactive proof assistant for verifying the correctness of CRDT algorithms. We avoid correctness issues that have dogged previous mechanised proofs in this area by including a network model in our formalisation, and proving that our theorems hold in all possible network behaviours. Our axiomatic network model is a standard abstraction that accurately reflects the behaviour of real-world computer networks. Moreover, we identify an abstract convergence theorem, a property of order relations, which provides a formal definition of strong eventual consistency. We then obtain the first machine-checked correctness theorems for three concrete CRDTs: the Replicated Growable Array, the Observed-Remove Set, and an Increment-Decrement Counter. We find that our framework is highly reusable, developing proofs of correctness for the latter two CRDTs in a few hours and with relatively little CRDT-specific code. Victor B. F. Gomes, Martin Kleppmann, Dominic P. Mulligan, Alastair R. Beresford |
Proc. ACM Program. Lang. | 4 |
| 2017 | A Conflict-Free Replicated JSON DatatypeabstractMany applications model their data in a general-purpose storage format such as JSON. This data structure is modified by the application as a result of user input. Such modifications are well understood if performed sequentially on a single copy of the data, but if the data is replicated and modified concurrently on multiple devices, it is unclear what the semantics should be. In this paper we present an algorithm and formal semantics for a JSON data structure that automatically resolves concurrent modifications such that no updates are lost, and such that all replicas converge towards the same state (a conflict-free replicated datatype or CRDT). It supports arbitrarily nested list and map types, which can be modified by insertion, deletion and assignment. The algorithm performs all merging client-side and does not depend on ordering guarantees from the network, making it suitable for deployment on mobile devices with poor network connectivity, in peer-to-peer networks, and in messaging systems with end-to-end encryption. Martin Kleppmann, Alastair R. Beresford |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2016 | Supporting Scalable Data Sharing in Online EducationabstractOnline educational tools often generate learning data, and sharing such data between tutors and students can often improve learning outcomes. Unfortunately the process of sharing learning data today is not always transparent to students. Our aim is to improve the transparency and user control aspects of sharing data whilst maintaining the educational utility of data sharing between tutors and students. To do so, we start by surveying the possible methods of sharing data, and we use this to design a token-based scheme for facilitating data sharing. We implemented our scheme and observed it in use by 7,798 students over the course of one year. We find that our proposed scheme provides a good balance between transparency, user control, educational utility and scalability. Stephen Cummins, Alastair R. Beresford, Ian Davies, Andrew C. Rice |
L@S | 2 |
| 2016 | Investigating the Use of Hints in Online Problem SolvingabstractWe investigate the use of hints as a form of scaffolding for 4,652 eligible users on a large-scale online learning environment called Isaac, which allows users to answer physics questions with up to five hints. We investigate user behaviour when using hints, users' engagement with fading (the process of gradually becoming less reliant on the hints provided), and hint strategies including Decomposition, Correction, Verification, or Comparison. Finally, we present recommendations for the design and development of online teaching tools that provide open access to hints, including a mechanism that may improve the speed at which users begin fading. Stephen Cummins, Alistair Stead, Lisa Jardine-Wright, Ian Davies, Alastair R. Beresford, Andrew C. Rice |
L@S | 5 |
| 2015 | Equality: A Tool for Free-form Equation EditingabstractWe describe a new tool, Equality, for equation entry using free-form layout of components drawn from a palette of symbols. Our approach is designed to enable learners to easily manipulate the structure of their equations, to be functional in both desktop and mobile environments, and to minimize the amount of learning required to use the tool. We present the results of a study comparing a prototype of our approach with Microsoft Equation Editor using a desktop machine. The initial results are promising with participants reporting that the mechanism is easy to learn and an easy way to manipulate their equations. We report the results of the study and the views of the participants and identify how these will inform the future development of Equality. Stephen Cummins, Ian Davies, Andrew C. Rice, Alastair R. Beresford |
ICALT | 4 |
| 2015 | Securacy: an empirical investigation of Android applications' network usage, privacy and securityabstractSmartphone users do not fully know what their apps do. For example, an applications' network usage and underlying security configuration is invisible to users. In this paper we introduce Securacy, a mobile app that explores users' privacy and security concerns with Android apps. Securacy takes a reactive, personalized approach, highlighting app permission settings that the user has previously stated are concerning, and provides feedback on the use of secure and insecure network communication for each app. We began our design of Securacy by conducting a literature review and in-depth interviews with 30 participants to understand their concerns. We used this knowledge to build Securacy and evaluated its use by another set of 218 anonymous participants who installed the application from the Google Play store. Our results show that access to address book information is by far the biggest privacy concern. Over half (56.4%) of the connections made by apps are insecure, and the destination of the majority of network traffic is North America, regardless of the location of the user. Our app provides unprecedented insight into Android applications' communications behavior globally, indicating that the majority of apps currently use insecure network connections. Denzil Ferreira, Vassilis Kostakos, Alastair R. Beresford, Janne Lindqvist, Anind K. Dey |
WISEC | 3 |
| 2015 | Device analyzer: a privacy-aware platform to support research on the Android ecosystemabstractDevice Analyzer is an Android app available from the Google Play store. It is designed to collect a large range of data from the handset and, with agreement from our contributors, share it with researchers around the world. Researchers can access the data collected, and can also use the platform to support their own user studies. In this paper we provide an overview of the privacy-enhancing techniques used in Device Analzyer, including transparency, consent, purpose, access, withdrawal, and accountability. We also demonstrate the utility of our platform by assessing the security of the Android ecosystem to privilege escalation attacks and determine that 88% of Android devices are, on average, vulnerable to one or more of these type of attacks. Daniel T. Wagner, Daniel R. Thomas, Alastair R. Beresford, Andrew C. Rice |
WISEC | 3 |
| 2013 | Device Analyzer: Understanding Smartphone Usage
Daniel T. Wagner, Andrew C. Rice, Alastair R. Beresford |
MobiQuitous | 3 |
| 2008 | TIME: An Open Platform for Capturing, Processing and Delivering Transport-Related DataabstractRoad congestion and traffic-related pollution have a large, negative social and economic impact, and we believe many of these problems can be reduced through investment in monitoring, distribution and processing of traffic information. This paper outlines how our on-going work on the TIME project (transport information monitoring environment) provides a solution, using traffic sensor systems and the design and development of an open and decentralised software framework. We also discuss how we address the privacy and security implications of the increased use of sensors and data processing. Jean Bacon, Alastair R. Beresford, David Evans 0002, David Ingram, Agathoniki Trigoni, Alexandre Guitton, Antonios Skordylis |
CCNC | 2 |
| 2008 | Language-Based Optimisation of Sensor-Driven Distributed Computing Applications
Jonathan J. Davies, Alastair R. Beresford, Alan Mycroft |
FASE | 2 |
| 2006 | Cantag: an open source software toolkit for designing and deploying marker-based vision systemsabstractThis paper presents Cantag, an open source software toolkit for building marker-based vision (MBV) systems that can identify and accurately locate printed markers in three dimensions. The extensibility of the system makes it ideal for dynamic location and poses determination in pervasive computing systems. Unlike prior MBV systems, Cantag supports multiple fiducial shapes, payload types, data sizes and image processing algorithms in one framework. It allows the application writer to generate a custom tag design and associated optimised executable for any given application. The system includes a test harness which can be used to quantify, compare and contrast the performance of different designs. This paper explores the design space of tags within the Cantag system, and describes the design parameters and performance characteristics which an application writer can use to select the best tag system for any given scenario. It presents quantitative analysis of different markers and processing algorithms, which are compared fairly for the first time Andrew C. Rice, Alastair R. Beresford, Robert K. Harle |
PerCom | 2 |
| 2006 | Analysing fundamental properties of marker-based vision system designs
Andrew C. Rice, Robert K. Harle, Alastair R. Beresford |
Pervasive Mob. Comput. | 3 |
| 2004 | The Carrot Approach: Encouraging Use of Location Systems
Kieran Mansley, Alastair R. Beresford, David J. Scott |
UbiComp | 2 |
| 2003 | Spatial Security Policies for Mobile Agents in a Sentient Computing Environment
David J. Scott, Alastair R. Beresford, Alan Mycroft |
FASE | 2 |