Trung Tin Nguyen

dblp:294/4401 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-author · 7 since 2021
YearPublicationVenuePosition
2025 Open Access Alert: Studying the Privacy Risks in Android WebView's Web Permission Enforcement
Trung Tin Nguyen, Ben Stock
AsiaCCS1
2025 Head(er)s Up! Detecting Security Header Inconsistencies in Browsers
abstract
In the modern Web, security headers are of the utmost importance for websites to provide protection against various attacks, such as Cross-Site Scripting, Clickjacking, and Cross-Site Leaks. As each security header uses a different syntax and has unique processing rules, correctly implementing them is a complex task for both browser and website developers. Inconsistency in browser behavior related to security headers harms websites as their security depends on their users' browsers. At the same time, compatibility issues may deter developers from deploying such headers in the first place.
Jannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben Stock
CCS2
2023 DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential Testing
Seongil Wi, Trung Tin Nguyen, Ben Stock, Sooel Son
NDSS2
2022 Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android Apps
abstract
Adopted in May 2018, the European Union's General Data Protection Regulation (GDPR) requires the consent for processing users' personal data to be freely given, specific, informed, and unambiguous. While prior work has shown that this often is not given through automated network traffic analysis, no research has systematically studied how consent notices are currently implemented and whether they conform to GDPR in mobile apps.
Trung Tin Nguyen, Michael Backes 0001, Ben Stock
CCS1
2021 Measuring User Perception for Detecting Unexpected Access to Sensitive Resource in Mobile Apps
abstract
Understanding users' perception of app behaviors is an important step to detect data access that violates user expectations. While existing works have used various proxies to infer user expectations (e.g., by analyzing app descriptions), how real-world users perceive an app's data access when they interact with graphical user interfaces (UI) has not been fully explored.
Trung Tin Nguyen, Duc Cuong Nguyen 0001, Michael Schilling 0001, Gang Wang 0011, Michael Backes 0001
AsiaCCS1
2021 Explanation Beats Context: The Effect of Timing & Rationales on Users' Runtime Permission Decisions
Yusra Elbitar, Michael Schilling 0001, Trung Tin Nguyen, Michael Backes 0001, Sven Bugiel
USENIX Security Symposium3
2021 Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android Apps
Trung Tin Nguyen, Michael Backes 0001, Ninja Marnau, Ben Stock
USENIX Security Symposium1