Jiska Classen

dblp:155/8567 · DBLP profile ↗
← Back
25ranked-venue papers
6as first author
13since 2021 · last 2026
0009-0006-4341-2808ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 5 first-author · 12 since 2021Computer networks · 3 · 1 since 2021
YearPublicationVenuePosition
2026 Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence
abstract
Many existing Artificial Intelligence (AI) solutions on mobile devices rely on an extensive collection of sensitive data, raising privacy concerns and often requiring storage for both context and model improvement. Apple's Private Cloud Compute (PCC) aims to address this by emphasizing mobile device integration and a privacy-first design. The central claim of PCC is that it does not store any user data and that user input and user accounts are unlinkable. While most of the PCC system specifications are public, compiled binaries add a layer of opaqueness. There are no reproducible builds, and there are no symbols within those binaries, creating potential discrepancies between the specification and what is shipped to the user. Additionally, the underlying models and interfaces for querying PCC are not openly accessible, limiting academic evaluation of model properties, such as accuracy. This poses a challenge in assessing whether a privacy-preserving approach like PCC is actually trustworthy while also providing high-quality answers. We are the first to reverse-engineer the PCC implementation on mobile devices to evaluate privacy aspects and to open its non-public interfaces on local devices to support custom PCC queries. We demonstrate this level of access beyond Apple's intended use cases by independently benchmarking the PCC model. We enable future research by making our PCC benchmarking framework publicly available.
Yannik Dittmar, Marvin Jerome Stephan, Thomas Völkl, Matthias Hollick, Jiska Classen
WISEC5
2026 DEMO: Recent Advancements in Detecting Cellular Attacks with CellGuard
abstract
A viable remote attack surface of smartphones is the baseband chip, which handles the communication with cellular networks. One attack that is often conducted, e.g., to track users, is the deployment of Rogue Base Stations (RBSs). We built and actively maintain CellGuard, an iOS app that analyzes the interaction of an iPhone with its baseband chip to detect whether the phone connects to an RBS. In this demo, we showcase CellGuard's base functionality of dissecting baseband communication packets and assessing nearby cells for trustworthiness, as well as recent developments. We present the latest changes to the app, including support for Apple's new C1 and C1X baseband chips, architectural improvements, user interface enhancements, and additional notifications for suspicious baseband activity.
Swantje Lange, Lukas Arnold, Maximilian Paß, Matthias Hollick, Jiska Classen
WISEC5
2025 Privacy Promises Unmasked: A Comprehensive Study of Privacy Proxies for the Masses
abstract
Internet browsing exposes private user information to websites and intermediate network providers, such as geographically linkable IP addresses and browsing history. Privacy proxies aim to address this internet privacy problem at scale. They are affordable for a large user base and do not compromise performance or usability—with a trend towards enabling them by default. Due to network encryption and closed-source code, their privacy promises cannot be verified using passive observations. We are the first to analyze the client-side implementations of three prominent privacy proxies available to over a billion users: Apple's iCloud Private Relay, Google's IP Protection, and Microsoft's Edge Secure Network VPN. We develop a deep understanding of these systems by reverse-engineering closed-source components and creating a client to bring Apple's, Google's, and Microsoft's solutions to Firefox on Linux. While privacy proxies offer privacy-enhancing features, we identify multiple issues deeply anchored in their architecture that weaken user privacy and security promises across all solutions. Our responsible disclosure and design recommendations aim to further strengthen this novel technology.
Heiko Kiesel, Jiska Classen
MobiHoc2
2025 Starshields for iOS: Navigating the Security Cosmos in Satellite Communication
Jiska Classen, Alexander Heinrich, Fabian Portner, Felix Rohrbach, Matthias Hollick
NDSS1
2025 WatchWitch: Interoperability, Privacy, and Autonomy for the Apple Watch
abstract
Smartwatches such as the Apple Watch collect vast amounts of intimate health and fitness data as we wear them. Users have little choice regarding how this data is processed: The Apple Watch can only be used with Apple's iPhones, using their software and their cloud services. We are the first to publicly reverse-engineer the watch's wireless protocols, which led to discovering multiple security issues in Apple's proprietary implementation. With WatchWitch, our custom Android reimplementation, we break out of Apple's walled garden-demonstrating practical interoperability with enhanced privacy controls and data autonomy. We thus pave the way for more consumer choice in the smartwatch ecosystem, offering users more control over their devices.
Nils Rollshausen, Alexander Heinrich, Matthias Hollick, Jiska Classen
Proc. Priv. Enhancing Technol.4
2024 Wherever I May Roam: Stealthy Interception and Injection Attacks Through Roaming Agreements
Swantje Lange, Francesco Gringoli, Matthias Hollick, Jiska Classen
ESORICS (4)4
2024 Catch You Cause I Can: Busting Rogue Base Stations using CellGuard and the Apple Cell Location Database
abstract
Mobile phones connect to the Internet and receive phone calls using a cellular baseband chip. Basebands pose a substantial attack surface, as they do not only process but also decrypt personal data. Cellular attackers usually force a phone to connect with a, e.g., to record identity information and locations, intercept or manipulate traffic, or execute arbitrary code by exploiting vulnerabilities in the baseband stack. s are stealthy, as smartphones attempt to connect to nearby base stations and do not display any indicators of compromise to the user. While their detection with Software-defined Radios (SDRs) is possible, usability and scalability are limited.
Lukas Arnold, Matthias Hollick, Jiska Classen
RAID3
2024 To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO Devices
abstract
The security of Linux kernel interfaces is paramount in preventing over-the-air, proximity, or other network attacks. The Linux kernel is fuzzed continuously to detect newly introduced bugs. Despite their long runtime, existing fuzzers fail to detect critical bugs, as they are unaware of physical device semantics and difficult to adapt to new devices. This paper proposes a novel fuzzer called VirtFuzz, which is based on Virtual I/O (VirtIO) device drivers. A proxy mechanism enables data collection from physical device interaction. These collected inputs are then used to fuzz through a virtual device. Using our universal VirtIO device, VirtFuzz is generic and can be easily adapted to various Linux VirtIO kernel drivers and their related subsystems. We use this approach to fuzz the Linux Bluetooth and Wireless LAN (WLAN) stacks. To demonstrate the adaptability of our approach, we additionally provide implementations to fuzz the networking and input stack. We find 31 new, manually confirmed bugs, with 6 Common Vulnerabilities and Exposuress (CVEs) assigned.
Sönke Huster, Matthias Hollick, Jiska Classen
SP3
2022 Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation
abstract
Modern mobile devices feature multiple wireless technologies, such as Bluetooth, Wi-Fi, and LTE. Each of them is implemented within a separate wireless chip, sometimes packaged as combo chips. However, these chips share components and resources, such as the same antenna or wireless spectrum. Wireless coexistence interfaces enable them to schedule packets without collisions despite shared resources, essential to maximizing networking performance. Today's hardwired coexistence interfaces hinder clear security boundaries and separation between chips and chip components. This paper shows practical coexistence attacks on Broadcom, Cypress, and Silicon Labs chips deployed in billions of devices. For example, we demonstrate that a Bluetooth chip can directly extract network passwords and manipulate traffic on a Wi-Fi chip. Coexistence attacks enable a novel type of lateral privilege escalation across chip boundaries. We responsibly disclosed the vulnerabilities to the vendors. Yet, only partial fixes were released for existing hardware since wireless chips would need to be redesigned from the ground up to prevent the presented attacks on coexistence.
Jiska Classen, Francesco Gringoli, Michael Hermann, Matthias Hollick
SP1
2022 Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Röschlin, Claudio Anliker, Matthias Hollick, Srdjan Capkun, Jiska Classen
USENIX Security Symposium8
2022 Evil Never Sleeps: When Wireless Malware Stays On after Turning Off iPhones
abstract
When an iPhone is turned off, most wireless chips stay on. For instance, upon user-initiated shutdown, the iPhone remains locatable via the Find My network. If the battery runs low, the iPhone shuts down automatically and enters a power reserve mode. Yet, users can still access credit cards, student passes, and other items in their Wallet. We analyze how Apple implements these standalone wireless features, working while iOS is not running, and determine their security boundaries. On recent iPhones, Bluetooth, Near Field Communication (NFC), and Ultra-wideband (UWB) keep running after power off, and all three wireless chips have direct access to the secure element. As a practical example what this means to security, we demonstrate the possibility to load malware onto a Bluetooth chip that is executed while the iPhone is off.
Jiska Classen, Alexander Heinrich, Robert Reith, Matthias Hollick
WISEC1
2021 ARIstoteles - Dissecting Apple's Baseband Interface
Tobias Kröll, Stephan Kleber, Frank Kargl, Matthias Hollick, Jiska Classen
ESORICS (1)5
2021 Happy MitM: fun and toys in every bluetooth device
abstract
Bluetooth pairing establishes trust on first use between two devices by creating a shared key. Similar to certificate warnings in TLS, the Bluetooth specification requires warning users upon issues with this key, because this can indicate ongoing Machine-in-the-Middle (MitM) attacks. This paper uncovers that none of the major Bluetooth stacks warns users, which violates the specification. Clear warnings would protect users from recently published and potential future security issues in Bluetooth authentication and encryption.
Jiska Classen, Matthias Hollick
WISEC1
2020 Demo: Analyzing Bluetooth Low Energy Connections on Off-the-Shelf Devices
Jiska Classen, Michael Spörk, Carlo Alberto Boano, Kay Römer, Matthias Hollick
EWSN1
2020 Improving the Reliability of Bluetooth Low Energy Connections
Michael Spörk, Jiska Classen, Carlo Alberto Boano, Matthias Hollick, Kay Römer
EWSN2
2020 Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets
Jan Ruge, Jiska Classen, Francesco Gringoli, Matthias Hollick
USENIX Security Symposium2
2020 MagicPairing: Apple's take on securing bluetooth peripherals
abstract
Device pairing in large Internet of Things (IoT) deployments is a challenge for device manufacturers and users. Bluetooth offers a comparably smooth trust on first use pairing experience. Bluetooth, though, is well-known for security flaws in the pairing process. In this paper, we analyze how Apple improves the security of Bluetooth pairing while still maintaining its usability and specification compliance. The proprietary protocol that resides on top of Bluetooth is called MagicPairing. It enables the user to pair a device once with Apple's ecosystem and then seamlessly use it with all their other Apple devices.
Dennis Heinze, Jiska Classen, Felix Rohrbach
WISEC2
2020 Acoustic integrity codes: secure device pairing using short-range acoustic communication
abstract
Secure Device Pairing (SDP) relies on an out-of-band channel to authenticate devices. This requires a common hardware interface, which limits the use of existing SDP systems. We propose to use short-range acoustic communication for the initial pairing. Audio hardware is commonly available on existing off-the-shelf devices and can be accessed from user space without requiring firmware or hardware modifications.
Florentin Putz, Flor Álvarez, Jiska Classen
WISEC3
2020 Lost and found: stopping bluetooth finders from leaking private information
abstract
A Bluetooth finder is a small battery-powered device that can be attached to important items such as bags, keychains, or bikes. The finder maintains a Bluetooth connection with the user's phone, and the user is notified immediately on connection loss. We provide the first comprehensive security and privacy analysis of current commercial Bluetooth finders. Our analysis reveals several significant security vulnerabilities in those products concerning mobile applications and the corresponding backend services in the cloud. We also show that all analyzed cloud-based products leak more private data than required for their respective cloud services.
Mira Weller, Jiska Classen, Fabian Ullrich, Denis Waßmann, Erik Tews
WISEC2
2019 Practical VLC to WiFi Handover Mechanisms
Richard Meister, Jiska Classen, Muhammad Saad Saud, Marcos D. Katz, Matthias Hollick
EWSN2
2019 InternalBlue - Bluetooth Binary Patching and Experimentation Framework
abstract
Bluetooth is one of the most established technologies for short range digital wireless data transmission. With the advent of wearables and the Internet of Things (IoT), Bluetooth has again gained importance, which makes security research and protocol optimizations imperative. Surprisingly, there is a lack of openly available tools and experimental platforms to scrutinize Bluetooth. In particular, system aspects and close to hardware protocol layers are mostly uncovered. We reverse engineer multiple Broadcom Bluetooth chipsets that are widespread in off-the-shelf devices. Thus, we offer deep insights into the internal architecture of a popular commercial family of Bluetooth controllers used in smartphones, wearables, and IoT platforms. Reverse engineered functions can then be altered with our InternalBlue Python framework---outperforming evaluation kits, which are limited to documented and vendor-defined functions. The modified Bluetooth stack remains fully functional and high-performance. Hence, it provides a portable low-cost research platform. InternalBlue is a versatile framework and we demonstrate its abilities by implementing tests and demos for known Bluetooth vulnerabilities. Moreover, we discover a novel critical security issue affecting a large selection of Broadcom chipsets that allows executing code within the attacked Bluetooth firmware. We further show how to use our framework to fix bugs in chipsets out of vendor support and how to add new security features to Bluetooth firmware.
Dennis Mantz, Jiska Classen, Matthias Schulz 0001, Matthias Hollick
MobiSys2
2019 Inside job: diagnosing bluetooth lower layers using off-the-shelf devices
abstract
Bluetooth is among the dominant standards for wireless short-range communication with multi-billion Bluetooth devices shipped each year. Basic Bluetooth analysis inside consumer hardware such as smartphones can be accomplished observing the Host Controller Interface (HCI) between the operating system's driver and the Bluetooth chip. However, the HCI does not provide insights to tasks running inside a Bluetooth chip or Link Layer (LL) packets exchanged over the air. As of today, consumer hardware internal behavior can only be observed with external, and often expensive tools, that need to be present during initial device pairing. In this paper, we leverage standard smartphones for on-device Bluetooth analysis and reverse engineer a diagnostic protocol that resides inside Broadcom chips. Diagnostic features include sniffing lower layers such as LL for Classic Bluetooth and Bluetooth Low Energy (BLE), transmission and reception statistics, test mode, and memory peek and poke.
Jiska Classen, Matthias Hollick
WiSec1
2017 Breaking Fitness Records Without Moving: Reverse Engineering and Spoofing Fitbit
Hossein Fereidooni, Jiska Classen, Tom Spink, Paul Patras, Markus Miettinen, Ahmad-Reza Sadeghi, Matthias Hollick, Mauro Conti
RAID2
2017 Pseudo Lateration: Millimeter-Wave Localization Using a Single RF Chain
abstract
While radio-based indoor localization schemes achieve decimeter-scale accuracy, they typically require precise reference measurements, multiple infrastructure nodes, or a multi-RF-chain anchor. In this paper, we propose Pseudo LATeration (PLAT), an indoor localization protocol that requires only a single RF chain infrastructure anchor and does not require prior knowledge of the environment. PLAT leverages the directionality and propagation characteristics of millimeter-wave transmissions to relax the requirement of multiple infrastructure anchors and RF chains by constructing pseudo anchors from reflected signal paths. By combining these pseudo anchors with time-of-flight measurements for distance estimation, PLAT can localize a user's device in indoors. Our evaluation reveals centimeter scale location accuracy for typical office environments. In testbed measurements and simulations, localization errors are centimeter scale for distances up to 1.5 m and beamwidths at or below 8.6 degrees. Although accuracy decreases to decimeter scale with additional propagation distance, we show that multiple reflection paths can mitigate this effect.
Joe Chen, Daniel Steinmetzer, Jiska Classen, Edward W. Knightly, Matthias Hollick
WCNC3
2014 CA trust management for the Web PKI
abstract
The steadily growing number of certification authorities (CAs) assigned to the Web Public Key Infrastructure (Web PKI) and trusted by current browsers imposes severe security issues.Apart from being impossible for relying entities to assess whom they actually trust, the current binary trust model implemented with the Web PKI makes each CA a single point of failure and creates an enormous attack surface.In this article, we present CA-TMS, a user-centric CA trust management system based on trust views.CA-TMS can be used by relying entities to individually reduce the attack surface.CA-TMS works by restricting the trust placed in CAs of the Web PKI to trusting in exactly those CAs actually required by a relying entity.This restriction is based on locally collected information and does not require the alteration of the existing Web PKI.CA-TMS is complemented by an optional reputation system that allows to utilize the knowledge of other entities while maintaining the minimal set of trusted CAs.Our evaluation of CA-TMS with real world data shows that an attack surface reduction by more than 95% is achievable.
Johannes Braun 0001, Florian Volk, Jiska Classen, Johannes Buchmann 0001, Max Mühlhäuser
J. Comput. Secur.3