EDBT 2026 Demo / reviewers in the wild / expert
Martin Schmiedecker
dblp:169/9708
· DBLP profile ↗
10ranked-venue papers
0as first author
0since 2021 · last 2017
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Network security · 100% |
Topics — the 2 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security
HTTPS deployment |
0.3 | 1 | 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS · USENIX Security Symposium 2017 |
Network security › secure communication › secure communication protocol
TLS |
0.1 | 1 | 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS · USENIX Security Symposium 2017 |
Methods — techniques the papers use, named apart from their topics
usability study · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | Timestamp hiccups: Detecting manipulated filesystem timestamps on NTFSabstractRedundant capacity in filesystem timestamps is recently proposed in the literature as an effective means for information hiding and data leakage. Sebastian Neuner, Artemios G. Voyiatzis, Martin Schmiedecker, Edgar R. Weippl |
ARES | 3 |
| 2017 | Block Me If You Can: A Large-Scale Study of Tracker-Blocking ToolsabstractIn this paper, we quantify the effectiveness of third-party tracker blockers on a large scale. First, we analyze the architecture of various state-of-the-art blocking solutions and discuss the advantages and disadvantages of each method. Second, we perform a two-part measurement study on the effectiveness of popular tracker-blocking tools. Our analysis quantifies the protection offered against trackers present on more than 100,000 popular websites and 10,000 popular Android applications. We provide novel insights into the ongoing arms race between trackers and developers of blocking tools as well as which tools achieve the best results under what circumstances. Among others, we discover that rule-based browser extensions outperform learning-based ones, trackers with smaller footprints are more successful at avoiding being blocked, and CDNs pose a major threat towards the future of tracker-blocking tools. Overall, the contributions of this paper advance the field of web privacy by providing not only the largest study to date on the effectiveness of tracker-blocking tools, but also by highlighting the most pressing challenges and privacy issues of third-party tracking. Georg Merzdovnik, Markus Huber 0001, Damjan Buhov, Nick Nikiforakis, Sebastian Neuner, Martin Schmiedecker, Edgar R. Weippl |
EuroS&P | 6 |
| 2017 | Real-Time Forensics Through Endpoint Visibility
Peter Kieseberg, Sebastian Neuner, Sebastian Schrittwieser, Martin Schmiedecker, Edgar R. Weippl |
ICDF2C | 4 |
| 2017 | Turning Active TLS Scanning to Eleven
Wilfried Mayer, Martin Schmiedecker |
SEC | 2 |
| 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS
Katharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. Weippl |
USENIX Security Symposium | 3 |
| 2016 | No Need for Black Chambers: Testing TLS in the E-mail Ecosystem at LargeabstractTLS is the most widely used cryptographic protocol on the Internet today. While multiple recent studies focused on its use in HTTPS and the adoption rate of additional security measures over time, the usage of TLS in e-mail-related protocols is still lacking detailed insights. End-to-end encryption mechanisms like PGP are seldomly used, and as such today's confidentiality in the e-mail ecosystem is based entirely on the encryption of the transport layer. However, a large fraction of e-mails is still transmitted unencrypted, which is highly disproportionate with the sensitive nature of e-mail communication content. A well-positioned attacker may be able to intercept plaintext communication content as well as communication metadata passively and at ease. We are the first to collect and analyze the complete state of today's e-mail-related TLS configuration, for the entire IPv4 address range. Our methodology is based on commodity hardware and open-source software, and we draw a comprehensive picture of the current state of security mechanisms on the transport layer for e-mail by scanning cipher suite support which was previously considered impossible due to numerous constraints. We collected and scanned a massive dataset of 20 million IP/port combinations of all e-mail-related protocols (SMTP, POP3, IMAP). Over a time span of approx. Three months we conducted more than 10 billion TLS handshakes. Additionally, we show that securing server-to-server communication using e.g. SMTP is inherently more difficult than securing client-to-server communication, and that while the overall trend points in the right direction there are still many steps needed towards secure e-mail. Wilfried Mayer, Aaron Zauner, Martin Schmiedecker, Markus Huber 0001 |
ARES | 3 |
| 2016 | Whom You Gonna Trust? A Longitudinal Study on TLS Notary Services
Georg Merzdovnik, Klaus Falb, Martin Schmiedecker, Artemios G. Voyiatzis, Edgar R. Weippl |
DBSec | 3 |
| 2016 | NavigaTor: Finding Faster Paths to AnonymityabstractThe Tor network is currently by far the most popular system for providing anonymity on the Internet. Even though both latency and throughput have been significantly improved in recent years, Tor users still experience variable delays on connecting to servers. Such delays have been shown to be especially harmful for browsing the web and prevent altogether the use of protocols where a certain quality of service is indispensable. In this paper we propose and evaluate methods to measure and improve performance in the Tor network. To estimate the quality of circuits for future traffic, we use active Round-Trip-Time (RTT) measurements and a-priori information of the distribution of RTT values. In this way, slow circuits can be discarded before having negative impact on user experience. Using NavigaTor, our high performance measurement software which includes a custom Tor path generator, we are the first to conduct large-scale performance measurements on the live Tor network, building millions of circuits within days, without stressing the anonymity network. As part of our study, we conduct several experiments from PlanetLab on the live Tor network to analyze the trade-off between the quality of protection and the quality of service. We compare our Circuit-RTT method to the current state-of-the-art method Circuit Build Time (CBT) and the more recently proposed congestion-aware scheme, finding that the congestion-aware scheme in its original design achieves only minor improvements on the current Tor network and that Circuit-RTT improves latency and throughput more effectively than CBT. Robert Annessi, Martin Schmiedecker |
EuroS&P | 2 |
| 2016 | Effectiveness of file-based deduplication in digital forensicsabstractAbstract Over the last decades, the increasing amount of storage became a pressing problem for forensic investigators. This is caused by the computerization of everyday life and the associated increasing number of different devices in typical households. Considering multi‐terabyte storage on the suspects' side, even more storage requirements emerge on the side of the investigator for secure backup and working copies. In this paper, we improve the standardized forensic process by proposing to rigorously use file deduplication across devices as well as file whitelisting in investigations in order to reduce the amount of data that needs to be stored for analysis as early as during data acquisition. These improvements happen in an automatic fashion and are completely transparent to the forensic investigator. They may furthermore be added without negative effects to the chain of custody or artifact validity in court and are evaluated in a realistic use case. Additionally, we illustrate the effectivity of our proposed approach on a real‐world corpus by showing a notable reduction in number of reduced files as well as storage. Copyright © 2016 John Wiley & Sons, Ltd. Sebastian Neuner, Martin Schmiedecker, Edgar R. Weippl |
Secur. Commun. Networks | 2 |
| 2015 | Privacy and data protection in smartphone messengersabstractEver since the Snowden revelations regarding mass surveillance, the role of privacy protection in commodity communication software has gained increasing awareness in the general public. Still, during the last years many new messengers were developed for Android, where often privacy was not considered to be a key issue. Due to the widespread use of these apps even in corporate environments this opens up attack vectors that can result in advanced persistent threats. In this paper we analyze the most prominent messenger apps with respect to privacy concepts, focusing not only on the transmission layer regarding the support of encrypted communication, but also attacks targeting the communication metadata, e.g. detecting the existence of communication between users, as well as providing an enumeration of all users of a service. Furthermore, device theft and loss is a major issue regarding the protection of user privacy. Thus, we also analyzed, whether the messages are stored in a secure way on the device itself, or if control over the physical device allows access to the message data. In order to analyze the possible usability of these messengers as means for targeted surveillance of users by the provider (or an entity controlling it), we also analyzed the rights and privileges the respective apps need in order to be able to install and work. Here, major differences could be detected, with several apps claiming privileges that could not be explained with the normal mode of operation, thus posing a serious risk for the privacy of the respective user base. Christoph Rottermanner, Peter Kieseberg, Markus Huber 0001, Martin Schmiedecker, Sebastian Schrittwieser |
iiWAS | 4 |