EDBT 2026 Demo / reviewers in the wild / expert
Wilfried Mayer
dblp:170/0100
· DBLP profile ↗
8ranked-venue papers
4as first author
3since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy Research
Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian Dabrowski |
USENIX Security Symposium | 2 |
| 2023 | An extended view on measuring tor AS-level adversariesabstractTor provides anonymity to millions of users around the globe which has made it a valuable target for malicious actors. As a low-latency anonymity system, it is vulnerable to traffic correlation attacks from strong passive adversaries such as large autonomous systems (ASes). In preliminary work Mayer et al.(2020), we have developed a measurement approach utilizing the RIPE Atlas framework – a network of more than 11,000 probes worldwide – to infer the risk of deanonymization for IPv4 clients in Germany and the US. In this paper, we apply our methodology to additional scenarios providing a broader picture of the potential for deanonymization in the Tor network. In particular, we (a) repeat our earlier (2020) measurements in 2022 to observe changes over time, (b) adopt our approach for IPv6 to analyze the risk of deanonymization when using this next-generation Internet protocol, and (c) investigate the current situation in Russia, where censorship has been intensified after the beginning of Russia’s full-scale invasion of Ukraine. According to our results, Tor provides user anonymity at consistent quality: While individual numbers vary in dependence of client and destination, we were able to identify ASes with the potential to conduct deanonymization attacks. For clients in Germany and the US, the overall picture, however, has not changed since 2020. In addition, the protocols (IPv4 vs. IPv6) do not significantly impact the risk of deanonymization. Russian users are able to securely evade censorship using Tor. Their general risk of deanonymization is, in fact, lower than in the other investigated countries. Beyond, the few ASes with the potential to successfully perform deanonymization are operated by Western companies, further reducing the risk for Russian users. Gabriel K. Gegenhuber, Florian Holzbauer, Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl, Johanna Ullrich |
Comput. Secur. | 4 |
| 2022 | Zero-Rating, One Big Mess: Analyzing Differential Pricing Practices of European MNOsabstractZero-rating, the practice of not billing data traffic that belongs to certain applications, has become popular within the mobile ecosystem around the globe. There is an ongoing debate whether mobile operators should be allowed to differentiate traffic or whether net neutrality regulations should prevent this. Despite the importance of this issue, we know little about the technical aspects of zero-rating offers since the implementation is kept secret by mobile operators and therefore is opaque to end-users and regulatory agencies. This work aims to independently audit classification practices used for zero-rating of four popular applications at seven different mobile operators in the EU. We execute and evaluate more than 300 controlled experiments within domestic and internationally roamed environments and identify potentially problematic behavior at almost all investigated operators. With this study, we hope to increase transparency around the current practices and inform future decisions and policies. Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl |
GLOBECOM | 2 |
| 2020 | Actively Probing Routes for Tor AS-Level Adversaries with RIPE Atlas
Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl |
SEC | 1 |
| 2018 | A Framework for Monitoring Net NeutralityabstractInternet service providers can discriminate traffic in certain ways, e.g., by the used protocol or application. This leads to advantages for providers, but also harms the freedom and innovation in the Internet. However, ISPs currently use a variety of technical measures. Some can be seen as questionable regarding net neutrality -- an important topic in legal and economic discussions. These methods are often neither technically identified nor continuously monitored, which prevents an informed discussion about the legitimacy of such methods. In this paper, we design and implement an open-source framework for monitoring such techniques within a country. Compared to other projects, we are able to fully control the client and server endpoint and therefore analyze network behavior in depth. We implement 17 different metrics that cover a wide range of the network spectrum. We test basic network features on transport layer as well as specific application layer protocols. We then use this framework to monitor five different Internet products in Austria over the time span of more than one year. We evaluate the results from our three measurement periods of three months each and find different questionable methods in place. This includes e.g., middleboxes used for various protocols, mon-etization of DNS results and different behavior for special DNS queries. However, many metrics show that currently no questionable techniques are used. Wilfried Mayer, Thomas Schreiber, Edgar R. Weippl |
ARES | 1 |
| 2017 | Turning Active TLS Scanning to Eleven
Wilfried Mayer, Martin Schmiedecker |
SEC | 1 |
| 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS
Katharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. Weippl |
USENIX Security Symposium | 2 |
| 2016 | No Need for Black Chambers: Testing TLS in the E-mail Ecosystem at LargeabstractTLS is the most widely used cryptographic protocol on the Internet today. While multiple recent studies focused on its use in HTTPS and the adoption rate of additional security measures over time, the usage of TLS in e-mail-related protocols is still lacking detailed insights. End-to-end encryption mechanisms like PGP are seldomly used, and as such today's confidentiality in the e-mail ecosystem is based entirely on the encryption of the transport layer. However, a large fraction of e-mails is still transmitted unencrypted, which is highly disproportionate with the sensitive nature of e-mail communication content. A well-positioned attacker may be able to intercept plaintext communication content as well as communication metadata passively and at ease. We are the first to collect and analyze the complete state of today's e-mail-related TLS configuration, for the entire IPv4 address range. Our methodology is based on commodity hardware and open-source software, and we draw a comprehensive picture of the current state of security mechanisms on the transport layer for e-mail by scanning cipher suite support which was previously considered impossible due to numerous constraints. We collected and scanned a massive dataset of 20 million IP/port combinations of all e-mail-related protocols (SMTP, POP3, IMAP). Over a time span of approx. Three months we conducted more than 10 billion TLS handshakes. Additionally, we show that securing server-to-server communication using e.g. SMTP is inherently more difficult than securing client-to-server communication, and that while the overall trend points in the right direction there are still many steps needed towards secure e-mail. Wilfried Mayer, Aaron Zauner, Martin Schmiedecker, Markus Huber 0001 |
ARES | 1 |