EDBT 2026 Demo / reviewers in the wild / expert
Ke Coby Wang
dblp:220/3081
· DBLP profile ↗
7ranked-venue papers
5as first author
5since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The 2FA Illusion: Uncovering Weak Links of Web Account Access in the WildabstractSingle-factor authentication (1FA) and two-factor authentication (2FA) for secure and reliable website account access have become everyday tasks for most users. However, the complexity of integrating 1FA, 2FA, and password reset mechanisms makes real-world deployments challenging to navigate, leaving key questions about their implications for account security and accessibility unanswered. In this paper, we present a comprehensive investigation into the deployment of 1FA, 2FA, and password reset mechanisms across 50 major websites in six industries. By formally modeling account access and password reset patterns and applying Karnaugh maps for logical optimization, we uncover surprising consequences of current integrations of authentication mechanisms. We present key findings on the implications of modern authentication integrations for account security and accessibility, highlighting both the overestimated strengths and overlooked weaknesses of current deployments. Our research aims to provide a valuable and practical understanding of real-world authentication deployments for advancing web authentication practices. Ke Coby Wang, Sunpreet S. Arora, Michael K. Reiter |
ACSAC | 1 |
| 2025 | A Composability Analysis Framework for Web3 Wallet Recovery MechanismsabstractModern Web3 wallets offer hybrid recovery solutions that combine multiple key recovery methods to balance security, availability, and usability. These methods include secret sharing of wallet private keys, encrypted cloud storage, and smart contract-based advanced recovery functionalities. However, such combined approaches can introduce new attack vectors that are not present in standalone recovery solutions. In this work, we propose a formal security analysis frame-work for blockchain/Web3 wallet designs with key or asset recovery functionalities. To assess whether a wallet design is secure, our framework considers several factors, including user availability and responsiveness to malicious actions, co-custodianship with external parties, the total value of assets managed by the wallet, and the reputation of the entities chosen by the user to facilitate spending or recovery functionalities. Through probabilistic model checking, our framework identifies the conditions under which a wallet design remains secure. We also include two examples of Web3 wallet designs with composite recovery mechanisms (inspired by existing designs) to demonstrate the effectiveness of our framework. Panagiotis Chatzigiannis, Ke Coby Wang, Sunpreet S. Arora, Mohsen Minaei |
SP | 2 |
| 2025 | Detecting Compromise of Passkey Storage on the Cloud
Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Ke Coby Wang |
USENIX Security Symposium | 4 |
| 2024 | Bernoulli Honeywords
Ke Coby Wang, Michael K. Reiter |
NDSS | 1 |
| 2021 | Using Amnesia to Detect Credential Database Breaches
Ke Coby Wang, Michael K. Reiter |
USENIX Security Symposium | 1 |
| 2020 | Detecting Stuffing of a User's Credentials at Her Own Accounts
Ke Coby Wang, Michael K. Reiter |
USENIX Security Symposium | 1 |
| 2019 | How to End Password Reuse on the Web
Ke Coby Wang, Michael K. Reiter |
NDSS | 1 |