EDBT 2026 Demo / reviewers in the wild / expert
Christian Burkert
dblp:225/5081
· DBLP profile ↗
8ranked-venue papers
3as first author
4since 2021 · last 2022
0000-0001-8187-5447ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Probing for Passwords - Privacy Implications of SSIDs in Probe Requests
Johanna Ansohn McDougall, Christian Burkert, Daniel Demmler, Monina Schwarz, Vincent Hubbe, Hannes Federrath |
ACNS | 2 |
| 2022 | Data Minimisation Potential for Timestamps in Git: An Empirical Analysis of User Configurations
Christian Burkert, Johanna Ansohn McDougall, Hannes Federrath |
SEC | 1 |
| 2021 | Analysing Leakage during VPN Establishment in Public Wi-Fi NetworksabstractThe use of public Wi-Fi networks can reveal sensitive data to both operators and bystanders. A VPN can prevent this. However, a machine that initiates a connection to a VPN server might already leak sensitive data before the VPN tunnel is fully established. Furthermore, it might not be immediately possible to establish a VPN connection if the network requires authentication via a captive portal, thus increasing the leakage potential. In this paper we examine both issues. For that, we analyse the behaviour of native and third-party VPN clients on various platforms, and introduce a new method called selective VPN bypassing to avoid captive portal deadlocks. Christian Burkert, Johanna Ansohn McDougall, Hannes Federrath, Mathias Fischer 0001 |
ICC | 1 |
| 2021 | Compiling Personal Data and Subject Categories from App Data Models
Christian Burkert, Maximilian Blochberger, Hannes Federrath |
SEC | 1 |
| 2020 | Enhanced Performance and Privacy for TLS over TCP Fast OpenabstractAbstract Small TCP flows make up the majority of web flows. For them, the TCP three-way handshake induces significant delay overhead. The TCP Fast Open (TFO) protocol can significantly decrease this delay via zero round-trip time (0-RTT) handshakes for all TCP handshakes that follow a full initial handshake to the same host. However, this comes at the cost of privacy limitations and also has some performance limitations. In this paper, we investigate the TFP deployment on popular websites and browsers. We found that a client revisiting a web site for the first time fails to use an abbreviated TFO handshake in 40% of all cases due to web server load-balancing using multiple IP addresses. Our analysis further reveals significant privacy problems of the protocol design and implementation. Network-based attackers and online trackers can exploit TFO to track the online activities of users. As a countermeasure, we introduce a novel protocol called TCP Fast Open Privacy (FOP). TCP FOP prevents tracking by network attackers and impedes third-party tracking, while still allowing 0-RTT handshakes as in TFO. As a proof-of-concept, we have implemented the proposed protocol for the Linux kernel and a TLS library. Our measurements indicate that TCP FOP outperforms TLS over TFO when websites are served from multiple IP addresses. Erik Sy, Tobias Mueller, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | QUICker Connection Establishment with Out-Of-Band Validation TokensabstractQUIC is a secure transport protocol that improves the performance of HTTPS. An initial QUIC handshake that enforces a strict validation of the client's source address requires two round-trips. In this work, we extend QUIC's address validation mechanism by an out-of-band validation token to save one round-trip time during the initial handshake. The proposed token allows sharing an address validation between the QUIC server and trusted entities issuing these tokens. This saves a round-trip time for the address validation. Furthermore, we propose distribution mechanisms for these tokens using DNS resolvers and QUIC connections to other hostnames. Our proposal can save up to 50% of the delay overhead of an initial QUIC handshake. Furthermore, our analytical results indicate that 363.6 ms in total can be saved for all connections required to retrieve an average website, if a round-trip time of 90 ms is assumed. Erik Sy, Christian Burkert, Tobias Mueller, Hannes Federrath, Mathias Fischer 0001 |
LCN | 2 |
| 2019 | A QUIC Look at Web TrackingabstractAbstract QUIC has been developed by Google to improve the transport performance of HTTPS traffic. It currently accounts for approx. 7% of the global Internet traffic. In this work, we investigate the feasibility of user tracking via QUIC from the perspective of an online service. Our analysis reveals that the protocol design contains violations of privacy best practices through which a tracker can passively and uniquely identify clients across several connections. This tracking mechanisms can achieve reduced delays and bandwidth requirements compared to conventional browser fingerprinting or HTTP cookies. This allows them to be applied in resource- or time-constrained scenarios such as real-time biddings in online advertising. To validate this finding, we investigated browsers which enable QUIC by default, e.g., Google Chrome. Our results suggest that the analyzed browsers do not provide protective measures against tracking via QUIC. However, the introduced mechanisms reset during a browser restart, which clears the cached connection data and thus limits achievable tracking periods. To mitigate the identified privacy issues, we propose changes to QUIC’s protocol design, the operation of QUIC-enabled web servers, and browser implementations. Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Tracking Users across the Web via TLS Session ResumptionabstractUser tracking on the Internet can come in various forms, e.g., via cookies or by fingerprinting web browsers. A technique that got less attention so far is user tracking based on TLS and specifically based on the TLS session resumption mechanism. To the best of our knowledge, we are the first that investigate the applicability of TLS session resumption for user tracking. For that, we evaluated the configuration of 48 popular browsers and one million of the most popular websites. Moreover, we present a so-called prolongation attack, which allows extending the tracking period beyond the lifetime of the session resumption mechanism. To show that under the observed browser configurations tracking via TLS session resumptions is feasible, we also looked into DNS data to understand the longest consecutive tracking period for a user by a particular website. Our results indicate that with the standard setting of the session resumption lifetime in many current browsers, the average user can be tracked for up to eight days. With a session resumption lifetime of seven days, as recommended upper limit in the draft for TLS version 1.3, 65% of all users in our dataset can be tracked permanently. Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
ACSAC | 2 |