EDBT 2026 Demo / reviewers in the wild / expert
Matilda Backendal
dblp:225/9712
· DBLP profile ↗
8ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-8677-8301ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 6 first-author · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Group Key Progression: Strong Security for Shared Persistent Data
Matilda Backendal, David Balbás, Miro Haller |
EUROCRYPT (2) | 1 |
| 2025 | Key Derivation Functions Without a Grain of Salt
Matilda Backendal, Sebastian Clermont, Marc Fischlin, Felix Günther 0001 |
EUROCRYPT (8) | 1 |
| 2024 | A Formal Treatment of End-to-End Encrypted Cloud Storage
Matilda Backendal, Hannah Davis, Felix Günther 0001, Miro Haller, Kenneth G. Paterson |
CRYPTO (2) | 1 |
| 2024 | Share with Care: Breaking E2EE in NextcloudabstractNextcloud is a leading cloud storage platform with more than 20 million users. Nextcloud offers an end-to-end encryption (E2EE) feature that is claimed to be able “to keep extremely sensitive data fully secure even in case of a full server breach”. They also claim that the Nextcloud server “has Zero Knowledge, that is, never has access to any of the data or keys in unencrypted form”. This is achieved by having encryption and decryption operations that are done using file keys that are only available to Nextcloud clients, with those file keys being protected by a key hierarchy that ultimately relies on long passphrases known exclusively to the users. We provide the first detailed documentation and security analysis of Nextcloud's E2EE feature. Nextcloud's strong security claims motivate conducting the analysis in the setting where the server itself is considered malicious. We present three distinct attacks against the E2EE security guarantees in this setting. Each one enables the confidentiality and integrity of all user files to be compromised. All three attacks are fully practical and we have built proof-of-concept implementations for each. The vulnerabilities make it trivial for a malicious Nextcloud server to access and manipulate users' data. We have responsibly disclosed the three vulnerabilities to N extcloud. The second and third vulnerabilities have been remediated. The first was addressed by temporarily disabling file sharing from the E2EE feature until a redesign of the feature can be made. We reflect on broader lessons that can be learned for designers of E2EE systems. Martin R. Albrecht, Matilda Backendal, Daniele Coppola, Kenneth G. Paterson |
EuroS&P | 2 |
| 2024 | MFKDF: Multiple Factors Knocked Down Flat
Matteo Scarlata, Matilda Backendal, Miro Haller |
USENIX Security Symposium | 2 |
| 2023 | When Messages Are Keys: Is HMAC a Dual-PRF?
Matilda Backendal, Mihir Bellare, Felix Günther 0001, Matteo Scarlata |
CRYPTO (3) | 1 |
| 2023 | MEGA: Malleable Encryption Goes AwryabstractMEGA is a leading cloud storage platform with more than 250 million users and 1000 Petabytes of stored data. MEGA claims to offer user-controlled, end-to-end security. This is achieved by having all data encryption and decryption operations done on MEGA clients, under the control of keys that are only available to those clients. This is intended to protect MEGA users from attacks by MEGA itself, or by adversaries who have taken control of MEGA’s infrastructure.We provide a detailed analysis of MEGA’s use of cryptography in such a malicious server setting. We present five distinct attacks against MEGA, which together allow for a full compromise of the confidentiality of user files. Additionally, the integrity of user data is damaged to the extent that an attacker can insert malicious files of their choice which pass all authenticity checks of the client. We built proof-of-concept versions of all the attacks. Four of the five attacks are eminently practical. They have all been responsibly disclosed to MEGA and remediation is underway.Taken together, our attacks highlight significant shortcomings in MEGA’s cryptographic architecture. We present immediately deployable countermeasures, as well as longer-term recommendations. We also provide a broader discussion of the challenges of cryptographic deployment at massive scale under strong threat models. Matilda Backendal, Miro Haller, Kenneth G. Paterson |
SP | 1 |
| 2022 | Puncturable Key Wrapping and Its Applications
Matilda Backendal, Felix Günther 0001, Kenneth G. Paterson |
ASIACRYPT (2) | 1 |