EDBT 2026 Demo / reviewers in the wild / expert
Karel Kubicek 0001
dblp:233/8369-1
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2024
0000-0002-7419-2784ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Automated Large-Scale Analysis of Cookie Notice Compliance
Ahmed Bouhoula, Karel Kubicek 0001, Amit Zac, Carlos Cotrini Jiménez, David A. Basin |
USENIX Security Symposium | 2 |
| 2024 | Automating Website Registration for Studying GDPR ComplianceabstractInvestigating how websites use sensitive user data is an active research area. However, research based on automated measurements has been limited to those websites that do not require user authentication. To overcome this limitation, we developed a crawler that automates website registrations and newsletter subscriptions and detects both security and privacy threats at scale. Karel Kubicek 0001, Jakob Merane, Ahmed Bouhoula, David A. Basin |
WWW | 1 |
| 2024 | Block Cookies, Not Websites: Analysing Mental Models and Usability of the Privacy-Preserving Browser Extension CookieBlockabstractIn the modern web, users are confronted with a plethora of complex privacy-related decisions about cookies and consent, often com- pounded by misleading policies and deceptive patterns. Past efforts to enhance online privacy have failed due to their dependence on website compliance. A solution to this lies in privacy-enhancing tools that are directly controlled by the user. However, challenges related to the usability and flawed understanding of the tools’ func- tionality hinder their widespread adoption. To address this problem, we evaluated the browser extension CookieBlock as an example of a current tool, which supports users by blocking tracking cookies independent of website compliance. We used a complementary approach consisting of an expert eval- uation of CookieBlock and the related tools NoScript and Ghostery, and a laboratory user study focusing on the unique details of how users interact with CookieBlock specifically. The laboratory study with 42 participants investigated usage, mental models, and us- ability of CookieBlock based on eye tracking, interaction, and self- report data. While CookieBlock received good usability ratings, 18 participants were unable to solve a website breakage caused by cookie misclassification on their own. Overall, the results revealed flawed mental models of CookieBlock’s functionality and resulting challenges in making the connection between website breakage and cookie misclassification. Implications for CookieBlock and related applications include interface design recommendations supporting accurate mental models and the proposal of improved heuristics to better guide users and warn them about potential identified website breakage. Lorin Schöni, Karel Kubicek 0001, Verena Zimmermann |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Locality-Sensitive Hashing Does Not Guarantee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy SystemabstractRecently proposed systems aim at achieving privacy using locality-sensitive hashing. We show how these approaches fail by presenting attacks against two such systems: Google's FLoC proposal for privacy-preserving targeted advertising and the MinHash Hierarchy, a system for processing location trajectories in a privacy-preserving way. Our attacks refute the pre-image resistance, anonymity, and privacy guarantees claimed for these systems. In the case of FLoC, we show how to deanonymize users using Sybil attacks and to reconstruct 10% or more of the browsing history for 30% of its users using Generative Adversarial Networks. We achieve this only analyzing the hashes used by FLoC. For MinHash, we precisely identify the location trajectory of a subset of individuals and, on average, we can limit users' trajectory to just 10% of the possible geographic area, again using just the hashes. In addition, we refute their differential privacy claims. Florian Turati, Karel Kubicek 0001, Carlos Cotrini Jiménez, David A. Basin |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Large-scale Randomness Study of Security Margins for 100+ Cryptographic FunctionsabstractThe output of cryptographic functions, be it encryption routines or hash functions, should be statistically indistinguishable from a truly random data for an external observer. The property can be partially tested automatically using batteries of statistical tests. However, it is not easy in practice: multiple incompatible test suites exist, with possibly overlapping and correlated tests, making the statistically robust interpretation of results difficult. Additionally, a significant amount of data processing is required to test every separate cryptographic function. Due to these obstacles, no large-scale systematic analysis of the the round-reduced cryptographic functions w.r.t their input mixing capability, which would provide an insight into the behaviour of the whole classes of functions rather than few selected ones, was yet published. We created a framework to consistently run 414 statistical tests and their variants from the commonly used statistical testing batteries (NIST ST S, Dieharder, TestU01, and BoolTest). Using the distributed computational cluster providing required significant processing power, we analyzed the output of 109 round-reduced cryptographic functions (hash, lightweight, and block-based encryption functions) in the multiple configurations, scrutinizing the mixing property of each one. As a result, we established the fraction of a function’s rounds with still detectable bias (a.k.a. security margin) when analyzed by randomness statistical tests. Dusan Klinec, Marek Sýs, Karel Kubicek 0001, Petr Svenda, Vashek Matyas |
SECRYPT | 3 |
| 2022 | Automating Cookie Consent and GDPR Violation Detection
Dino Bollinger, Karel Kubicek 0001, Carlos Cotrini Jiménez, David A. Basin |
USENIX Security Symposium | 2 |
| 2022 | Checking Websites' GDPR Consent Compliance for Marketing EmailsabstractAbstract The sending of marketing emails is regulated to protect users from unsolicited emails. For instance, the European Union’s ePrivacy Directive states that marketers must obtain users’ prior consent, and the General Data Protection Regulation (GDPR) specifies further that such consent must be freely given, specific, informed, and unambiguous. Based on these requirements, we design a labeling of legal characteristics for websites and emails. This leads to a simple decision procedure that detects potential legal violations. Using our procedure, we evaluated 1000 websites and the 5000 emails resulting from registering to these websites. Both datasets and evaluations are available upon request. We find that 21.9% of the websites contain potential violations of privacy and unfair competition rules, either in the registration process (17.3%) or email communication (17.7%). We demonstrate with a statistical analysis the possibility of automatically detecting such potential violations. Karel Kubicek 0001, Jakob Merane, Carlos Cotrini Jiménez, Alexander Stremitzer, Stefan Bechtold, David A. Basin |
Proc. Priv. Enhancing Technol. | 1 |