EDBT 2026 Demo / reviewers in the wild / expert
Thomas Ristenpart
dblp:26/3399
· DBLP profile ↗
116ranked-venue papers
9as first author
36since 2021 · last 2026
0000-0002-8642-9558ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 94 · 9 first-author · 28 since 2021Human-computer interaction and ubiquitous computing · 14 · 8 since 2021Systems, architecture and hardware · 3Computer networks · 2Databases, data management, data science and information retrieval · 2Theory of computation · 2Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AI-Facilitated Coercive Control: An Experimental StudyabstractWe present an experimental study that investigates how LLM-driven conversational AI tools might be weaponized to facilitate, exacerbate, or commoditize coercive control. Inspired by speculative design, we construct four scenarios that combine well-known coercive control tactics with the current capabilities of conversational AI tools. Then, we explore these scenarios via interactions with popular AI agents (ChatGPT, Gemini). We find that although AI tools refuse straightforward requests for harmful content, their guardrails can be circumvented via strategies such as gradual persuasion, splitting conversations, pre-prompting, and manipulating the AI agent’s settings. Collectively, these strategies enable AI agents to be leveraged in ways that facilitate harassment, intimidation, gaslighting, monitoring, surveillance, and other coercive control tactics. To make these tools safer for everyone, we discuss opportunities for AI agents to resist being abused for coercive control via analysis of users’ conversational patterns, and ensuring that pre-programmed settings are clearly visible to prevent covert manipulation. Haesoo Kim, Thomas Ristenpart, Nicola Dell |
CHI | 2 |
| 2026 | Random-Access AEAD for Fast Lightweight Online Encryption
Andrés Fábrega, Julia Len, Thomas Ristenpart, Gregory Rubin |
EUROCRYPT | 3 |
| 2026 | Access Control in Interpersonal Abuse ContextsabstractComputer security is traditionally about the protection of digital systems from adversaries such as criminals or governments, with access control playing a key role in preventing intrusions. Less attention has been paid to the harms that arise in interpersonal threat models, in which the adversary is a member of the victim's social circles---an intimate partner, family member, or other close acquaintance---and seeks to cause harm to the victim via technology. Such known-adversary threat models are a widespread and increasingly severe problem, and their study opens up a new frontier for computer security research and practice. Thomas Ristenpart |
SACMAT | 1 |
| 2026 | SoK: Offline Finding Protocols for Lightweight Location TrackingabstractOffline finding (OF) protocols---such as Apple's Find My, Google's Find Hub, Samsung’s SmartThingsFind, and Tile---enable hundreds of millions of users to track their belongings via Bluetooth-based tracker tags. However, their scale and tracking capabilities give rise to privacy risks for tag owners and bystanders, as well as safety risks for victims of tag-facilitated stalking. In response, academics and practitioners have suggested cryptographic and non-cryptographic mitigations to improve privacy and anti-stalking protections, working to navigate complex and subtle tensions between these goals. The result is a large landscape of privacy goals, threat models, protocol designs, implementations, and analyses. In this work, we systematize the OF protocol landscape. We gather and analyze a corpus of 49 research papers and OF protocol technical specifications, and use it to develop a taxonomy capturing the functionality, security, and privacy goals of OF protocols. We use the taxonomy to guide a focused assessment of the four major OF deployments along with six academic constructions, comparing design choices, consolidating known attacks, and analyzing the designs' trade-offs between privacy, security, abusability, and efficiency. We provide a simple OF protocol that achieves most security goals, and which clarifies the essential cryptographic components underlying OF protocols. We also provide a survey of physical layer attacks and usability issues that undermine protections in practice. Finally, we discuss open problems and potential research directions towards secure, interoperable, and abuse-resistant OF systems. Akshaya Kumar, Carolina Ortega Pérez, Joseph Jaeger, Thomas Ristenpart, Michael A. Specter |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Transcript Franking for Encrypted Messaging
Armin Namavari, Thomas Ristenpart |
ASIACRYPT (2) | 2 |
| 2025 | The OCH Authenticated Encryption SchemeabstractWe specify OCH, the first authenticated encryption with associated data scheme built to provide 128-bit multi-user AE security, 128-bit context commitment security, and 256-bit nonces with optional nonce privacy. It therefore addresses pressing limitations of currently widely-deployed schemes. We construct and formally analyze the security of OCH in a modular fashion, with transforms that are of broader applicability. On Intel Raptor Lake CPUs, OCH using the Areion permutation family has a peak encryption speed of 0.62 cycles per byte (cpb), not far off from AES128-GCM (0.38cpb) and outperforming both ChaCha20/Poly1305 (1.63cpb) and TurboSHAKE128-Wrap (3.52cpb). Sanketh Menda, Mihir Bellare, Viet Tung Hoang, Julia Len, Thomas Ristenpart |
CCS | 5 |
| 2025 | Interoperable Symmetric Message FrankingabstractThe recent Digital Markets Act (DMA), a regulation passed by the European Union in 2022, requires messaging applications with large user bases to support interoperable end-to-end encrypted (E2EE) communication. This raises numerous questions about how to adapt cryptographic protocols to this setting in a way that preserves security and privacy. This question is not only limited to the main messaging protocols, but also extends to protocols for abuse mitigation such as the symmetric message franking protocol first proposed by Facebook. The latter uses symmetric cryptography to enable reporting abusive E2EE messages in a way that allows the platform to cryptographically verify the report's veracity. Carolina Ortega Pérez, Thomas Ristenpart, Julia Len |
CCS | 2 |
| 2025 | Digital Technologies and Human Trafficking: Combating Coercive Control and Navigating Digital AutonomyabstractThis paper describes a qualitative study that interrogates the types of technology-facilitated coercive control faced by survivors of human trafcking and uncovers potential interventions to aid survivors' recovery.Via semi-structured interviews with 21 participants, including trafcking survivors and professional advocates, we show how trafckers use technology as a lever for control, engaging in surveillance, blackmail, impersonation, and harassment as they compel survivors to stay in the trafcking situation.In recovery, digital footprints keep survivors tethered to their traffcking experience, impacting their digital autonomy, economic mobility, and feelings of safety.Nevertheless, technology can also be a valuable tool for survivors' recovery, connecting them to essential resources and support systems.We discuss the need for interventions and services that account for the specifcity of the trafcking context to help survivors attain digital safety and autonomy, including the potential to adapt existing tech safety services designed for other contexts to human trafcking. CCS Concepts• Human-centered computing → Empirical studies in HCI ; • Security and privacy → Human and societal aspects of security and privacy. Sophie Stephenson, Lana Ramjit, Thomas Ristenpart, Nicola Dell |
CHI | 3 |
| 2025 | A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models
Alaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee 0001, Nicola Dell, Rosanna Bellini, Thomas Ristenpart |
USENIX Security Symposium | 7 |
| 2025 | Mitigating Injection Attacks against E2EE Applications via View-Based Partitioning
Andrés Fábrega, Samuel Breckenridge, Armin Namavari, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2025 | Mitigating Trauma in Qualitative Research Infrastructure: Roles for Machine Assistance and Trauma-Informed DesignabstractResearchers increasingly look to understand experiences of pain, harm, and marginalization via qualitative analysis. Such work is needed to understand and address social ills, but poses risks to researchers' well-being: sifting through volumes of data on painful human experiences risks incurring traumatic exposure in the researcher. In this paper, we explore how the principles of trauma-informed computing (TIC) can be applied to reimagine healthier tools and workflows for qualitative analysis. We apply TIC to create a design provocation called TIQA, a system for qualitative coding that leverages language modeling, semantic search, and recommendation systems to measure and mitigate an analyst's exposure to concepts they find traumatic. Through a formative study of TIQA with 15 participants, we illuminate the complexities of enacting TIC in qualitative knowledge infrastructure, and potential roles for machine assistance in mitigating researchers' trauma. To assist scholars in translating the high-level principles of TIC into sociotechnical system design, we argue for: (a) a conceptual shift from safety as exposure reduction towards safety as enablement; and (b) renewed attention to evaluating the trauma-informedness of design processes, in tandem with the outcomes of designed objects on users' well-being. Emily Tseng, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2024 | Is ML-Based Cryptanalysis Inherently Limited? Simulating Cryptographic Adversaries via Gradient-Based Methods
Avital Shafran, Eran Malach, Thomas Ristenpart, Gil Segev 0001, Stefano Tessaro |
CRYPTO (6) | 3 |
| 2024 | SoK: Safer Digital-Safety Research Involving At-Risk UsersabstractResearch involving at-risk users—that is, users who are more likely to experience a digital attack or to be disproportionately affected when harm from such an attack occurs—can pose significant safety challenges to both users and researchers. Nevertheless, pursuing research in computer security & privacy (S&P) is crucial to understanding how to meet the digital-safety needs of at-risk users and to design safer technology for all. To standardize and bolster safer research involving such users, we offer an analysis of 196 academic works to elicit 14 research risks and 36 safety practices used by a growing community of researchers. We pair this inconsistent set of reported safety practices with oral histories from 12 domain experts to contribute scaffolded and consolidated pragmatic guidance that researchers can use to plan, execute, and share safer digital-safety research involving at-risk users. We conclude by suggesting areas for future research regarding the reporting, study, and funding of at-risk user research. Rosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla, Tara Matthews, Sunny Consolvo, Jill Palzkill Woelfer, Patrick Gage Kelley, Michelle L. Mazurek, Dana Cuomo, Nicola Dell, Thomas Ristenpart |
SP | 12 |
| 2024 | Injection Attacks Against End-to-End Encrypted ApplicationsabstractWe explore an emerging threat model for end-to-end (E2E) encrypted applications: an adversary sends chosen messages to a target client, thereby "injecting" adversarial content into the application state. Such state is subsequently encrypted and synchronized to an adversarially-visible storage. By observing the lengths of the resulting cloud-stored cipher-texts, the attacker backs out confidential information.We investigate this injection threat model in the context of state-of-the-art encrypted messaging applications that support E2E encrypted backups. We show proof-of-concept attacks that can recover information about E2E encrypted messages or attachments sent via WhatsApp, assuming the ability to compromise the target user’s Google or Apple account (which gives access to encrypted backups). We also show weaknesses in Signal’s encrypted backup design that would allow injection attacks to infer metadata including a target user’s number of contacts and conversations, should the adversary somehow obtain access to the user’s encrypted Signal backup.While we do not believe our results should be of immediate concern for users of these messaging applications, our results do suggest that more work is needed to build tools that enjoy strong E2E security guarantees. Andrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi, Rachit Agarwal 0001, Thomas Ristenpart |
SP | 6 |
| 2024 | Private Hierarchical Governance for Encrypted MessagingabstractThe increasing harms caused by hate, harassment, and other forms of abuse online have motivated major platforms to explore hierarchical governance. The idea is to allow communities to have designated members take on moderation and leadership duties; meanwhile, members can still escalate issues to the platform. But these promising approaches have only been explored in plaintext settings where community content is public to the platform. It is unclear how one can realize hierarchical governance in the huge and increasing number of online communities that utilize end-to-end encrypted (E2EE) messaging for privacy.We propose private hierarchical governance systems. These should enable similar levels of community governance as in plaintext settings, while maintaining cryptographic privacy of content and governance actions not reported to the platform. We design the first such system, taking a layered approach that adds governance logic on top of an encrypted messaging protocol; we show how an extension to the message layer security (MLS) protocol suffices for achieving a rich set of governance policies. Our approach allows developers to rapidly prototype new governance features, taking inspiration from a plaintext system called PolicyKit. We build a prototype E2EE messaging system called MlsGov that supports content-based community and platform moderation, elections of community moderators, votes to remove abusive users, and more. Armin Namavari, Barry Wang, Sanketh Menda, Ben Nassi, Nirvan Tyagi, James Grimmelmann, Amy X. Zhang, Thomas Ristenpart |
SP | 8 |
| 2024 | Exploiting Leakage in Password Managers via Injection Attacks
Andrés Fábrega, Armin Namavari, Rachit Agarwal 0001, Ben Nassi, Thomas Ristenpart |
USENIX Security Symposium | 5 |
| 2024 | Navigating Traumatic Stress Reactions During Computer Security Interventions
Lana Ramjit, Natalie Dolci, Francesca Rossi 0001, Ryan Garcia, Thomas Ristenpart, Dana Cuomo |
USENIX Security Symposium | 5 |
| 2024 | Data Stewardship in Clinical Computer Security: Balancing Benefit and Burden in Participatory SystemsabstractThe mass collection and reuse of social data requires a reimagining of privacy and consent, with particular attention to the (in)equitable distribution of benefits and burdens between researchers and subjects. Instrumenting frontline clinical services to collect and steward data might mitigate the exploitation inherent to data collection---with attention to how subjects can meaningfully participate in stewardship. We explore participatory data stewardship in the context of clinical computer security for survivors of intimate partner violence (IPV). Via semi-structured interviews with IPV support workers, we explore how data are produced within the IPV care ecosystem at the Clinic to End Tech Abuse (CETA). We then conduct design provocations with clients of IPV services and their support workers, exploring possibilities for participatory data mechanisms like open records and dynamic consent. We find participation in data stewardship may benefit clients through improved agency, self-reflection, and control of self-narrative, and that incurred burdens may be alleviated by enlisting trusted stewards. We close with future work for CSCW interrogating how knowledge of digital-safety harms can and should be produced from clinical encounters, towards more equitable ways of knowing. Emily Tseng, Rosanna Bellini, Yeuk-Yu Lee, Lana Ramjit, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2023 | Context Discovery and Commitment Attacks - How to Break CCM, EAX, SIV, and More
Sanketh Menda, Julia Len, Paul Grubbs, Thomas Ristenpart |
EUROCRYPT (4) | 4 |
| 2023 | The Digital-Safety Risks of Financial Technologies for Survivors of Intimate Partner Violence
Rosanna Bellini, Kevin Lee 0001, Megan A. Brown, Jeremy Shaffer, Rasika Bhalerao, Thomas Ristenpart |
USENIX Security Symposium | 6 |
| 2023 | Account Security Interfaces: Important, Unintuitive, and Untrustworthy
Alaa Daffalla, Marina Sanusi Bohuk, Nicola Dell, Rosanna Bellini, Thomas Ristenpart |
USENIX Security Symposium | 5 |
| 2023 | Araña: Discovering and Characterizing Password Guessing Attacks in Practice
Mazharul Islam 0002, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 4 |
| 2022 | Authenticated Encryption with Key Identification
Julia Len, Paul Grubbs, Thomas Ristenpart |
ASIACRYPT (3) | 3 |
| 2022 | Trauma-Informed Computing: Towards Safer Technology Experiences for AllabstractTrauma is the physical, emotional, or psychological harm caused by deeply distressing experiences. Research with communities that may experience high rates of trauma has shown that digital technologies can create or exacerbate traumatic experiences. Via three vignettes, we discuss how considering the possible effects of trauma and traumatic stress reactions provides an explanatory lens with new insights into people’s technology experiences. Then, we present a framework—trauma-informed computing—in which we adapt and show how to apply six key principles of trauma-informed approaches to computing: safety, trust, peer support, collaboration, enablement, and intersectionality. Through specific examples, we describe how to apply trauma-informed computing in four areas of computing research and practice: user experience research & design, security & privacy, artificial intelligence & machine learning, and organizational culture in tech companies. We conclude by discussing how adopting trauma-informed computing will lead to benefits for all users, not only those experiencing trauma. Janet X. Chen, Allison McDonald, Yixin Zou, Emily Tseng, Kevin A. Roundy, Acar Tamersoy, Florian Schaub, Thomas Ristenpart, Nicola Dell |
CHI | 8 |
| 2022 | Care Infrastructures for Digital Security in Intimate Partner ViolenceabstractSurvivors of intimate partner violence (IPV) face complex threats to their digital privacy and security. Prior work has established protocols for directly helping them mitigate these harms; however, there remains a need for flexible and pluralistic systems that can support survivors’ long-term needs. This paper describes the design and development of sociotechnical infrastructure that incorporates feminist notions of care to connect IPV survivors experiencing technology abuse with volunteer computer security consultants. We present findings from a mixed methods study that draws on data from an 8-month, real-world deployment, as well as interviews with 7 volunteer technology consultants and 18 IPV professionals. Our findings illuminate emergent challenges in safely and adaptively providing computer security advice as care. We discuss implications of these findings for feminist approaches to computer security and privacy, and provide broader lessons for interventions that aim to directly assist at-risk and marginalized people experiencing digital insecurity. Emily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi, Thomas Ristenpart, Nicola Dell |
CHI | 5 |
| 2022 | A Fast and Simple Partially Oblivious PRF, with Applications
Nirvan Tyagi, Sofía Celi, Thomas Ristenpart, Nick Sullivan, Stefano Tessaro, Christopher A. Wood |
EUROCRYPT (2) | 3 |
| 2022 | Gossamer: Securely Measuring Password-based Logins
Marina Sanusi Bohuk, Mazharul Islam 0002, Suleman Ahmad, Michael M. Swift, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 5 |
| 2022 | Increasing Adversarial Uncertainty to Scale Private Similarity Testing
Yiqing Hua, Armin Namavari, Kaishuo Cheng, Mor Naaman, Thomas Ristenpart |
USENIX Security Symposium | 5 |
| 2022 | Might I Get Pwned: A Second Generation Compromised Credential Checking Service
Bijeeta Pal, Mazharul Islam 0002, Marina Sanusi Bohuk, Nick Sullivan, Luke Valenta, Tara Whalen, Christopher A. Wood, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 8 |
| 2022 | Orca: Blocklisting in Sender-Anonymous Messaging
Nirvan Tyagi, Julia Len, Ian Miers, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2022 | Characterizing Alternative Monetization Strategies on YouTubeabstractOne of the key emerging roles of the YouTube platform is providing creators the ability to generate revenue from their content and interactions. Alongside tools provided directly by the platform, such as revenue-sharing from advertising, creators co-opt the platform to use a variety of off-platform monetization opportunities. In this work, we focus on studying and characterizing these alternative monetization strategies. Leveraging a large longitudinal YouTube dataset of popular creators, we develop a taxonomy of alternative monetization strategies and a simple methodology to detect their usage automatically. We then proceed to characterize the adoption of these strategies. First, we find that the use of external monetization is expansive and increasingly prevalent, used in 18% of all videos, with 61% of channels using one such strategy at least once. Second, we show that the adoption of these strategies varies substantially among channels of different kinds and popularity, and that channels that establish these alternative revenue streams often become more productive on the platform. Lastly, we investigate how potentially problematic channels -- those that produce Alt-lite, Alt-right, and Manosphere content -- leverage alternative monetization strategies, finding that they employ a more diverse set of such strategies significantly more often than a carefully chosen comparison set of channels. This finding complicates YouTube's role as a gatekeeper, since the practice of excluding policy-violating content from its native on-platform monetization may not be effective. Overall, this work provides an important step toward broadening the understanding of the monetary incentives behind content creation on YouTube. Yiqing Hua, Manoel Horta Ribeiro, Thomas Ristenpart, Robert West 0001, Mor Naaman |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2021 | A Digital Safety Dilemma: Analysis of Computer-Mediated Computer Security Interventions for Intimate Partner Violence During COVID-19abstractThe shutdown measures necessary to stop the spread of COVID-19 have amplified the role of technology in intimate partner violence (IPV). Survivors may be forced to endure lockdowns with their abusers, intensifying the dangers of technology-enabled abuse (e.g. stalking, harassment, monitoring, surveillance). They may also be forced to rely on potentially compromised devices to reach support networks: a dangerous dilemma for digital safety. This qualitative study examines how technologists with computer security expertise provided remote assistance to IPV survivors during the pandemic. Findings from 24 consults with survivors and five focus groups with technologist consultants show how remote delivery of technology support services raised three fundamental challenges: (1) ensuring safety for survivors and consultants; (2) assessing device security over a remote connection; and (3) navigating new burdens for consultants, including emotional labor. We highlight implications for HCI researchers creating systems that enable access to remote expert services for vulnerable people. Emily Tseng, Diana Freed, Kristen Engel, Thomas Ristenpart, Nicola Dell |
CHI | 4 |
| 2021 | SoK: Hate, Harassment, and the Changing Landscape of Online AbuseabstractWe argue that existing security, privacy, and antiabuse protections fail to address the growing threat of online hate and harassment. In order for our community to understand and address this gap, we propose a taxonomy for reasoning about online hate and harassment. Our taxonomy draws on over 150 interdisciplinary research papers that cover disparate threats ranging from intimate partner violence to coordinated mobs. In the process, we identify seven classes of attacks—such as toxic content and surveillance—that each stem from different attacker capabilities and intents. We also provide longitudinal evidence from a three-year survey that hate and harassment is a pervasive, growing experience for online users, particularly for at-risk communities like young adults and people who identify as LGBTQ+. Responding to each class of hate and harassment requires a unique strategy and we highlight five such potential research directions that ultimately empower individuals, communities, and platforms to do so. Kurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh, Elie Bursztein, Sunny Consolvo, Nicola Dell, Zakir Durumeric, Patrick Gage Kelley, Deepak Kumar 0006, Damon McCoy, Sarah Meiklejohn, Thomas Ristenpart, Gianluca Stringhini |
SP | 13 |
| 2021 | Partitioning Oracle Attacks
Julia Len, Paul Grubbs, Thomas Ristenpart |
USENIX Security Symposium | 3 |
| 2021 | Searching Encrypted Data with Size-Locked Indexes
Armin Namavari, David Cash, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2021 | The Role of Computer Security Customer Support in Helping Survivors of Intimate Partner Violence
Yixin Zou, Allison McDonald, Julia Narakornpichit, Nicola Dell, Thomas Ristenpart, Kevin A. Roundy, Florian Schaub, Acar Tamersoy |
USENIX Security Symposium | 5 |
| 2020 | Characterizing Twitter Users Who Engage in Adversarial Interactions against Political CandidatesabstractSocial media provides a critical communication platform for political figures, but also makes them easy targets for harassment. In this paper, we characterize users who adversarially interact with political figures on Twitter using mixed-method techniques. The analysis is based on a dataset of 400 thousand users' 1.2 million replies to 756 candidates for the U.S. House of Representatives in the two months leading up to the 2018 midterm elections. We show that among moderately active users, adversarial activity is associated with decreased centrality in the social graph and increased attention to candidates from the opposing party. When compared to users who are similarly active, highly adversarial users tend to engage in fewer supportive interactions with their own party's candidates and express negativity in their user profiles. Our results can inform the design of platform moderation mechanisms to support political figures countering online harassment. Yiqing Hua, Mor Naaman, Thomas Ristenpart |
CHI | 3 |
| 2020 | Towards Measuring Adversarial Twitter Interactions against Candidates in the US Midterm Elections
Yiqing Hua, Thomas Ristenpart, Mor Naaman |
ICWSM | 2 |
| 2020 | The Many Kinds of Creepware Used for Interpersonal AttacksabstractTechnology increasingly facilitates interpersonal attacks such as stalking, abuse, and other forms of harassment. While prior studies have examined the ecosystem of software designed for stalking, there exists an unstudied, larger landscape of apps-what we call creepware-used for interpersonal attacks. In this paper, we initiate a study of creepware using access to a dataset detailing the mobile apps installed on over 50 million Android devices. We develop a new algorithm, CreepRank, that uses the principle of guilt by association to help surface previously unknown examples of creepware, which we then characterize through a combination of quantitative and qualitative methods. We discovered apps used for harassment, impersonation, fraud, information theft, concealment, and even apps that purport to defend victims against such threats. As a result of our work, the Google Play Store has already removed hundreds of apps for policy violations. More broadly, our findings and techniques improve understanding of the creepware ecosystem, and will inform future efforts that aim to mitigate interpersonal attacks. Kevin A. Roundy, Paula Barmaimon Mendelberg, Nicola Dell, Damon McCoy, Daniel Nissani, Thomas Ristenpart, Acar Tamersoy |
SP | 6 |
| 2020 | Pancake: Frequency Smoothing for Encrypted Data Stores
Paul Grubbs, Anurag Khandelwal, Marie-Sarah Lacharité, Lloyd Brown, Lucy Li, Rachit Agarwal 0001, Thomas Ristenpart |
USENIX Security Symposium | 7 |
| 2020 | The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity Forums
Emily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos, Rachel Greenstadt, Damon McCoy, Nicola Dell, Thomas Ristenpart |
USENIX Security Symposium | 8 |
| 2020 | "So-called privacy breeds evil": Narrative Justifications for Intimate Partner Surveillance in Online ForumsabstractA growing body of research suggests that intimate partner abusers use digital technologies to surveil their partners, including by installing spyware apps, compromising devices and online accounts, and employing social engineering tactics. However, to date, this form of privacy violation, called intimate partner surveillance (IPS), has primarily been studied from the perspective of victim-survivors. We present a qualitative study of how potential perpetrators of IPS harness the emotive power of sharing personal narratives to validate and legitimise their abusive behaviours. We analysed 556 stories of IPS posted on publicly accessible online forums dedicated to the discussion of sexual infidelity. We found that many users share narrative posts describing IPS as they boast about their actions, advise others on how to perform IPS without detection, and seek suggestions for next steps to take. We identify a set of common thematic story structures, justifications for abuse, and outcomes within the stories that provide a window into how these individuals believe their behaviour to be justified. Using these stories, we develop a four-stage framework that captures the change in a potential perpetrator's approach to IPS. We use our findings and framework to guide a discussion of efforts to combat abuse, including how we can identify crucial moments where interventions might be safely applied to prevent or deescalate IPS. Rosanna Bellini, Emily Tseng, Nora McDonald, Rachel Greenstadt, Damon McCoy, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2019 | Protocols for Checking Compromised CredentialsabstractTo prevent credential stuffing attacks, industry best practice now proactively checks if user credentials are present in known data breaches. Recently, some web services, such as HaveIBeenPwned (HIBP) and Google Password Checkup (GPC), have started providing APIs to check for breached passwords. We refer to such services as compromised credential checking (C3) services. We give the first formal description of C3 services, detailing different settings and operational requirements, and we give relevant threat models. One key security requirement is the secrecy of a user's passwords that are being checked. Current widely deployed C3 services have the user share a small prefix of a hash computed over the user's password. We provide a framework for empirically analyzing the leakage of such protocols, showing that in some contexts knowing the hash prefixes leads to a 12x increase in the efficacy of remote guessing attacks. We propose two new protocols that provide stronger protection for users' passwords, implement them, and show experimentally that they remain practical to deploy. Lucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan, Rahul Chatterjee 0001, Thomas Ristenpart |
CCS | 6 |
| 2019 | Traceback for End-to-End Encrypted Messaging
Nirvan Tyagi, Ian Miers, Thomas Ristenpart |
CCS | 3 |
| 2019 | Asymmetric Message Franking: Content Moderation for Metadata-Private End-to-End Encryption
Nirvan Tyagi, Paul Grubbs, Julia Len, Ian Miers, Thomas Ristenpart |
CRYPTO (3) | 5 |
| 2019 | Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksabstractAttackers increasingly use passwords leaked from one website to compromise associated accounts on other websites. Such targeted attacks work because users reuse, or pick similar, passwords for different websites. We recast one of the core technical challenges underlying targeted attacks as the task of modeling similarity of human-chosen passwords. We show how to learn good password similarity models using a compilation of 1.4 billion leaked email, password pairs. Using our trained models of password similarity, we exhibit the most damaging targeted attack to date. Simulations indicate that our attack compromises more than 16% of user accounts in less than a thousand guesses, should one of their other passwords be known to the attacker and despite the use of state-of-the art countermeasures. We show via a case study involving a large university authentication service that the attacks are also effective in practice. We go on to propose the first-ever defense against such targeted attacks, by way of personalized password strength meters (PPSMs). These are password strength meters that can warn users when they are picking passwords that are vulnerable to attacks, including targeted ones that take advantage of the user's previously compromised passwords. We design and build a PPSM that can be compressed to less than 3 MB, making it easy to deploy in order to accurately estimate the strength of a password against all known guessing attacks. Bijeeta Pal, Tal Daniel, Rahul Chatterjee 0001, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | Blind Certificate AuthoritiesabstractWe explore how to build a blind certificate authority (CA). Unlike conventional CAs, which learn the exact identity of those registering a public key, a blind CA can simultaneously validate an identity and provide a certificate binding a public key to it, without ever learning the identity. Blind CAs would therefore allow bootstrapping truly anonymous systems in which no party ever learns who participates. In this work we focus on constructing blind CAs that can bind an email address to a public key. To do so, we first introduce secure channel injection (SCI) protocols. These allow one party (in our setting, the blind CA) to insert a private message into another party's encrypted communications. We construct an efficient SCI protocol for communications delivered over TLS, and use it to realize anonymous proofs of account ownership for SMTP servers. Combined with a zero-knowledge certificate signing protocol, we build the first blind CA that allows Alice to obtain a X.509 certificate binding her email address [email protected] to a public key of her choosing without ever revealing ``alice'' to the CA. We show experimentally that our system works with standard email server implementations as well as Gmail. Liang Wang 0023, Gilad Asharov, Rafael Pass, Thomas Ristenpart, Abhi Shelat |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | Clinical Computer Security for Victims of Intimate Partner Violence
Sam Havron, Diana Freed, Rahul Chatterjee 0001, Damon McCoy, Nicola Dell, Thomas Ristenpart |
USENIX Security Symposium | 6 |
| 2019 | "Is my phone hacked?" Analyzing Clinical Computer Security Interventions with Survivors of Intimate Partner ViolenceabstractIntimate partner abusers use technology to track, monitor, harass, and otherwise harm their victims, and prior work reports that victims have few resources for obtaining help with such attacks. This paper presents a qualitative analysis of data from a field study of an approach to helping survivors of intimate partner violence (IPV) with technology abuse. In this approach, called clinical computer security, a trained technologist performs a face-to-face consultation with an IPV survivor to help them understand and navigate technology issues. Findings from consultations with 31 survivors, as well as IPV professionals working on their behalf, uncovered a range of digital security and privacy vulnerabilities exacerbated by the nuanced social context of such abuse. In this paper we explore survivor experiences with, and reactions to, the consultations, discussing (1) the ways in which survivors present their tech concerns, (2) the cooperative work required to guide survivors towards understanding probable causes of tech insecurity, (3) survivors' reactions to the consultations, particularly when security vulnerabilities or spyware are discovered, and (4) the role we play as consultants and interventionists in the complex socio-technical systems involved in mitigating IPV. We conclude by discussing some of the broad ethical and sustainability challenges raised by our work, and provide design opportunities for tech platforms to better support survivors of IPV. Diana Freed, Sam Havron, Emily Tseng, Andrea Gallardo, Rahul Chatterjee 0001, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2018 | "A Stalker's Paradise": How Intimate Partner Abusers Exploit TechnologyabstractThis paper describes a qualitative study with 89 participants that details how abusers in intimate partner violence (IPV) contexts exploit technologies to intimidate, threaten, monitor, impersonate, harass, or otherwise harm their victims. We show that, at their core, many of the attacks in IPV contexts are technologically unsophisticated from the perspective of a security practitioner or researcher. For example, they are often carried out by a UI-bound adversary - an adversarial but authenticated user that interacts with a victim»s device or account via standard user interfaces - or by downloading and installing a ready-made application that enables spying on a victim. Nevertheless, we show how the sociotechnical and relational factors that characterize IPV make such attacks both extremely damaging to victims and challenging to counteract, in part because they undermine the predominant threat models under which systems have been designed. We discuss the nature of these new IPV threat models and outline opportunities for HCI research and design to mitigate these attacks. Diana Freed, Jackeline Palmer, Diana Elizabeth Minchala, Karen Levy, Thomas Ristenpart, Nicola Dell |
CHI | 5 |
| 2018 | Fast Message Franking: From Invisible Salamanders to Encryptment
Yevgeniy Dodis, Paul Grubbs, Thomas Ristenpart, Joanne Woodage |
CRYPTO (1) | 3 |
| 2018 | The Spyware Used in Intimate Partner ViolenceabstractSurvivors of intimate partner violence increasingly report that abusers install spyware on devices to track their location, monitor communications, and cause emotional and physical harm. To date there has been only cursory investigation into the spyware used in such intimate partner surveillance (IPS). We provide the first in-depth study of the IPS spyware ecosystem. We design, implement, and evaluate a measurement pipeline that combines web and app store crawling with machine learning to find and label apps that are potentially dangerous in IPS contexts. Ultimately we identify several hundred such IPS-relevant apps. While we find dozens of overt spyware tools, the majority are "dual-use" apps - they have a legitimate purpose (e.g., child safety or anti-theft), but are easily and effectively repurposed for spying on a partner. We document that a wealth of online resources are available to educate abusers about exploiting apps for IPS. We also show how some dual-use app developers are encouraging their use in IPS via advertisements, blogs, and customer support services. We analyze existing anti-virus and anti-spyware tools, which universally fail to identify dual-use apps as a threat. Rahul Chatterjee 0001, Periwinkle Doerfler, Hadas Orgad, Sam Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 10 |
| 2018 | Peeking Behind the Curtains of Serverless Platforms
Liang Wang 0023, Mengyuan Li 0004, Yinqian Zhang, Thomas Ristenpart, Michael M. Swift |
USENIX ATC | 4 |
| 2018 | BurnBox: Self-Revocable Encryption in a World Of Compelled Access
Nirvan Tyagi, Muhammad Haris Mughees, Thomas Ristenpart, Ian Miers |
USENIX Security Symposium | 3 |
| 2018 | The Tao of Inference in Privacy-Protected DatabasesabstractTo protect database confidentiality even in the face of full compromise while supporting standard functionality, recent academic proposals and commercial products rely on a mix of encryption schemes. The recommendation is to apply strong, semantically secure encryption to the "sensitive" columns and protect other columns with property-revealing encryption (PRE) that supports operations such as sorting. We design, implement, and evaluate a new methodology for inferring data stored in such encrypted databases. The cornerstone is the multinomial attack , a new inference technique that is analytically optimal and empirically outperforms prior heuristic attacks against PRE-encrypted data. We also extend the multinomial attack to take advantage of correlations across multiple columns. This recovers PRE-encrypted data with sufficient accuracy to then apply machine learning and record linkage methods to infer columns protected by semantically secure encryption or redaction. We evaluate our methodology on medical, census, and union-membership datasets, showing for the first time how to infer full database records. For PRE-encrypted attributes such as demographics and ZIP codes, our attack outperforms the best prior heuristic by a factor of 16. Unlike any prior technique, we also infer attributes, such as incomes and medical diagnoses, protected by strong encryption. For example, when we infer that a patient in a hospital-discharge dataset has a mental health or substance abuse condition, this prediction is 97% accurate. Vincent Bindschaedler, Paul Grubbs, David Cash, Thomas Ristenpart, Vitaly Shmatikov |
Proc. VLDB Endow. | 4 |
| 2017 | The TypTop System: Personalized Typo-Tolerant Password CheckingabstractPassword checking systems traditionally allow login only if the correct password is submitted. Recent work on typo-tolerant password checking suggests that usability can be improved, with negligible security loss, by allowing a small number of typographical errors. Existing systems, however, can only correct a handful of errors, such as accidentally leaving caps lock on or incorrect capitalization of the first letter in a password. This leaves out numerous kinds of typos made by users, such as transposition errors, substitutions, or capitalization errors elsewhere in a password. Some users therefore receive no benefit from existing typo-tolerance mechanisms. Rahul Chatterjee 0001, Joanne Woodage, Yuval Pnueli, Anusha Chowdhury, Thomas Ristenpart |
CCS | 5 |
| 2017 | Using Program Analysis to Synthesize Sensor Spoofing AttacksabstractIn a sensor spoofing attack, an adversary modifies the physical environment in a certain way so as to force an embedded system into unwanted or unintended behaviors. This usually requires a thorough understanding of the system's control logic. The conventional methods for discovering this logic are manual code inspection and experimentation. Ivan Pustogarov, Thomas Ristenpart, Vitaly Shmatikov |
AsiaCCS | 2 |
| 2017 | Machine Learning Models that Remember Too MuchabstractMachine learning (ML) is becoming a commodity. Numerous ML frameworks and services are available to data holders who are not ML experts but want to train predictive models on their data. It is important that ML models trained on sensitive inputs (e.g., personal images or documents) not leak too much information about the training data. Congzheng Song, Thomas Ristenpart, Vitaly Shmatikov |
CCS | 2 |
| 2017 | Key Rotation for Authenticated Encryption
Adam Everspaugh, Kenneth G. Paterson, Thomas Ristenpart, Samuel Scott |
CRYPTO (3) | 3 |
| 2017 | Message Franking via Committing Authenticated Encryption
Paul Grubbs, Thomas Ristenpart |
CRYPTO (3) | 3 |
| 2017 | A New Distribution-Sensitive Secure Sketch and Popularity-Proportional Hashing
Joanne Woodage, Rahul Chatterjee 0001, Yevgeniy Dodis, Ari Juels, Thomas Ristenpart |
CRYPTO (3) | 5 |
| 2017 | Modifying an Enciphering Scheme After Deployment
Paul Grubbs, Thomas Ristenpart, Yuval Yarom |
EUROCRYPT (2) | 2 |
| 2017 | Why Your Encrypted Database Is Not SecureabstractEncrypted databases, a popular approach to protecting data from compromised database management systems (DBMS's), use abstract threat models that capture neither realistic databases, nor realistic attack scenarios. In particular, the "snapshot attacker" model used to support the security claims for many encrypted databases does not reflect the information about past queries available in any snapshot attack on an actual DBMS. Paul Grubbs, Thomas Ristenpart, Vitaly Shmatikov |
HotOS | 2 |
| 2017 | Leakage-Abuse Attacks against Order-Revealing EncryptionabstractOrder-preserving encryption and its generalization order-revealing encryption (OPE/ORE) allow sorting, performing range queries, and filtering data - all while only having access to ciphertexts. But OPE and ORE ciphertexts necessarily leak information about plaintexts, and what level of security they provide in practice has been unclear. In this work, we introduce new leakage-abuse attacks that recover plaintexts from OPE/ORE-encrypted databases. Underlying our new attacks is a framework in which we cast the adversary's challenge as a non-crossing bipartite matching problem. This allows easy tailoring of attacks to a specific scheme's leakage profile. In a case study of customer records, we show attacks that recover 99% of first names, 97% of last names, and 90% of birthdates held in a database, despite all values being encrypted with the OPE scheme most widely used in practice. We also show the first attack against the recent frequency-hiding Kerschbaum scheme, to which no prior attacks have been demonstrated. Our attack recovers frequently occurring plaintexts most of the time. Paul Grubbs, Kevin Sekniqi, Vincent Bindschaedler, Muhammad Naveed 0001, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 5 |
| 2017 | Side-Channel Attacks on Shared Search IndexesabstractFull-text search systems, such as Elasticsearch and Apache Solr, enable document retrieval based on keyword queries. In many deployments these systems are multi-tenant, meaning distinct users' documents reside in, and their queries are answered by, one or more shared search indexes. Large deployments may use hundreds of indexes across which user documents are randomly assigned. The results of a search query are filtered to remove documents to which a client should not have access. We show the existence of exploitable side channels in modern multi-tenant search. The starting point for our attacks is a decade-old observation that the TF-IDF scores used to rank search results can potentially leak information about other users' documents. To the best of our knowledge, no attacks have been shown that exploit this side channel in practice, and constructing a working side channel requires overcoming numerous challenges in real deployments. We nevertheless develop a new attack, called STRESS (Search Text RElevance Score Side channel), and in so doing show how an attacker can map out the number of indexes used by a service, obtain placement of a document within each index, and then exploit co-tenancy with all other users to (1) discover the terms in other tenants' documents or (2) determine the number of documents (belonging to other tenants) that contain a term of interest. In controlled experiments, we demonstrate the attacks on popular services such as GitHub and Xen.do. We conclude with a discussion of countermeasures. Liang Wang 0023, Paul Grubbs, Vincent Bindschaedler, David Cash, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 6 |
| 2017 | Digital Technologies and Intimate Partner Violence: A Qualitative Analysis with Multiple StakeholdersabstractDigital technologies, including mobile devices, cloud computing services, and social networks, play a nuanced role in intimate partner violence (IPV) settings, including domestic abuse, stalking, and surveillance of victims by abusive partners. However, the interactions among victims of IPV, abusers, law enforcement, counselors, and others --- and the roles that digital technologies play in these interactions --- are poorly understood. We present a qualitative study that analyzes the role of digital technologies in the IPV ecosystem in New York City. Findings from semi-structured interviews with 40 IPV professionals and nine focus groups with 32 survivors of IPV reveal a complex set of socio-technical challenges that stem from the intimate nature of the relationships involved and the complexities of managing shared social circles. Both IPV professionals and survivors feel that they do not possess adequate expertise to be able to identify or cope with technology-enabled IPV, and there are currently insufficient best practices to help them deal with abuse via technology. We also reveal a number of tensions and trade-offs in negotiating technology's role in social support and legal procedures. Taken together, our findings contribute a nuanced understanding of technology's role in the IPV ecosystem and yield recommendations for HCI and technology experts interested in aiding victims of abuse. Diana Freed, Jackeline Palmer, Diana Elizabeth Minchala, Karen Levy, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2016 | Breaking Web Applications Built On Top of Encrypted DataabstractWe develop a systematic approach for analyzing client-server applications that aim to hide sensitive user data from untrusted servers. We then apply it to Mylar, a framework that uses multi-key searchable encryption (MKSE) to build Web applications on top of encrypted data. Paul Grubbs, Richard McPherson, Muhammad Naveed 0001, Thomas Ristenpart, Vitaly Shmatikov |
CCS | 4 |
| 2016 | CQSTR: Securing Cross-Tenant Applications with Cloud ContainersabstractCloud providers are in a position to greatly improve the trust clients have in network services: IaaS platforms can isolate services so they cannot leak data, and can help verify that they are securely deployed. We describe a new system called CQSTR that allows clients to verify a service's security properties. CQSTR provides a new cloud container abstraction similar to Linux containers but for VM clusters within IaaS clouds. Cloud containers enforce constraints on what software can run, and control where and how much data can be communicated across service boundaries. With CQSTR, IaaS providers can make assertions about the security properties of a service running in the cloud. Yan Zhai, Lichao Yin, Jeffrey S. Chase, Thomas Ristenpart, Michael M. Swift |
SoCC | 4 |
| 2016 | Honey Encryption Beyond Message Recovery Security
Joseph Jaeger, Thomas Ristenpart, Qiang Tang 0005 |
EUROCRYPT (1) | 2 |
| 2016 | pASSWORD tYPOS and How to Correct Them SecurelyabstractWe provide the first treatment of typo-tolerant password authentication for arbitrary user-selected passwords. Such a system, rather than simply rejecting a login attempt with an incorrect password, tries to correct common typographical errors on behalf of the user. Limited forms of typo-tolerance have been used in some industry settings, but to date there has been no analysis of the utility and security of such schemes. We quantify the kinds and rates of typos made by users via studies conducted on Amazon Mechanical Turk and via instrumentation of the production login infrastructure at Dropbox. The instrumentation at Dropbox did not record user passwords or otherwise change authentication policy, but recorded only the frequency of observed typos. Our experiments reveal that almost 10% of login attempts fail due to a handful of simple, easily correctable typos, such as capitalization errors. We show that correcting just a few of these typos would reduce login delays for a significant fraction of users as well as enable an additional 3% of users to achieve successful login. We introduce a framework for reasoning about typo-tolerance, and investigate the seemingly inherent tension here between security and usability of passwords. We use our framework to show that there exist typo-tolerant authentication schemes that can get corrections for "free": we prove they are as secure as schemes that always reject mistyped passwords. Building off this theory, we detail a variety of practical strategies for securely implementing typo-tolerance. Rahul Chatterjee 0001, Anish Athayle, Devdatta Akhawe, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 5 |
| 2016 | Stealing Machine Learning Models via Prediction APIs
Florian Tramèr, Fan Zhang 0022, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
USENIX Security Symposium | 5 |
| 2015 | Leakage-Abuse Attacks Against Searchable EncryptionabstractSchemes for secure outsourcing of client data with search capability are being increasingly marketed and deployed. In the literature, schemes for accomplishing this efficiently are called Searchable Encryption (SE). They achieve high efficiency with provable security by means of a quantifiable leakage profile. However, the degree to which SE leakage can be exploited by an adversary is not well understood. David Cash, Paul Grubbs, Jason Perry, Thomas Ristenpart |
CCS | 4 |
| 2015 | Model Inversion Attacks that Exploit Confidence Information and Basic CountermeasuresabstractMachine-learning (ML) algorithms are increasingly utilized in privacy-sensitive applications such as predicting lifestyle choices, making medical diagnoses, and facial recognition. In a model inversion attack, recently introduced in a case study of linear classifiers in personalized medicine by Fredrikson et al., adversarial access to an ML model is abused to learn sensitive genomic information about individuals. Whether model inversion attacks apply to settings outside theirs, however, is unknown. We develop a new class of model inversion attack that exploits confidence values revealed along with predictions. Our new attacks are applicable in a variety of settings, and we explore two in depth: decision trees for lifestyle surveys as used on machine-learning-as-a-service systems and neural networks for facial recognition. In both cases confidence values are revealed to those with the ability to make prediction queries to models. We experimentally show attacks that are able to estimate whether a respondent in a lifestyle survey admitted to cheating on their significant other and, in the other context, show how to recover recognizable images of people's faces given only their name and access to the ML model. We also initiate experimental exploration of natural countermeasures, investigating a privacy-aware decision tree training algorithm that is a simple variant of CART learning, as well as revealing only rounded confidence values. The lesson that emerges is that one can avoid these kinds of MI attacks with negligible degradation to utility. Matt Fredrikson, Somesh Jha, Thomas Ristenpart |
CCS | 3 |
| 2015 | Seeing through Network-Protocol ObfuscationabstractCensorship-circumvention systems are designed to help users bypass Internet censorship. As more sophisticated deep-packet-inspection (DPI) mechanisms have been deployed by censors to detect circumvention tools, activists and researchers have responded by developing network protocol obfuscation tools. These have proved to be effective in practice against existing DPI and are now distributed with systems such as Tor. In this work, we provide the first in-depth investigation of the detectability of in-use protocol obfuscators by DPI. We build a framework for evaluation that uses real network traffic captures to evaluate detectability, based on metrics such as the false-positive rate against background (i.e., non obfuscated) traffic. We first exercise our framework to show that some previously proposed attacks from the literature are not as effective as a censor might like. We go on to develop new attacks against five obfuscation tools as they are configured in Tor, including: two variants of obfsproxy, FTE, and two variants of meek. We conclude by using our framework to show that all of these obfuscation mechanisms could be reliably detected by a determined censor with sufficiently low false-positive rates for use in many censorship settings. Liang Wang 0023, Kevin P. Dyer, Aditya Akella, Thomas Ristenpart, Thomas Shrimpton |
CCS | 4 |
| 2015 | A Formal Treatment of Backdoored Pseudorandom Generators
Yevgeniy Dodis, Chaya Ganesh, Alexander Golovnev, Ari Juels, Thomas Ristenpart |
EUROCRYPT (1) | 5 |
| 2015 | Cracking-Resistant Password Vaults Using Natural Language EncodersabstractPassword vaults are increasingly popular applications that store multiple passwords encrypted under a single master password that the user memorizes. A password vault can greatly reduce the burden on a user of remembering passwords, but introduces a single point of failure. An attacker that obtains a user's encrypted vault can mount offline brute-force attacks and, if successful, compromise all of the passwords in the vault. In this paper, we investigate the construction of encrypted vaults that resist such offline cracking attacks and force attackers instead to mount online attacks. Our contributions are as follows. We present an attack and supporting analysis showing that a previous design for cracking-resistant vaults -- the only one of which we are aware -- actually degrades security relative to conventional password-based approaches. We then introduce a new type of secure encoding scheme that we call a natural language encoder (NLE). An NLE permits the construction of vaults which, when decrypted with the wrong master password, produce plausible-looking decoy passwords. We show how to build NLEs using existing tools from natural language processing, such as n-gram models and probabilistic context-free grammars, and evaluate their ability to generate plausible decoys. Finally, we present, implement, and evaluate a full, NLE-based cracking-resistant vault system called NoCrack. Rahul Chatterjee 0001, Joseph Bonneau, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | The Pythia PRF Service
Adam Everspaugh, Rahul Chatterjee 0001, Samuel Scott, Ari Juels, Thomas Ristenpart |
USENIX Security Symposium | 5 |
| 2015 | A Placement Vulnerability Study in Multi-Tenant Public Clouds
Venkatanathan Varadarajan, Yinqian Zhang, Thomas Ristenpart, Michael M. Swift |
USENIX Security Symposium | 3 |
| 2014 | Formatted Encryption Beyond Regular LanguagesabstractFormat-preserving and format-transforming encryption (FPE and FTE, respectively) are relatively new cryptographic primitives, yet are already being used in a broad range of real-world applications. The most flexible existing FPE and FTE implementations use regular expressions to specify plaintext and/or ciphertext formats. These constructions rely on the ability to efficiently map strings accepted by a regular expression to integers and back, called ranking and unranking, respectively. Daniel Luchaup, Thomas Shrimpton, Thomas Ristenpart, Somesh Jha |
CCS | 3 |
| 2014 | Cross-Tenant Side-Channel Attacks in PaaS CloudsabstractWe present a new attack framework for conducting cache-based side-channel attacks and demonstrate this framework in attacks between tenants on commercial Platform-as-a-Service (PaaS) clouds. Our framework uses the FLUSH-RELOAD attack of Gullasch et al. as a primitive, and extends this work by leveraging it within an automaton-driven strategy for tracing a victim's execution. We leverage our framework first to confirm co-location of tenants and then to extract secrets across tenant boundaries. We specifically demonstrate attacks to collect potentially sensitive application data (e.g., the number of items in a shopping cart), to hijack user accounts, and to break SAML single sign-on. To the best of our knowledge, our attacks are the first granular, cross-tenant, side-channel attacks successfully demonstrated on state-of-the-art commercial clouds, PaaS or otherwise. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
CCS | 4 |
| 2014 | Honey Encryption: Security Beyond the Brute-Force Bound
Ari Juels, Thomas Ristenpart |
EUROCRYPT | 2 |
| 2014 | WhoWas: A Platform for Measuring Web Deployments on IaaS CloudsabstractPublic infrastructure-as-a-service (IaaS) clouds such as Amazon EC2 and Microsoft Azure host an increasing number of web services. The dynamic, pay-as-you-go nature of modern IaaS systems enable web services to scale up or down with demand, and only pay for the resources they need. We are unaware, however, of any studies reporting on measurements of the patterns of usage over time in IaaS clouds as seen in practice. We fill this gap, offering a measurement platform that we call WhoWas. Using active, but lightweight, probing, it enables associating web content to public IP addresses on a day-by-day basis. We exercise WhoWas to provide the first measurement study of churn rates in EC2 and Azure, the efficacy of IP blacklists for malicious activity in clouds, the rate of adoption of new web software by public cloud customers, and more. Liang Wang 0023, Antonio Nappa, Juan Caballero, Thomas Ristenpart, Aditya Akella |
Internet Measurement Conference | 4 |
| 2014 | Not-So-Random Numbers in Virtualized Linux and the Whirlwind RNGabstractVirtualized environments are widely thought to cause problems for software-based random number generators (RNGs), due to use of virtual machine (VM) snapshots as well as fewer and believed-to-be lower quality entropy sources. Despite this, we are unaware of any published analysis of the security of critical RNGs when running in VMs. We fill this gap, using measurements of Linux's RNG systems (without the aid of hardware RNGs, the most common use case today) on Xen, VMware, and Amazon EC2. Despite CPU cycle counters providing a significant source of entropy, various deficiencies in the design of the Linux RNG makes its first output vulnerable during VM boots and, more critically, makes it suffer from catastrophic reset vulnerabilities. We show cases in which the RNG will output the exact same sequence of bits each time it is resumed from the same snapshot. This can compromise, for example, cryptographic secrets generated after resumption. We explore legacy-compatible countermeasures, as well as a clean-slate solution. The latter is a new RNG called Whirlwind that provides a simpler, more-secure solution for providing system randomness. Adam Everspaugh, Yan Zhai, Robert Jellinek, Thomas Ristenpart, Michael M. Swift |
IEEE Symposium on Security and Privacy | 4 |
| 2014 | On the Practical Exploitability of Dual EC in TLS Implementations
Stephen Checkoway, Ruben Niederhagen, Adam Everspaugh, Matthew Green 0001, Tanja Lange 0001, Thomas Ristenpart, Daniel J. Bernstein, Jake Maskiewicz, Hovav Shacham, Matt Fredrikson |
USENIX Security Symposium | 6 |
| 2014 | Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing
Matt Fredrikson, Eric Lantz, Somesh Jha, Simon M. Lin, David Page, Thomas Ristenpart |
USENIX Security Symposium | 6 |
| 2014 | LibFTE: A Toolkit for Constructing Practical, Format-Abiding Encryption Schemes
Daniel Luchaup, Kevin P. Dyer, Somesh Jha, Thomas Ristenpart, Thomas Shrimpton |
USENIX Security Symposium | 4 |
| 2014 | Scheduler-based Defenses against Cross-VM Side-channels
Venkatanathan Varadarajan, Thomas Ristenpart, Michael M. Swift |
USENIX Security Symposium | 2 |
| 2013 | Protocol misidentification made easy with format-transforming encryptionabstractDeep packet inspection (DPI) technologies provide much-needed visibility and control of network traffic using port-independent protocol identification, where a network flow is labeled with its application-layer protocol based on packet contents. In this paper, we provide the first comprehensive evaluation of a large set of DPI systems from the point of view of protocol misidentification attacks, in which adversaries on the network attempt to force the DPI to mislabel connections. Our approach uses a new cryptographic primitive called format-transforming encryption (FTE), which extends conventional symmetric encryption with the ability to transform the ciphertext into a format of our choosing. We design an FTE-based record layer that can encrypt arbitrary application-layer traffic, and we experimentally show that this forces misidentification for all of the evaluated DPI systems. This set includes a proprietary, enterprise-class DPI system used by large corporations and nation-states. We also show that using FTE as a proxy system incurs no latency overhead and as little as 16\% bandwidth overhead compared to standard SSH tunnels. Finally, we integrate our FTE proxy into the Tor anonymity network and demonstrate that it evades real-world censorship by the Great Firewall of China. Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
CCS | 3 |
| 2013 | The Mix-and-Cut Shuffle: Small-Domain Encryption Secure against N Queries
Thomas Ristenpart, Scott Yilek |
CRYPTO (1) | 1 |
| 2013 | Message-Locked Encryption and Secure Deduplication
Mihir Bellare, Sriram Keelveedhi, Thomas Ristenpart |
EUROCRYPT | 3 |
| 2013 | Next stop, the cloud: understanding modern web service deployment in EC2 and azureabstractAn increasingly large fraction of Internet services are hosted on a cloud computing system such as Amazon EC2 or Windows Azure. But to date, no in-depth studies about cloud usage by Internet services has been performed. We provide a detailed measurement study to shed light on how modern web service deployments use the cloud and to identify ways in which cloud-using services might improve these deployments. Our results show that: 4% of the Alexa top million use EC2/Azure; there exist several common deployment patterns for cloud-using web service front ends; and services can significantly improve their wide-area performance and failure tolerance by making better use of existing regional diversity in EC2. Driving these analyses are several new datasets, including one with over 34 million DNS records for Alexa websites and a packet capture from a large university network. Keqiang He, Alexis Fisher, Liang Wang 0023, Aaron Gember, Aditya Akella, Thomas Ristenpart |
Internet Measurement Conference | 6 |
| 2013 | FIE on Firmware: Finding Vulnerabilities in Embedded Systems Using Symbolic Execution
Drew Davidson, Benjamin Moench, Thomas Ristenpart, Somesh Jha |
USENIX Security Symposium | 3 |
| 2013 | DupLESS: Server-Aided Encryption for Deduplicated Storage
Sriram Keelveedhi, Mihir Bellare, Thomas Ristenpart |
USENIX Security Symposium | 3 |
| 2012 | Resource-freeing attacks: improve your cloud performance (at your neighbor's expense)abstractCloud computing promises great efficiencies by multiplexing resources among disparate customers. For example, Amazon's Elastic Compute Cloud (EC2), Microsoft Azure, Google's Compute Engine, and Rack-space Hosting all offer Infrastructure as a Service (IaaS) solutions that pack multiple customer virtual machines (VMs) onto the same physical server. Venkatanathan Varadarajan, Thawan Kooburat, Benjamin Farley, Thomas Ristenpart, Michael M. Swift |
CCS | 4 |
| 2012 | Cross-VM side channels and their use to extract private keysabstractThis paper details the construction of an access-driven side-channel attack by which a malicious virtual machine (VM) extracts fine-grained information from a victim VM running on the same physical computer. This attack is the first such attack demonstrated on a symmetric multiprocessing system virtualized using a modern VMM (Xen). Such systems are very common today, ranging from desktops that use virtualization to sandbox application or OS compromises, to clouds that co-locate the workloads of mutually distrustful customers. Constructing such a side-channel requires overcoming challenges including core migration, numerous sources of channel noise, and the difficulty of preempting the victim with sufficient frequency to extract fine-grained information from it. This paper addresses these challenges and demonstrates the attack in a lab setting by extracting an ElGamal decryption key from a victim using the most recent version of the libgcrypt cryptographic library. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
CCS | 4 |
| 2012 | More for your money: exploiting performance heterogeneity in public cloudsabstractInfrastructure-as-a-system compute clouds such as Amazon's EC2 allow users to pay a flat hourly rate to run their virtual machine (VM) on a server providing some combination of CPU access, storage, and network. But not all VM instances are created equal: distinct underlying hardware differences, contention, and other phenomena can result in vastly differing performance across supposedly equivalent instances. The result is striking variability in the resources received for the same price. Benjamin Farley, Ari Juels, Venkatanathan Varadarajan, Thomas Ristenpart, Kevin D. Bowers, Michael M. Swift |
SoCC | 4 |
| 2012 | Multi-instance Security and Its Application to Password-Based Cryptography
Mihir Bellare, Thomas Ristenpart, Stefano Tessaro |
CRYPTO | 2 |
| 2012 | To Hash or Not to Hash Again? (In)Differentiability Results for H 2 and HMAC
Yevgeniy Dodis, Thomas Ristenpart, John P. Steinberger, Stefano Tessaro |
CRYPTO | 2 |
| 2012 | Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures FailabstractWe consider the setting of HTTP traffic over encrypted tunnels, as used to conceal the identity of websites visited by a user. It is well known that traffic analysis (TA) attacks can accurately identify the website a user visits despite the use of encryption, and previous work has looked at specific attack/countermeasure pairings. We provide the first comprehensive analysis of general-purpose TA countermeasures. We show that nine known countermeasures are vulnerable to simple attacks that exploit coarse features of traffic (e.g., total time and bandwidth). The considered countermeasures include ones like those standardized by TLS, SSH, and IPsec, and even more complex ones like the traffic morphing scheme of Wright et al. As just one of our results, we show that despite the use of traffic morphing, one can use only total upstream and downstream bandwidth to identify -- with 98% accuracy - which of two websites was visited. One implication of what we find is that, in the context of website identification, it is unlikely that bandwidth-efficient, general-purpose TA countermeasures can ever provide the type of security targeted in prior work. Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
IEEE Symposium on Security and Privacy | 3 |
| 2012 | Randomness Condensers for Efficiently Samplable, Seed-Dependent Sources
Yevgeniy Dodis, Thomas Ristenpart, Salil P. Vadhan |
TCC | 2 |
| 2011 | Tag Size Does Matter: Attacks and Proofs for the TLS Record Protocol
Kenneth G. Paterson, Thomas Ristenpart, Thomas Shrimpton |
ASIACRYPT | 2 |
| 2011 | Careful with Composition: Limitations of the Indifferentiability Framework
Thomas Ristenpart, Hovav Shacham, Thomas Shrimpton |
EUROCRYPT | 1 |
| 2010 | Random Oracles with(out) Programmability
Marc Fischlin, Anja Lehmann, Thomas Ristenpart, Thomas Shrimpton, Martijn Stam, Stefano Tessaro |
ASIACRYPT | 3 |
| 2010 | When Good Randomness Goes Bad: Virtual Machine Reset Vulnerabilities and Hedging Deployed Cryptography
Thomas Ristenpart, Scott Yilek |
NDSS | 1 |
| 2009 | Hedged Public-Key Encryption: How to Protect against Bad Randomness
Mihir Bellare, Zvika Brakerski, Moni Naor, Thomas Ristenpart, Gil Segev 0001, Hovav Shacham, Scott Yilek |
ASIACRYPT | 4 |
| 2009 | Hey, you, get off of my cloud: exploring information leakage in third-party compute cloudsabstractThird-party cloud computing represents the promise of outsourcing as applied to computation. Services, such as Microsoft's Azure and Amazon's EC2, allow users to instantiate virtual machines (VMs) on demand and thus purchase precisely the capacity they require when they require it. In turn, the use of virtualization allows third-party cloud providers to maximize the utilization of their sunk capital costs by multiplexing many customer VMs across a shared physical infrastructure. However, in this paper, we show that this approach can also introduce new vulnerabilities. Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine. Thomas Ristenpart, Eran Tromer, Hovav Shacham, Stefan Savage |
CCS | 1 |
| 2009 | Simulation without the Artificial Abort: Simplified Proof and Improved Concrete Security for Waters' IBE Scheme
Mihir Bellare, Thomas Ristenpart |
EUROCRYPT | 2 |
| 2009 | Salvaging Merkle-Damgård for Practical Applications
Yevgeniy Dodis, Thomas Ristenpart, Thomas Shrimpton |
EUROCRYPT | 2 |
| 2008 | Deterministic Encryption: Definitional Equivalences and Constructions without Random Oracles
Mihir Bellare, Marc Fischlin, Adam O'Neill, Thomas Ristenpart |
CRYPTO | 4 |
| 2008 | Privacy-Preserving Location Tracking of Lost or Stolen Devices: Cryptographic Techniques and Replacing Trusted Third Parties with DHTs
Thomas Ristenpart, Gabriel Maganis, Arvind Krishnamurthy, Tadayoshi Kohno |
USENIX Security Symposium | 1 |
| 2007 | How to Build a Hash Function from Any Collision-Resistant Function
Thomas Ristenpart, Thomas Shrimpton |
ASIACRYPT | 1 |
| 2007 | The Power of Proofs-of-Possession: Securing Multiparty Signatures against Rogue-Key Attacks
Thomas Ristenpart, Scott Yilek |
EUROCRYPT | 1 |
| 2007 | How to Enrich the Message Space of a Cipher
Thomas Ristenpart, Phillip Rogaway |
FSE | 1 |
| 2007 | Hash Functions in the Dedicated-Key Setting: Design Choices and MPP Transforms
Mihir Bellare, Thomas Ristenpart |
ICALP | 2 |
| 2006 | Back to the Future: A Framework for Automatic Malware Removal and System RepairabstractMalware, software with malicious intent, has emerged as a widely-spread threat to system security. It is difficult to detect malware reliably because new and polymorphic malware programs appear frequently. It is also difficult to remove malware and repair its damage to the system because it can extensively modify a system. We propose a novel framework for automatically removing malware from and repairing its damage to a system. The primary goal of our framework is to preserve system integrity. Our framework monitors and logs untrusted programs' operations. Using the logs, it can completely remove malware programs and their effects on the system. Our framework does not require signatures or other prior knowledge of malware behavior. We implemented this framework on Windows and evaluated it with seven spyware, trojan horses, and email worms. Comparing our tool with two popular commercial anti-malware tools, we found that our tool detected all the malware's modifications to the system detected by the commercial tools, but the commercial tools overlooked up to 97% of the modifications detected by our tool. The runtime and space overhead of our prototype tool is acceptable. Our experience suggests that this framework offers an effective new defense against malware. Francis Hsu, Hao Chen 0003, Thomas Ristenpart, Jason Li 0003, Zhendong Su 0001 |
ACSAC | 3 |
| 2006 | Multi-Property-Preserving Hash Domain Extension and the EMD Transform
Mihir Bellare, Thomas Ristenpart |
ASIACRYPT | 2 |