EDBT 2026 Demo / reviewers in the wild / expert
Jenny Blessing
dblp:265/6412
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2026
0009-0007-7470-6435ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | KeyDroid: A Large-Scale Analysis of Secure Key Storage in Android AppsabstractMost contemporary mobile devices offer hardware-backed storage for cryptographic keys, user data, and other sensitive credentials. Such hardware is capable of protecting credentials from extraction by an adversary who has compromised the main operating system, such as a malicious third-party app. Since 2011, Android app developers can access trusted hardware via the Android Keystore API, making hardware-backed key storage a widely accessible PET. In this work, we conduct the first comprehensive survey of hardware-backed key storage in Android devices. We analyze 490,119 Android apps, collecting data on how trusted hardware is used by app developers (if at all) and cross-referencing our findings with sensitive user data collected by each app, as self-reported by developers via the Play Store’s data safety labels. We find that despite industry-wide initiatives to encourage adoption, 56% of apps self-reporting as processing sensitive user data do not use Android’s trusted hardware capabilities at all, while just 5% of apps collecting some form of sensitive data use the strongest form of trusted hardware, a secure element distinct from the main processor. To better understand the potential downsides of using secure hardware, we conduct the first empirical analysis of trusted hardware performance in mobile devices, measuring the runtime of common cryptographic operations across both software- and hardware-backed keystores and providing the first empirical analysis to date of the performance of secure elements in mobile devices. We find that while hardware-backed key storage using a coprocessor is viable for most common cryptographic operations, secure elements capable of preventing more advanced attacks make performance infeasible for symmetric encryption with non-negligible payloads. Jenny Blessing, Ross J. Anderson, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | SoK: Web Authentication and Recovery in the Age of End-to-End EncryptionabstractThe advent of end-to-end encryption (E2EE) has brought new challenges for usable authentication and recovery. Compared to regular web services, the nature of E2EE requires that the provider cannot recover data for users who have forgotten passwords or lost devices. More robust recovery schemes are therefore required, leading to a plethora of solutions ranging from randomly-generated recovery codes to social authentication. These implications have spread to new forms of authentication and legacy web services: passwordless authentication (``passkeys'') has become a promising candidate to replace passwords altogether, but is inherently device-bound. However, users expect that they can login from multiple devices and recover their passwords in case of device loss---prompting providers to sync credentials to cloud storage using E2EE and making contemporary authentication for even non-E2EE services dependent on E2EE. Hence, E2EE authentication quickly becomes relevant not only for a niche group of dedicated E2EE enthusiasts but for the general public using the passwordless authentication techniques promoted by their device vendors. In this paper we systematize existing research literature and industry practice relating to security, privacy, usability, and recoverability of both end-user authentication to E2EE services and the use of E2EE in securing backend credential databases. We investigate authentication and recovery schemes in all widely-used E2EE web services, analyze syncing protocols for E2EE credential managers, and survey passwordless authentication deployment in the top-300 most popular websites. Finally, we present concrete research directions based on observed gaps between industry deployment and academic literature. Jenny Blessing, Daniel Hugenroth, Ross J. Anderson, Alastair R. Beresford |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic LibrariesabstractThe security of the Internet and numerous other applications rests on a small number of open-source cryptographic libraries: A vulnerability in any one of them threatens to compromise a significant percentage of web traffic. Despite this potential for security impact, the characteristics and causes of vulnerabilities in cryptographic software are not well understood. In this work, we conduct the first systematic, longitudinal analysis of cryptographic libraries and the vulnerabilities they produce. We collect data from the National Vulnerability Database, individual project repositories and mailing lists, and other relevant sources for all widely used cryptographic libraries. Jenny Blessing, Michael A. Specter, Daniel J. Weitzner |
AsiaCCS | 1 |
| 2024 | Threat models over space and time: A case study of end-to-end-encrypted messaging applicationsabstractAbstract Threat modeling is one of the foundations of secure systems engineering and must take heed of the context within which systems operate. In this work, we explore the extent to which real‐world systems engineering reflects a changing threat context. We examine the desktop clients of six widely used end‐to‐end‐encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short‐lived adversarial access against these desktop clients and analyzed the results using two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to track threats in the evolving context within which systems operate and, more importantly, mitigate them by rescoping trust boundaries so that they remain consistent with administrative boundaries. A nuanced understanding of the relationship between trust and administration is vital for robust security, including the provision of safe defaults. Partha Das Chowdhury, Maria Sameen, Jenny Blessing, Nicholas Boucher, Joseph Gardiner, Tom Burrows, Ross J. Anderson, Awais Rashid |
Softw. Pract. Exp. | 3 |