Soroush Karami

dblp:270/2346 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0001-8694-1423ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 5 since 2021
YearPublicationVenuePosition
2023 When Push Comes to Shove: Empirical Analysis of Web Push Implementations in the Wild
abstract
Web push notifications are becoming an increasingly prevalent capability of modern web apps, intended to create a direct communication pipeline with users and increase user engagement. The seemingly straightforward functionality of push notifications obscures the complexities of the underlying design and implementation, which deviates from a near-universal practice in the web ecosystem: the ability to access an account (and the associated functionality) from practically any browser or device upon successful completion of the authentication process. Instead, push notifications create a communication endpoint for a specific browser instance. As a result, the challenges of deploying push notifications are further exacerbated due to the integration obstacles that arise from other aspects of web apps and user browsing behaviors (e.g., multi-device environments, account and session management). In this paper, we conduct an empirical analysis of push notification implementations in the wild, and identify common deployment pitfalls. We also demonstrate a series of attacks that target push notification functionality, including a novel subscription-sniffing attack, through a selection of use cases. To better understand current practices in push notifications implementations, we present a large-scale measurement of their deployment and also provide the first, to our knowledge, exploration and analysis of third-party service providers. Finally, we provide guidelines for developers and propose an approach for correctly handling push notifications in multi-browser, post-authentication settings.
Alberto Carboneri, Mohammad Ghasemisharif, Soroush Karami, Iasonas Polakis
ACSAC3
2023 Pool-Party: Exploiting Browser Resource Pools for Web Tracking
Peter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits, Hamed Haddadi 0001
USENIX Security Symposium2
2022 Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention
Soroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso, Erik Trickel, Panagiotis Ilia, Yan Shoshitaishvili, Adam Doupé, Iasonas Polakis
USENIX Security Symposium1
2022 The Dangers of Human Touch: Fingerprinting Browser Extensions through User Actions
Kostas Solomos, Panagiotis Ilia, Soroush Karami, Nick Nikiforakis, Iasonas Polakis
USENIX Security Symposium3
2021 Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage
Soroush Karami, Panagiotis Ilia, Iasonas Polakis
NDSS1
2020 Carnus: Exploring the Privacy Threats of Browser Extension Fingerprinting
Soroush Karami, Panagiotis Ilia, Kostas Solomos, Iasonas Polakis
NDSS1