EDBT 2026 Demo / reviewers in the wild / expert
Soroush Karami
dblp:270/2346
· DBLP profile ↗
6ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0001-8694-1423ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | When Push Comes to Shove: Empirical Analysis of Web Push Implementations in the WildabstractWeb push notifications are becoming an increasingly prevalent capability of modern web apps, intended to create a direct communication pipeline with users and increase user engagement. The seemingly straightforward functionality of push notifications obscures the complexities of the underlying design and implementation, which deviates from a near-universal practice in the web ecosystem: the ability to access an account (and the associated functionality) from practically any browser or device upon successful completion of the authentication process. Instead, push notifications create a communication endpoint for a specific browser instance. As a result, the challenges of deploying push notifications are further exacerbated due to the integration obstacles that arise from other aspects of web apps and user browsing behaviors (e.g., multi-device environments, account and session management). In this paper, we conduct an empirical analysis of push notification implementations in the wild, and identify common deployment pitfalls. We also demonstrate a series of attacks that target push notification functionality, including a novel subscription-sniffing attack, through a selection of use cases. To better understand current practices in push notifications implementations, we present a large-scale measurement of their deployment and also provide the first, to our knowledge, exploration and analysis of third-party service providers. Finally, we provide guidelines for developers and propose an approach for correctly handling push notifications in multi-browser, post-authentication settings. Alberto Carboneri, Mohammad Ghasemisharif, Soroush Karami, Iasonas Polakis |
ACSAC | 3 |
| 2023 | Pool-Party: Exploiting Browser Resource Pools for Web Tracking
Peter Snyder, Soroush Karami, Arthur Edelstein, Benjamin Livshits, Hamed Haddadi 0001 |
USENIX Security Symposium | 2 |
| 2022 | Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention
Soroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso, Erik Trickel, Panagiotis Ilia, Yan Shoshitaishvili, Adam Doupé, Iasonas Polakis |
USENIX Security Symposium | 1 |
| 2022 | The Dangers of Human Touch: Fingerprinting Browser Extensions through User Actions
Kostas Solomos, Panagiotis Ilia, Soroush Karami, Nick Nikiforakis, Iasonas Polakis |
USENIX Security Symposium | 3 |
| 2021 | Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy Leakage
Soroush Karami, Panagiotis Ilia, Iasonas Polakis |
NDSS | 1 |
| 2020 | Carnus: Exploring the Privacy Threats of Browser Extension Fingerprinting
Soroush Karami, Panagiotis Ilia, Kostas Solomos, Iasonas Polakis |
NDSS | 1 |