EDBT 2026 Demo / reviewers in the wild / expert
Jannis Rautenstrauch
dblp:352/6792
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0002-4816-0428ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 5 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Console Clutter: A Cross-Browser Measurement of Console Messages
Thomas Helbrecht, Jannis Rautenstrauch |
ICWE | 2 |
| 2026 | LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning ServicesabstractURL scanning services are widely used in security workflows to detect malicious websites and protect users from online threats. However, their common practice of publicly indexing scanned URLs may unintentionally expose sensitive user information through URL-embedded access credentials. Although isolated accounts of such privacy incidents exist, a systematic assessment of their prevalence is still lacking. We present leakylinks, an automated analysis pipeline that combines URL filtering with LLM-driven semantic classification to identify URLs exposing Sensitive Personal Information (SPI). Using LEAKYLINKS, we analyze URLs collected from public feeds of six prominent URL scanning services over a period of three weeks. With the framework, we visited 332k URLs, identifying over 4 k URLs which leak SPI with a precision of 97 %. To further assess the extent to which published URLs are actively accessed by third parties, we deploy honeypages and submit their links to the selected URL scanning services. Our measurements confirm that external entities access URLs submitted to these scanners, often from potentially suspicious IPs exhibiting behavior commonly associated with reconnaissance or opportunistic probing. Taken together, these findings indicate that URL scanning services represent a valuable target for web adversaries and may already be subject to active exploitation in the wild. Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal 0006, Stefano Calzavara, Ben Stock |
SP | 2 |
| 2025 | Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersabstractIn the modern Web, security headers are of the utmost importance for websites to provide protection against various attacks, such as Cross-Site Scripting, Clickjacking, and Cross-Site Leaks. As each security header uses a different syntax and has unique processing rules, correctly implementing them is a complex task for both browser and website developers. Inconsistency in browser behavior related to security headers harms websites as their security depends on their users' browsers. At the same time, compatibility issues may deter developers from deploying such headers in the first place. Jannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben Stock |
CCS | 1 |
| 2025 | A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern WebsitesabstractModern websites behave like OS-native applications and use powerful APIs, such as camera or microphone.To ensure that untrusted third-party components, such as ads, cannot abuse powerful features granted to web applications, these features are governed via a permission system: containing the Permissions-Policy header and iframe allow attribute.Even though the first versions of the permission system were implemented when browsers first allowed access to powerful features more than ten years ago, it is unclear if and how websites are using the permission system.To answer these questions, we systematically measured the permission ecosystem across the top 1,000,000 websites.Our results show that 48.52% of visited websites exhibit permissionrelated functionality, and 12.07% of websites delegate permissions to embedded iframes using the allow attribute.Out of these delegations, many appear overly broad and unused by the iframe, posing a threat in the context of supply chain attacks.Additionally, only 4.5% websites use the Permissions-Policy header, and the primary use case is to turn off powerful APIs such as a camera entirely.Finally, we developed open-source tools to help developers deploy the correct Permission-Policy header and iframe allow attributes following the principle of least privilege. CCS Concepts• Security and privacy → Privacy protections Alberto Fernández de Retana, Jannis Rautenstrauch, Igor Santos, Ben Stock |
IMC | 2 |
| 2024 | Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security ImpactabstractHTTP is everywhere, and a consistent interpretation of the protocol's specification is essential for interoperability and security. In 2022, after more than 30 years of evolution, the core HTTP specifications became an Internet Standard. However, apart from anecdotal evidence showing that HTTP installations violate parts of the specifications, no insights on the state of conformance of deployed HTTP systems exist. To close this knowledge gap, we systematically analyze the conformance landscape of HTTP systems with a focus on the potential security impact of rule violations. Jannis Rautenstrauch, Ben Stock |
AsiaCCS | 1 |
| 2024 | To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security LandscapeabstractThe web has evolved from a way to serve static content into a full-fledged application platform. Given its pervasive presence in our daily lives, it is therefore imperative to conduct studies that accurately reflect the state of security on the web. Many research works have focussed on detecting vulnerabilities, measuring security header deployment, or identifying roadblocks to a more secure web. To conduct these studies at a large scale, they all have a common denominator: they operate in automated fashions without human interaction, i.e., visit applications in an unauthenticated manner.To understand whether this unauthenticated view of the web accurately reflects its security as observed by regular users, we conduct a comparative analysis of 200 websites. By relying on a semi-automated framework to log into applications and crawl them, we analyze the differences between unauthenticated and authenticated states w.r.t. client-side XSS flaws, usage of security headers, postMessage handlers, and JavaScript inclusions. In doing so, we discover that the unauthenticated web could provide a significantly skewed picture of security depending on the type of research question. Jannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich, Ben Stock |
SP | 1 |
| 2023 | The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the WebabstractWhen browsing the web, none of us want sites to infer which other sites we may have visited before or are logged in to. However, attacker-controlled sites may infer this state through browser side-channels dubbed Cross-Site Leaks (XS-Leaks). Although these issues have been known since the 2000s, prior reports mostly found individual instances of issues rather than systematically studying the problem space. Further, actual impact in the wild often remained opaque.To address these open problems, we develop the first automated framework to systematically discover observation channels in browsers. In doing so, we detect and characterize 280 observation channels that leak information cross-site in the engines of Chromium, Firefox, and Safari, which include many variations of supposedly fixed leaks. Atop this framework, we create an automatic pipeline to find XS-Leaks in real-world websites. With this pipeline, we conduct the largest to-date study on XS-Leak prevalence in the wild by performing visit inference and a newly proposed variant cookie acceptance inference attack on the Tranco Top10K. In addition, we test 100 websites for the classic XS-Leak attack vector of login detection.Our results show that XS-Leaks pose a significant threat to the web ecosystem as at least 15%, 34%, and 77% of all tested sites are vulnerable to the three attacks. Also, we present substantial implementation differences between the browsers resulting in differing attack surfaces that matter in the wild. To ensure browser vendors and web developers alike can check their applications for XS-Leaks, we open-source our framework and include an extensive discussion on countermeasures to get rid of XS-Leaks in the near future and ensure new features in browsers do not introduce new XS-Leaks. Jannis Rautenstrauch, Giancarlo Pellegrino, Ben Stock |
SP | 1 |