Gabriel Maganis

dblp:66/2982 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
0since 2021 · last 2012
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3Computer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Privacy and data protection · 39% Authentication and access control · 32% Systems and software security · 18%

Topics — the 7 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
anonymous authentication
0.112012
Opaak: using mobile phones to limit anonymous identities online · MobiSys 2012
Authentication and access control
anonymous credentials
0.112012
Opaak: using mobile phones to limit anonymous identities online · MobiSys 2012
Privacy and data protection › anonymity
unlinkability
0.112012
Opaak: using mobile phones to limit anonymous identities online · MobiSys 2012
Privacy and data protection › information leakage
personal information exposure
0.112010
The Wi-Fi privacy ticker: improving awareness & control of personal information exposure on Wi-Fi · UbiComp 2010
Systems and software security › information flow control
information leak detection
0.112008
Privacy oracle: a system for finding application leaks with black box differential testing · CCS 2008
Privacy and data protection
location privacy
0.112008
Privacy-Preserving Location Tracking of Lost or Stolen Devices: Cryptographic Techniques and Replacing Trusted Third Parties with DHTs · USENIX Security Symposium 2008
Privacy and data protection
mobile app privacy
0.012008
Privacy oracle: a system for finding application leaks with black box differential testing · CCS 2008

Methods — techniques the papers use, named apart from their topics

anonymous credentials · 0.1field study · 0.1sequence alignment · 0.1distributed hash table · 0.1differential testing · 0.1
YearPublicationVenuePosition
2012 Opaak: using mobile phones to limit anonymous identities online
abstract
Trust and anonymity are both desirable properties on the Internet. However, online services and users often have to make the trade off between trust and anonymity due to the lack of usable frameworks for achieving them both. We propose Opaak, a practical anonymous authentication framework. Opaak enables its users to establish identities with different online services while ensuring that these identities cannot be linked with each other or their real identity. In addition, Opaak allows online service providers to control the rate at which users utilize their services while preserving their anonymity. Hence, allowing the service providers to prevent abuse in the form of spam or Sybil attacks, which are prevalent in such online services that offer anonymity. Opaak leverages the mobile phone as a scarce resource combined with anonymous credentials in order to provide these features. We target two kinds of applications for Opaak and identify their requirements in order to achieve both trust and anonymity. We develop efficient protocols for these applications based on anonymous credentials. In addition, we design an architecture that facilitates integration with existing mobile and web applications and allows application developers to transparently utilize our protocols. We implement a prototype on Android and evaluate its performance to demonstrate the practicality of our approach.
Gabriel Maganis, Elaine Shi, Hao Chen 0003, Dawn Song
MobiSys1
2010 The Wi-Fi privacy ticker: improving awareness & control of personal information exposure on Wi-Fi
abstract
Anyone within range of an 802.11 wireless network ("Wi-Fi") can use free software to collect the unencrypted web traffic of others on the network. However, many Wi-Fi users are completely unaware of the risk that this creates. This work aims to improve users' awareness about what they expose to others on Wi-Fi networks and provide them with some control. Our system, the Wi-Fi Privacy Ticker, displays information about the exposure of sensitive terms that are sent to and from a user's computer and prevents the unencrypted transmission of terms from the user's computer that she has identified as highly sensitive. In a three-week field study with 17 participants, we found that the Wi-Fi Privacy Ticker improved participants' awareness of the circumstances in which their personal information is transmitted. We show that this heightened awareness contributed to changes in their behavior while on Wi-Fi.
Sunny Consolvo, Jaeyeon Jung, Ben Greenstein, Pauline S. Powledge, Gabriel Maganis, Daniel Avrahami
UbiComp5
2009 Mitigating DoS Attacks on the Paging Channel by Efficient Encoding in Page Messages
Gabriel Maganis, Hui Zang, Hao Chen 0003
SecureComm2
2008 Privacy oracle: a system for finding application leaks with black box differential testing
abstract
We describe the design and implementation of Privacy Oracle, a system that reports on application leaks of user information via the network traffic that they send. Privacy Oracle treats each application as a black box, without access to either its internal structure or communication protocols. This means that it can be used over a broad range of applications and information leaks (i.e., not only Web traffic or credit card numbers). To accomplish this, we develop a differential testing technique in which perturbations in the application inputs are mapped to perturbations in the application outputs to discover likely leaks; we leverage alignment algorithms from computational biology to find high quality mappings between different byte-sequences efficiently. Privacy Oracle includes this technique and a virtual machine-based testing system. To evaluate it, we tested 26 popular applications, including system and file utilities, media players, and IM clients. We found that Privacy Oracle discovered many small and previously undisclosed information leaks. In several cases, these are leaks of directly identifying information that are regularly sent in the clear (without end-to-end encryption) and which could make users vulnerable to tracking by third parties or providers.
Jaeyeon Jung, Anmol Sheth, Ben Greenstein, David Wetherall, Gabriel Maganis, Tadayoshi Kohno
CCS5
2008 Privacy-Preserving Location Tracking of Lost or Stolen Devices: Cryptographic Techniques and Replacing Trusted Third Parties with DHTs
Thomas Ristenpart, Gabriel Maganis, Arvind Krishnamurthy, Tadayoshi Kohno
USENIX Security Symposium2