EDBT 2026 Demo / reviewers in the wild / expert
Tobias Pulls
dblp:72/11061
· DBLP profile ↗
14ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0001-6459-8409ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 6 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ephemeral Network-Layer Fingerprinting DefensesabstractFingerprinting attacks on encrypted network traffic may reveal sensitive information about users of anonymous communication systems, such as visited websites or watched videos, linking users' activities to their identities. Defenses come at the cost of bandwidth and delay overheads, impacting the user experience and making wide-scale deployment challenging. There is a rich history of attacks and defenses, with continual improvements in deep learning as a catalyst, making deployment of defenses an ever more pressing matter. This paper introduces a new defense strategy against fingerprinting attacks---ephemeral defenses---where efficient defense search enables the generation of unique per-connection defenses. We demonstrate that ephemeral defenses are multipurpose network-layer defenses against circuit, website, and video fingerprinting attacks, achieving competitive performance compared to related work. Furthermore, we create tunable ephemeral defenses that are not overly specialized to a particular fingerprinting attack, dataset, or network conditions. Ephemeral defenses are practical, demonstrated through integration with WireGuard and deployment at Mullvad VPN for a year, serving thousands of daily users. Tobias Pulls, Topi Korhonen, Ethan Witwer, Niklas Carlsson |
Proc. Priv. Enhancing Technol. | 1 |
| 2026 | Dodge: A Client-Side Framework for Application-Layer Video Fingerprinting DefensesabstractAs reliance on online video continues to increase throughout all facets of society, it is critical to address the security and privacy threat of video fingerprinting, in which a local, passive adversary monitors a victim’s encrypted connection to a video server to infer which videos they are watching. These attacks attain high accuracy in realistic scenarios, while defenses that offer an acceptable trade-off between protection, overhead, and user experience are lacking. In this paper, we motivate application-layer defenses against video fingerprinting and present Dodge, a client-side framework for application-layer video fingerprinting defenses, implemented as a fork of the dash.js video player. Dodge provides the infrastructure and building blocks for defenses as well as a plug-and-play interface, making defense development and use straightforward while still providing maximal control over video flows. As a proof of concept, we use Dodge to implement a mimicry defense and show through live deployments that Dodge and the defense operate seamlessly, with modest overhead and very low user experience impact, while reducing attacker success close to theoretical bounds. Dodge can easily be deployed at scale and in a number of scenarios, with no changes to servers or network components; our analyses also lead to a host of insights that we hope will aid in deployment efforts. Ethan Witwer, David Hasselquist, Tobias Pulls, Niklas Carlsson |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Onion-Location Measurements and FingerprintingabstractOnion-Location makes it easy for websites offering onion service access to support automatic discovery in Tor Browser of the random-looking onion address associated with their domain. We provide the first measurement study of how many websites are currently using Onion-Location. We also describe the open-source tools we created to conduct the study. Onion-Location has been criticized elsewhere for its lack of transparency and vulnerability to blocking. Perhaps even more troubling, we show that Onion-Location is vulnerable to very accurate fingerprinting. We present recommended changes to and alternatives to Onion-Location as well as steps towards even more secure onion discovery and association. Paul F. Syverson, Rasmus Dahlberg, Tobias Pulls, Rob Jansen |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | A Second Look at DNS QNAME MinimizationabstractAbstract The Domain Name System (DNS) is a critical Internet infrastructure that translates human-readable domain names to IP addresses. It was originally designed over 35 years ago and multiple enhancements have since then been made, in particular to make DNS lookups more secure and privacy preserving. Query name minimization () was initially introduced in 2016 to limit the exposure of queries sent across DNS and thereby enhance privacy. In this paper, we take a look at the adoption of , building upon and extending measurements made by De Vries et al. in 2018. We analyze adoption on the Internet using active measurements both on resolvers used by RIPE Atlas probes and on open resolvers. Aside from adding more vantage points when measuring adoption on open resolvers, we also increase the number of repetitions, which reveals conflicting resolvers – resolvers that support for some queries but not for others. For the passive measurements at root and Top-Level Domain (TLD) name servers, we extend the analysis over a longer period of time, introduce additional sources, and filter out non-valid queries. Furthermore, our controlled experiments measure performance and result quality of newer versions of the -enabled open source resolvers used in the previous study, with the addition of PowerDNS. Our results, using extended methods from previous work, show that the adoption of has significantly increased since 2018. New controlled experiments also show a trend of higher number of packets used by resolvers and lower error rates in the DNS queries. Since is a balance between performance and privacy, we further discuss the depth limit of minimizing labels and propose the use of a public suffix list for setting this limit. Jonathan Magnusson, Anna Brunström, Tobias Pulls |
PAM | 4 |
| 2023 | Timeless Timing Attacks and Preload Defenses in Tor's DNS Cache
Rasmus Dahlberg, Tobias Pulls |
USENIX Security Symposium | 2 |
| 2021 | Privacy-Preserving & Incrementally-Deployable Support for Certificate Transparency in TorabstractAbstract The security of the web improved greatly throughout the last couple of years. A large majority of the web is now served encrypted as part of HTTPS, and web browsers accordingly moved from positive to negative security indicators that warn the user if a connection is insecure. A secure connection requires that the server presents a valid certificate that binds the domain name in question to a public key. A certificate used to be valid if signed by a trusted Certificate Authority (CA), but web browsers like Google Chrome and Apple’s Safari have additionally started to mandate Certificate Transparency (CT) logging to overcome the weakest-link security of the CA ecosystem. Tor and the Firefox-based Tor Browser have yet to enforce CT. In this paper, we present privacy-preserving and incrementally-deployable designs that add support for CT in Tor. Our designs go beyond the currently deployed CT enforcements that are based on blind trust: if a user that uses Tor Browser is man-in-the-middled over HTTPS, we probabilistically detect and disclose cryptographic evidence of CA and/or CT log misbehavior. The first design increment allows Tor to play a vital role in the overall goal of CT: detect mis-issued certificates and hold CAs accountable. We achieve this by randomly cross-logging a subset of certificates into other CT logs. The final increments hold misbehaving CT logs accountable, initially assuming that some logs are benign and then without any such assumption. Given that the current CT deployment lacks strong mechanisms to verify if log operators play by the rules, exposing misbehavior is important for the web in general and not just Tor. The full design turns Tor into a system for maintaining a probabilistically-verified view of the CT log ecosystem available from Tor’s consensus. Each increment leading up to it preserves privacy due to and how we use Tor. Rasmus Dahlberg, Tobias Pulls, Tom Ritter, Paul F. Syverson |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | Website Fingerprinting with Website OraclesabstractAbstract Website Fingerprinting (WF) attacks are a subset of traffic analysis attacks where a local passive attacker attempts to infer which websites a target victim is visiting over an encrypted tunnel, such as the anonymity network Tor. We introduce the security notion of a Website Oracle (WO) that gives a WF attacker the capability to determine whether a particular monitored website was among the websites visited by Tor clients at the time of a victim’s trace. Our simulations show that combining a WO with a WF attack—which we refer to as a WF+WO attack—significantly reduces false positives for about half of all website visits and for the vast majority of websites visited over Tor. The measured false positive rate is on the order one false positive per million classified website trace for websites around Alexa rank 10,000. Less popular monitored websites show orders of magnitude lower false positive rates. We argue that WOs are inherent to the setting of anonymity networks and should be an assumed capability of attackers when assessing WF attacks and defenses. Sources of WOs are abundant and available to a wide range of realistic attackers, e.g., due to the use of DNS, OCSP, and real-time bidding for online advertisement on the Internet, as well as the abundance of middleboxes and access logs. Access to a WO indicates that the evaluation of WF defenses in the open world should focus on the highest possible recall an attacker can achieve. Our simulations show that augmenting the Deep Fingerprinting WF attack by Sirinam et al. [60] with access to a WO significantly improves the attack against five state-of-the-art WF defenses, rendering some of them largely ineffective in this new WF+WO setting. Tobias Pulls, Rasmus Dahlberg |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | The Effect of DNS on Tor's Anonymity
Benjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter, Nick Feamster |
NDSS | 2 |
| 2017 | How Much Privilege Does an App Need? Investigating Resource Usage of Android Apps (Short Paper)abstractArguably, one of the default solutions to many of today's everyday errands is to install an app. In order to deliver a variety of convenient and user-centric services, apps need to access different types of information stored in mobile devices, much of which is personal information. In principle, access to such privacy sensitive data should be kept to a minimum. In this study, we focus on privilege utilization patterns by apps installed on Android devices. Though explicit consent is required prior to first time access to the resource, the unavailability of usage information makes it unclear when trying to reassess the users initial decision. On the other hand, if granted privilege with little or no usage, it would suggest the likely violation of the principle of least privilege. Our findings illustrate a plausible requirement for visualising resource usage to aid the user in their decisionmaking and finer access control mechanisms. Nurul Momen, Tobias Pulls, Lothar Fritsch, Stefan Lindskog |
PST | 2 |
| 2016 | Insynd: Improved Privacy-Preserving Transparency Logging
Roel Peeters, Tobias Pulls |
ESORICS (2) | 2 |
| 2015 | Secure Evidence Collection and Storage for Cloud Accountability Audits
Thomas Rübsamen, Tobias Pulls, Christoph Reich |
CLOSER | 2 |
| 2015 | Balloon: A Forward-Secure Append-Only Persistent Authenticated Data Structure
Tobias Pulls, Roel Peeters |
ESORICS (2) | 1 |
| 2012 | Hardware Strengthening a Distributed Logging SchemeabstractIn the online world, service providers allow users to upload data to be stored or processed. In some cases, privacy will become an essential feature. Sensitive content can be the data provided to or the services used at the service provider. Logging of the actions of the service providers can therefore also generate privacy-sensitive content. However, to enhance transparency towards users, logging can be a very useful tool. In this paper, we build upon the concept of distributed privacy-preserving log trails. The trust in such a system lies in the storage of a vector in a certain register stored in software. With a piece of malicious software, a hacker or curious user could misuse this register to learn about a certain process or to learn for whom a service is performed, although the scheme ensures forward-unlinkability and forward-integrity. In this paper, we strengthen the conventional software approach by implementing the vector in external hardware. This hardens the scheme further, and reduces the level to which the log server has to be trusted, at the cost of additional but solvable security threats. Jo Vliegen, Karel Wouters, Christian Grahn, Tobias Pulls |
DSD | 4 |
| 2012 | Towards Usable Privacy Policy Display & Management for PrimeLifeabstractPurpose The purpose of this paper is to present the approach taken within the PrimeLife project for designing user‐friendly privacy policy interfaces for the PrimeLife Policy Language (PPL) and report on the lessons learned when designing interfaces for privacy policy management and display. Design/methodology/approach Taking an iterative process of design, the authors developed the interface of the “Send Data?” prototype, a browser extension designed and developed to deal with the powerful features provided by PPL, and having the purpose of helping users to make conscious decisions on the dissemination of their personal information. The proposed interface introduces the novel features of “on the fly” privacy management, predefined levels of privacy settings, and simplified selection of anonymous credentials. The last iteration of the prototype has been tested using a cognitive walkthrough approach. Findings Results from usability tests show that users understood and appreciate most of the features contained within the interface and they perceived their benefit for protecting their privacy online. However, improvement is still needed in order to make the display and management of privacy policies more intuitive and seamless. Showing privacy mismatches inside a two‐dimensional table was preferred by users in general. Originality/value The paper introduces the novelty of “on the fly” privacy management, which lets users adapt and organize their own privacy preferences whilst an online transaction takes place, Also, it allows users to select credentials to identify themselves in a simpler manner. Julio Angulo, Simone Fischer-Hübner, Erik Wästlund, Tobias Pulls |
Inf. Manag. Comput. Secur. | 4 |