EDBT 2026 Demo / reviewers in the wild / expert
Tadayoshi Kohno
dblp:k/TadayoshiKohno
· DBLP profile ↗
123ranked-venue papers
8as first author
39since 2021 · last 2026
0000-0002-4899-226XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 80 · 7 first-author · 22 since 2021Human-computer interaction and ubiquitous computing · 23 · 1 first-author · 12 since 2021Computer networks · 9 · 3 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Software engineering, systems software and programming languages · 3Databases, data management, data science and information retrieval · 3 · 1 since 2021Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Automating Data Access Permissions in AI AgentsabstractAs AI agents attempt to autonomously act on users' behalf, they raise transparency and control issues. We argue that permission-based access control is indispensable in providing meaningful control to the users, but conventional permission models are inadequate for the automated agentic execution paradigm. We therefore propose automated permission management for AI agents. Our key idea is to conduct a user study to identify the factors influencing users' permission decisions and to encode these factors into an ML-based permission management assistant capable of predicting users' future decisions. We find that participants' permission decisions are influenced by communication context but importantly individual preferences tend to remain consistent within contexts, and align with those of other participants. Leveraging these insights, we develop a permission prediction model achieving 85.1% accuracy overall and 94.4% for high-confidence predictions. We find that even without using permission history, our model achieves an accuracy of 66.9%, and a slight increase of training samples (i.e., 1-4) can substantially increase the accuracy by 10.8%. Yuhao Wu 0006, Franziska Roesner, Tadayoshi Kohno, Ning Zhang 0017, Umar Iqbal 0002 |
SP | 4 |
| 2025 | Poster: Computer Security Researchers' Experiences with Vulnerability DisclosuresabstractVulnerability disclosures are necessary to improve the security of our digital ecosystem. However, they can also be challenging for researchers: it may be hard to find out who the affected parties even are, or how to contact them. Researchers may be ignored or face adversity when disclosing vulnerabilities. We investigate researchers' experiences with vulnerability disclosures, extract best practices, and make recommendations for researchers, institutions that employ them, industry, and regulators to enable effective vulnerability disclosures. Harshini Sri Ramulu, Anna Lena Rotthaler, Jost Rossel, Rachel Gonzalez Rodriguez, Dominik Wermke, Sascha Fahl, Tadayoshi Kohno, Juraj Somorovsky, Yasemin Acar |
CCS | 7 |
| 2025 | Ethics in Computer Security Research: A Data-Driven Assessment of the Past, the Present, and the Possible FutureabstractEthical questions are discussed regularly in computer security. Still, researchers in computer security lack clear guidance on how to make, document, and assess ethical decisions in research when what is morally right or acceptable is not clear-cut. In this work, we give an overview of the discussion of ethical implications in current published work in computer security by reviewing all 1154 publications at top 4 security conferences published in 2024, finding inconsistent levels of ethics reporting with a strong focus of reporting institutional or ethics board approval, human subjects protection, and responsible disclosure, and a lack of discussion of balancing harms and benefits. We further report on the results of a semi-structured interview study with 24 computer security and privacy researchers (among whom were also: reviewers, ethics committee members, and/or program chairs) and their ethical decision-making both as authors and during peer review, finding a strong desire for ethical research, but a lack of consistency in considered values, ethical frameworks (if articulated), decision-making, and outcomes. We present an overview of the current state of the discussion of ethics and current de-facto standards in computer security research, contributing suggestions to improve the state of ethics in computer security research. Harshini Sri Ramulu, Helen Schmitt, Bogdan Rerich, Rachel Gonzalez Rodriguez, Tadayoshi Kohno, Yasemin Acar |
CCS | 5 |
| 2025 | "We're utterly ill-prepared to deal with something like this": Teachers' Perspectives on Student Generation of Synthetic Nonconsensual Explicit Imagery
Miranda Wei, Christina Yeung, Franziska Roesner, Tadayoshi Kohno |
CHI | 4 |
| 2025 | IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems
Yuhao Wu 0006, Franziska Roesner, Tadayoshi Kohno, Ning Zhang 0017, Umar Iqbal 0002 |
NDSS | 3 |
| 2025 | "You Have to Ignore the Dangers": User Perceptions of the Security and Privacy Benefits of WhatsApp ModsabstractWhatsApp is the most popular social messaging platform, and modified versions (or “mods”) of the official WhatsApp are increasingly popular. Mods advertise additional features and customization. However, some of these features, e.g., retaining deleted messages and statuses, enable mod users to subvert the privacy of others, and have the potential for seri-ous security and privacy implications. In this study, we explore user perspectives of WhatsApp mods through an interview study$(n=20)$of mod users in Kenya, one of the countries with the highest WhatsApp mod usage. Many turned to WhatsApp mods for their “advanced” features to protect themselves (e.g., “anti-delete” for legal liability), while others admitted to using mod features to hide their behavior or to stalk others. To understand how users' expectations of WhatsApp mods align with the apps' behavior, we identify and analyze 13 instances of the most common mod (GB WhatsApp). While WhatsApp mods contained the features they claimed to offer, some participants incorrectly believed that features currently available in the official app only existed in mods. Additionally, several mods were significantly over-permissioned compared to the official WhatsApp, despite participants believing that they requested the same permissions as the official app. While almost half of participants indicated they trust mods more than the official WhatsApp, we found two mods contained malware. The use of WhatsApp mods poses risks to mod users and those they communicate with, but also empowers users in ways that the official app does not. We caution developers and mod users to do their due diligence before using or distributing mods. Collins W. Munyendo, Kentrell Owens, Faith Strong, Adam J. Aviv, Tadayoshi Kohno, Franziska Roesner |
SP | 6 |
| 2025 | Analyzing the AI Nudification Application Ecosystem
Cassidy Gibson, Daniel Olszewski, Natalie Grace Brigham, Anna Crowder, Kevin R. B. Butler, Patrick Traynor, Elissa M. Redmiles, Tadayoshi Kohno |
USENIX Security Symposium | 8 |
| 2025 | To Reveal or Conceal: Privacy and Marginalization in AvatarsabstractThe present and future transition of lives and activities into virtual worlds --- worlds in which people interact using avatars --- creates novel privacy challenges and opportunities. Avatars present an opportunity for people to control the way they are represented to other users and the information shared or implied by that representation. Importantly, users with marginalized identities may have a unique set of concerns when choosing what information about themselves (and their identities) to conceal or expose in an avatar. We present a theoretical basis, supported by two empirical studies, to understand how marginalization impacts the ways in which people create avatars and perceive others' avatars: what information do people choose to reveal or conceal, and how do others react to these choices? In Study 1, participants from historically marginalized backgrounds felt more concerned about being devalued based on their identities in virtual worlds, which related to a lower desire to reveal their identities in an avatar, compared to non-marginalized participants. However, in Study 2 participants were often uncomfortable with others changing visible characteristics in an avatar, weighing concerns about others' anonymity with possible threats to their own safety and security online. Our findings demonstrate asymmetries in what information people prefer the self vs. others to reveal in their online representations: participants want privacy for themselves but to feel informed about others. Although avatars allow people to choose what information to reveal about themselves, people from marginalized backgrounds may still face backlash for concealing components of their identities to avoid harm. Mattea Sim, Basia Radka, Emi Yoshikawa, Franziska Roesner, Kurt Hugenberg, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 6 |
| 2024 | LLM Platform Security: Applying a Systematic Evaluation Framework to OpenAI's ChatGPT PluginsabstractLarge language model (LLM) platforms, such as ChatGPT, have recently begun offering an app ecosystem to interface with third-party services on the internet. While these apps extend the capabilities of LLM platforms, they are developed by arbitrary third parties and thus cannot be implicitly trusted. Apps also interface with LLM platforms and users using natural language, which can have imprecise interpretations. In this paper, we propose a framework that lays a foundation for LLM platform designers to analyze and improve the security, privacy, and safety of current and future third-party integrated LLM platforms. Our framework is a formulation of an attack taxonomy that is developed by iteratively exploring how LLM platform stakeholders could leverage their capabilities and responsibilities to mount attacks against each other. As part of our iterative process, we apply our framework in the context of OpenAI's plugin (apps) ecosystem. We uncover plugins that concretely demonstrate the potential for the types of issues that we outline in our attack taxonomy. We conclude by discussing novel challenges and by providing recommendations to improve the security, privacy, and safety of present and future LLM-based computing platforms. The full version of this paper is available online at https://arxiv.org/abs/2309.10254 Umar Iqbal 0002, Tadayoshi Kohno, Franziska Roesner |
AIES (1) | 2 |
| 2024 | Particip-AI: A Democratic Surveying Framework for Anticipating Future AI Use Cases, Harms and BenefitsabstractGeneral purpose AI, such as ChatGPT, seems to have lowered the barriers for the public to use AI and harness its power. However, the governance and development of AI still remain in the hands of a few, and the pace of development is accelerating without a comprehensive assessment of risks. As a first step towards democratic risk assessment and design of general purpose AI, we introduce PARTICIP-AI, a carefully designed framework for laypeople to speculate and assess AI use cases and their impacts. Our framework allows us to study more nuanced and detailed public opinions on AI through collecting use cases, surfacing diverse harms through risk assessment under alternate scenarios (i.e., developing and not developing a use case), and illuminating tensions over AI devel- opment through making a concluding choice on its development. To showcase the promise of our framework towards informing democratic AI development, we run a medium-scale study with inputs from 295 demographically diverse participants. Our analyses show that participants’ responses emphasize applications for personal life and society, contrasting with most current AI development’s business focus. We also surface diverse set of envisioned harms such as distrust in AI and institutions, complementary to those defined by experts. Furthermore, we found that perceived impact of not developing use cases significantly predicted participants’ judgements of whether AI use cases should be developed, and highlighted lay users’ concerns of techno-solutionism. We conclude with a discussion on how frameworks like PARTICIP-AI can further guide democratic AI development and governance. Jimin Mun, Jenny T. Liang, Inyoung Cheong, Nicole DeCario, Yejin Choi 0001, Tadayoshi Kohno, Maarten Sap |
AIES (1) | 7 |
| 2024 | Face the Facts: Using Face Averaging to Visualize Gender-by-Race Bias in Facial Analysis AlgorithmsabstractWe applied techniques from psychology --- typically used to visualize human bias --- to facial analysis systems, providing novel approaches for diagnosing and communicating algorithmic bias. First, we aggregated a diverse corpus of human facial images (N=1492) with self-identified gender and race. We tested four automated gender recognition (AGR) systems and found that some exhibited intersectional gender-by-race biases. Employing a technique developed by psychologists --- face averaging --- we created composite images to visualize these systems' outputs. For example, we visualized what an "average woman" looks like, according to a system's output. Second, we conducted two online experiments wherein participants judged the bias of hypothetical AGR systems. The first experiment involved participants (N=228) from a convenience sample. When depicting the same results in different formats, facial visualizations communicated bias to the same magnitude as statistics. In the second experiment with only Black participants (N=223), facial visualizations communicated bias significantly more than statistics, suggesting that face averages are meaningful for communicating algorithmic bias. Kentrell Owens, Erin Freiburger, Ryan Hutchings, Mattea Sim, Kurt Hugenberg, Franziska Roesner, Tadayoshi Kohno |
AIES (1) | 7 |
| 2024 | It's Trying Too Hard To Look Real: Deepfake Moderation Mistakes and Identity-Based BiasabstractOnline platforms employ manual human moderation to distinguish human-created social media profiles from deepfake-generated ones. Biased misclassification of real profiles as artificial can harm general users as well as specific identity groups; however, no work has yet systematically investigated such mistakes and biases. We conducted a user study (n=695) that investigates how 1) the identity of the profile, 2) whether the moderator shares that identity, and 3) components of a profile shown affect the perceived artificiality of the profile. We find statistically significant biases in people’s moderation of LinkedIn profiles based on all three factors. Further, upon examining how moderators make decisions, we find they rely on mental models of AI and attackers, as well as typicality expectations (how they think the world works). The latter includes reliance on race/gender stereotypes. Based on our findings, we synthesize recommendations for the design of moderation interfaces, moderation teams, and security training. Jaron Mink, Miranda Wei, Collins W. Munyendo, Kurt Hugenberg, Tadayoshi Kohno, Elissa M. Redmiles, Gang Wang 0011 |
CHI | 5 |
| 2024 | Analyzing the (In)Accessibility of Online AdvertisementsabstractAds are often designed visually, with images and videos conveying information. In this work, we study the accessibility of ads on the web to users of screen readers. We approach this in two ways: first, we conducted a measurement and analysis of 90 websites over a month, collecting ads and auditing their behavior against a subset of best practices established by the Web Content Accessibility Guidelines (WCAG). Then, to put our measurement findings in context, we interviewed 13 blind participants who navigate the web with a screen reader to understand their experiences with (in)accessible ads. We find that the overall web ad ecosystem is fairly inaccessible in multiple ways: many images are missing alt-text, unlabeled links make it confusing for folks to navigate, and closing ads can be tricky. But, there are straightforward ways to improve: because only a few large companies dominate the ad ecosystem, making small changes to the way they enforce accessibility standards can make a large difference. Christina Yeung, Tadayoshi Kohno, Franziska Roesner |
IMC | 2 |
| 2024 | Experimental Analyses of the Physical Surveillance Risks in Client-Side Content Scanning
Ashish Hooda, Andrey Labunets, Tadayoshi Kohno, Earlence Fernandes |
NDSS | 3 |
| 2024 | When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented Reality
Kaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 0005, Aroosh Kumar, Jeffery F. Tian, Tadayoshi Kohno, Franziska Roesner |
USENIX Security Symposium | 7 |
| 2024 | "But they have overlooked a few things in Afghanistan: " An Analysis of the Integration of Biometric Voter Verification in the 2019 Afghan Presidential Elections
Kabir Panahi, Shawn Robertson, Yasemin Acar, Alexandru G. Bardas, Tadayoshi Kohno, Lucy Simko |
USENIX Security Symposium | 5 |
| 2024 | Understanding Help-Seeking and Help-Giving on Social Media for Image-Based Sexual Abuse
Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Tara Matthews, Sarah Meiklejohn, Franziska Roesner, Renee Shelby, Kurt Thomas, Rebecca Umbach |
USENIX Security Symposium | 4 |
| 2024 | SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security Behaviors
Miranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno, Elissa M. Redmiles, Franziska Roesner |
USENIX Security Symposium | 4 |
| 2024 | Over Fences and Into Yards: Privacy Threats and Concerns of Commercial SatellitesabstractCommercial satellite imaging is used for diverse applications in a wide range of sectors, from agriculture to the military. As satellite images continue to become more widely available and detailed in resolution, the potential for individual and population-level monitoring increases and raises new privacy concerns compared to previous Earth observation technologies. We anticipate that these technologies will only continue to improve in the upcoming decade. To better understand privacy threats and concerns of commercial satellite imagery, we conducted a survey of 99 participants from the United States. We found that most respondents were not aware that commercial satellites existed, and once informed about the capabilities of commercial satellites, most are not comfortable with how good the current state-of-the-art satellite imaging capabilities are. Few respondents want satellite imagery cost-free and widely available, which conflicts with current trends in geospatial data. In addition to aiding our understanding of the public's current perception and relationship with remote sensing technologies, we use these results to propose possible new satellite image legislation, regulation, and technological mitigations, both nationally and internationally. Rachel McAmis, Mattea Sim, Mia M. Bennett, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Evaluation of targeted dataset collection on racial equity in face recognitionabstractAlgorithmic audits of industry face recognition models have recently incentivized companies to diversify their data collection methods, which in turn has reduced error disparities along demographic lines, such as gender or race. We argue that it is important to understand exactly how various forms of targeted data collection mitigate performance disparities in these updated face recognition models. We propose an empirical framework to assess the impact of additional dataset collection targeted towards various racial groups. We apply our framework to three racially-annotated benchmark datasets using three standard face recognition models. Our findings empirically validate the notion that the introduction of data from the demographic group with the initially-lowest performance improves performance on that group significantly more than adding from other groups. We also observe that in all settings, the introduction of data from a previously omitted group does not harm the performance of other groups. Furthermore, investigation of feature embeddings reveals that performance increases are associated with a larger separation among images of different identities. Despite the commonalities we observe across datasets, we also find key differences: for example, in one dataset, training on one racial group generalizes well across all groups. These differences speak to the criticality of re-applying empirical evaluation methods, such as the methods in this work, when introducing new datasets or models. Rachel Hong, Tadayoshi Kohno, Jamie Morgenstern |
AIES | 2 |
| 2023 | Understanding People's Concerns and Attitudes Toward Smart CitiesabstractDesigning privacy-respecting and human-centric smart cities requires a careful investigation of people’s attitudes and concerns toward city-wide data collection scenarios. To capture a holistic view, we carried out this investigation in two phases. We first surfaced people’s understanding, concerns, and expectations toward smart city scenarios by conducting 21 semi-structured interviews with people in underserved communities. We complemented this in-depth qualitative study with a 348-participant online survey of the general population to quantify the significance of smart city factors (e.g., type of collected data) on attitudes and concerns. Depending on demographics, privacy and ethics were the two most common types of concerns among participants. We found the type of collected data to have the most and the retention time to have the least impact on participants’ perceptions and concerns about smart cities. We highlight key takeaways and recommendations for city stakeholders to consider when designing inclusive and protective smart cities. Pardis Emami Naeini, Joseph Breda, Wei Dai 0007, Tadayoshi Kohno, Kim Laine, Shwetak N. Patel, Franziska Roesner |
CHI | 4 |
| 2023 | How Language Formality in Security and Privacy Interfaces Impacts Intended ComplianceabstractStrong end-user security practices benefit both the user and hosting platform, but it is not well understood how companies communicate with their users to encourage these practices. This paper explores whether web companies and their platforms use different levels of language formality in these communications and tests the hypothesis that higher language formality leads to users’ increased intention to comply. We contribute a dataset and systematic analysis of 1,817 English language strings in web security and privacy interfaces across 13 web platforms, showing strong variations in language. An online study with 512 participants further demonstrated that people perceive differences in the language formality across platforms and that a higher language formality is associated with higher self-reported intention to comply. Our findings suggest that formality can be an important factor in designing effective security and privacy prompts. We discuss implications of these results, including how to balance formality with platform language style. In addition to being the first piece of work to analyze language formality in user security, these findings provide valuable insights into how platforms can best communicate with users about account security. Jackson Stokes, Tal August, Robert A Marver, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno, Katharina Reinecke |
CHI | 6 |
| 2023 | "There's so much responsibility on users right now: " Expert Advice for Staying Safer From Hate and HarassmentabstractOnline hate and harassment poses a threat to the digital safety of people globally. In light of this risk, there is a need to equip as many people as possible with advice to stay safer online. We interviewed 24 experts to understand what threats and advice internet users should prioritize to prevent or mitigate harm. As part of this, we asked experts to evaluate 45 pieces of existing hate-and-harassment-specific digital-safety advice to understand why they felt advice was viable or not. We find that experts frequently had competing perspectives for which threats and advice they would prioritize. We synthesize sources of disagreement, while also highlighting the primary threats and advice where experts concurred. Our results inform immediate efforts to protect users from online hate and harassment, as well as more expansive socio-technical efforts to establish enduring safety. Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Franziska Roesner, Kurt Thomas |
CHI | 4 |
| 2023 | A Scalable Inclusive Security Intervention to Center Marginalized & Vulnerable Populations in Security & Privacy DesignabstractResearch in computer security has increasingly considered the needs of marginalized and vulnerable groups in technology. Through this work, we hope to translate this research movement into practice and, ultimately, cause designers-in-training (and, eventually, designers) to consider a more inclusive range of stakeholders. Thus, we created an educational intervention to center marginalized and vulnerable populations in the context of threat modeling. We find that computer security students are more likely to consider unique threats and vulnerabilities facing marginalized and vulnerable populations after being exposed to an intervention prompting them to think about populations that might often be overlooked. We suggest practical methods to teach designers-in-training inclusive methods in computer security and discuss other possible adoptions of this practice across the field. This work is part of an important shift toward inclusive security that centers marginalized and vulnerable populations both in research and in practice. Mattea Sim, Kurt Hugenberg, Tadayoshi Kohno, Franziska Roesner |
NSPW | 3 |
| 2023 | Skilled or Gullibleƒ Gender Stereotypes Related to Computer Security and PrivacyabstractGender stereotypes remain common in U.S. society and harm people of all genders. Focusing on binary genders (women and men) as a first investigation, we empirically study gender stereotypes related to computer security and privacy. We used Prolific to conduct two surveys with U.S. participants that aimed to: (1) surface potential gender stereotypes related to security and privacy (N = 202), and (2) assess belief in gender stereotypes about security and privacy engagement, personal characteristics, and behaviors (N = 190). We find that stereotype beliefs are significantly correlated with participants’ gender as well as level of sexism, and we delve into the justifications our participants offered for their beliefs. Beyond scientifically studying the existence and prevalence of such stereotypes, we describe potential implications, including biasing crowdworker-faciliated user research. Further, our work lays a foundation for deeper investigations of the impacts of stereotypes in computer security and privacy, as well as stereotypes across the whole gender and identity spectrum. Miranda Wei, Pardis Emami Naeini, Franziska Roesner, Tadayoshi Kohno |
SP | 4 |
| 2023 | Exploring User Reactions and Mental Models Towards Perceptual Manipulation Attacks in Mixed Reality
Kaiming Cheng, Jeffery F. Tian, Tadayoshi Kohno, Franziska Roesner |
USENIX Security Symposium | 3 |
| 2023 | Ethical Frameworks and Computer Security Trolley Problems: Foundations for Conversations
Tadayoshi Kohno, Yasemin Acar, Wulf Loh |
USENIX Security Symposium | 1 |
| 2023 | The Writing on the Wall and 3D Digital Twins: Personal Information in (not so) Private Real Estate
Rachel McAmis, Tadayoshi Kohno |
USENIX Security Symposium | 2 |
| 2023 | Online Advertising in Ukraine and Russia During the 2022 Russian InvasionabstractOnline ads are a major source of information on the web. The mass reach of online advertising is often leveraged for information dissemination, at times with an objective to influence public opinion (e.g., election misinformation). We hypothesized that online advertising, due to its reach and potential, might have been used to spread information around the 2022 Russian invasion of Ukraine. Thus, to understand the online ad ecosystem during this conflict, we conducted a five-month long large-scale measurement study of online advertising in Ukraine, Russia, and the US. We studied advertising trends of ad platforms that delivered ads in Ukraine, Russia, and the US and conducted an in-depth qualitative analysis of the conflict-related ad content. We found that prominent US-based advertisers continued to support Russian websites, and a portion of online ads were used to spread conflict-related information, including protesting the invasion, and spreading awareness, which might have otherwise potentially been censored in Russia. Christina Yeung, Umar Iqbal 0002, Yekaterina Tsipenyuk O'Neil, Tadayoshi Kohno, Franziska Roesner |
WWW | 4 |
| 2023 | The Use and Non-Use of Technology During HurricanesabstractHurricanes can cause catastrophic damage; it is critical for those affected to access information about conditions, loved ones, and resources. Prior work in the HCI and CSCW communities has focused on how social media can be vital during natural disasters; non-social media technologies have been under-researched. To understand how technology other than social media can support or harm people during crises, we explore hurricane survivors' use and disuse of multiple kinds of technologies in online surveys with 138 US participants. We find substantial technology use supporting survivors' comfort and safety other than social media. We also observe that designing technologies for high-resource environments--as with many mainstream apps--causes users to decrease use of potentially critical technologies during utility outages, which are common during hurricanes. With themes of both (a) broad technology use and (b) conditions preventing technology use, we make recommendations for technical design, policy, and research to empower communities susceptible to hurricanes. Lucy Simko, Harshini Sri Ramulu, Tadayoshi Kohno, Yasemin Acar |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | What factors affect targeting and bids in online advertising?: a field measurement studyabstractTargeted online advertising is a well-known but extremely opaque phenomenon. Though the targeting capabilities of the ad tech ecosystem are public knowledge, from an outside perspective, it is difficult to measure and quantify ad targeting at scale. To shed light on the extent of targeted advertising on the web today, we conducted a controlled field measurement study of the ads shown to a representative sample of 286 participants in the U.S. Using a browser extension, we collected data on ads seen by users on 10 popular websites, including the topic of the ad, the value of the bid placed by the advertiser (via header bidding), and participants' perceptions of targeting. We analyzed how ads were targeted across individuals, websites, and demographic groups, how those factors affected the amount advertisers bid, and how those results correlated with participants' perceptions of targeting. Among our findings, we observed that the primary factors that affected targeting and bid values were the website the ad appeared on and individual user profiles. Surprisingly, we found few differences in how advertisers target and bid across demographic groups. We also found that high outliers in bid values (10x higher than baseline) may be indicative of retargeting. Our measurements provide a rare in situ view of targeting and bidding across a diversity of users. Eric Zeng 0001, Rachel McAmis, Tadayoshi Kohno, Franziska Roesner |
IMC | 3 |
| 2022 | Electronic Monitoring Smartphone Apps: An Analysis of Risks from Technical, Human-Centered, and Legal Perspectives
Kentrell Owens, Anita Alem, Franziska Roesner, Tadayoshi Kohno |
USENIX Security Symposium | 4 |
| 2021 | Would You Rather: A Focus Group Method for Eliciting and Discussing Formative Design Insights with ChildrenabstractWould you rather go 1000 days without the Internet or five days where anyone can read your mind? We present “Would You Rather” (WYR), a technique for generating formative design insights (inspired by the conversational game of the same name) that combines design provocations with forced-choice scaffolding. Here, we describe the components of a WYR session, which include scenario generation, voting, and group discussion. As children disproportionately benefit from scaffolding during the co-design process, we also report on an evaluation of the technique with 16 children, conducted across seven sessions and spanning the course of one year. We find that WYR fulfills recommendations for focus groups (e.g. eliciting mental models and values, producing focused yet animated discussion) and leverages playfulness, humor, structure, and forced choice to overcome known common challenges of designing with children. Lucy Simko, Britnie Chin, Sungmin Na, Harkiran Kaur Saluja, Tian Qi Zhu, Tadayoshi Kohno, Alexis Hiniker, Jason C. Yip 0001, Camille Cobb |
IDC | 6 |
| 2021 | What Makes a "Bad" Ad? User Perceptions of Problematic Online AdvertisingabstractOnline display advertising on websites is widely disliked by users, with many turning to ad blockers to avoid “bad” ads. Recent evidence suggests that today’s ads contain potentially problematic content, in addition to well-studied concerns about the privacy and intrusiveness of ads. However, we lack knowledge of which types of ad content users consider problematic and detrimental to their browsing experience. Our work bridges this gap: first, we create a taxonomy of 15 positive and negative user reactions to online advertising from a survey of 60 participants. Second, we characterize classes of online ad content that users dislike or find problematic, using a dataset of 500 ads crawled from popular websites, labeled by 1000 participants using our taxonomy. Among our findings, we report that users consider a substantial amount of ads on the web today to be clickbait, untrustworthy, or distasteful, including ads for software downloads, listicles, and health & supplements. Eric Zeng 0001, Tadayoshi Kohno, Franziska Roesner |
CHI | 2 |
| 2021 | Polls, clickbait, and commemorative $2 bills: problematic political advertising on news and media websites around the 2020 U.S. electionsabstractOnline advertising can be used to mislead, deceive, and manipulate Internet users, and political advertising is no exception. In this paper, we present a measurement study of online advertising around the 2020 United States elections, with a focus on identifying dark patterns and other potentially problematic content in political advertising. We scraped ad content on 745 news and media websites from six geographic locations in the U.S. from September 2020 to January 2021, collecting 1.4 million ads. We perform a systematic qualitative analysis of political content in these ads, as well as a quantitative analysis of the distribution of political ads on different types of websites. Our findings reveal the widespread use of problematic tactics in political ads, such as bait-and-switch ads formatted as opinion polls to entice users to click, the use of political controversy by content farms for clickbait, and the more frequent occurrence of political ads on highly partisan news websites. We make policy recommendations for online political advertising, including greater scrutiny of non-official political ads and comprehensive standards across advertising platforms. Eric Zeng 0001, Miranda Wei, Theo Gregersen, Tadayoshi Kohno, Franziska Roesner |
Internet Measurement Conference | 4 |
| 2021 | Reliable and Trustworthy Machine Learning for Health Using Dataset Shift DetectionabstractUnpredictable ML model behavior on unseen data, especially in the health domain, raises serious concerns about its safety as repercussions for mistakes can be fatal. In this paper, we explore the feasibility of using state-of-the-art out-of-distribution detectors for reliable and trustworthy diagnostic predictions. We select publicly available deep learning models relating to various health conditions (e.g., skin cancer, lung sound, and Parkinson's disease) using various input data types (e.g., image, audio, and motion data). We demonstrate that these models show unreasonable predictions on out-of-distribution datasets. We show that Mahalanobis distance- and Gram matrices-based out-of-distribution detection methods are able to detect out-of-distribution data with high accuracy for the health models that operate on different modalities. We then translate the out-of-distribution score into a human interpretable \textsc{confidence score} to investigate its effect on the users' interaction with health ML applications. Our user study shows that the \textsc{confidence score} helped the participants only trust the results with a high score to make a medical decision and disregard results with a low score. Through this work, we demonstrate that dataset shift is a critical piece of information for high-stake ML applications, such as medical diagnosis and healthcare, to provide reliable and trustworthy predictions to the users. Chunjong Park, Anas Awadalla, Tadayoshi Kohno, Shwetak N. Patel |
NeurIPS | 3 |
| 2021 | Defensive Technology Use by Political Activists During the Sudanese RevolutionabstractPolitical activism is a worldwide force in geopolitical change and has, historically, helped lead to greater justice, equality, and stopping human rights abuses. A modern revolution—an extreme form of political activism—pits activists, who rely on technology for critical operational tasks, against a resource-rich government that controls the very telecommunications network they must use to operationalize, putting the technology they use under extreme stress. Our work presents insights about activists’ technological defense strategies from interviews with 13 political activists who were active during the 2018-2019 Sudanese revolution. We find that politics and society are driving factors of security and privacy behavior and app adoption. Moreover, a social media blockade can trigger a series of anti-censorship approaches at scale, while a complete internet blackout can cripple activists’ use of technology. Even though the activists’ technological defenses against the threats of surveillance, arrest and physical device seizure were low tech, they were largely sufficient against their adversary. Through these results, we surface key design principles, but we observe that the generalization of design recommendations often runs into fundamental tensions between the security and usability needs of different user groups. Thus, we provide a set of structured questions in an attempt to turn these tensions into opportunities for technology designers and policy makers. Alaa Daffalla, Lucy Simko, Tadayoshi Kohno, Alexandru G. Bardas |
SP | 3 |
| 2021 | FoggySight: A Scheme for Facial Lookup PrivacyabstractAdvances in deep learning algorithms have enabled better-than-human performance on face recognition tasks. In parallel, private companies have been scraping social media and other public websites that tie photos to identities and have built up large databases of labeled face images. Searches in these databases are now being offered as a service to law enforcement and others and carry a multitude of privacy risks for social media users. In this work, we tackle the problem of providing privacy from such face recognition systems. We propose and evaluate FoggySight, a solution that applies lessons learned from the adversarial examples literature to modify facial photos in a privacy-preserving manner before they are uploaded to social media. FoggySight’s core feature is a community protection strategy where users acting as protectors of privacy for others upload decoy photos generated by adversarial machine learning algorithms. We explore different settings for this scheme and find that it does enable protection of facial privacy – including against a facial recognition service with unknown internals. Ivan Evtimov, Pascal Sturmfels, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | DNA Sequencing Flow Cells and the Security of the Molecular-Digital InterfaceabstractAbstract DNA sequencing is the molecular-to-digital conversion of DNA molecules, which are made up of a linear sequence of bases (A,C,G,T), into digital information. Central to this conversion are specialized fluidic devices, called sequencing flow cells, that distribute DNA onto a surface where the molecules can be read. As more computing becomes integrated with physical systems, we set out to explore how sequencing flow cell architecture can affect the security and privacy of the sequencing process and downstream data analysis. In the course of our investigation, we found that the unusual nature of molecular processing and flow cell design contributes to two security and privacy issues. First, DNA molecules are ‘sticky’ and stable for long periods of time. In a manner analogous to data recovery from discarded hard drives, we hypothesized that residual DNA attached to used flow cells could be collected and re-sequenced to recover a significant portion of the previously sequenced data. In experiments we were able to recover over 23.4% of a previously sequenced genome sample and perfectly decode image files encoded in DNA, suggesting that flow cells may be at risk of data recovery attacks. Second, we hypothesized that methods used to simultaneously sequence separate DNA samples together to increase sequencing throughput (multiplex sequencing), which incidentally leaks small amounts of data between samples, could cause data corruption and allow samples to adversarially manipulate sequencing data. We find that a maliciously crafted synthetic DNA sample can be used to alter targeted genetic variants in other samples using this vulnerability. Such a sample could be used to corrupt sequencing data or even be spiked into tissue samples, whenever untrusted samples are sequenced together. Taken together, these results suggest that, like many computing boundaries, the molecular-to-digital interface raises potential issues that should be considered in future sequencing and molecular sensing systems, especially as they become more ubiquitous. Peter Ney, Lee Organick, Jeff Nivala, Luis Ceze, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | User Experiences with Online Status IndicatorsabstractOnline status indicators (OSIs) improve online communication by helping users convey and assess availability, but they also let users infer potentially sensitive information about one another. We surveyed 200 smartphone users to understand the extent to which users are aware of information shared via OSIs and the extent to which this shapes their behavior. Despite familiarity with OSIs, participants misunderstand many aspects of OSIs, and they describe carefully curating and seeking to control their self-presentation via OSIs. Some users further report leveraging OSI-conveyed information for problematic and malicious purposes. Drawing on existing constructs of app dependence (i.e., when users contort their behavior to meet an app's demands) and app enablement (i.e., when apps enable users to engage in behaviors they feel good about), we demonstrate that current OSI design patterns promote app dependence, and we call for a shift toward OSI designs that are more enabling for users. Camille Cobb, Lucy Simko, Tadayoshi Kohno, Alexis Hiniker |
CHI | 3 |
| 2020 | Accept the Risk and Continue: Measuring the Long Tail of Government https AdoptionabstractAcross the world, government websites are expected to be reliable sources of information, regardless of their view count. Interactions with these websites often contain sensitive information, such as identity, medical, or legal data, whose integrity must be protected for citizens to remain safe. To better understand the government website ecosystem, we measure the adoption of https including the "long tail" of government websites around the world, which are typically not captured in the top-million datasets used for such studies. We identify and measure major categories and frequencies of https adoption errors, including misconfiguration of certificates via expiration, reuse of keys and serial numbers between unrelated government departments, use of insecure cryptographic protocols and keys, and untrustworthy root Certificate Authorities (CAs). Finally, we observe an overall lower https rate and a steeper dropoff with descending popularity among government sites compared to the commercial websites & provide recommendations to improve the usage of https in governments worldwide. Sudheesh Singanamalla, Esther Han Beol Jang, Richard J. Anderson 0001, Tadayoshi Kohno, Kurtis Heimerl |
Internet Measurement Conference | 4 |
| 2020 | Genotype Extraction and False Relative Attacks: Security Risks to Third-Party Genetic Genealogy Services Beyond Identity Inference
Peter Ney, Luis Ceze, Tadayoshi Kohno |
NDSS | 3 |
| 2020 | A Privacy-Focused Systematic Analysis of Online Status IndicatorsabstractAbstract Online status indicators (or OSIs, i.e., interface elements that communicate whether a user is online) can leak potentially sensitive information about users. In this work, we analyze 184 mobile applications to systematically characterize the existing design space of OSIs. We identified 40 apps with OSIs across a variety of genres and conducted a design review of the OSIs in each, examining both Android and iOS versions of these apps. We found that OSI design decisions clustered into four major categories, namely: appearance, audience, settings, and fidelity to actual user behavior. Less than half of these apps allow users change the default settings for OSIs. Informed by our findings, we discuss: 1) how these design choices support adversarial behavior, 2) design guidelines for creating consistent, privacy-conscious OSIs, and 3) a set of novel design concepts for building future tools to augment users’ ability to control and understand the presence information they broadcast. By connecting the common design patterns we document to prior work on privacy in social technologies, we contribute an empirical understanding of the systematic ways in which OSIs can make users more or less vulnerable to unwanted information disclosure. Camille Cobb, Lucy Simko, Tadayoshi Kohno, Alexis Hiniker |
Proc. Priv. Enhancing Technol. | 3 |
| 2020 | Smart Devices in Airbnbs: Considering Privacy and Security for both Guests and HostsabstractAbstract Consumer smart home devices are becoming increasingly pervasive. As Airbnb hosts deploy smart devices in spaces shared with guests, we seek to understand the security and privacy implications of these devices for both hosts and guests. We conducted a large-scale survey of 82 hosts and 554 guests to explore their current technology practices, their preferences for smart devices and data collection/sharing, and their privacy and security concerns in the context of Airbnbs. We found that guests preferred smart devices, even viewed them as a luxury, but some guests were concerned that smart devices enable excessive monitoring and control, which could lead to repercussions from hosts (e.g., locked thermostat). On average, the views of guests and hosts on data collection in Airbnb were aligned, but for the data types where differences occur, serious privacy violations might happen. For example, 90% of our guest participants did not want to share their Internet history with hosts, but one in five hosts wanted access to that information. Overall, our findings surface tensions between hosts and guests around the use of smart devices and in-home data collection. We synthesize recommendations to address the surfaced tensions and identify broader research challenges. Shrirang Mare, Franziska Roesner, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | Secure Multi-User Content Sharing for Augmented Reality Applications
Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner |
USENIX Security Symposium | 2 |
| 2018 | Robust Physical-World Attacks on Deep Learning Visual ClassificationabstractRecent studies show that the state-of-the-art deep neural networks (DNNs) are vulnerable to adversarial examples, resulting from small-magnitude perturbations added to the input. Given that that emerging physical systems are using DNNs in safety-critical situations, adversarial examples could mislead these systems and cause dangerous situations. Therefore, understanding adversarial examples in the physical world is an important step towards developing resilient learning algorithms. We propose a general attack algorithm, Robust Physical Perturbations (RP2), to generate robust visual adversarial perturbations under different physical conditions. Using the real-world case of road sign classification, we show that adversarial examples generated using RP2 achieve high targeted misclassification rates against standard-architecture road sign classifiers in the physical world under various environmental conditions, including viewpoints. Due to the current lack of a standardized testing method, we propose a two-stage evaluation methodology for robust physical adversarial examples consisting of lab and field tests. Using this methodology, we evaluate the efficacy of physical adversarial manipulations on real objects. With a perturbation in the form of only black and white stickers, we attack a real stop sign, causing targeted misclassification in 100% of the images obtained in lab settings, and in 84.8% of the captured video frames obtained on a moving vehicle (field test) for the target classifier. Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li 0026, Amir Rahmati, Chaowei Xiao, Atul Prakash 0001, Tadayoshi Kohno, Dawn Song |
CVPR | 8 |
| 2018 | Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersabstractImmersive augmented reality (AR) technologies are becoming a reality. Prior works have identified security and privacy risks raised by these technologies, primarily considering individual users or AR devices. However, we make two key observations: (1) users will not always use AR in isolation, but also in ecosystems of other users, and (2) since immersive AR devices have only recently become available, the risks of AR have been largely hypothetical to date. To provide a foundation for understanding and addressing the security and privacy challenges of emerging AR technologies, grounded in the experiences of real users, we conduct a qualitative lab study with an immersive AR headset, the Microsoft HoloLens. We conduct our study in pairs - 22 participants across 11 pairs - wherein participants engage in paired and individual (but physically co-located) HoloLens activities. Through semi-structured interviews, we explore participants' security, privacy, and other concerns, raising key findings. For example, we find that despite the HoloLens's limitations, participants were easily immersed, treating virtual objects as real (e.g., stepping around them for fear of tripping). We also uncover numerous security, privacy, and safety concerns unique to AR (e.g., deceptive virtual objects misleading users about the real world), and a need for access control among users to manage shared physical spaces and virtual content embedded in those spaces. Our findings give us the opportunity to identify broader lessons and key challenges to inform the design of emerging single-and multi-user AR technologies. Kiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner |
IEEE Symposium on Security and Privacy | 3 |
| 2018 | Computer Security and Privacy for Refugees in the United StatesabstractIn this work, we consider the computer security and privacy practices and needs of recently resettled refugees in the United States. We ask: How do refugees use and rely on technology as they settle in the US? What computer security and privacy practices do they have, and what barriers do they face that may put them at risk? And how are their computer security mental models and practices shaped by the advice they receive? We study these questions through in-depth qualitative interviews with case managers and teachers who work with refugees at a local NGO, as well as through focus groups with refugees themselves. We find that refugees must rely heavily on technology (e.g., email) as they attempt to establish their lives and find jobs; that they also rely heavily on their case managers and teachers for help with those technologies; and that these pressures can push security practices into the background or make common security "best practices" infeasible. At the same time, we identify fundamental challenges to computer security and privacy for refugees, including barriers due to limited technical expertise, language skills, and cultural knowledge-for example, we find that scams as a threat are a new concept for many of the refugees we studied, and that many common security practices (e.g., password creation techniques and security questions) rely on US cultural knowledge. From these and other findings, we distill recommendations for the computer security community to better serve the computer security and privacy needs and constraints of refugees, a potentially vulnerable population that has not been previously studied in this context. Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, Tadayoshi Kohno |
IEEE Symposium on Security and Privacy | 5 |
| 2018 | Recognizing and Imitating Programmer Style: Adversaries in Program Authorship AttributionabstractAbstract Source code attribution classifiers have recently become powerful. We consider the possibility that an adversary could craft code with the intention of causing a misclassification, i.e., creating a forgery of another author’s programming style in order to hide the forger’s own identity or blame the other author. We find that it is possible for a non-expert adversary to defeat such a system. In order to inform the design of adversarially resistant source code attribution classifiers, we conduct two studies with C/C++ programmers to explore the potential tactics and capabilities both of such adversaries and, conversely, of human analysts doing source code authorship attribution. Through the quantitative and qualitative analysis of these studies, we (1) evaluate a state-of-the-art machine classifier against forgeries, (2) evaluate programmers as human analysts/forgery detectors, and (3) compile a set of modifications made to create forgeries. Based on our analyses, we then suggest features that future source code attribution systems might incorporate in order to be adversarially resistant. Lucy Simko, Luke Zettlemoyer, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Rewriting History: Changing the Archived Web from the PresentabstractThe Internet Archive's Wayback Machine is the largest modern web archive, preserving web content since 1996. We discover and analyze several vulnerabilities in how the Wayback Machine archives data, and then leverage these vulnerabilities to create what are to our knowledge the first attacks against a user's view of the archived web. Our vulnerabilities are enabled by the unique interaction between the Wayback Machine's archives, other websites, and a user's browser, and attackers do not need to compromise the archives in order to compromise users' views of a stored page. We demonstrate the effectiveness of our attacks through proof-of-concept implementations. Then, we conduct a measurement study to quantify the prevalence of vulnerabilities in the archive. Finally, we explore defenses which might be deployed by archives, website publishers, and the users of archives, and present the prototype of a defense for clients of the Wayback Machine, ArchiveWatcher. Ada Lerner, Tadayoshi Kohno, Franziska Roesner |
CCS | 2 |
| 2017 | Internet Censorship in Thailand: User Practices and Potential ThreatsabstractThe "cat-and-mouse" game of Internet censorship and circumvention cannot be won by capable technology alone. Instead, that technology must be available, comprehensible, and trustworthy to users. However, the field largely focuses only on censors and the technical means to circumvent them. Thailand, with its superlatives in Internet use and government information controls, offers a rich case study for exploring users' assessments of and interactions with censorship. We survey 229 and interview 13 Internet users in Thailand, and report on their current practices, experienced and perceived threats, and unresolved problems regarding censorship and digital security. Our findings indicate that existing circumvention tools were adequate for respondents to access blocked information, that respondents relied to some extent on risky tool selection and inaccurate assessment of blocked content, and that attempts to take action with sensitive content on social media led to the most concrete threats with the least available technical defenses. Based on these findings and in direct response to these problems, we make recommendations for shifting objectives in anti-censorship work, as well as for technical directions and future research to address users' on-the-ground needs. Genevieve Gebhart, Tadayoshi Kohno |
EuroS&P | 2 |
| 2017 | Securing Augmented Reality OutputabstractAugmented reality (AR) technologies, such as Microsoft's HoloLens head-mounted display and AR-enabled car windshields, are rapidly emerging. AR applications provide users with immersive virtual experiences by capturing input from a user's surroundings and overlaying virtual output on the user's perception of the real world. These applications enable users to interact with and perceive virtual content in fundamentally new ways. However, the immersive nature of AR applications raises serious security and privacy concerns. Prior work has focused primarily on input privacy risks stemming from applications with unrestricted access to sensor data. However, the risks associated with malicious or buggy AR output remain largely unexplored. For example, an AR windshield application could intentionally or accidentally obscure oncoming vehicles or safety-critical output of other AR applications. In this work, we address the fundamental challenge of securing AR output in the face of malicious or buggy applications. We design, prototype, and evaluate Arya, an AR platform that controls application output according to policies specified in a constrained yet expressive policy framework. In doing so, we identify and overcome numerous challenges in securing AR output. Kiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska Roesner |
IEEE Symposium on Security and Privacy | 3 |
| 2017 | Computer Security, Privacy, and DNA Sequencing: Compromising Computers with Synthesized DNA, Privacy Leaks, and More
Peter Ney, Karl Koscher, Lee Organick, Luis Ceze, Tadayoshi Kohno |
USENIX Security Symposium | 5 |
| 2017 | How Public Is My Private Life?: Privacy in Online DatingabstractOnline dating services let users expand their dating pool beyond their social network and specify important characteristics of potential partners. To assess compatibility, users share personal information -- e.g., identifying details or sensitive opinions about sexual preferences or worldviews -- in profiles or in one-on-one communication. Thus, participating in online dating poses inherent privacy risks. How people reason about these privacy risks in modern online dating ecosystems has not been extensively studied. We present the results of a survey we designed to examine privacy-related risks, practices, and expectations of people who use or have used online dating, then delve deeper using semi-structured interviews. We additionally analyzed 400 Tinder profiles to explore how these issues manifest in practice. Our results reveal tensions between privacy and competing user values and goals, and we demonstrate how these results can inform future designs. Camille Cobb, Tadayoshi Kohno |
WWW | 2 |
| 2017 | SeaGlass: Enabling City-Wide IMSI-Catcher DetectionabstractAbstract Cell-site simulators, also known as IMSI-catchers and stingrays, are used around the world by governments and criminals to track and eavesdrop on cell phones. Despite extensive public debate surrounding their use, few hard facts about them are available. For example, the richest sources of information on U.S. government cell-site simulator usage are from anonymous leaks, public records requests, and court proceedings. This lack of concrete information and the difficulty of independently obtaining such information hampers the public discussion. To address this deficiency, we build, deploy, and evaluate SeaGlass, a city-wide cellsite simulator detection network. SeaGlass consists of sensors that measure and upload data on the cellular environment to find the signatures of portable cell-site simulators. SeaGlass sensors are designed to be robust, low-maintenance, and deployable in vehicles for long durations. The data they generate is used to learn a city’s network properties to find anomalies consistent with cell-site simulators. We installed SeaGlass sensors into 15 ridesharing vehicles across two cities, collecting two months of data in each city. Using this data, we evaluate the system and show how SeaGlass can be used to detect signatures of portable cell-site simulators. Finally, we evaluate our signature detection methods and discuss anomalies discovered in the data. Peter Ney, Ian Smith, Gabriel Cadamuro, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 4 |
| 2016 | MyTime: Designing and Evaluating an Intervention for Smartphone Non-UseabstractThough many people report an interest in self-limiting certain aspects of their phone use, challenges adhering to self-defined limits are common. We conducted a design exercise and online survey to map the design space of interventions for smartphone non-use and distilled these into a small taxonomy of intervention categories. Using these findings, we implemented "MyTime," an intervention to support people in achieving goals related to smartphone non-use. We conducted a deployment study with 23 participants over two weeks and found that participants reduced their time with the apps they feel are a poor use of time by 21% while their use of the apps they feel are a good use of time remained unchanged. We found that a small taxonomy describes users' diverse set of desired behavior changes relating to smartphone non-use, and that these desired changes predict: 1) the hypothetical features they are interested in trying, 2) the extent to which they engage with these features in practice, and 3) their changes in behavior in response to the intervention. We link users' desired behaviors to the categories of our design taxonomy, providing a foundation for a theoretical model of designing for smartphone non-use. Alexis Hiniker, Sungsoo Ray Hong, Tadayoshi Kohno, Julie A. Kientz |
CHI | 3 |
| 2016 | Why would you do that? predicting the uses and gratifications behind smartphone-usage behaviorsabstractWhile people often use smartphones to achieve specific goals, at other times they use them out of habit or to pass the time. Uses and Gratifications Theory explains that users' motivations for engaging with technology can be divided into instrumental and ritualistic purposes. Instrumental uses of technology are goal-directed and purposeful, while ritualistic uses are habitual and diversionary. In this paper, we provide an empirical account of the nature of instrumental vs. ritualistic use of smartphones based on data collected from 43 Android users over 2 weeks through logging application use and collecting ESM survey data about the purpose of use. We describe the phone-use behaviors users exhibit when seeking instrumental and ritualistic gratifications, and we develop a classification scheme for predicting ritualistic vs. instrumental use with an accuracy of 77% for a general model, increasing to more than 97% with a sliding confidence threshold. We discuss how such a model might be used to improve the experience of smartphone users in application areas such as recommender systems and social media. Alexis Hiniker, Shwetak N. Patel, Tadayoshi Kohno, Julie A. Kientz |
UbiComp | 3 |
| 2016 | Computer Security for Data Collection TechnologiesabstractMany organizations in the developing world (e.g., NGOs), include digital data collection in their workflow. Data collected can include information that may be considered sensitive, such as medical or socioeconomic data, and which could be affected by computer security attacks or unintentional mishandling. The attitudes and practices of organizations collecting data have implications for confidentiality, availability, and integrity of data. This work, a collaboration between computer security and ICTD researchers, explores security and privacy attitudes, practices, and needs within organizations that use Open Data Kit (ODK), a prominent digital data collection platform. We conduct a detailed threat modeling exercise to inform our view on potential security threats, and then conduct and analyze a survey and interviews with technology experts in these organizations to ground this analysis in real deployment experiences. We then reflect upon our results, drawing lessons for both organizations collecting data and for tool developers. Camille Cobb, Samuel Sudar, Nicholas Reiter, Richard J. Anderson 0001, Franziska Roesner, Tadayoshi Kohno |
ICTD | 6 |
| 2016 | Satellite: Joint Analysis of CDNs and Network-Level Interference
Will Scott, Thomas E. Anderson, Tadayoshi Kohno, Arvind Krishnamurthy |
USENIX ATC | 3 |
| 2016 | Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016
Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska Roesner |
USENIX Security Symposium | 3 |
| 2016 | Automobile Driver FingerprintingabstractAbstract Today’s automobiles leverage powerful sensors and embedded computers to optimize efficiency, safety, and driver engagement. However the complexity of possible inferences using in-car sensor data is not well understood. While we do not know of attempts by automotive manufacturers or makers of after-market components (like insurance dongles) to violate privacy, a key question we ask is: could they (or their collection and later accidental leaks of data) violate a driver’s privacy? In the present study, we experimentally investigate the potential to identify individuals using sensor data snippets of their natural driving behavior. More specifically we record the in-vehicle sensor data on the controllerarea- network (CAN) of a typical modern vehicle (popular 2009 sedan) as each of 15 participants (a) performed a series of maneuvers in an isolated parking lot, and (b) drove the vehicle in traffic along a defined ~ 50 mile loop through the Seattle metropolitan area. We then split the data into training and testing sets, train an ensemble of classifiers, and evaluate identification accuracy of test data queries by looking at the highest voted candidate when considering all possible one-vs-one comparisons. Our results indicate that, at least among small sets, drivers are indeed distinguishable using only incar sensors. In particular, we find that it is possible to differentiate our 15 drivers with 100% accuracy when training with all of the available sensors using 90% of driving data from each person. Furthermore, it is possible to reach high identification rates using less than 8 minutes of training data. When more training data is available it is possible to reach very high identification using only a single sensor (e.g., the brake pedal). As an extension, we also demonstrate the feasibility of performing driver identification across multiple days of data collection Miro Enev, Alex Takakuwa, Karl Koscher, Tadayoshi Kohno |
Proc. Priv. Enhancing Technol. | 4 |
| 2015 | Analyzing the Use of Quick Response Codes in the WildabstractOne- and two-dimensional barcodes, including Quick Response (QR) codes, have become a convenient way to communicate small amounts of information from physical objects to mobile devices. While there is much discussion, awareness, and proposed use of such barcodes, both in aca-demia and in industry, to our knowledge there has not been a systematic and in-depth analysis of the actual ecosystem surrounding these codes. To fill this gap, we analyze a log of all scans performed by users of a popular QR and barcode scanning app available for Android, iPhone, and Windows Phone. Our dataset includes over 87 million scans performed over a 10-month period from May 2013 to March 2014. We examine general use patterns of QR and barcodes in the wild and identify common and uncommon uses and misuses. We see the presence of both conventional (e.g., web) and emerging (e.g., Bitcoin) uses of QR codes, and develop an informed understanding of the types of QR codes being created and how users interact with QR and barcodes in the wild. Ada Lerner, Alisha Saxena, Kirk Ouimet, Ben Turley, Anthony Vance, Tadayoshi Kohno, Franziska Roesner |
MobiSys | 6 |
| 2015 | Securing RFIDs by Randomizing the Modulation and Channel
Haitham Hassanieh, Jue Wang 0012, Dina Katabi, Tadayoshi Kohno |
NSDI | 4 |
| 2014 | Polymorphism as a Defense for Automated Attack of Websites
Tadayoshi Kohno, Bob Blakley 0001 |
ACNS | 2 |
| 2014 | CPS: beyond usability: applying value sensitive design based methods to investigate domain characteristics for security for implantable cardiac devicesabstractWireless implantable medical devices (IMDs) are cyber-physical systems that deliver life-saving treatments to cardiac patients with dangerous heart conditions. Current access control models for these systems are insufficient; more security is necessary. In response to this problem, the technical security community has investigated new directions for improving security on these resource-constrained devices. Defenses, however, must not only be technically secure; in order to be deployable, defenses must be designed to work within the needs and constraints of their relevant application spaces. Designing for an application space---particularly a specialized one---requires a deep understanding of the stakeholders, their values, and the contexts of technology usage. Grounding our work in value sensitive design (VSD), we collaborated as an interdisciplinary team to conduct three workshops with medical providers for the purpose of gathering their values and perspectives. The structure of our workshop builds on known workshop structures within the human-computer interaction (HCI) community, and the number of participants in our workshops (N=24) is compatible with current practices for inductive, exploratory studies. We present results on: what the participants find important with respect to providing care and performing their jobs; their reactions to potential security system concepts; and their views on what security system properties should be sought or avoided due to side effects within the context of their work practice. We synthesize these results, use the results to articulate design considerations for future technical security systems, and suggest directions for further research. Our research not only provides a contribution to security research for an important class of cyber-physical systems (IMDs); it also provides an example of leveraging techniques from other communities to better explore the landscape of security designs for technologies. Tamara Denning, Daniel B. Kramer, Batya Friedman, Matthew R. Reynolds, Brian T. Gill, Tadayoshi Kohno |
ACSAC | 6 |
| 2014 | World-Driven Access Control for Continuous SensingabstractModern applications increasingly rely on continuous monitoring of video, audio, or other sensor data to provide their functionality, particularly in platforms such as the Microsoft Kinect and Google Glass. Continuous sensing by untrusted applications poses significant privacy challenges for both device users and bystanders. Even honest users will struggle to manage application permissions using existing approaches. Franziska Roesner, David Molnar, Alexander Moshchuk, Tadayoshi Kohno, Helen J. Wang |
CCS | 4 |
| 2014 | In situ with bystanders of augmented reality glasses: perspectives on recording and privacy-mediating technologiesabstractAugmented reality (AR) devices are poised to enter the market. It is unclear how the properties of these devices will affect individuals' privacy. In this study, we investigate the privacy perspectives of individuals when they are bystanders around AR devices. We conducted 12 field sessions in cafés and interviewed 31 bystanders regarding their reactions to a co-located AR device. Participants were predominantly split between having indifferent and negative reactions to the device. Participants who expressed that AR devices change the bystander experience attributed this difference to subtleness, ease of recording, and the technology's lack of prevalence. Additionally, participants surfaced a variety of factors that make recording more or less acceptable, including what they are doing when the recording is being taken. Participants expressed interest in being asked permission before being recorded and in recording-blocking devices. We use the interview results to guide an exploration of design directions for privacy-mediating technologies. Tamara Denning, Zakariya Dehlawi, Tadayoshi Kohno |
CHI | 3 |
| 2013 | Control-Alt-Hack: the design and evaluation of a card game for computer security awareness and educationabstractWe scoped, designed, produced, and evaluated the effectiveness of a recreational tabletop card game created to raise awareness of and alter perceptions regarding-computer security. We discuss our process, the challenges that arose, and the decisions we made to address those challenges. As of May 2013, we have shipped approximately 800 free copies to 150 educators. We analyze and report on feedback from 22 of these educators about their experiences using Control-Alt-Hack with over 450 students in classroom and non-classroom contexts. The responses from the 14 educators who reported on their use of the game in a classroom context variously indicated that: their students' awareness of computer security as a complex and interesting field was increased (11/14); they would use the game again in their classroom (10/14); and they would recommend the game to others (13/14). Of note, 2 of the 14 classroom educators reported that they would not have otherwise covered the material. Additionally, we present results from user studies with 11 individuals and find that their responses indicate that 8 of the 11 had an increased awareness of computer security or a changed perception; furthermore, all of our intended goals are touched upon in their responses. Tamara Denning, Ada Lerner, Adam Shostack, Tadayoshi Kohno |
CCS | 4 |
| 2013 | Operating System Support for Augmented Reality Applications
Loris D'Antoni, Alan M. Dunn, Suman Jana, Tadayoshi Kohno, Benjamin Livshits, David Molnar, Alexander Moshchuk, Eyal Ofek, Franziska Roesner, T. Scott Saponas, Margus Veanes, Helen J. Wang |
HotOS | 4 |
| 2013 | Control-Alt-Hack™: a card game for computer security outreach and education (abstract only)abstractIn this poster, we present Control-Alt-Hack": White Hat Hacking for Fun and Profit--a card game for computer security outreach and education. A general lack of awareness about computer security contributes to the insecurity of new consumer technologies. We seek to increase people's prioritization of computer security and their understanding of the variety of attacks and technologies that can be vulnerable to compromise. We work towards this goal via a recreational tabletop card game where people play as white hat hackers, using their characters' skills to perform a variety of hacking Missions. We licensed a game mechanic from a hobbyist game company, worked with graphic designers and illustrators, and rewrote card text to make the game about working as a computer security professional. Visit www.controlalthack.com for supplementary educational materials and to request free educator copies. Tamara Denning, Tadayoshi Kohno, Adam Shostack |
SIGCSE | 2 |
| 2013 | Securing Embedded User Interfaces: Android and Beyond
Franziska Roesner, Tadayoshi Kohno |
USENIX Security Symposium | 2 |
| 2013 | Lightweight server support for browser-based CSRF protectionabstractCross-Site Request Forgery (CSRF) attacks are one of the top threats on the web today. These attacks exploit ambient authority in browsers (eg cookies, HTTP authentication state), turning them into confused deputies and causing undesired side effects on vulnerable web sites. Existing defenses against CSRFs fall short in their coverage and/or ease of deployment. In this paper, we present a browser/server solution, Allowed Referrer Lists (ARLs), that addresses the root cause of CSRFs and removes ambient authority for participating web sites that want to be resilient to CSRF attacks. Our solution is easy for web sites to adopt and does not affect any functionality on non-participating sites. We have implemented our design in Firefox and have evaluated it with real-world sites. We found that ARLs successfully block CSRF attacks, are simpler to implement than existing defenses, and do not significantly impact browser performance. Alexei Czeskis, Alexander Moshchuk, Tadayoshi Kohno, Helen J. Wang |
WWW | 3 |
| 2012 | SensorSift: balancing sensor data privacy and utility in automated face understandingabstractWe introduce SensorSift, a new theoretical scheme for balancing utility and privacy in smart sensor applications. At the heart of our contribution is an algorithm which transforms raw sensor data into a 'sifted' representation which minimizes exposure of user defined private attributes while maximally exposing application-requested public attributes. We envision multiple applications using the same platform, and requesting access to public attributes explicitly not known at the time of the platform creation. Support for future-defined public attributes, while still preserving the defined privacy of the private attributes, is a central challenge that we tackle. Miro Enev, Jaeyeon Jung, Liefeng Bo, Xiaofeng Ren, Tadayoshi Kohno |
ACSAC | 5 |
| 2012 | Strengthening user authentication through opportunistic cryptographic identity assertionsabstractUser authentication systems are at an impasse. The most ubiquitous method -- the password -- has numerous problems, including susceptibility to unintentional exposure via phishing and cross-site password reuse. Second-factor authentication schemes have the potential to increase security but face usability and deployability challenges. For example, conventional second-factor schemes change the user authentication experience. Furthermore, while more secure than passwords, second-factor schemes still fail to provide sufficient protection against (single-use) phishing attacks. Alexei Czeskis, Michael Dietz, Tadayoshi Kohno, Dan S. Wallach, Dirk Balfanz |
CCS | 3 |
| 2012 | Detecting and Defending Against Third-Party Tracking on the Web
Franziska Roesner, Tadayoshi Kohno, David Wetherall |
NSDI | 2 |
| 2012 | User-Driven Access Control: Rethinking Permission Granting in Modern Operating SystemsabstractModern client platforms, such as iOS, Android, Windows Phone, Windows 8, and web browsers, run each application in an isolated environment with limited privileges. A pressing open problem in such systems is how to allow users to grant applications access to user-owned resources, e.g., to privacy- and cost-sensitive devices like the camera or to user data residing in other applications. A key challenge is to enable such access in a way that is non-disruptive to users while still maintaining least-privilege restrictions on applications. In this paper, we take the approach of user-driven access control, whereby permission granting is built into existing user actions in the context of an application, rather than added as an afterthought via manifests or system prompts. To allow the system to precisely capture permission-granting intent in an application's context, we introduce access control gadgets (ACGs). Each user-owned resource exposes ACGs for applications to embed. The user's authentic UI interactions with an ACG grant the application permission to access the corresponding resource. Our prototyping and evaluation experience indicates that user-driven access control is a promising direction for enabling in-context, non-disruptive, and least-privilege permission granting on modern client platforms. Franziska Roesner, Tadayoshi Kohno, Alexander Moshchuk, Bryan Parno, Helen J. Wang, Crispin Cowan |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | User interface toolkit mechanisms for securing interface elementsabstractUser interface toolkit research has traditionally assumed that developers have full control of an interface. This assumption is challenged by the mashup nature of many modern interfaces, in which different portions of a single interface are implemented by multiple, potentially mutually distrusting developers (e.g., an Android application embedding a third-party advertisement). We propose considering security as a primary goal for user interface toolkits. We motivate the need for security at this level by examining today's mashup scenarios, in which security and interface flexibility are not simultaneously achieved. We describe a security-aware user interface toolkit architecture that secures interface elements while providing developers with the flexibility and expressivity traditionally desired in a user interface toolkit. By challenging trust assumptions inherent in existing approaches, this architecture effectively addresses important interface-level security concerns. Franziska Roesner, James Fogarty, Tadayoshi Kohno |
UIST | 3 |
| 2012 | Security for cyber-physical systems: case studies with medical devices, robots, and automobilesabstractToday's and tomorrow's emerging technologies and cyber-physical systems have the potential to greatly improve the quality of our lives. Without the appropriate checks and balances, however, these emerging technologies also have the potential to compromise our digital and physical security and privacy. This talk will explore three case studies in the design and analysis of secure cyber-physical systems: wireless medical devices, robots, and automobiles. We will discuss the discovery of vulnerabilities in leading examples of these technologies, the challenges to securing these technologies and the ecosystem leading to their vulnerabilities, and new directions for security. Tadayoshi Kohno |
WISEC | 1 |
| 2011 | Televisions, video privacy, and powerline electromagnetic interferenceabstractWe conduct an extensive study of information leakage over the powerline infrastructure from eight televisions (TVs) spanning multiple makes, models, and underlying technologies. In addition to being of scientific interest, our findings contribute to the overall debate of whether or not measurements of residential powerlines reveal significant information about the activities within a home. We find that the power supplies of modern TVs produce discernible electromagnetic interference (EMI) signatures that are indicative of the video content being displayed. We measure the stability of these signatures over time and across multiple instances of the same TV model, as well as the robustness of these signatures in the presence of other noisy electronic devices connected to the same powerline. Miro Enev, Sidhant Gupta, Tadayoshi Kohno, Shwetak N. Patel |
CCS | 3 |
| 2011 | Keypad: an auditing file system for theft-prone devicesabstractThis paper presents Keypad, an auditing file system for theft-prone devices, such as laptops and USB sticks. Keypad provides two important properties. First, Keypad supports fine-grained file auditing: a user can obtain explicit evidence that no files have been accessed after a device's loss. Second, a user can disable future file access after a device's loss, even in the absence of device network connectivity. Keypad achieves these properties by weaving together encryption and remote key storage. By encrypting files locally but storing encryption keys remotely, Keypad requires the involvement of an audit server with every protected file access. By alerting the audit server to refuse to return a particular file's key, the user can prevent new accesses after theft. Roxana Geambasu, John P. John, Steve D. Gribble, Tadayoshi Kohno, Henry M. Levy |
EuroSys | 4 |
| 2011 | Science fiction prototyping and security education: cultivating contextual and societal thinking in computer security education and beyondabstractComputer security courses typically cover a breadth of technical topics, including threat modeling, applied cryptography, software security, and Web security. The technical artifacts of computer systems - and their associated computer security risks and defenses - do not exist in isolation, however; rather, these systems interact intimately with the needs, beliefs, and values of people. This is especially true as computers become more pervasive, embedding themselves not only into laptops, desktops, and the Web, but also into our cars, medical devices, and toys. Therefore, in addition to the standard technical material, we argue that students would benefit from developing a mindset focused on the broader societal and contextual issues surrounding computer security systems and risks. We used science fiction (SF) prototyping to facilitate such societal and contextual thinking in a recent undergraduate computer security course. We report on our approach and experiences here, as well as our recommendations for future computer security and other computer science courses. Tadayoshi Kohno, Brian David Johnson |
SIGCSE | 1 |
| 2011 | Comprehensive Experimental Analyses of Automotive Attack Surfaces
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno |
USENIX Security Symposium | 10 |
| 2010 | Patients, pacemakers, and implantable defibrillators: human values and security for wireless implantable medical devicesabstractImplantable medical devices (IMDs) improve patients' quality of life and help sustain their lives. In this study, we explore patient views and values regarding their devices to inform the design of computer security for wireless IMDs. We interviewed 13 individuals with implanted cardiac devices. Key questions concerned the evaluation of 8 mockups of IMD security systems. Our results suggest that some systems that are technically viable are nonetheless undesirable to patients. Patients called out a number of values that affected their attitudes towards the systems, including perceived security, safety, freedom from unwanted cultural and historical associations, and self-image. In our analysis, we extend the Value Sensitive Design value dams and flows technique in order to suggest multiple, complementary systems; in our discussion, we highlight some of the usability, regulatory, and economic complexities that arise from offering multiple options. We conclude by offering design guidelines for future security systems for IMDs. Tamara Denning, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno, William H. Maisel |
CHI | 5 |
| 2010 | Seeing through Obscure Glass
Qi Shan, Brian Curless, Tadayoshi Kohno |
ECCV (6) | 3 |
| 2010 | Comet: An active distributed key-value store
Roxana Geambasu, Amit Levy 0001, Tadayoshi Kohno, Arvind Krishnamurthy, Henry M. Levy |
OSDI | 3 |
| 2010 | Parenting from the pocket: value tensions and technical directions for secure and private parent-teen mobile safetyabstractAn increasing number of high-tech devices, such as driver monitoring systems and Internet usage monitoring tools, are advertised as useful or even necessary for good parenting of teens. Simultaneously, there is a growing market for mobile personal safety devices. As these trends merge, there will be significant implications for parent-teen relationships, affecting domains such as privacy, trust, and maturation. Not only the teen and his or her parents are affected; other important stakeholders include the teen's friends who may be unwittingly monitored. This problem space, with less clear-cut assets, risks, and affected parties, thus lies well outside of more typical computer security applications.To help understand this problem domain and what, if anything, should be built, we turn to the theory and methods of Value Sensitive Design, a systematic approach to designing for human values in technology. We first develop value scenarios that highlight potential issues, benefits, harms, and challenges. We then conducted semi-structured interviews with 18 participants (9 teens and their parents). Results show significant differences with respect to information about: 1) internal state (e.g., mood) versus external environment (e.g., location) state; 2) situation (e.g., emergency vs. non-emergency); and 3) awareness (e.g., notification vs. non-notification). The value scenario and interview results positioned us to identify key technical challenges -- such as strongly protecting the privacy of a teen's contextual information during ordinary situations but immediately exposing that information to others as appropriate in an emergency -- and corresponding architectural levers for these technologies.In addition to laying a foundation for future work in this area, this research serves as a prototypical example of using Value Sensitive Design to explicate the underlying human values in complex security domains. Alexei Czeskis, Ivayla Dermendjieva, Hussein Yapit, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno |
SOUPS | 7 |
| 2010 | Experimental Security Analysis of a Modern AutomobileabstractModern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks. In this paper we experimentally evaluate these issues on a modern automobile and demonstrate the fragility of the underlying system structure. We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input\dash including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car's two internal subnets. We also present composite attacks that leverage individual weaknesses, including an attack that embeds malicious code in a car's telematics unit and that will completely erase any evidence of its presence after a crash. Looking forward, we discuss the complex challenges in addressing these vulnerabilities while considering the existing automotive ecosystem. Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage |
IEEE Symposium on Security and Privacy | 5 |
| 2009 | EPC RFID tag security weaknesses and defenses: passport cards, enhanced drivers licenses, and beyondabstractEPC (Electronic Product Code) tags are industry-standard RFID devices poised to supplant optical barcodes in many applications. We explore the systemic risks and challenges created by the increasingly common use of EPC for security applications. As a central case study, we examine the recently issued United States Passport Card and Washington State "enhanced drivers license" (WA EDL), both of which incorporate Gen-2 EPC tags. We measure multiple weaknesses, including susceptibility to cloning, extended read ranges, and the ability to remotely kill a WA EDL. We study the implications of these vulnerabilities to overall system security, and offer suggestions for improvement. We demonstrate anti-cloning techniques for off-the-shelf EPC tags, overcoming practical challenges in a previous proposal to co-opt the EPC "kill" command to achieve tag authentication. Our paper fills a vacuum of experimentally grounded evaluation of and guidance for security applications for EPC tags not just in identity documents, but more broadly in the authentication of objects and people. Karl Koscher, Ari Juels, Vjekoslav Brajkovic, Tadayoshi Kohno |
CCS | 4 |
| 2009 | A comprehensive study of frequency, interference, and training of multiple graphical passwordsabstractGraphical password systems have received significant attention as one potential solution to the need for more usable authentication, but nearly all prior work makes the unrealistic assumption of studying a single password. This paper presents the first study of multiple graphical passwords to systematically examine frequency of access to a graphical password, interference resulting from interleaving access to multiple graphical passwords, and patterns of access while training multiple graphical passwords. We find that all of these factors significantly impact the ease of authenticating using multiple facial graphical passwords. For example, participants who accessed four different graphical passwords per week were ten times more likely to completely fail to authenticate than participants who accessed a single password once per week. Our results underscore the need for more realistic evaluations of the use of multiple graphical passwords, have a number of implications for the adoption of graphical password systems, and provide a new basis for comparing proposed graphical password systems. Katherine Everitt, Tanya Bragin, James Fogarty, Tadayoshi Kohno |
CHI | 4 |
| 2009 | A spotlight on security and privacy risks with future household robots: attacks and lessonsabstractFuture homes will be populated with large numbers of robots with diverse functionalities, ranging from chore robots to elder care robots to entertainment robots. While household robots will offer numerous benefits, they also have the potential to introduce new security and privacy vulnerabilities into the home. Our research consists of three parts. First, to serve as a foundation for our study, we experimentally analyze three of today's household robots for security and privacy vulnerabilities: the WowWee Rovio, the Erector Spykee, and the WowWee RoboSapien V2. Second, we synthesize the results of our experimental analyses and identify key lessons and challenges for securing future household robots. Finally, we use our experiments and lessons learned to construct a set of design questions aimed at facilitating the future development of household robots that are secure and preserve their users' privacy. Tamara Denning, Cynthia Matuszek, Karl Koscher, Joshua R. Smith 0001, Tadayoshi Kohno |
UbiComp | 5 |
| 2009 | Enlisting ISPs to Improve Online Privacy: IP Address Mixing by Default
Barath Raghavan, Tadayoshi Kohno, Alex C. Snoeren, David Wetherall |
Privacy Enhancing Technologies | 2 |
| 2009 | Vanish: Increasing Data Privacy with Self-Destructing Data
Roxana Geambasu, Tadayoshi Kohno, Amit Levy 0001, Henry M. Levy |
USENIX Security Symposium | 2 |
| 2008 | RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communicationsabstractWe tackle the problem of defending against ghost-and-leech (a.k.a. proxying, relay, or man-in-the-middle) attacks against RFID tags and other contactless cards. The approach we take -- which we dub secret handshakes -- is to incorporate gesture recognition techniques directly on the RFID tags or contactless cards. These cards will only engage in wireless communications when they internally detect these secret handshakes. We demonstrate the effectiveness of this approach by implementing our secret handshake recognition system on a passive WISP RFID tag with a built-in accelerometer. Our secret handshakes approach is backward compatible with existing deployments of RFID tag and contactless card readers. Alexei Czeskis, Karl Koscher, Joshua R. Smith 0001, Tadayoshi Kohno |
CCS | 4 |
| 2008 | Privacy oracle: a system for finding application leaks with black box differential testingabstractWe describe the design and implementation of Privacy Oracle, a system that reports on application leaks of user information via the network traffic that they send. Privacy Oracle treats each application as a black box, without access to either its internal structure or communication protocols. This means that it can be used over a broad range of applications and information leaks (i.e., not only Web traffic or credit card numbers). To accomplish this, we develop a differential testing technique in which perturbations in the application inputs are mapped to perturbations in the application outputs to discover likely leaks; we leverage alignment algorithms from computational biology to find high quality mappings between different byte-sequences efficiently. Privacy Oracle includes this technique and a virtual machine-based testing system. To evaluate it, we tested 26 popular applications, including system and file utilities, media players, and IM clients. We found that Privacy Oracle discovered many small and previously undisclosed information leaks. In several cases, these are leaks of directly identifying information that are regularly sent in the clear (without end-to-end encryption) and which could make users vulnerable to tracking by third parties or providers. Jaeyeon Jung, Anmol Sheth, Ben Greenstein, David Wetherall, Gabriel Maganis, Tadayoshi Kohno |
CCS | 6 |
| 2008 | Improving wireless privacy with an identifier-free link layer protocolabstractWe present the design and evaluation of an 802.11-like wireless link layer protocol that obfuscates all transmitted bits to increase privacy. This includes explicit identifiers such as MAC addresses, the contents of management messages, and other protocol fields that the existing 802.11 protocol relies on to be sent in the clear. By obscuring these fields, we greatly increase the difficulty of identifying or profiling users from their transmissions in ways that are otherwise straightforward. Our design, called SlyFi, is nearly as efficient as existing schemes such as WPA for discovery, link setup, and data delivery despite its heightened protections; transmission requires only symmetric key encryption and reception requires a table lookup followed by symmetric key decryption. Experiments using our implementation on Atheros 802.11 drivers show that SlyFi can discover and associate with networks faster than 802.11 using WPA-PSK. The overhead SlyFi introduces in packet delivery is only slightly higher than that added by WPA-CCMP encryption (10% vs. 3% decrease in throughput). Ben Greenstein, Damon McCoy, Jeffrey Pang, Tadayoshi Kohno, Srinivasan Seshan, David Wetherall |
MobiSys | 4 |
| 2008 | Detecting In-Flight Page Changes with Web Tripwires
Charles Reis, Steve D. Gribble, Tadayoshi Kohno, Nicholas C. Weaver |
NSDI | 3 |
| 2008 | Shining Light in Dark Places: Understanding the Tor Network
Damon McCoy, Kevin S. Bauer, Dirk Grunwald, Tadayoshi Kohno, Douglas C. Sicker |
Privacy Enhancing Technologies | 4 |
| 2008 | Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power DefensesabstractOur study analyzes the security and privacy properties of an implantable cardioverter defibrillator (ICD). Introduced to the U.S. market in 2003, this model of ICD includes pacemaker technology and is designed to communicate wirelessly with a nearby external programmer in the 175 kHz frequency range. After partially reverse-engineering the ICD's communications protocol with an oscilloscope and a software radio, we implemented several software radio-based attacks that could compromise patient safety and patient privacy. Motivated by our desire to improve patient safety, and mindful of conventional trade-offs between security and power consumption for resource-constrained devices, we introduce three new zero-power defenses based on RF power harvesting. Two of these defenses are human-centric, bringing patients into the loop with respect to the security and privacy of their implantable medical devices (IMDs). Our contributions provide a scientific baseline for understanding the potential security and privacy risks of current and future IMDs, and introduce human-perceptible and zero-power mitigation techniques that address those risks. To the best of our knowledge, this paper is the first in our community to use general-purpose software radios to analyze and attack previously unknown radio communications protocols. Daniel Halperin, Thomas S. Benjamin, Benjamin Ransford, Shane S. Clark, Benessa Defend, Will Morgan, Kevin Fu, Tadayoshi Kohno, William H. Maisel |
SP | 8 |
| 2008 | Defeating Encrypted and Deniable File Systems: TrueCrypt v5.1a and the Case of the Tattling OS and Applications
Alexei Czeskis, David J. St. Hilaire, Karl Koscher, Steve D. Gribble, Tadayoshi Kohno, Bruce Schneier |
HotSec | 5 |
| 2008 | Absence Makes the Heart Grow Fonder: New Directions for Implantable Medical Device Security
Tamara Denning, Kevin Fu, Tadayoshi Kohno |
HotSec | 3 |
| 2008 | Challenges and Directions for Monitoring P2P File Sharing Networks - or - Why My Printer Received a DMCA Takedown Notice
Michael Piatek, Tadayoshi Kohno, Arvind Krishnamurthy |
HotSec | 2 |
| 2008 | Privacy-Preserving Location Tracking of Lost or Stolen Devices: Cryptographic Techniques and Replacing Trusted Third Parties with DHTs
Thomas Ristenpart, Gabriel Maganis, Arvind Krishnamurthy, Tadayoshi Kohno |
USENIX Security Symposium | 4 |
| 2008 | Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi |
J. Cryptol. | 5 |
| 2007 | Can Ferris Bueller Still Have His Day Off? Protecting Privacy in the Wireless Era
Ben Greenstein, Ramakrishna Gummadi, Jeffrey Pang, Mike Y. Chen, Tadayoshi Kohno, Srinivasan Seshan, David Wetherall |
HotOS | 5 |
| 2007 | Devices That Tell on You: Privacy Trends in Consumer Ubiquitous Computing
T. Scott Saponas, Jonathan Lester, Carl Hartung, Sameer Agarwal 0001, Tadayoshi Kohno |
USENIX Security Symposium | 5 |
| 2006 | Stateful public-key cryptosystems: how to encrypt with one 160-bit exponentiationabstractWe show how to significantly speed-up the encryption portion of some public-key cryptosystems by the simple expedient of allowing a sender to maintain state that is re-used across different encryptions.In particular we present stateful versions of the DHIES and Kurosawa-Desmedt schemes that each use only 1 exponentiation to encrypt, as opposed to 2 and 3 respectively in the original schemes, yielding the fastest discrete-log based public-key encryption schemes known in the random-oracle and standard models respectively. The schemes are proven to meet an appropriate extension of the standard definition of IND-CCA security that takes into account novel types of attacks possible in the stateful setting. Mihir Bellare, Tadayoshi Kohno, Victor Shoup |
CCS | 2 |
| 2006 | Herding Hash Functions and the Nostradamus Attack
John Kelsey, Tadayoshi Kohno |
EUROCRYPT | 2 |
| 2006 | Tamper-Evident, History-Independent, Subliminal-Free Data Structures on PROM Storage-or-How to Store Ballots on a Voting Machine (Extended Abstract)abstractWe enumerate requirements and give constructions for the vote storage unit of an electronic voting machine. In this application, the record of votes must survive even an unexpected failure of the machine; hence the data structure should be durable. At the same time, the order in which votes are cast must be hidden to protect the privacy of voters, so the data structure should be history-independent. Adversaries may try to surreptitiously add or delete votes from the storage unit after the election has concluded, so the storage should be tamper-evident. Finally, we must guard against an adversarial voting machine's attempts to mark ballots through the representation of the data structure, so we desire a subliminal-free representation. We leverage the properties of Programmable Read Only Memory (PROM), a special kind of write-once storage medium, to meet these requirements. We give constructions for data structures on PROM storage that simultaneously satisfy all our desired properties. Our techniques can significantly reduce the need to verify code running on a voting machine. David Molnar, Tadayoshi Kohno, Naveen Sastry, David A. Wagner 0001 |
S&P | 2 |
| 2005 | Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions
Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange 0001, John Malone-Lee, Gregory Neven, Pascal Paillier, Haixia Shi |
CRYPTO | 5 |
| 2005 | Remote Physical Device FingerprintingabstractWe introduce the area of remote physical device fingerprinting, or fingerprinting a physical device, as opposed to an operating system or class of devices, remotely, and without the fingerprinted device's known cooperation. We accomplish this goal by exploiting small, microscopic deviations in device hardware: clock skews. Our techniques do not require any modification to the fingerprinted devices. Our techniques report consistent measurements when the measurer is thousands of miles, multiple hops, and tens of milliseconds away from the fingerprinted device, and when the fingerprinted device is connected to the Internet from different locations and via different access technologies. Further one can apply our passive and semi-passive techniques when the fingerprinted device is behind a NAT or firewall, and also when the device's system time is maintained via NTP or SNTP. One can use our techniques to obtain information about whether two devices an the Internet, possibly shifted in time or IP addresses, are actually the same physical device. Example applications include: computer forensics; tracking, with some probability, a physical device as it connects to the Internet from different public access points; counting the number of devices behind a NAT even when the devices use constant or random IP ID; remotely probing a block of addresses to determine if the addresses correspond to virtual hosts, e.g., as part of a virtual honeynet; and unanonymizing anonymized network traces. Tadayoshi Kohno, Andre Broido, K. C. Claffy |
S&P | 1 |
| 2005 | Remote Physical Device FingerprintinabstractWe introduce the area of remote physical device fingerprinting, or fingerprinting a physical device, as opposed to an operating system or class of devices, remotely, and without the fingerprinted device's known cooperation. We accomplish this goal by exploiting small, microscopic deviations in device hardware: clock skews. Our techniques do not require any modification to the fingerprinted devices. Our techniques report consistent measurements when the measurer is thousands of miles, multiple hops, and tens of milliseconds away from the fingerprinted device and when the fingerprinted device is connected to the Internet from different locations and via different access technologies. Further, one can apply our passive and semipassive techniques when the fingerprinted device is behind a NAT or firewall, and. also when the device's system time is maintained via NTP or SNTP. One can use our techniques to obtain information about whether two devices on the Internet, possibly shifted in time or IP addresses, are actually the same physical device. Example applications include: computer forensics; tracking, with some probability, a physical device as it connects to the Internet from different public access points; counting the number of devices behind a NAT even when the devices use constant or random IP IDs; remotely probing a block of addresses to determine if the addresses correspond to virtual hosts, e.g., as part of a virtual honeynet; and unanonymizing anonymized network traces. Tadayoshi Kohno, Andre Broido, K. C. Claffy |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2004 | Attacking and repairing the winZip encryption schemeabstractWinZip is a popular compression utility for Microsoft Windows computers, the latest version of which is advertised as having "easy-to-use AES encryption to protect your sensitive data." We exhibit several attacks against WinZip's new encryption method, dubbed "AE-2" or "Advanced Encryption, version two." We then discuss secure alternatives. Since at a high level the underlying WinZip encryption method appears secure (the core is exactly Encrypt-then-Authenticate using AES-CTR and HMAC-SHA1), and since one of our attacks was made possible because of the way that WinZip Computing, Inc. decided to fix a different security problem with its previous encryption method AE-1, our attacks further underscore the subtlety of designing cryptographically secure software. Tadayoshi Kohno |
CCS | 1 |
| 2004 | Hash Function Balance and Its Impact on Birthday Attacks
Mihir Bellare, Tadayoshi Kohno |
EUROCRYPT | 2 |
| 2004 | New Security Proofs for the 3GPP Confidentiality and Integrity Algorithms
Tetsu Iwata, Tadayoshi Kohno |
FSE | 2 |
| 2004 | CWC: A High-Performance Conventional Authenticated Encryption Mode
Tadayoshi Kohno, John Viega, Doug Whiting |
FSE | 1 |
| 2004 | Analysis of an Electronic Voting SystemabstractWith significant U.S. federal funds now available to replace outdated punch-card and mechanical voting systems, municipalities and states throughout the U.S. are adopting paperless electronic voting systems from a number of different vendors. We present a security analysis of the source code to one such machine used in a significant share of the market. Our analysis shows that this voting system is far below even the most minimal security standards applicable in other contexts. We identify several problems including unauthorized privilege escalation, incorrect use of cryptography, vulnerabilities to network threats, and poor software development processes. We show that voters, without any insider privileges, can cast unlimited votes without being detected by any mechanisms within the voting terminal software. Furthermore, we show that even the most serious of our outsider attacks could have been discovered and executed without access to the source code. In the face of such attacks, the usual worries about insider threats are not the only concerns; outsiders can do the damage. That said, we demonstrate that the insider threat is also quite considerable, showing that not only can an insider, such as a poll worker, modify the votes, but that insiders can also violate voter privacy and match votes with the voters who cast them. We conclude that this voting system is unsuitable for use in a general election. Any paperless electronic voting system might suffer similar flaws, despite any certification it could have otherwise received. We suggest that the best solutions are voting systems having a voter-verifiable audit trail, where a computerized voting system might print a paper ballot that can be read and verified by the voter. Tadayoshi Kohno, Adam Stubblefield, Aviel D. Rubin, Dan S. Wallach |
S&P | 1 |
| 2004 | Breaking and provably repairing the SSH authenticated encryption scheme: A case study of the Encode-then-Encrypt-and-MAC paradigmabstractThe secure shell (SSH) protocol is one of the most popular cryptographic protocols on the Internet. Unfortunately, the current SSH authenticated encryption mechanism is insecure. In this paper, we propose several fixes to the SSH protocol and, using techniques from modern cryptography, we prove that our modified versions of SSH meet strong new chosen-ciphertext privacy and integrity requirements. Furthermore, our proposed fixes will require relatively little modification to the SSH protocol and to SSH implementations. We believe that our new notions of privacy and integrity for encryption schemes with stateful decryption algorithms will be of independent interest. Mihir Bellare, Tadayoshi Kohno, Chanathip Namprempre |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2003 | A Theoretical Treatment of Related-Key Attacks: RKA-PRPs, RKA-PRFs, and Applications
Mihir Bellare, Tadayoshi Kohno |
EUROCRYPT | 2 |
| 2003 | Helix: Fast Encryption and Authentication in a Single Cryptographic Primitive
Niels Ferguson, Doug Whiting, Bruce Schneier, John Kelsey, Stefan Lucks, Tadayoshi Kohno |
FSE | 6 |
| 2003 | Analysis of RMAC
Lars R. Knudsen, Tadayoshi Kohno |
FSE | 2 |
| 2002 | Authenticated encryption in SSH: provably fixing the SSH binary packet protocolabstractThe Secure Shell (SSH) protocol is one of the most popular cryptographic protocols on the Internet. Unfortunately, the current SSH authenticated encryption mechanism is insecure. In this paper we propose several fixes to the SSH protocol and, using techniques from modern cryptography, we prove that our modified versions of SSH meet strong new chosen-ciphertext privacy and integrity requirements. Furthermore, our proposed fixes will require relatively little modification to the SSH protocol or to SSH implementations. We believe that our new notions of privacy and integrity for encryption schemes with stateful decryption algorithms will be of independent interest. Mihir Bellare, Tadayoshi Kohno, Chanathip Namprempre |
CCS | 2 |
| 2002 | Token-based scanning of source code for security problemsabstractWe describe ITS4 , a tool for statically scanning C and C++ source code for security vulnerabilities. Compared to other approaches, our scanning technique stakes out a new middle ground between accuracy and efficiency. This method is efficient enough to offer real-time feedback to developers during coding while producing few false negatives. Unlike other techniques, our method is also simple enough to scan C++ code despite the complexities inherent in the language. Using ITS4 , we found new remotely exploitable vulnerabilities in a widely distributed software package as well as in a major piece of e-commerce software.We also describe functionality in more recent tools modeled after ITS4 , and discuss algorithms that could easily be used to augment these kinds of tools. Particularly, we describe a solution we have prototyped that allows for more rigorous analysis of C and C++ source code, without failing to analyze parts of the program due to preprocessor conditionals. John Viega, J. T. Bloch, Tadayoshi Kohno, Gary McGraw 0001 |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2000 | Amplified Boomerang Attacks Against Reduced-Round MARS and Serpent
John Kelsey, Tadayoshi Kohno, Bruce Schneier |
FSE | 2 |