---
_id: '54435'
abstract:
- lang: eng
  text: Web browsers are among the most important but also complex software solutions
    to access the web. It is therefore not surprising that web browsers are an attractive
    target for attackers. Especially in the last decade, security researchers and
    browser vendors have developed sandboxing mechanisms like security-relevant HTTP
    headers to tackle the problem of getting a more secure browser. Although the security
    community is aware of the importance of security-relevant HTTP headers, legacy
    applications and individual requests from different parties have led to possible
    insecure configurations of these headers. Even if specific security headers are
    configured correctly, conflicts in their functionalities may lead to unforeseen
    browser behaviors and vulnerabilities. Recently, the first work which analyzed
    duplicated headers and conflicts in headers was published by Calzavara et al.
    at USENIX Security [1]. The authors focused on inconsistent protections by using
    both, the HTTP header X-Frame-Options and the framing protection of the Content-Security-Policy.
    We extend their work by analyzing browser behaviors when parsing duplicated headers,
    conflicting directives, and values that do not conform to the defined ABNF metalanguage
    specification. We created an open-source testbed running over 19,800 test cases,
    at which nearly 300 test cases are executed in the set of 66 different browsers.
    Our work shows that browsers conform to the specification and behave securely.
    However, all tested browsers behave differently when it comes, for example, to
    parsing the Strict-Transport-Security header. Moreover, Chrome, Safari, and Firefox
    behave differently if the header contains a character, which is not allowed by
    the defined ABNF. This results in the protection mechanism being fully enforced,
    partially enforced, or not enforced and thus completely bypassable.
author:
- first_name: Hendrik
  full_name: Siewert, Hendrik
  last_name: Siewert
- first_name: Martin
  full_name: Kretschmer, Martin
  last_name: Kretschmer
- first_name: Marcus
  full_name: Niemietz, Marcus
  last_name: Niemietz
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
citation:
  ama: 'Siewert H, Kretschmer M, Niemietz M, Somorovsky J. On the Security of Parsing
    Security-Relevant HTTP Headers in Modern Browsers. In: <i>2022 IEEE Security and
    Privacy Workshops (SPW)</i>. IEEE; 2022. doi:<a href="https://doi.org/10.1109/spw54247.2022.9833880">10.1109/spw54247.2022.9833880</a>'
  apa: Siewert, H., Kretschmer, M., Niemietz, M., &#38; Somorovsky, J. (2022). On
    the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers. <i>2022
    IEEE Security and Privacy Workshops (SPW)</i>. <a href="https://doi.org/10.1109/spw54247.2022.9833880">https://doi.org/10.1109/spw54247.2022.9833880</a>
  bibtex: '@inproceedings{Siewert_Kretschmer_Niemietz_Somorovsky_2022, title={On the
    Security of Parsing Security-Relevant HTTP Headers in Modern Browsers}, DOI={<a
    href="https://doi.org/10.1109/spw54247.2022.9833880">10.1109/spw54247.2022.9833880</a>},
    booktitle={2022 IEEE Security and Privacy Workshops (SPW)}, publisher={IEEE},
    author={Siewert, Hendrik and Kretschmer, Martin and Niemietz, Marcus and Somorovsky,
    Juraj}, year={2022} }'
  chicago: Siewert, Hendrik, Martin Kretschmer, Marcus Niemietz, and Juraj Somorovsky.
    “On the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers.”
    In <i>2022 IEEE Security and Privacy Workshops (SPW)</i>. IEEE, 2022. <a href="https://doi.org/10.1109/spw54247.2022.9833880">https://doi.org/10.1109/spw54247.2022.9833880</a>.
  ieee: 'H. Siewert, M. Kretschmer, M. Niemietz, and J. Somorovsky, “On the Security
    of Parsing Security-Relevant HTTP Headers in Modern Browsers,” 2022, doi: <a href="https://doi.org/10.1109/spw54247.2022.9833880">10.1109/spw54247.2022.9833880</a>.'
  mla: Siewert, Hendrik, et al. “On the Security of Parsing Security-Relevant HTTP
    Headers in Modern Browsers.” <i>2022 IEEE Security and Privacy Workshops (SPW)</i>,
    IEEE, 2022, doi:<a href="https://doi.org/10.1109/spw54247.2022.9833880">10.1109/spw54247.2022.9833880</a>.
  short: 'H. Siewert, M. Kretschmer, M. Niemietz, J. Somorovsky, in: 2022 IEEE Security
    and Privacy Workshops (SPW), IEEE, 2022.'
date_created: 2024-05-23T10:49:19Z
date_updated: 2024-05-23T11:01:43Z
department:
- _id: '632'
doi: 10.1109/spw54247.2022.9833880
language:
- iso: eng
publication: 2022 IEEE Security and Privacy Workshops (SPW)
publication_status: published
publisher: IEEE
status: public
title: On the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers
type: conference
user_id: '74619'
year: '2022'
...
---
_id: '25331'
author:
- first_name: Marcus
  full_name: Brinkmann, Marcus
  last_name: Brinkmann
- first_name: Christian
  full_name: Dresen, Christian
  last_name: Dresen
- first_name: Robert
  full_name: Merget, Robert
  last_name: Merget
- first_name: Damian
  full_name: Poddebniak, Damian
  last_name: Poddebniak
- first_name: Jens
  full_name: Müller, Jens
  last_name: Müller
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
citation:
  ama: 'Brinkmann M, Dresen C, Merget R, et al. ALPACA: Application Layer Protocol
    Confusion - Analyzing and Mitigating Cracks in TLS Authentication. In: <i>30th
    {USENIX} Security Symposium ({USENIX} Security 21)</i>. {USENIX} Association;
    2021:4293-4310.'
  apa: 'Brinkmann, M., Dresen, C., Merget, R., Poddebniak, D., Müller, J., Somorovsky,
    J., Schwenk, J., &#38; Schinzel, S. (2021). ALPACA: Application Layer Protocol
    Confusion - Analyzing and Mitigating Cracks in TLS Authentication. <i>30th {USENIX}
    Security Symposium ({USENIX} Security 21)</i>, 4293–4310.'
  bibtex: '@inproceedings{Brinkmann_Dresen_Merget_Poddebniak_Müller_Somorovsky_Schwenk_Schinzel_2021,
    title={ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating
    Cracks in TLS Authentication}, booktitle={30th {USENIX} Security Symposium ({USENIX}
    Security 21)}, publisher={{USENIX} Association}, author={Brinkmann, Marcus and
    Dresen, Christian and Merget, Robert and Poddebniak, Damian and Müller, Jens and
    Somorovsky, Juraj and Schwenk, Jörg and Schinzel, Sebastian}, year={2021}, pages={4293–4310}
    }'
  chicago: 'Brinkmann, Marcus, Christian Dresen, Robert Merget, Damian Poddebniak,
    Jens Müller, Juraj Somorovsky, Jörg Schwenk, and Sebastian Schinzel. “ALPACA:
    Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS
    Authentication.” In <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>,
    4293–4310. {USENIX} Association, 2021.'
  ieee: 'M. Brinkmann <i>et al.</i>, “ALPACA: Application Layer Protocol Confusion
    - Analyzing and Mitigating Cracks in TLS Authentication,” in <i>30th {USENIX}
    Security Symposium ({USENIX} Security 21)</i>, 2021, pp. 4293–4310.'
  mla: 'Brinkmann, Marcus, et al. “ALPACA: Application Layer Protocol Confusion -
    Analyzing and Mitigating Cracks in TLS Authentication.” <i>30th {USENIX} Security
    Symposium ({USENIX} Security 21)</i>, {USENIX} Association, 2021, pp. 4293–310.'
  short: 'M. Brinkmann, C. Dresen, R. Merget, D. Poddebniak, J. Müller, J. Somorovsky,
    J. Schwenk, S. Schinzel, in: 30th {USENIX} Security Symposium ({USENIX} Security
    21), {USENIX} Association, 2021, pp. 4293–4310.'
date_created: 2021-10-04T18:53:47Z
date_updated: 2022-01-06T06:57:01Z
department:
- _id: '632'
language:
- iso: eng
page: 4293-4310
publication: 30th {USENIX} Security Symposium ({USENIX} Security 21)
publication_identifier:
  isbn:
  - 978-1-939133-24-3
publisher: '{USENIX} Association'
status: public
title: 'ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks
  in TLS Authentication'
type: conference
user_id: '83504'
year: '2021'
...
---
_id: '25332'
author:
- first_name: Robert
  full_name: Merget, Robert
  last_name: Merget
- first_name: Marcus
  full_name: Brinkmann, Marcus
  last_name: Brinkmann
- first_name: Nimrod
  full_name: Aviram, Nimrod
  last_name: Aviram
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Johannes
  full_name: Mittmann, Johannes
  last_name: Mittmann
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Merget R, Brinkmann M, Aviram N, Somorovsky J, Mittmann J, Schwenk J. Raccoon
    Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E). In:
    <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>. {USENIX} Association;
    2021:213-230.'
  apa: 'Merget, R., Brinkmann, M., Aviram, N., Somorovsky, J., Mittmann, J., &#38;
    Schwenk, J. (2021). Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles
    in TLS-DH(E). <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>,
    213–230.'
  bibtex: '@inproceedings{Merget_Brinkmann_Aviram_Somorovsky_Mittmann_Schwenk_2021,
    title={Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in
    TLS-DH(E)}, booktitle={30th {USENIX} Security Symposium ({USENIX} Security 21)},
    publisher={{USENIX} Association}, author={Merget, Robert and Brinkmann, Marcus
    and Aviram, Nimrod and Somorovsky, Juraj and Mittmann, Johannes and Schwenk, Jörg},
    year={2021}, pages={213–230} }'
  chicago: 'Merget, Robert, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky, Johannes
    Mittmann, and Jörg Schwenk. “Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles
    in TLS-DH(E).” In <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>,
    213–30. {USENIX} Association, 2021.'
  ieee: 'R. Merget, M. Brinkmann, N. Aviram, J. Somorovsky, J. Mittmann, and J. Schwenk,
    “Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E),”
    in <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>, 2021, pp. 213–230.'
  mla: 'Merget, Robert, et al. “Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles
    in TLS-DH(E).” <i>30th {USENIX} Security Symposium ({USENIX} Security 21)</i>,
    {USENIX} Association, 2021, pp. 213–30.'
  short: 'R. Merget, M. Brinkmann, N. Aviram, J. Somorovsky, J. Mittmann, J. Schwenk,
    in: 30th {USENIX} Security Symposium ({USENIX} Security 21), {USENIX} Association,
    2021, pp. 213–230.'
date_created: 2021-10-04T18:55:36Z
date_updated: 2022-01-06T06:57:01Z
department:
- _id: '632'
language:
- iso: eng
page: 213-230
publication: 30th {USENIX} Security Symposium ({USENIX} Security 21)
publication_identifier:
  isbn:
  - 978-1-939133-24-3
publisher: '{USENIX} Association'
status: public
title: 'Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)'
type: conference
user_id: '83504'
year: '2021'
...
---
_id: '24143'
author:
- first_name: Jan Peter
  full_name: Drees, Jan Peter
  last_name: Drees
- first_name: Pritha
  full_name: Gupta, Pritha
  id: '54803'
  last_name: Gupta
- first_name: Eyke
  full_name: Hüllermeier, Eyke
  id: '48129'
  last_name: Hüllermeier
- first_name: Tibor
  full_name: Jager, Tibor
  last_name: Jager
- first_name: Alexander
  full_name: Konze, Alexander
  last_name: Konze
- first_name: Claudia
  full_name: Priesterjahn, Claudia
  last_name: Priesterjahn
- first_name: Arunselvan
  full_name: Ramaswamy, Arunselvan
  id: '66937'
  last_name: Ramaswamy
  orcid: https://orcid.org/ 0000-0001-7547-8111
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
citation:
  ama: 'Drees JP, Gupta P, Hüllermeier E, et al. Automated Detection of Side Channels
    in Cryptographic Protocols: DROWN the ROBOTs! <i>14th ACM Workshop on Artificial
    Intelligence and Security</i>. Published online 2021.'
  apa: 'Drees, J. P., Gupta, P., Hüllermeier, E., Jager, T., Konze, A., Priesterjahn,
    C., Ramaswamy, A., &#38; Somorovsky, J. (2021). Automated Detection of Side Channels
    in Cryptographic Protocols: DROWN the ROBOTs! <i>14th ACM Workshop on Artificial
    Intelligence and Security</i>.'
  bibtex: '@article{Drees_Gupta_Hüllermeier_Jager_Konze_Priesterjahn_Ramaswamy_Somorovsky_2021,
    title={Automated Detection of Side Channels in Cryptographic Protocols: DROWN
    the ROBOTs!}, journal={14th ACM Workshop on Artificial Intelligence and Security},
    author={Drees, Jan Peter and Gupta, Pritha and Hüllermeier, Eyke and Jager, Tibor
    and Konze, Alexander and Priesterjahn, Claudia and Ramaswamy, Arunselvan and Somorovsky,
    Juraj}, year={2021} }'
  chicago: 'Drees, Jan Peter, Pritha Gupta, Eyke Hüllermeier, Tibor Jager, Alexander
    Konze, Claudia Priesterjahn, Arunselvan Ramaswamy, and Juraj Somorovsky. “Automated
    Detection of Side Channels in Cryptographic Protocols: DROWN the ROBOTs!” <i>14th
    ACM Workshop on Artificial Intelligence and Security</i>, 2021.'
  ieee: 'J. P. Drees <i>et al.</i>, “Automated Detection of Side Channels in Cryptographic
    Protocols: DROWN the ROBOTs!,” <i>14th ACM Workshop on Artificial Intelligence
    and Security</i>, 2021.'
  mla: 'Drees, Jan Peter, et al. “Automated Detection of Side Channels in Cryptographic
    Protocols: DROWN the ROBOTs!” <i>14th ACM Workshop on Artificial Intelligence
    and Security</i>, 2021.'
  short: J.P. Drees, P. Gupta, E. Hüllermeier, T. Jager, A. Konze, C. Priesterjahn,
    A. Ramaswamy, J. Somorovsky, 14th ACM Workshop on Artificial Intelligence and
    Security (2021).
date_created: 2021-09-10T09:56:27Z
date_updated: 2022-01-06T06:56:08Z
department:
- _id: '632'
language:
- iso: eng
publication: 14th ACM Workshop on Artificial Intelligence and Security
status: public
title: 'Automated Detection of Side Channels in Cryptographic Protocols: DROWN the
  ROBOTs!'
type: journal_article
user_id: '83504'
year: '2021'
...
---
_id: '25334'
author:
- first_name: Paul
  full_name: Fiterau-Brostean, Paul
  last_name: Fiterau-Brostean
- first_name: Bengt
  full_name: Jonsson, Bengt
  last_name: Jonsson
- first_name: Robert
  full_name: Merget, Robert
  last_name: Merget
- first_name: Joeri
  full_name: de Ruiter, Joeri
  last_name: de Ruiter
- first_name: Konstantinos
  full_name: Sagonas, Konstantinos
  last_name: Sagonas
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
citation:
  ama: 'Fiterau-Brostean P, Jonsson B, Merget R, de Ruiter J, Sagonas K, Somorovsky
    J. Analysis of DTLS Implementations Using Protocol State Fuzzing. In: <i>29th
    {USENIX} Security Symposium ({USENIX} Security 20)</i>. {USENIX} Association;
    2020:2523-2540.'
  apa: Fiterau-Brostean, P., Jonsson, B., Merget, R., de Ruiter, J., Sagonas, K.,
    &#38; Somorovsky, J. (2020). Analysis of DTLS Implementations Using Protocol State
    Fuzzing. <i>29th {USENIX} Security Symposium ({USENIX} Security 20)</i>, 2523–2540.
  bibtex: '@inproceedings{Fiterau-Brostean_Jonsson_Merget_de Ruiter_Sagonas_Somorovsky_2020,
    title={Analysis of DTLS Implementations Using Protocol State Fuzzing}, booktitle={29th
    {USENIX} Security Symposium ({USENIX} Security 20)}, publisher={{USENIX} Association},
    author={Fiterau-Brostean, Paul and Jonsson, Bengt and Merget, Robert and de Ruiter,
    Joeri and Sagonas, Konstantinos and Somorovsky, Juraj}, year={2020}, pages={2523–2540}
    }'
  chicago: Fiterau-Brostean, Paul, Bengt Jonsson, Robert Merget, Joeri de Ruiter,
    Konstantinos Sagonas, and Juraj Somorovsky. “Analysis of DTLS Implementations
    Using Protocol State Fuzzing.” In <i>29th {USENIX} Security Symposium ({USENIX}
    Security 20)</i>, 2523–40. {USENIX} Association, 2020.
  ieee: P. Fiterau-Brostean, B. Jonsson, R. Merget, J. de Ruiter, K. Sagonas, and
    J. Somorovsky, “Analysis of DTLS Implementations Using Protocol State Fuzzing,”
    in <i>29th {USENIX} Security Symposium ({USENIX} Security 20)</i>, 2020, pp. 2523–2540.
  mla: Fiterau-Brostean, Paul, et al. “Analysis of DTLS Implementations Using Protocol
    State Fuzzing.” <i>29th {USENIX} Security Symposium ({USENIX} Security 20)</i>,
    {USENIX} Association, 2020, pp. 2523–40.
  short: 'P. Fiterau-Brostean, B. Jonsson, R. Merget, J. de Ruiter, K. Sagonas, J.
    Somorovsky, in: 29th {USENIX} Security Symposium ({USENIX} Security 20), {USENIX}
    Association, 2020, pp. 2523–2540.'
date_created: 2021-10-04T18:56:41Z
date_updated: 2022-01-06T06:57:01Z
department:
- _id: '632'
language:
- iso: eng
page: 2523-2540
publication: 29th {USENIX} Security Symposium ({USENIX} Security 20)
publication_identifier:
  isbn:
  - 978-1-939133-17-5
publisher: '{USENIX} Association'
status: public
title: Analysis of DTLS Implementations Using Protocol State Fuzzing
type: conference
user_id: '83504'
year: '2020'
...
---
_id: '25336'
abstract:
- lang: eng
  text: OpenPGP and S/MIME are two major standards for securing email communication
    introduced in the early 1990s. Three recent classes of attacks exploit weak cipher
    modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email
    structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the
    email client (REPLY attacks). Although all three break message confidentiality
    by using standardized email features, only EFAIL-MG has been mitigated in IETF
    standards with the introduction of AEAD algorithms. So far, no uniform and reliable
    countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY
    attacks. Instead, email clients implement a variety of different ad-hoc countermeasures
    which are only partially effective, cause interoperability problems, and fragment
    the secure email ecosystem.We present the first generic countermeasure against
    both REPLY and EFAIL-DE attacks by checking the decryption context including SMTP
    headers and MIME structure during decryption. The decryption context is encoded
    into a string DC and used as Associated Data (AD) in the AEAD encryption. Thus
    the proposed solution seamlessly extends the EFAIL-MG countermeasures. The decryption
    context changes whenever an attacker alters the email source code in a critical
    way, for example, if the attacker changes the MIME structure or adds a new Reply-To
    header. The proposed solution does not cause any interoperability problems and
    legacy emails can still be decrypted. We evaluate our approach by implementing
    the decryption contexts in Thunderbird/Enigmail and by verifying their correct
    functionality after the email has been transported over all major email providers,
    including Gmail and iCloud Mail.
author:
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
- first_name: Marcus
  full_name: Brinkmann, Marcus
  last_name: Brinkmann
- first_name: Damian
  full_name: Poddebniak, Damian
  last_name: Poddebniak
- first_name: Jens
  full_name: Müller, Jens
  last_name: Müller
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
citation:
  ama: 'Schwenk J, Brinkmann M, Poddebniak D, Müller J, Somorovsky J, Schinzel S.
    Mitigation of Attacks on Email End-to-End Encryption. In: <i>Proceedings of the
    2020 ACM SIGSAC Conference on Computer and Communications Security</i>. CCS ’20.
    Association for Computing Machinery; 2020:1647–1664. doi:<a href="https://doi.org/10.1145/3372297.3417878">10.1145/3372297.3417878</a>'
  apa: Schwenk, J., Brinkmann, M., Poddebniak, D., Müller, J., Somorovsky, J., &#38;
    Schinzel, S. (2020). Mitigation of Attacks on Email End-to-End Encryption. <i>Proceedings
    of the 2020 ACM SIGSAC Conference on Computer and Communications Security</i>,
    1647–1664. <a href="https://doi.org/10.1145/3372297.3417878">https://doi.org/10.1145/3372297.3417878</a>
  bibtex: '@inproceedings{Schwenk_Brinkmann_Poddebniak_Müller_Somorovsky_Schinzel_2020,
    place={New York, NY, USA}, series={CCS ’20}, title={Mitigation of Attacks on Email
    End-to-End Encryption}, DOI={<a href="https://doi.org/10.1145/3372297.3417878">10.1145/3372297.3417878</a>},
    booktitle={Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications
    Security}, publisher={Association for Computing Machinery}, author={Schwenk, Jörg
    and Brinkmann, Marcus and Poddebniak, Damian and Müller, Jens and Somorovsky,
    Juraj and Schinzel, Sebastian}, year={2020}, pages={1647–1664}, collection={CCS
    ’20} }'
  chicago: 'Schwenk, Jörg, Marcus Brinkmann, Damian Poddebniak, Jens Müller, Juraj
    Somorovsky, and Sebastian Schinzel. “Mitigation of Attacks on Email End-to-End
    Encryption.” In <i>Proceedings of the 2020 ACM SIGSAC Conference on Computer and
    Communications Security</i>, 1647–1664. CCS ’20. New York, NY, USA: Association
    for Computing Machinery, 2020. <a href="https://doi.org/10.1145/3372297.3417878">https://doi.org/10.1145/3372297.3417878</a>.'
  ieee: 'J. Schwenk, M. Brinkmann, D. Poddebniak, J. Müller, J. Somorovsky, and S.
    Schinzel, “Mitigation of Attacks on Email End-to-End Encryption,” in <i>Proceedings
    of the 2020 ACM SIGSAC Conference on Computer and Communications Security</i>,
    2020, pp. 1647–1664, doi: <a href="https://doi.org/10.1145/3372297.3417878">10.1145/3372297.3417878</a>.'
  mla: Schwenk, Jörg, et al. “Mitigation of Attacks on Email End-to-End Encryption.”
    <i>Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications
    Security</i>, Association for Computing Machinery, 2020, pp. 1647–1664, doi:<a
    href="https://doi.org/10.1145/3372297.3417878">10.1145/3372297.3417878</a>.
  short: 'J. Schwenk, M. Brinkmann, D. Poddebniak, J. Müller, J. Somorovsky, S. Schinzel,
    in: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications
    Security, Association for Computing Machinery, New York, NY, USA, 2020, pp. 1647–1664.'
date_created: 2021-10-04T18:58:37Z
date_updated: 2022-08-03T09:57:27Z
department:
- _id: '632'
doi: 10.1145/3372297.3417878
keyword:
- decryption contexts
- EFAIL
- OpenPGP
- S/MIME
- AEAD
language:
- iso: eng
page: 1647–1664
place: New York, NY, USA
publication: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications
  Security
publication_identifier:
  isbn:
  - '9781450370899'
publication_status: published
publisher: Association for Computing Machinery
series_title: CCS '20
status: public
title: Mitigation of Attacks on Email End-to-End Encryption
type: conference
user_id: '83504'
year: '2020'
...
---
_id: '15908'
author:
- first_name: Jens
  full_name: Müller, Jens
  last_name: Müller
- first_name: Marcus
  full_name: Brinkmann, Marcus
  last_name: Brinkmann
- first_name: Damian
  full_name: Poddebniak, Damian
  last_name: Poddebniak
- first_name: Hanno
  full_name: Böck, Hanno
  last_name: Böck
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Müller J, Brinkmann M, Poddebniak D, et al. “Johnny, you are fired!” -- Spoofing
    OpenPGP and S/MIME Signatures in Emails. In: <i>28th {USENIX} Security Symposium
    ({USENIX} Security 19)</i>. Santa Clara, CA: {USENIX} Association; 2019:1011-1028.'
  apa: 'Müller, J., Brinkmann, M., Poddebniak, D., Böck, H., Schinzel, S., Somorovsky,
    J., &#38; Schwenk, J. (2019). “Johnny, you are fired!” -- Spoofing OpenPGP and
    S/MIME Signatures in Emails. In <i>28th {USENIX} Security Symposium ({USENIX}
    Security 19)</i> (pp. 1011–1028). Santa Clara, CA: {USENIX} Association.'
  bibtex: '@inproceedings{Müller_Brinkmann_Poddebniak_Böck_Schinzel_Somorovsky_Schwenk_2019,
    place={Santa Clara, CA}, title={“Johnny, you are fired!” -- Spoofing OpenPGP and
    S/MIME Signatures in Emails}, booktitle={28th {USENIX} Security Symposium ({USENIX}
    Security 19)}, publisher={{USENIX} Association}, author={Müller, Jens and Brinkmann,
    Marcus and Poddebniak, Damian and Böck, Hanno and Schinzel, Sebastian and Somorovsky,
    Juraj and Schwenk, Jörg}, year={2019}, pages={1011–1028} }'
  chicago: 'Müller, Jens, Marcus Brinkmann, Damian Poddebniak, Hanno Böck, Sebastian
    Schinzel, Juraj Somorovsky, and Jörg Schwenk. “‘Johnny, You Are Fired!’ -- Spoofing
    OpenPGP and S/MIME Signatures in Emails.” In <i>28th {USENIX} Security Symposium
    ({USENIX} Security 19)</i>, 1011–28. Santa Clara, CA: {USENIX} Association, 2019.'
  ieee: J. Müller <i>et al.</i>, “‘Johnny, you are fired!’ -- Spoofing OpenPGP and
    S/MIME Signatures in Emails,” in <i>28th {USENIX} Security Symposium ({USENIX}
    Security 19)</i>, 2019, pp. 1011–1028.
  mla: Müller, Jens, et al. “‘Johnny, You Are Fired!’ -- Spoofing OpenPGP and S/MIME
    Signatures in Emails.” <i>28th {USENIX} Security Symposium ({USENIX} Security
    19)</i>, {USENIX} Association, 2019, pp. 1011–28.
  short: 'J. Müller, M. Brinkmann, D. Poddebniak, H. Böck, S. Schinzel, J. Somorovsky,
    J. Schwenk, in: 28th {USENIX} Security Symposium ({USENIX} Security 19), {USENIX}
    Association, Santa Clara, CA, 2019, pp. 1011–1028.'
date_created: 2020-02-15T09:50:57Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/conference/usenixsecurity19/presentation/muller
oa: '1'
page: 1011-1028
place: Santa Clara, CA
publication: 28th {USENIX} Security Symposium ({USENIX} Security 19)
publication_identifier:
  isbn:
  - 978-1-939133-06-9
publisher: '{USENIX} Association'
status: public
title: '"Johnny, you are fired!" -- Spoofing OpenPGP and S/MIME Signatures in Emails'
type: conference
user_id: '83504'
year: '2019'
...
---
_id: '15909'
author:
- first_name: Robert
  full_name: Merget, Robert
  last_name: Merget
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Nimrod
  full_name: Aviram, Nimrod
  last_name: Aviram
- first_name: Craig
  full_name: Young, Craig
  last_name: Young
- first_name: Janis
  full_name: Fliegenschmidt, Janis
  last_name: Fliegenschmidt
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
- first_name: Yuval
  full_name: Shavitt, Yuval
  last_name: Shavitt
citation:
  ama: 'Merget R, Somorovsky J, Aviram N, et al. Scalable Scanning and Automatic Classification
    of TLS Padding Oracle Vulnerabilities. In: <i>28th {USENIX} Security Symposium
    ({USENIX} Security 19)</i>. Santa Clara, CA: {USENIX} Association; 2019:1029-1046.'
  apa: 'Merget, R., Somorovsky, J., Aviram, N., Young, C., Fliegenschmidt, J., Schwenk,
    J., &#38; Shavitt, Y. (2019). Scalable Scanning and Automatic Classification of
    TLS Padding Oracle Vulnerabilities. In <i>28th {USENIX} Security Symposium ({USENIX}
    Security 19)</i> (pp. 1029–1046). Santa Clara, CA: {USENIX} Association.'
  bibtex: '@inproceedings{Merget_Somorovsky_Aviram_Young_Fliegenschmidt_Schwenk_Shavitt_2019,
    place={Santa Clara, CA}, title={Scalable Scanning and Automatic Classification
    of TLS Padding Oracle Vulnerabilities}, booktitle={28th {USENIX} Security Symposium
    ({USENIX} Security 19)}, publisher={{USENIX} Association}, author={Merget, Robert
    and Somorovsky, Juraj and Aviram, Nimrod and Young, Craig and Fliegenschmidt,
    Janis and Schwenk, Jörg and Shavitt, Yuval}, year={2019}, pages={1029–1046} }'
  chicago: 'Merget, Robert, Juraj Somorovsky, Nimrod Aviram, Craig Young, Janis Fliegenschmidt,
    Jörg Schwenk, and Yuval Shavitt. “Scalable Scanning and Automatic Classification
    of TLS Padding Oracle Vulnerabilities.” In <i>28th {USENIX} Security Symposium
    ({USENIX} Security 19)</i>, 1029–46. Santa Clara, CA: {USENIX} Association, 2019.'
  ieee: R. Merget <i>et al.</i>, “Scalable Scanning and Automatic Classification of
    TLS Padding Oracle Vulnerabilities,” in <i>28th {USENIX} Security Symposium ({USENIX}
    Security 19)</i>, 2019, pp. 1029–1046.
  mla: Merget, Robert, et al. “Scalable Scanning and Automatic Classification of TLS
    Padding Oracle Vulnerabilities.” <i>28th {USENIX} Security Symposium ({USENIX}
    Security 19)</i>, {USENIX} Association, 2019, pp. 1029–46.
  short: 'R. Merget, J. Somorovsky, N. Aviram, C. Young, J. Fliegenschmidt, J. Schwenk,
    Y. Shavitt, in: 28th {USENIX} Security Symposium ({USENIX} Security 19), {USENIX}
    Association, Santa Clara, CA, 2019, pp. 1029–1046.'
date_created: 2020-02-15T09:51:09Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/conference/usenixsecurity19/presentation/merget
oa: '1'
page: 1029-1046
place: Santa Clara, CA
publication: 28th {USENIX} Security Symposium ({USENIX} Security 19)
publication_identifier:
  isbn:
  - 978-1-939133-06-9
publisher: '{USENIX} Association'
status: public
title: Scalable Scanning and Automatic Classification of TLS Padding Oracle Vulnerabilities
type: conference
user_id: '83504'
year: '2019'
...
---
_id: '15910'
author:
- first_name: Nils
  full_name: Engelbertz, Nils
  last_name: Engelbertz
- first_name: Vladislav
  full_name: Mladenov, Vladislav
  last_name: Mladenov
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: David
  full_name: Herring, David
  last_name: Herring
- first_name: Nurullah
  full_name: Erinola, Nurullah
  last_name: Erinola
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Engelbertz N, Mladenov V, Somorovsky J, Herring D, Erinola N, Schwenk J. Security
    Analysis of XAdES Validation in the CEF Digital Signature Services (DSS). In:
    Roßnagel H, Wagner S, Hühnlein D, eds. <i>Open Identity Summit 2019</i>. Gesellschaft
    für Informatik, Bonn; 2019:95-106.'
  apa: Engelbertz, N., Mladenov, V., Somorovsky, J., Herring, D., Erinola, N., &#38;
    Schwenk, J. (2019). Security Analysis of XAdES Validation in the CEF Digital Signature
    Services (DSS). In H. Roßnagel, S. Wagner, &#38; D. Hühnlein (Eds.), <i>Open Identity
    Summit 2019</i> (pp. 95–106). Gesellschaft für Informatik, Bonn.
  bibtex: '@inproceedings{Engelbertz_Mladenov_Somorovsky_Herring_Erinola_Schwenk_2019,
    title={Security Analysis of XAdES Validation in the CEF Digital Signature Services
    (DSS)}, booktitle={Open Identity Summit 2019}, publisher={Gesellschaft für Informatik,
    Bonn}, author={Engelbertz, Nils and Mladenov, Vladislav and Somorovsky, Juraj
    and Herring, David and Erinola, Nurullah and Schwenk, Jörg}, editor={Roßnagel,
    Heiko and Wagner, Sven and Hühnlein, DetlefEditors}, year={2019}, pages={95–106}
    }'
  chicago: Engelbertz, Nils, Vladislav Mladenov, Juraj Somorovsky, David Herring,
    Nurullah Erinola, and Jörg Schwenk. “Security Analysis of XAdES Validation in
    the CEF Digital Signature Services (DSS).” In <i>Open Identity Summit 2019</i>,
    edited by Heiko Roßnagel, Sven Wagner, and Detlef Hühnlein, 95–106. Gesellschaft
    für Informatik, Bonn, 2019.
  ieee: N. Engelbertz, V. Mladenov, J. Somorovsky, D. Herring, N. Erinola, and J.
    Schwenk, “Security Analysis of XAdES Validation in the CEF Digital Signature Services
    (DSS),” in <i>Open Identity Summit 2019</i>, 2019, pp. 95–106.
  mla: Engelbertz, Nils, et al. “Security Analysis of XAdES Validation in the CEF
    Digital Signature Services (DSS).” <i>Open Identity Summit 2019</i>, edited by
    Heiko Roßnagel et al., Gesellschaft für Informatik, Bonn, 2019, pp. 95–106.
  short: 'N. Engelbertz, V. Mladenov, J. Somorovsky, D. Herring, N. Erinola, J. Schwenk,
    in: H. Roßnagel, S. Wagner, D. Hühnlein (Eds.), Open Identity Summit 2019, Gesellschaft
    für Informatik, Bonn, 2019, pp. 95–106.'
date_created: 2020-02-15T10:01:05Z
date_updated: 2022-01-06T06:52:40Z
editor:
- first_name: Heiko
  full_name: Roßnagel, Heiko
  last_name: Roßnagel
- first_name: Sven
  full_name: Wagner, Sven
  last_name: Wagner
- first_name: Detlef
  full_name: Hühnlein, Detlef
  last_name: Hühnlein
language:
- iso: eng
page: ' 95-106 '
publication: Open Identity Summit 2019
publisher: Gesellschaft für Informatik, Bonn
status: public
title: Security Analysis of XAdES Validation in the CEF Digital Signature Services
  (DSS)
type: conference
user_id: '83504'
year: '2019'
...
---
_id: '15892'
author:
- first_name: Martin R.
  full_name: Albrecht, Martin R.
  last_name: Albrecht
- first_name: Jake
  full_name: Massimo, Jake
  last_name: Massimo
- first_name: Kenneth G.
  full_name: Paterson, Kenneth G.
  last_name: Paterson
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
citation:
  ama: 'Albrecht MR, Massimo J, Paterson KG, Somorovsky J. Prime and Prejudice: Primality
    Testing Under Adversarial Conditions. In: <i>Proceedings of the 2018 ACM SIGSAC
    Conference on Computer and Communications Security</i>. ; 2018. doi:<a href="https://doi.org/10.1145/3243734.3243787">10.1145/3243734.3243787</a>'
  apa: 'Albrecht, M. R., Massimo, J., Paterson, K. G., &#38; Somorovsky, J. (2018).
    Prime and Prejudice: Primality Testing Under Adversarial Conditions. In <i>Proceedings
    of the 2018 ACM SIGSAC Conference on Computer and Communications Security</i>.
    <a href="https://doi.org/10.1145/3243734.3243787">https://doi.org/10.1145/3243734.3243787</a>'
  bibtex: '@inproceedings{Albrecht_Massimo_Paterson_Somorovsky_2018, title={Prime
    and Prejudice: Primality Testing Under Adversarial Conditions}, DOI={<a href="https://doi.org/10.1145/3243734.3243787">10.1145/3243734.3243787</a>},
    booktitle={Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications
    Security}, author={Albrecht, Martin R. and Massimo, Jake and Paterson, Kenneth
    G. and Somorovsky, Juraj}, year={2018} }'
  chicago: 'Albrecht, Martin R., Jake Massimo, Kenneth G. Paterson, and Juraj Somorovsky.
    “Prime and Prejudice: Primality Testing Under Adversarial Conditions.” In <i>Proceedings
    of the 2018 ACM SIGSAC Conference on Computer and Communications Security</i>,
    2018. <a href="https://doi.org/10.1145/3243734.3243787">https://doi.org/10.1145/3243734.3243787</a>.'
  ieee: 'M. R. Albrecht, J. Massimo, K. G. Paterson, and J. Somorovsky, “Prime and
    Prejudice: Primality Testing Under Adversarial Conditions,” in <i>Proceedings
    of the 2018 ACM SIGSAC Conference on Computer and Communications Security</i>,
    2018.'
  mla: 'Albrecht, Martin R., et al. “Prime and Prejudice: Primality Testing Under
    Adversarial Conditions.” <i>Proceedings of the 2018 ACM SIGSAC Conference on Computer
    and Communications Security</i>, 2018, doi:<a href="https://doi.org/10.1145/3243734.3243787">10.1145/3243734.3243787</a>.'
  short: 'M.R. Albrecht, J. Massimo, K.G. Paterson, J. Somorovsky, in: Proceedings
    of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018.'
date_created: 2020-02-15T09:34:47Z
date_updated: 2022-01-06T06:52:39Z
doi: 10.1145/3243734.3243787
extern: '1'
language:
- iso: eng
main_file_link:
- url: https://eprint.iacr.org/2018/749
publication: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications
  Security
publication_identifier:
  isbn:
  - '9781450356930'
publication_status: published
status: public
title: 'Prime and Prejudice: Primality Testing Under Adversarial Conditions'
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15893'
author:
- first_name: Damian
  full_name: Poddebniak, Damian
  last_name: Poddebniak
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
- first_name: Manfred
  full_name: Lochter, Manfred
  last_name: Lochter
- first_name: Paul
  full_name: Rosler, Paul
  last_name: Rosler
citation:
  ama: 'Poddebniak D, Somorovsky J, Schinzel S, Lochter M, Rosler P. Attacking Deterministic
    Signature Schemes Using Fault Attacks. In: <i>2018 IEEE European Symposium on
    Security and Privacy (EuroS&#38;P)</i>. ; 2018. doi:<a href="https://doi.org/10.1109/eurosp.2018.00031">10.1109/eurosp.2018.00031</a>'
  apa: Poddebniak, D., Somorovsky, J., Schinzel, S., Lochter, M., &#38; Rosler, P.
    (2018). Attacking Deterministic Signature Schemes Using Fault Attacks. In <i>2018
    IEEE European Symposium on Security and Privacy (EuroS&#38;P)</i>. <a href="https://doi.org/10.1109/eurosp.2018.00031">https://doi.org/10.1109/eurosp.2018.00031</a>
  bibtex: '@inproceedings{Poddebniak_Somorovsky_Schinzel_Lochter_Rosler_2018, title={Attacking
    Deterministic Signature Schemes Using Fault Attacks}, DOI={<a href="https://doi.org/10.1109/eurosp.2018.00031">10.1109/eurosp.2018.00031</a>},
    booktitle={2018 IEEE European Symposium on Security and Privacy (EuroS&#38;P)},
    author={Poddebniak, Damian and Somorovsky, Juraj and Schinzel, Sebastian and Lochter,
    Manfred and Rosler, Paul}, year={2018} }'
  chicago: Poddebniak, Damian, Juraj Somorovsky, Sebastian Schinzel, Manfred Lochter,
    and Paul Rosler. “Attacking Deterministic Signature Schemes Using Fault Attacks.”
    In <i>2018 IEEE European Symposium on Security and Privacy (EuroS&#38;P)</i>,
    2018. <a href="https://doi.org/10.1109/eurosp.2018.00031">https://doi.org/10.1109/eurosp.2018.00031</a>.
  ieee: D. Poddebniak, J. Somorovsky, S. Schinzel, M. Lochter, and P. Rosler, “Attacking
    Deterministic Signature Schemes Using Fault Attacks,” in <i>2018 IEEE European
    Symposium on Security and Privacy (EuroS&#38;P)</i>, 2018.
  mla: Poddebniak, Damian, et al. “Attacking Deterministic Signature Schemes Using
    Fault Attacks.” <i>2018 IEEE European Symposium on Security and Privacy (EuroS&#38;P)</i>,
    2018, doi:<a href="https://doi.org/10.1109/eurosp.2018.00031">10.1109/eurosp.2018.00031</a>.
  short: 'D. Poddebniak, J. Somorovsky, S. Schinzel, M. Lochter, P. Rosler, in: 2018
    IEEE European Symposium on Security and Privacy (EuroS&#38;P), 2018.'
date_created: 2020-02-15T09:35:53Z
date_updated: 2022-01-06T06:52:39Z
doi: 10.1109/eurosp.2018.00031
language:
- iso: eng
publication: 2018 IEEE European Symposium on Security and Privacy (EuroS&P)
publication_identifier:
  isbn:
  - '9781538642283'
publication_status: published
status: public
title: Attacking Deterministic Signature Schemes Using Fault Attacks
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15894'
author:
- first_name: Dennis
  full_name: Detering, Dennis
  last_name: Detering
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Christian
  full_name: Mainka, Christian
  last_name: Mainka
- first_name: Vladislav
  full_name: Mladenov, Vladislav
  last_name: Mladenov
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Detering D, Somorovsky J, Mainka C, Mladenov V, Schwenk J. On The (In-)Security
    Of JavaScript Object Signing And Encryption. In: <i>Proceedings of the 1st Reversing
    and Offensive-Oriented Trends Symposium on - ROOTS</i>. ; 2018. doi:<a href="https://doi.org/10.1145/3150376.3150379">10.1145/3150376.3150379</a>'
  apa: Detering, D., Somorovsky, J., Mainka, C., Mladenov, V., &#38; Schwenk, J. (2018).
    On The (In-)Security Of JavaScript Object Signing And Encryption. In <i>Proceedings
    of the 1st Reversing and Offensive-oriented Trends Symposium on - ROOTS</i>. <a
    href="https://doi.org/10.1145/3150376.3150379">https://doi.org/10.1145/3150376.3150379</a>
  bibtex: '@inproceedings{Detering_Somorovsky_Mainka_Mladenov_Schwenk_2018, title={On
    The (In-)Security Of JavaScript Object Signing And Encryption}, DOI={<a href="https://doi.org/10.1145/3150376.3150379">10.1145/3150376.3150379</a>},
    booktitle={Proceedings of the 1st Reversing and Offensive-oriented Trends Symposium
    on - ROOTS}, author={Detering, Dennis and Somorovsky, Juraj and Mainka, Christian
    and Mladenov, Vladislav and Schwenk, Jörg}, year={2018} }'
  chicago: Detering, Dennis, Juraj Somorovsky, Christian Mainka, Vladislav Mladenov,
    and Jörg Schwenk. “On The (In-)Security Of JavaScript Object Signing And Encryption.”
    In <i>Proceedings of the 1st Reversing and Offensive-Oriented Trends Symposium
    on - ROOTS</i>, 2018. <a href="https://doi.org/10.1145/3150376.3150379">https://doi.org/10.1145/3150376.3150379</a>.
  ieee: D. Detering, J. Somorovsky, C. Mainka, V. Mladenov, and J. Schwenk, “On The
    (In-)Security Of JavaScript Object Signing And Encryption,” in <i>Proceedings
    of the 1st Reversing and Offensive-oriented Trends Symposium on - ROOTS</i>, 2018.
  mla: Detering, Dennis, et al. “On The (In-)Security Of JavaScript Object Signing
    And Encryption.” <i>Proceedings of the 1st Reversing and Offensive-Oriented Trends
    Symposium on - ROOTS</i>, 2018, doi:<a href="https://doi.org/10.1145/3150376.3150379">10.1145/3150376.3150379</a>.
  short: 'D. Detering, J. Somorovsky, C. Mainka, V. Mladenov, J. Schwenk, in: Proceedings
    of the 1st Reversing and Offensive-Oriented Trends Symposium on - ROOTS, 2018.'
date_created: 2020-02-15T09:36:33Z
date_updated: 2022-01-06T06:52:39Z
doi: 10.1145/3150376.3150379
language:
- iso: eng
publication: Proceedings of the 1st Reversing and Offensive-oriented Trends Symposium
  on - ROOTS
publication_identifier:
  isbn:
  - '9781450353212'
publication_status: published
status: public
title: On The (In-)Security Of JavaScript Object Signing And Encryption
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15905'
author:
- first_name: Damian
  full_name: Poddebniak, Damian
  last_name: Poddebniak
- first_name: Christian
  full_name: Dresen, Christian
  last_name: Dresen
- first_name: Jens
  full_name: Müller, Jens
  last_name: Müller
- first_name: Fabian
  full_name: Ising, Fabian
  last_name: Ising
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
- first_name: Simon
  full_name: Friedberger, Simon
  last_name: Friedberger
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Poddebniak D, Dresen C, Müller J, et al. Efail: Breaking S/MIME and OpenPGP
    Email Encryption using Exfiltration Channels. In: <i>27th {USENIX} Security Symposium
    ({USENIX} Security 18)</i>. Baltimore, MD: {USENIX} Association; 2018:549-566.'
  apa: 'Poddebniak, D., Dresen, C., Müller, J., Ising, F., Schinzel, S., Friedberger,
    S., … Schwenk, J. (2018). Efail: Breaking S/MIME and OpenPGP Email Encryption
    using Exfiltration Channels. In <i>27th {USENIX} Security Symposium ({USENIX}
    Security 18)</i> (pp. 549–566). Baltimore, MD: {USENIX} Association.'
  bibtex: '@inproceedings{Poddebniak_Dresen_Müller_Ising_Schinzel_Friedberger_Somorovsky_Schwenk_2018,
    place={Baltimore, MD}, title={Efail: Breaking S/MIME and OpenPGP Email Encryption
    using Exfiltration Channels}, booktitle={27th {USENIX} Security Symposium ({USENIX}
    Security 18)}, publisher={{USENIX} Association}, author={Poddebniak, Damian and
    Dresen, Christian and Müller, Jens and Ising, Fabian and Schinzel, Sebastian and
    Friedberger, Simon and Somorovsky, Juraj and Schwenk, Jörg}, year={2018}, pages={549–566}
    }'
  chicago: 'Poddebniak, Damian, Christian Dresen, Jens Müller, Fabian Ising, Sebastian
    Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg Schwenk. “Efail: Breaking
    S/MIME and OpenPGP Email Encryption Using Exfiltration Channels.” In <i>27th {USENIX}
    Security Symposium ({USENIX} Security 18)</i>, 549–66. Baltimore, MD: {USENIX}
    Association, 2018.'
  ieee: 'D. Poddebniak <i>et al.</i>, “Efail: Breaking S/MIME and OpenPGP Email Encryption
    using Exfiltration Channels,” in <i>27th {USENIX} Security Symposium ({USENIX}
    Security 18)</i>, 2018, pp. 549–566.'
  mla: 'Poddebniak, Damian, et al. “Efail: Breaking S/MIME and OpenPGP Email Encryption
    Using Exfiltration Channels.” <i>27th {USENIX} Security Symposium ({USENIX} Security
    18)</i>, {USENIX} Association, 2018, pp. 549–66.'
  short: 'D. Poddebniak, C. Dresen, J. Müller, F. Ising, S. Schinzel, S. Friedberger,
    J. Somorovsky, J. Schwenk, in: 27th {USENIX} Security Symposium ({USENIX} Security
    18), {USENIX} Association, Baltimore, MD, 2018, pp. 549–566.'
date_created: 2020-02-15T09:49:36Z
date_updated: 2022-01-06T06:52:40Z
extern: '1'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/node/217635
oa: '1'
page: 549-566
place: Baltimore, MD
publication: 27th {USENIX} Security Symposium ({USENIX} Security 18)
publication_identifier:
  isbn:
  - 978-1-939133-04-5
publisher: '{USENIX} Association'
status: public
title: 'Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels'
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15906'
author:
- first_name: Hanno
  full_name: Böck, Hanno
  last_name: Böck
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Craig
  full_name: Young, Craig
  last_name: Young
citation:
  ama: 'Böck H, Somorovsky J, Young C. Return Of Bleichenbacher\textquoterights Oracle
    Threat (ROBOT). In: <i>27th {USENIX} Security Symposium ({USENIX} Security 18)</i>.
    Baltimore, MD: {USENIX} Association; 2018:817-849.'
  apa: 'Böck, H., Somorovsky, J., &#38; Young, C. (2018). Return Of Bleichenbacher\textquoterights
    Oracle Threat (ROBOT). In <i>27th {USENIX} Security Symposium ({USENIX} Security
    18)</i> (pp. 817–849). Baltimore, MD: {USENIX} Association.'
  bibtex: '@inproceedings{Böck_Somorovsky_Young_2018, place={Baltimore, MD}, title={Return
    Of Bleichenbacher\textquoterights Oracle Threat (ROBOT)}, booktitle={27th {USENIX}
    Security Symposium ({USENIX} Security 18)}, publisher={{USENIX} Association},
    author={Böck, Hanno and Somorovsky, Juraj and Young, Craig}, year={2018}, pages={817–849}
    }'
  chicago: 'Böck, Hanno, Juraj Somorovsky, and Craig Young. “Return Of Bleichenbacher\textquoterights
    Oracle Threat (ROBOT).” In <i>27th {USENIX} Security Symposium ({USENIX} Security
    18)</i>, 817–49. Baltimore, MD: {USENIX} Association, 2018.'
  ieee: H. Böck, J. Somorovsky, and C. Young, “Return Of Bleichenbacher\textquoterights
    Oracle Threat (ROBOT),” in <i>27th {USENIX} Security Symposium ({USENIX} Security
    18)</i>, 2018, pp. 817–849.
  mla: Böck, Hanno, et al. “Return Of Bleichenbacher\textquoterights Oracle Threat
    (ROBOT).” <i>27th {USENIX} Security Symposium ({USENIX} Security 18)</i>, {USENIX}
    Association, 2018, pp. 817–49.
  short: 'H. Böck, J. Somorovsky, C. Young, in: 27th {USENIX} Security Symposium ({USENIX}
    Security 18), {USENIX} Association, Baltimore, MD, 2018, pp. 817–849.'
date_created: 2020-02-15T09:49:57Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/node/217495
oa: '1'
page: 817-849
place: Baltimore, MD
publication: 27th {USENIX} Security Symposium ({USENIX} Security 18)
publication_identifier:
  isbn:
  - 978-1-939133-04-5
publisher: '{USENIX} Association'
status: public
title: Return Of Bleichenbacher\textquoterights Oracle Threat (ROBOT)
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15914'
author:
- first_name: Nils
  full_name: Engelbertz, Nils
  last_name: Engelbertz
- first_name: Nurullah
  full_name: Erinola, Nurullah
  last_name: Erinola
- first_name: David
  full_name: Herring, David
  last_name: Herring
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Vladislav
  full_name: Mladenov, Vladislav
  last_name: Mladenov
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Engelbertz N, Erinola N, Herring D, Somorovsky J, Mladenov V, Schwenk J. Security
    Analysis of eIDAS -- The Cross-Country Authentication Scheme in Europe. In: <i>12th
    {USENIX} Workshop on Offensive Technologies ({WOOT} 18)</i>. Baltimore, MD: {USENIX}
    Association; 2018.'
  apa: 'Engelbertz, N., Erinola, N., Herring, D., Somorovsky, J., Mladenov, V., &#38;
    Schwenk, J. (2018). Security Analysis of eIDAS -- The Cross-Country Authentication
    Scheme in Europe. In <i>12th {USENIX} Workshop on Offensive Technologies ({WOOT}
    18)</i>. Baltimore, MD: {USENIX} Association.'
  bibtex: '@inproceedings{Engelbertz_Erinola_Herring_Somorovsky_Mladenov_Schwenk_2018,
    place={Baltimore, MD}, title={Security Analysis of eIDAS -- The Cross-Country
    Authentication Scheme in Europe}, booktitle={12th {USENIX} Workshop on Offensive
    Technologies ({WOOT} 18)}, publisher={{USENIX} Association}, author={Engelbertz,
    Nils and Erinola, Nurullah and Herring, David and Somorovsky, Juraj and Mladenov,
    Vladislav and Schwenk, Jörg}, year={2018} }'
  chicago: 'Engelbertz, Nils, Nurullah Erinola, David Herring, Juraj Somorovsky, Vladislav
    Mladenov, and Jörg Schwenk. “Security Analysis of EIDAS -- The Cross-Country Authentication
    Scheme in Europe.” In <i>12th {USENIX} Workshop on Offensive Technologies ({WOOT}
    18)</i>. Baltimore, MD: {USENIX} Association, 2018.'
  ieee: N. Engelbertz, N. Erinola, D. Herring, J. Somorovsky, V. Mladenov, and J.
    Schwenk, “Security Analysis of eIDAS -- The Cross-Country Authentication Scheme
    in Europe,” in <i>12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18)</i>,
    2018.
  mla: Engelbertz, Nils, et al. “Security Analysis of EIDAS -- The Cross-Country Authentication
    Scheme in Europe.” <i>12th {USENIX} Workshop on Offensive Technologies ({WOOT}
    18)</i>, {USENIX} Association, 2018.
  short: 'N. Engelbertz, N. Erinola, D. Herring, J. Somorovsky, V. Mladenov, J. Schwenk,
    in: 12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18), {USENIX} Association,
    Baltimore, MD, 2018.'
date_created: 2020-02-15T10:07:49Z
date_updated: 2022-01-06T06:52:40Z
extern: '1'
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/node/220571
oa: '1'
place: Baltimore, MD
publication: 12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18)
publisher: '{USENIX} Association'
status: public
title: Security Analysis of eIDAS -- The Cross-Country Authentication Scheme in Europe
type: conference
user_id: '83504'
year: '2018'
...
---
_id: '15895'
author:
- first_name: Jens
  full_name: Muller, Jens
  last_name: Muller
- first_name: Vladislav
  full_name: Mladenov, Vladislav
  last_name: Mladenov
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Muller J, Mladenov V, Somorovsky J, Schwenk J. SoK: Exploiting Network Printers.
    In: <i>2017 IEEE Symposium on Security and Privacy (SP)</i>. ; 2017. doi:<a href="https://doi.org/10.1109/sp.2017.47">10.1109/sp.2017.47</a>'
  apa: 'Muller, J., Mladenov, V., Somorovsky, J., &#38; Schwenk, J. (2017). SoK: Exploiting
    Network Printers. In <i>2017 IEEE Symposium on Security and Privacy (SP)</i>.
    <a href="https://doi.org/10.1109/sp.2017.47">https://doi.org/10.1109/sp.2017.47</a>'
  bibtex: '@inproceedings{Muller_Mladenov_Somorovsky_Schwenk_2017, title={SoK: Exploiting
    Network Printers}, DOI={<a href="https://doi.org/10.1109/sp.2017.47">10.1109/sp.2017.47</a>},
    booktitle={2017 IEEE Symposium on Security and Privacy (SP)}, author={Muller,
    Jens and Mladenov, Vladislav and Somorovsky, Juraj and Schwenk, Jörg}, year={2017}
    }'
  chicago: 'Muller, Jens, Vladislav Mladenov, Juraj Somorovsky, and Jörg Schwenk.
    “SoK: Exploiting Network Printers.” In <i>2017 IEEE Symposium on Security and
    Privacy (SP)</i>, 2017. <a href="https://doi.org/10.1109/sp.2017.47">https://doi.org/10.1109/sp.2017.47</a>.'
  ieee: 'J. Muller, V. Mladenov, J. Somorovsky, and J. Schwenk, “SoK: Exploiting Network
    Printers,” in <i>2017 IEEE Symposium on Security and Privacy (SP)</i>, 2017.'
  mla: 'Muller, Jens, et al. “SoK: Exploiting Network Printers.” <i>2017 IEEE Symposium
    on Security and Privacy (SP)</i>, 2017, doi:<a href="https://doi.org/10.1109/sp.2017.47">10.1109/sp.2017.47</a>.'
  short: 'J. Muller, V. Mladenov, J. Somorovsky, J. Schwenk, in: 2017 IEEE Symposium
    on Security and Privacy (SP), 2017.'
date_created: 2020-02-15T09:37:12Z
date_updated: 2022-01-06T06:52:39Z
doi: 10.1109/sp.2017.47
extern: '1'
language:
- iso: eng
main_file_link:
- url: https://www.nds.ruhr-uni-bochum.de/research/publications/sok-exploiting-network-printers/
publication: 2017 IEEE Symposium on Security and Privacy (SP)
publication_identifier:
  isbn:
  - '9781509055333'
publication_status: published
status: public
title: 'SoK: Exploiting Network Printers'
type: conference
user_id: '83504'
year: '2017'
...
---
_id: '15912'
author:
- first_name: Martin
  full_name: Grothe, Martin
  last_name: Grothe
- first_name: Tobias
  full_name: Niemann, Tobias
  last_name: Niemann
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Jörg
  full_name: Schwenk, Jörg
  last_name: Schwenk
citation:
  ama: 'Grothe M, Niemann T, Somorovsky J, Schwenk J. Breaking and Fixing Gridcoin.
    In: <i>11th {USENIX} Workshop on Offensive Technologies ({WOOT} 17)</i>. Vancouver,
    BC: {USENIX} Association; 2017.'
  apa: 'Grothe, M., Niemann, T., Somorovsky, J., &#38; Schwenk, J. (2017). Breaking
    and Fixing Gridcoin. In <i>11th {USENIX} Workshop on Offensive Technologies ({WOOT}
    17)</i>. Vancouver, BC: {USENIX} Association.'
  bibtex: '@inproceedings{Grothe_Niemann_Somorovsky_Schwenk_2017, place={Vancouver,
    BC}, title={Breaking and Fixing Gridcoin}, booktitle={11th {USENIX} Workshop on
    Offensive Technologies ({WOOT} 17)}, publisher={{USENIX} Association}, author={Grothe,
    Martin and Niemann, Tobias and Somorovsky, Juraj and Schwenk, Jörg}, year={2017}
    }'
  chicago: 'Grothe, Martin, Tobias Niemann, Juraj Somorovsky, and Jörg Schwenk. “Breaking
    and Fixing Gridcoin.” In <i>11th {USENIX} Workshop on Offensive Technologies ({WOOT}
    17)</i>. Vancouver, BC: {USENIX} Association, 2017.'
  ieee: M. Grothe, T. Niemann, J. Somorovsky, and J. Schwenk, “Breaking and Fixing
    Gridcoin,” in <i>11th {USENIX} Workshop on Offensive Technologies ({WOOT} 17)</i>,
    2017.
  mla: Grothe, Martin, et al. “Breaking and Fixing Gridcoin.” <i>11th {USENIX} Workshop
    on Offensive Technologies ({WOOT} 17)</i>, {USENIX} Association, 2017.
  short: 'M. Grothe, T. Niemann, J. Somorovsky, J. Schwenk, in: 11th {USENIX} Workshop
    on Offensive Technologies ({WOOT} 17), {USENIX} Association, Vancouver, BC, 2017.'
date_created: 2020-02-15T10:05:49Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/conference/woot17/workshop-program/presentation/grothe
oa: '1'
place: Vancouver, BC
publication: 11th {USENIX} Workshop on Offensive Technologies ({WOOT} 17)
publisher: '{USENIX} Association'
status: public
title: Breaking and Fixing Gridcoin
type: conference
user_id: '83504'
year: '2017'
...
---
_id: '15896'
author:
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
citation:
  ama: 'Somorovsky J. Systematic Fuzzing and Testing of TLS Libraries. In: <i>Proceedings
    of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS’16</i>.
    ; 2016. doi:<a href="https://doi.org/10.1145/2976749.2978411">10.1145/2976749.2978411</a>'
  apa: Somorovsky, J. (2016). Systematic Fuzzing and Testing of TLS Libraries. In
    <i>Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications
    Security - CCS’16</i>. <a href="https://doi.org/10.1145/2976749.2978411">https://doi.org/10.1145/2976749.2978411</a>
  bibtex: '@inproceedings{Somorovsky_2016, title={Systematic Fuzzing and Testing of
    TLS Libraries}, DOI={<a href="https://doi.org/10.1145/2976749.2978411">10.1145/2976749.2978411</a>},
    booktitle={Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications
    Security - CCS’16}, author={Somorovsky, Juraj}, year={2016} }'
  chicago: Somorovsky, Juraj. “Systematic Fuzzing and Testing of TLS Libraries.” In
    <i>Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications
    Security - CCS’16</i>, 2016. <a href="https://doi.org/10.1145/2976749.2978411">https://doi.org/10.1145/2976749.2978411</a>.
  ieee: J. Somorovsky, “Systematic Fuzzing and Testing of TLS Libraries,” in <i>Proceedings
    of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS’16</i>,
    2016.
  mla: Somorovsky, Juraj. “Systematic Fuzzing and Testing of TLS Libraries.” <i>Proceedings
    of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS’16</i>,
    2016, doi:<a href="https://doi.org/10.1145/2976749.2978411">10.1145/2976749.2978411</a>.
  short: 'J. Somorovsky, in: Proceedings of the 2016 ACM SIGSAC Conference on Computer
    and Communications Security - CCS’16, 2016.'
date_created: 2020-02-15T09:37:47Z
date_updated: 2022-01-06T06:52:39Z
doi: 10.1145/2976749.2978411
extern: '1'
language:
- iso: eng
main_file_link:
- url: https://www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2016/10/19/tls-attacker-ccs16.pdf
publication: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications
  Security - CCS'16
publication_identifier:
  isbn:
  - '9781450341394'
publication_status: published
status: public
title: Systematic Fuzzing and Testing of TLS Libraries
type: conference
user_id: '83504'
year: '2016'
...
---
_id: '15907'
author:
- first_name: Nimrod
  full_name: Aviram, Nimrod
  last_name: Aviram
- first_name: Sebastian
  full_name: Schinzel, Sebastian
  last_name: Schinzel
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Nadia
  full_name: Heninger, Nadia
  last_name: Heninger
- first_name: Maik
  full_name: Dankel, Maik
  last_name: Dankel
- first_name: Jens
  full_name: Steube, Jens
  last_name: Steube
- first_name: Luke
  full_name: Valenta, Luke
  last_name: Valenta
- first_name: David
  full_name: Adrian, David
  last_name: Adrian
- first_name: J. Alex
  full_name: Halderman, J. Alex
  last_name: Halderman
- first_name: Viktor
  full_name: Dukhovni, Viktor
  last_name: Dukhovni
- first_name: Emilia
  full_name: Käsper, Emilia
  last_name: Käsper
- first_name: Shaanan
  full_name: Cohney, Shaanan
  last_name: Cohney
- first_name: Susanne
  full_name: Engels, Susanne
  last_name: Engels
- first_name: Christof
  full_name: Paar, Christof
  last_name: Paar
- first_name: Yuval
  full_name: Shavitt, Yuval
  last_name: Shavitt
citation:
  ama: 'Aviram N, Schinzel S, Somorovsky J, et al. DROWN: Breaking TLS Using SSLv2.
    In: <i>25th {USENIX} Security Symposium ({USENIX} Security 16)</i>. Austin, TX:
    {USENIX} Association; 2016:689-706.'
  apa: 'Aviram, N., Schinzel, S., Somorovsky, J., Heninger, N., Dankel, M., Steube,
    J., … Shavitt, Y. (2016). DROWN: Breaking TLS Using SSLv2. In <i>25th {USENIX}
    Security Symposium ({USENIX} Security 16)</i> (pp. 689–706). Austin, TX: {USENIX}
    Association.'
  bibtex: '@inproceedings{Aviram_Schinzel_Somorovsky_Heninger_Dankel_Steube_Valenta_Adrian_Halderman_Dukhovni_et
    al._2016, place={Austin, TX}, title={DROWN: Breaking TLS Using SSLv2}, booktitle={25th
    {USENIX} Security Symposium ({USENIX} Security 16)}, publisher={{USENIX} Association},
    author={Aviram, Nimrod and Schinzel, Sebastian and Somorovsky, Juraj and Heninger,
    Nadia and Dankel, Maik and Steube, Jens and Valenta, Luke and Adrian, David and
    Halderman, J. Alex and Dukhovni, Viktor and et al.}, year={2016}, pages={689–706}
    }'
  chicago: 'Aviram, Nimrod, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger,
    Maik Dankel, Jens Steube, Luke Valenta, et al. “DROWN: Breaking TLS Using SSLv2.”
    In <i>25th {USENIX} Security Symposium ({USENIX} Security 16)</i>, 689–706. Austin,
    TX: {USENIX} Association, 2016.'
  ieee: 'N. Aviram <i>et al.</i>, “DROWN: Breaking TLS Using SSLv2,” in <i>25th {USENIX}
    Security Symposium ({USENIX} Security 16)</i>, 2016, pp. 689–706.'
  mla: 'Aviram, Nimrod, et al. “DROWN: Breaking TLS Using SSLv2.” <i>25th {USENIX}
    Security Symposium ({USENIX} Security 16)</i>, {USENIX} Association, 2016, pp.
    689–706.'
  short: 'N. Aviram, S. Schinzel, J. Somorovsky, N. Heninger, M. Dankel, J. Steube,
    L. Valenta, D. Adrian, J.A. Halderman, V. Dukhovni, E. Käsper, S. Cohney, S. Engels,
    C. Paar, Y. Shavitt, in: 25th {USENIX} Security Symposium ({USENIX} Security 16),
    {USENIX} Association, Austin, TX, 2016, pp. 689–706.'
date_created: 2020-02-15T09:50:14Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/node/197246
oa: '1'
page: 689-706
place: Austin, TX
publication: 25th {USENIX} Security Symposium ({USENIX} Security 16)
publication_identifier:
  isbn:
  - 978-1-931971-32-4
publisher: '{USENIX} Association'
status: public
title: 'DROWN: Breaking TLS Using SSLv2'
type: conference
user_id: '83504'
year: '2016'
...
---
_id: '15913'
author:
- first_name: Hanno
  full_name: Böck, Hanno
  last_name: Böck
- first_name: Aaron
  full_name: Zauner, Aaron
  last_name: Zauner
- first_name: Sean
  full_name: Devlin, Sean
  last_name: Devlin
- first_name: Juraj
  full_name: Somorovsky, Juraj
  id: '83504'
  last_name: Somorovsky
  orcid: 0000-0002-3593-7720
- first_name: Philipp
  full_name: Jovanovic, Philipp
  last_name: Jovanovic
citation:
  ama: 'Böck H, Zauner A, Devlin S, Somorovsky J, Jovanovic P. Nonce-Disrespecting
    Adversaries: Practical Forgery Attacks on GCM in TLS. In: <i>10th {USENIX} Workshop
    on Offensive Technologies ({WOOT} 16)</i>. Austin, TX: {USENIX} Association; 2016.'
  apa: 'Böck, H., Zauner, A., Devlin, S., Somorovsky, J., &#38; Jovanovic, P. (2016).
    Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS. In <i>10th
    {USENIX} Workshop on Offensive Technologies ({WOOT} 16)</i>. Austin, TX: {USENIX}
    Association.'
  bibtex: '@inproceedings{Böck_Zauner_Devlin_Somorovsky_Jovanovic_2016, place={Austin,
    TX}, title={Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM
    in TLS}, booktitle={10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16)},
    publisher={{USENIX} Association}, author={Böck, Hanno and Zauner, Aaron and Devlin,
    Sean and Somorovsky, Juraj and Jovanovic, Philipp}, year={2016} }'
  chicago: 'Böck, Hanno, Aaron Zauner, Sean Devlin, Juraj Somorovsky, and Philipp
    Jovanovic. “Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM
    in TLS.” In <i>10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16)</i>.
    Austin, TX: {USENIX} Association, 2016.'
  ieee: 'H. Böck, A. Zauner, S. Devlin, J. Somorovsky, and P. Jovanovic, “Nonce-Disrespecting
    Adversaries: Practical Forgery Attacks on GCM in TLS,” in <i>10th {USENIX} Workshop
    on Offensive Technologies ({WOOT} 16)</i>, 2016.'
  mla: 'Böck, Hanno, et al. “Nonce-Disrespecting Adversaries: Practical Forgery Attacks
    on GCM in TLS.” <i>10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16)</i>,
    {USENIX} Association, 2016.'
  short: 'H. Böck, A. Zauner, S. Devlin, J. Somorovsky, P. Jovanovic, in: 10th {USENIX}
    Workshop on Offensive Technologies ({WOOT} 16), {USENIX} Association, Austin,
    TX, 2016.'
date_created: 2020-02-15T10:06:33Z
date_updated: 2022-01-06T06:52:40Z
language:
- iso: eng
main_file_link:
- open_access: '1'
  url: https://www.usenix.org/conference/woot16/workshop-program/presentation/bock
oa: '1'
place: Austin, TX
publication: 10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16)
publisher: '{USENIX} Association'
status: public
title: 'Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS'
type: conference
user_id: '83504'
year: '2016'
...
