Publications
BibTeX
No Results Found, Please Adjust Your Search
Generalized Power Attacks against Crypto Hardware using Long-Range Deep Learning
publications
CHES 2024
Leveraging Virtual Reality to Enhance Diversity and Inclusion training at Google
publications
CHI 2024
RETSim: Resilient and Efficient Text Similarity
publications
ICLR 2024
RETVec: Resilient and Efficient Text Vectorizer
publications
NeurIPS 2023
Hybrid Post-Quantum Signatures in Hardware Security Keys
publications
ACNS 2023
It's common and a part of being a content creator: Understanding How Creators Experience and Cope with Hate and Harassment Online
publications
CHI 2022
Designing Toxic Content Classification for a Diversity of Perspectives
publications
SOUPS 2021
SoK: Hate, Harassment, and the Changing Landscape of Online Abuse
publications
S&P 2021
Who is targeted by email-based phishing and malware? Measuring factors that differentiate risk
publications
IMC 2020
Why wouldn't someone think of democracy as a target? Security practices & challenges of people involved with U.S. political campaigns"
publications
Usenix Security 2021
Spotlight: Malware Lead Generation At Scale
publications
ACSAC 2020
Five years of the Right to Be Forgotten
publications
CCS 2019
Protecting accounts from credential stuffing with password breach alerting
publications
Usenix Security 2019
Rethinking the detection of child sexual abuse imagery on the Internet
publications
WWW 2019
They Don't Leave Us Alone Anywhere We Go - Gender and Digital Abuse in South Asia
publications
CHI 2019
Data Breaches: User Comprehension, Expectations, and Concerns with Handling Exposed Data
publications
SOUPS 2018
Tracking desktop ransomware payments end to end
publications
S&P 2018
Data Breaches, Phishing, or Malware? Understanding the Risks of Stolen Credentials
publications
CCS 2017
The first collision for full SHA-1
publications
Crypto 2017
Understanding the Mirai Botnet
publications
Usenix Security 2017
Pinning Down Abuse on Google Maps
publications
WWW 2017
The Security Impact of HTTPS Interception
publications
NDSS 2017
Picasso: Lightweight Device Class Fingerprinting for Web Clients
publications
SPSM 2016
I am a legend hacking hearthstone using statistical learning methods
publications
CIG 2016
The Abuse Sharing Economy: Understanding the Limits of Threat Exchanges
publications
RAID 2016
Investigating commercial pay-per-install and the distribution of unwanted software
publications
Usenix Security 2016
Cloak of visibility: detecting when machines browse a different web
publications
S&P 2016
Remedying web hijacking notification effectiveness and webmaster comprehension
publications
WWW 2016
Users really do plug in usb drives they find
publications
S&P 2016
Neither snow nor rain nor mitm . . . an empirical analysis of email delivery security
publications
IMC 2015
Framing dependencies introduced by underground commoditization
publications
WEIS 2015
Secrets, lies, and account recovery: lessons from the use of personal knowledge questions at google
publications
WWW 2015
Ad injection at scale: assessing deceptive advertisement modifications
publications
S&P 2015
Handcrafted fraud and extortion: manual account hijacking in the wild
publications
IMC 2014
Dialing back abuse on phone verified accounts
publications
CCS 2014
The end is nigh: generic solving of text-based captchas
publications
WOOT 2014
Cloak and swagger: understanding data sensitivity through the lens of user anonymity
publications
S&P 2014
Easy does it: more usable captchas
publications
CHI 2014
Online microsurveys for user experience research
publications
CHI 2014
Sessionjuggler secure web login from an untrusted terminal using session hijacking
publications
WWW 2012
Text-based captcha strengths and weaknesses
publications
CCS 2011
Reclaiming the blogosphere talkback a secure linkback protocol for weblogs
publications
ESORICS 2011
Towards secure embedded web interfaces
publications
Usenix Security 2011
Openconflict preventing real time map hacks in online games
publications
S&P 2011
The failure of noise-based non-continuous audio captchas
publications
S&P 2011
Kamouflage loss-resistant password management
publications
ESORICS 2010
An analysis of private browsing modes in modern browsers
publications
Usenix Security 2010
Framing attacks on smartphones and dumb routers: social sites tap-jacking and geo-localization attacks
publications
WOOT 2010
Recovering windows secrets and efs certificates offline
publications
WOOT 2010
Webseclab security education workbench
publications
CEST 2010
The emergence of cross channel scripting
publications
CACM 2010
Busting frame busting a study of clickjacking vulnerabilities on popular sites
publications
W2SP 2010
How good are humans at solving captchas a large scale evaluation
publications
S&P 2010
State of the art automated black-box web application vulnerability testing
publications
S&P 2010
Using strategy objectives for network security analysis
publications
Inscrypt 2009
Trackback spam abuse and prevention
publications
CCSW 2009
Xcs cross channel scripting and its impact on web applications
publications
CCS 2009
Decaptcha breaking 75% of ebay audio captchas
publications
WOOT 2009
Extending anticipation games with location penalty and timeline
publications
FAST 2008
Netqi a model checker for anticipation game
publications
ATVA 2008
Probabilistic protocol identification for hard to classify protocol
publications
WISTP 2008
A logical framework for evaluating network resilience against faults and attacks
publications
ASIAN 2007
Time has something to tell us about network address translation
publications
NordSec 2007