Categories
research security

Dropbox Security: Dark Clouds on the Horizon at USENIX’11

Back in March 2010 we started an investigation into online file storage services and Dropbox in particular. Sebastian and Manuel started to disassemble the Dropbox binary and in essence created an alternative client by patching its crypto libraries. In the months that followed we found a number of security flaws with Dropbox. In November 2010 […]

Categories
personal random research

autumn is here

Finally arrived back in Vienna last Thursday. Pittsburgh turned out to be a neat city and I had a good time there. In Australia I ran into Richard Stallman and had some great discussions on free software. Amir showed me around Sydney – thank you so much! before I ended up in Byron Bay. Below […]

Categories
fitm research security

Technical Report: Friend-in-the-Middle (FITM) Attacks

Abstract. In the ongoing arms race between spammers and the multi-million dollar anti-spam industry, the number of unsolicited e-mail messages (better known as “spam”) and phishing has increased heavily in the last decade. In this paper, we show that our novel friend-in-the-middle attack on social networking sites (SNSs) can be used to harvest social data […]