26 Mar 2019

Website on Risk-based Authentication launched

Accompanying the accepted IFIP SEC paper, we launched the website rbainfo.org to inform about Risk-based Authentication (RBA) in general. The website presents the RBA state-of-the-art and discloses how eight popular online services use this technology.

Besides the paper and detailed results, the website also provides a video of the Facebook privacy leak which was discovered in the study.

German technology news website GIGA.de gave press coverage on the Facebook privacy leak, including an interview with Stephan Wiefling.

22 Aug 2018

New Cache Testing Tool published

We developed a cache testing tool based on the paper “Systematic Analysis of Web Browser Caches”. This tool allows to analyze the compliance RFC 7240 compliance of web caching systems. More details can be found here

14 Aug 2018

Paper published at Soups 2018

The paper “Developers Deserve Security Warnings, Too: On the Effect of Integrated Security Advice on Cryptographic API Misuse” by Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian Möller, Yasemin Acar, Sascha Fahl has been published at the 14th Symposium on Usable Privacy and Security (SOUPS). The conference took place from 12th - 14th August in Baltimore, MD, USA.

British technology news website The Register gave press coverage of the paper in the article “Here’s a fab idea: Get crypto libs to warn devs when they screw up”.