General information
Staff
Seminars / Courses
Project involvement
Publications
Education
Press releases
Upcoming / Past events
Job opportunities
Contact information
|
Abstracts:
Martin R. Albrecht,
King's College London
Rikke Bjerg Jensen,
Royal Holloway University
London
At-Compromise Security: The Case for Alert Blindness
We start from the observation in prior work (Blanchette’12) that cryptography broadly intuits security goals – as modelled in games or ideal functionalities – while claiming realism. This stands in contrast to cryptography’s attentive approach towards examining assumptions and constructions through cryptanalysis and reductions. To close this gap, we introduce a technique for determining security goals. Given that games and ideal functionalities model specific social relations between various honest and adversarial parties, our methodology is ethnography: a careful social science methodology for studying social relations in their contexts. As a first application of this technique, i.e. ethnography in cryptography, we study security at-compromise (neither pre- nor post-) and introduce the security goal of alert blindness. Specifically, in our 2024/2025 six-and-a-half-month ethnographic fieldwork with protesters in Kenya, we observed that alert blindness captures a security goal of abducted persons who were taken by Kenyan security forces for their presumed activism. We discussed both the notion and the construction with some interlocutors in Kenya.
Joint work with Simone Colombo and Benjamin Dowling.
https://ia.cr/2026/252
Ralf Bendrath,
Advisor on Civil Liberties, Justice and Home Affairs, Greens/EFA in the European Parliament
Thomas Lohninger
epicenter.works
Throwing your rights under the Omnibus – how the EU's reform agenda threatens to erase a decade of digital rights
The EU Commission has an agenda. What started with the report of former European Central Bank chief Mario Draghi on Europe's "competitiveness" has quickly turned into "getting rid of bureaucracy", then into "simplification", and finally open "deregulation". What this means is that a large number of European laws that were adopted in the last decade to ensure sustainability, protect human rights along the whole supply chain, or to ensure our digital rights, are watered down, and core elements are scrapped.
In terms of the EU's digital rulebook, a large revision has been proposed on 19th November 2025, with the "omnibus" legislation dubbed "Digital Simplification Package". This will affect rules on data protection, data governance, AI, obligations to report cybersecurity incidents, and protections against cookies and other tracking technologies. Furthermore, the EU's net neutrality rules are opened for reform by the so called Digital Networks Act.
In this talk we discuss what to expect from the new EU agenda, who is driving it and how to resists. Our goal is to leave you better informed and equipped to fight back against this deregulatory trend. This talk may contain traces of hope.
Chloé Berthélémy,
Senior Policy Advisor
EDRi
(see also EDRi Mastodon)
European Union's looming attack on encryption. State of play.
In April 2025, the European Commission announced in its ProtectEU
strategy "a Technology Roadmap on encryption, to identify and assess
technological solutions that would enable law enforcement authorities to
access encrypted data in a lawful manner". Since then, a group of 12 experts
has been recruited to develop the Roadmap. While the outcomes of their
research won't be known before 2027, this talk will give an overview of the
origin of the project, the ongoing debates on encryption at EU level and the
role of the EU in this new chapter of the Crypto-Wars, including its policies
and practices.
Matthias Meijers,
Eindhoven University of Technology
Machine-Checked Cryptography: A Selective Overview
Cryptography underpins the security of our communications and data, yet the
confidence we place in it depends on a long chain of reasoning: protocols must
achieve their intended security goals, cryptographic schemes and primitives
must satisfy their claimed security guarantees, implementations must faithfully
realize their specifications, and execution must not leak secrets through side
channels. As cryptographic systems and requirements become increasingly
complex, reliably checking this chain using traditional (largely manual)
methods becomes increasingly difficult. This challenge is further exacerbated
when relatively novel constructions and approaches must be deployed under time
pressure, as is currently the case with post-quantum cryptography.
This talk gives a selective, high-level overview of how machine-checked
reasoning can increase assurance across the cryptographic spectrum. We will
consider its potential application to the analysis of security protocols,
scheme- and primitive-level security proofs, and the correctness and
side-channel security of cryptographic implementations. Particular attention
will be given to efforts that aim to (additionally) bridge gaps between
different layers of the cryptographic stack, for example between specifications
and implementations, especially the combination of EasyCrypt and Jasmin (from
the Formosa project).
Elisa Pioldi,
Eindhoven University of Technology
GNU Taler: The ethical privacy-preserving digital payment system
GNU Taler is a private-by-design token-based payment system, that offers
cash-like privacy to customers, while ensuring honest income reporting by
merchants, making it ideal for a real-world deployment as a digital currency
since it complies with banking regulations.
The talk is divided into two parts.
The first part introduces GNU Taler, highlighting its design goals, how it
differs from cryptocurrencies and conventional electronic payment systems, and
its potential application domains.
The second part focuses on its protocols, and, at high level, on the
cryptographic primitives that enable its security and privacy guarantees, with
particular emphasis on the protocol that allows users to obtain change from
partially spent coins while preserving privacy and preventing fraud.
Björn Ruytenberg,
Vrije Universiteit Amsterdam
Now Playing in Plaintext: Extracting Audio from Hardware-Backed DRM
Digital Rights Management (DRM) protects high value audio/video content, such
as offered by major streaming services. Prior research has extensively studied
DRM security, finding design flaws and cryptographic weaknesses in
software-based DRM (e.g. MovieStealer, youtube-dlp, WideLeak, Narrowbeer).
More recent work focuses on higher security tiers, including similar flaws in
hybrid software-hardware tiers (e.g. Security Explorations), and TEE
implementation bugs in hardware tiers (e.g. Wideshears).
We introduce DReaMcatcher, a class break attack that enables bit-perfect
extraction of DRM-protected audio under hardware-backed, maximum security
tiers. Using a lightweight hypervisor and VMI techniques, it exploits a
critical design oversight, without breaking security protocols and
cryptographic primitives, relying on leaked keys, or exploiting TEE
implementation vulnerabilities.
We validate our approach against major streaming services, including Netflix
and Spotify, and demonstrate plaintext extraction under state of the art,
hardware-based DRM technologies, including Microsoft PlayReady SL3000 and
Google Widevine L1. Our proof of concept operates transparently to the OS and
remains effective despite user space, kernel space and device driver
attestation, as well as trusted execution-based runtime defenses.
DReaMcatcher has been disclosed to affected vendors in September 2025, with
vendor mitigations pending today. Given DReaMcatcher exploits a critical
design oversight, however, we believe it would be reasonable to assume it
cannot be fixed, and likely requires an HD Audio standard and silicon
redesign.
Beyond DReaMcatcher, we examine the security tradeoffs of these 'strong' DRM
tiers: they rely on highly privileged black-box code that is difficult to
audit, potentially creating hidden attack surfaces and risk. We also discuss
the privacy implications of device-unique DRM identifiers for licensing,
especially in web browsing, where they can become a durable user tracking
primitive. We close by showing why current secure audio paths fail
architecturally, and what that means for DRM's future.
Carmela Troncoso,
Max Planck Institute for
Security and Privacy
Why PETs are not always the solution to surveillance
When talking about surveillance, privacy enhancing technologies (PETs)
immediately come to mind as the solution. This is because PETs can minimize the
amount of data being available, and that should end surveillance capabilities.
But the reason why surveillance is believed to not be good for society is not
that data is available but the consequences of that availability. In this talk,
we discuss the role and limitations of PETs in preventing these harmful consequences.
.Back to current page for Security in Times of Surveillance.
|