/ W&I / EiΨ


 
 


General information
Staff
Seminars / Courses
Project involvement
Publications
Education
Press releases
Upcoming /
Past events

Job opportunities
Contact information

Logo - Security in Times of Surveillance

Abstracts:

Martin R. Albrecht, King's College London
Rikke Bjerg Jensen, Royal Holloway University London
At-Compromise Security: The Case for Alert Blindness
We start from the observation in prior work (Blanchette’12) that cryptography broadly intuits security goals – as modelled in games or ideal functionalities – while claiming realism. This stands in contrast to cryptography’s attentive approach towards examining assumptions and constructions through cryptanalysis and reductions. To close this gap, we introduce a technique for determining security goals. Given that games and ideal functionalities model specific social relations between various honest and adversarial parties, our methodology is ethnography: a careful social science methodology for studying social relations in their contexts. As a first application of this technique, i.e. ethnography in cryptography, we study security at-compromise (neither pre- nor post-) and introduce the security goal of alert blindness. Specifically, in our 2024/2025 six-and-a-half-month ethnographic fieldwork with protesters in Kenya, we observed that alert blindness captures a security goal of abducted persons who were taken by Kenyan security forces for their presumed activism. We discussed both the notion and the construction with some interlocutors in Kenya.
Joint work with Simone Colombo and Benjamin Dowling. https://ia.cr/2026/252

Ralf Bendrath, Advisor on Civil Liberties, Justice and Home Affairs, Greens/EFA in the European Parliament
Thomas Lohninger epicenter.works
Throwing your rights under the Omnibus – how the EU's reform agenda threatens to erase a decade of digital rights
The EU Commission has an agenda. What started with the report of former European Central Bank chief Mario Draghi on Europe's "competitiveness" has quickly turned into "getting rid of bureaucracy", then into "simplification", and finally open "deregulation". What this means is that a large number of European laws that were adopted in the last decade to ensure sustainability, protect human rights along the whole supply chain, or to ensure our digital rights, are watered down, and core elements are scrapped.
In terms of the EU's digital rulebook, a large revision has been proposed on 19th November 2025, with the "omnibus" legislation dubbed "Digital Simplification Package". This will affect rules on data protection, data governance, AI, obligations to report cybersecurity incidents, and protections against cookies and other tracking technologies. Furthermore, the EU's net neutrality rules are opened for reform by the so called Digital Networks Act.
In this talk we discuss what to expect from the new EU agenda, who is driving it and how to resists. Our goal is to leave you better informed and equipped to fight back against this deregulatory trend. This talk may contain traces of hope.

Chloé Berthélémy, Senior Policy Advisor EDRi (see also EDRi Mastodon)
European Union's looming attack on encryption. State of play.
In April 2025, the European Commission announced in its ProtectEU strategy "a Technology Roadmap on encryption, to identify and assess technological solutions that would enable law enforcement authorities to access encrypted data in a lawful manner". Since then, a group of 12 experts has been recruited to develop the Roadmap. While the outcomes of their research won't be known before 2027, this talk will give an overview of the origin of the project, the ongoing debates on encryption at EU level and the role of the EU in this new chapter of the Crypto-Wars, including its policies and practices.

Matthias Meijers, Eindhoven University of Technology
Machine-Checked Cryptography: A Selective Overview
Cryptography underpins the security of our communications and data, yet the confidence we place in it depends on a long chain of reasoning: protocols must achieve their intended security goals, cryptographic schemes and primitives must satisfy their claimed security guarantees, implementations must faithfully realize their specifications, and execution must not leak secrets through side channels. As cryptographic systems and requirements become increasingly complex, reliably checking this chain using traditional (largely manual) methods becomes increasingly difficult. This challenge is further exacerbated when relatively novel constructions and approaches must be deployed under time pressure, as is currently the case with post-quantum cryptography.
This talk gives a selective, high-level overview of how machine-checked reasoning can increase assurance across the cryptographic spectrum. We will consider its potential application to the analysis of security protocols, scheme- and primitive-level security proofs, and the correctness and side-channel security of cryptographic implementations. Particular attention will be given to efforts that aim to (additionally) bridge gaps between different layers of the cryptographic stack, for example between specifications and implementations, especially the combination of EasyCrypt and Jasmin (from the Formosa project).

Elisa Pioldi, Eindhoven University of Technology GNU Taler: The ethical privacy-preserving digital payment system
GNU Taler is a private-by-design token-based payment system, that offers cash-like privacy to customers, while ensuring honest income reporting by merchants, making it ideal for a real-world deployment as a digital currency since it complies with banking regulations.
The talk is divided into two parts.
The first part introduces GNU Taler, highlighting its design goals, how it differs from cryptocurrencies and conventional electronic payment systems, and its potential application domains.
The second part focuses on its protocols, and, at high level, on the cryptographic primitives that enable its security and privacy guarantees, with particular emphasis on the protocol that allows users to obtain change from partially spent coins while preserving privacy and preventing fraud.

Björn Ruytenberg, Vrije Universiteit Amsterdam
Now Playing in Plaintext: Extracting Audio from Hardware-Backed DRM
Digital Rights Management (DRM) protects high value audio/video content, such as offered by major streaming services. Prior research has extensively studied DRM security, finding design flaws and cryptographic weaknesses in software-based DRM (e.g. MovieStealer, youtube-dlp, WideLeak, Narrowbeer). More recent work focuses on higher security tiers, including similar flaws in hybrid software-hardware tiers (e.g. Security Explorations), and TEE implementation bugs in hardware tiers (e.g. Wideshears).
We introduce DReaMcatcher, a class break attack that enables bit-perfect extraction of DRM-protected audio under hardware-backed, maximum security tiers. Using a lightweight hypervisor and VMI techniques, it exploits a critical design oversight, without breaking security protocols and cryptographic primitives, relying on leaked keys, or exploiting TEE implementation vulnerabilities.
We validate our approach against major streaming services, including Netflix and Spotify, and demonstrate plaintext extraction under state of the art, hardware-based DRM technologies, including Microsoft PlayReady SL3000 and Google Widevine L1. Our proof of concept operates transparently to the OS and remains effective despite user space, kernel space and device driver attestation, as well as trusted execution-based runtime defenses.
DReaMcatcher has been disclosed to affected vendors in September 2025, with vendor mitigations pending today. Given DReaMcatcher exploits a critical design oversight, however, we believe it would be reasonable to assume it cannot be fixed, and likely requires an HD Audio standard and silicon redesign.
Beyond DReaMcatcher, we examine the security tradeoffs of these 'strong' DRM tiers: they rely on highly privileged black-box code that is difficult to audit, potentially creating hidden attack surfaces and risk. We also discuss the privacy implications of device-unique DRM identifiers for licensing, especially in web browsing, where they can become a durable user tracking primitive. We close by showing why current secure audio paths fail architecturally, and what that means for DRM's future.

Carmela Troncoso, Max Planck Institute for Security and Privacy
Why PETs are not always the solution to surveillance
When talking about surveillance, privacy enhancing technologies (PETs) immediately come to mind as the solution. This is because PETs can minimize the amount of data being available, and that should end surveillance capabilities. But the reason why surveillance is believed to not be good for society is not that data is available but the consequences of that availability. In this talk, we discuss the role and limitations of PETs in preventing these harmful consequences.

.Back to current page for Security in Times of Surveillance.