For this #ThrowbackThursday, we will look at #ACSAC2024's Web Security and Privacy session. The links in this thread will lead you to the paper pdfs and the slide decks, so be sure to check them out! 1/6
First in the session came Dafalla et al.'s "Web-Armour: Mitigating Reconnaissance and Vulnerability Scanning with Scan-Impeding Delays in Web Deployments," which incurs delays of up to 396x in online settings. (https://www.acsac.org/2024/program/final/s190.html) 2/6
#InternetSecurity #CyberDefense
Continuing the session, we had Solomos et al.'s "Harnessing Multiplicity: Granular Browser Extension Fingerprinting through User Configurations," exploring the #PrivacyRisks of browser extension fingerprinting. (https://www.acsac.org/2024/program/final/s193.html) 3/6
#Cybersecurity #BrowserFingerprinting
Following that was Kondracki et al.'s "Ready or Not, Here I Come: Characterizing the Security of Prematurely-public Web Applications," revealing insights into web security gaps due to early #TLS certificate announcements. (https://www.acsac.org/2024/program/final/s195.html) 4/6
#WebSecurity #WebScanning
Thereafter came Shin et al.'s "You Only Perturb Once: Bypassing (Robust) Ad-Blockers Using Universal Adversarial Perturbations", revealing vulnerabilities in ATS models to universal adversarial attacks. (https://www.acsac.org/2024/program/final/s363.html) 5/6
#Privacy #AdversarialAttacks #WebSecurity
Concluding the session was Syrmoudis et al.'s "A Longitudinal Analysis of Corporate Data Portability Practices Across Industries," revealing stagnation in #DataPortability compliance and challenges in fostering competition. (https://www.acsac.org/2024/program/final/s53.html) 6/6
#DigitalMarket