{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T16:10:48Z","timestamp":1781194248941,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,8,23]],"date-time":"2022-08-23T00:00:00Z","timestamp":1661212800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,8,23]]},"DOI":"10.1145\/3538969.3538977","type":"proceedings-article","created":{"date-parts":[[2022,8,17]],"date-time":"2022-08-17T23:41:40Z","timestamp":1660779700000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Web Cryptography API: Prevalence and Possible Developer Mistakes"],"prefix":"10.1145","author":[{"given":"Pascal","family":"Wichmann","sequence":"first","affiliation":[{"name":"Security in Distributed Systems, Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maximilian","family":"Blochberger","sequence":"additional","affiliation":[{"name":"Security in Distributed Systems, Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hannes","family":"Federrath","sequence":"additional","affiliation":[{"name":"Security in Distributed Systems, Universit\u00e4t Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,8,23]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Comparing the Usability of Cryptographic APIs. In IEEE Symposium on Security and Privacy. 154\u2013171","author":"Yasemin","unstructured":"Yasemin Acar et al. 2017. Comparing the Usability of Cryptographic APIs. In IEEE Symposium on Security and Privacy. 154\u2013171."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2010.27"},{"key":"e_1_3_2_1_3_1","unstructured":"Amit\u00a0Seal Ami et al. 2021. Why Crypto-detectors Fail: A Systematic Evaluation of Cryptographic Misuse Detection Techniques. CoRR abs\/2107.07065(2021)."},{"key":"e_1_3_2_1_4_1","unstructured":"Jenny Blessing Michael\u00a0A. Specter and Daniel\u00a0J. Weitzner. 2021. You Really Shouldn\u2019t Roll Your Own Crypto: An Empirical Study of Vulnerabilities in Cryptographic Libraries. CoRR abs\/2107.04940(2021)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.18420\/muc2019-ws-302-02"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2019.2937214"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-49100-4_5"},{"key":"e_1_3_2_1_8_1","volume-title":"Developer-Resistant Cryptography. W3C workshop on Strengthening the Internet Against Pervasive Monitoring","author":"Cairns Kelsey","year":"2014","unstructured":"Kelsey Cairns and Graham Steel. 2014. Developer-Resistant Cryptography. W3C workshop on Strengthening the Internet Against Pervasive Monitoring (2014)."},{"key":"e_1_3_2_1_9_1","unstructured":"Alexis Deveria. 2021. Can I use Web Cryptography?https:\/\/caniuse.com\/cryptography"},{"key":"e_1_3_2_1_10_1","unstructured":"Thomas\u00a0E. Dickey. 2020. LYNX \u2013 The Text Web-Browser. https:\/\/invisible-island.net\/lynx\/"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.42"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","unstructured":"Manuel Egele et al. 2013. An empirical study of cryptographic misuse in android applications. In ACM SIGSAC. 73\u201384. https:\/\/doi.org\/10.1145\/2508859.2516693","DOI":"10.1145\/2508859.2516693"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2013.6648192"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2567948.2579224"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER48275.2020.9054799"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719050"},{"key":"e_1_3_2_1_20_1","unstructured":"Ian Hickson et al. 2021. HTML Living Standard: Broadcasting to other browsing contexts. Technical Report. WHATWG. https:\/\/html.spec.whatwg.org\/commit-snapshots\/8f1841e7be5e057977ee1f42589685c961d67dac\/#broadcasting-to-other-browsing-contexts"},{"key":"e_1_3_2_1_21_1","unstructured":"Ian Hickson et al. 2021. HTML Living Standard: Session history and navigation. Technical Report. WHATWG. https:\/\/html.spec.whatwg.org\/commit-snapshots\/8f1841e7be5e057977ee1f42589685c961d67dac\/#history"},{"key":"e_1_3_2_1_22_1","unstructured":"Georgios Kontaxis and Monica Chew. 2015. Tracking Protection in Firefox For Privacy and Performance. CoRR abs\/1506.04104(2015)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115707"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"David Lazar et al. 2014. Why does cryptographic software fail?: a case study and open problems. In APSys\u201914. 7:1\u20137:7. https:\/\/doi.org\/10.1145\/2637166.2637237","DOI":"10.1145\/2637166.2637237"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion.2019.00069"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2019.04.005"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_17"},{"key":"e_1_3_2_1_29_1","volume-title":"Through Hoops\u201d: Why do Java Developers Struggle With Cryptography APIs?. In Software Engineering. 57. https:\/\/dl.gi.de\/20.500.12116\/1268","author":"Sarah Nadi","year":"2017","unstructured":"Sarah Nadi et al. 2017. \u201dJumping Through Hoops\u201d: Why do Java Developers Struggle With Cryptography APIs?. In Software Engineering. 57. https:\/\/dl.gi.de\/20.500.12116\/1268"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","unstructured":"Hoai\u00a0Viet Nguyen Luigi\u00a0Lo Iacono and Hannes Federrath. 2019. Your Cache Has Fallen: Cache-Poisoned Denial-of-Service Attack. In ACM SIGSAC. 1915\u20131936. https:\/\/doi.org\/10.1145\/3319535.3354215","DOI":"10.1145\/3319535.3354215"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240431.3240443"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2013.18"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","unstructured":"Peter Snyder Cynthia\u00a0Bagier Taylor and Chris Kanich. 2017. Most Websites Don\u2019t Need to Vibrate: A Cost-Benefit Approach to Improving Browser Security. In ACM SIGSAC. 179\u2013194. https:\/\/doi.org\/10.1145\/3133956.3133966","DOI":"10.1145\/3133956.3133966"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380203"},{"key":"e_1_3_2_1_35_1","unstructured":"Mark Watson. 2017. Web Cryptography API. W3C Recommendation. W3C. https:\/\/www.w3.org\/TR\/2017\/REC-WebCryptoAPI-20170126\/"},{"key":"e_1_3_2_1_36_1","volume-title":"25th USENIX Security Symposium. 157\u2013173","author":"Wheeler Daniel\u00a0Lowe","year":"2016","unstructured":"Daniel\u00a0Lowe Wheeler. 2016. zxcvbn: Low-Budget Password Strength Estimation. In 25th USENIX Security Symposium. 157\u2013173. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/wheeler"},{"key":"e_1_3_2_1_37_1","volume-title":"Pull request: subtlecrypto: Random key\/IV for 2nd AES-CTR encryption example (#6443). https:\/\/github.com\/mdn\/content\/pull\/6443","author":"Wichmann Pascal","unstructured":"Pascal Wichmann. 2021. Pull request: subtlecrypto: Random key\/IV for 2nd AES-CTR encryption example (#6443). https:\/\/github.com\/mdn\/content\/pull\/6443"},{"key":"e_1_3_2_1_38_1","unstructured":"Pascal Wichmann Maximilian Blochberger and Hannes Federrath. 2022. Demonstrators for Web Cryptography API Developer Mistakes. https:\/\/github.com\/wichmannpas\/webcrypto-mistakes-demonstrators"}],"event":{"name":"ARES 2022: The 17th International Conference on Availability, Reliability and Security","location":"Vienna Austria","acronym":"ARES 2022"},"container-title":["Proceedings of the 17th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3538977","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3538969.3538977","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:40Z","timestamp":1750183780000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3538977"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,23]]},"references-count":37,"alternative-id":["10.1145\/3538969.3538977","10.1145\/3538969"],"URL":"https:\/\/doi.org\/10.1145\/3538969.3538977","relation":{},"subject":[],"published":{"date-parts":[[2022,8,23]]},"assertion":[{"value":"2022-08-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}