{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T01:02:09Z","timestamp":1704848529112},"reference-count":39,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2018,2,20]],"date-time":"2018-02-20T00:00:00Z","timestamp":1519084800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>An important line of privacy research is investigating the design of systems for secure input and output (I\/O) within Internet browsers. These systems would allow for users\u2019 information to be encrypted and decrypted by the browser, and the specific web applications will <jats:italic>only have access to the users\u2019 information in encrypted form<\/jats:italic>. The state-of-the-art approach for a secure I\/O system within Internet browsers is a system called ShadowCrypt created by UC Berkeley researchers [23]. This paper will explore the limitations of ShadowCrypt in order to provide a foundation for the general principles that must be followed when designing a secure I\/O system within Internet browsers. First, we developed a comprehensive UI attack that cannot be mitigated with popular UI defenses, and tested the efficacy of the attack through a user study administered on Amazon Mechanical Turk. Only 1 of the 59 participants who were under attack successfully noticed the UI attack, which validates the stealthiness of the attack. Second, we present multiple attack vectors against Shadow-Crypt that do not rely upon UI deception. These attack vectors expose the privacy weaknesses of Shadow DOM\u2014the key browser primitive leveraged by ShadowCrypt. Finally, we present a sketch of potential countermeasures that can enable the design of future secure I\/O systems within Internet browsers.<\/jats:p>","DOI":"10.1515\/popets-2018-0012","type":"journal-article","created":{"date-parts":[[2018,2,27]],"date-time":"2018-02-27T10:49:28Z","timestamp":1519728568000},"page":"47-63","source":"Crossref","is-referenced-by-count":6,"title":["Cracking ShadowCrypt: Exploring the Limitations of Secure I\/O Systems in Internet Browsers"],"prefix":"10.56553","volume":"2018","author":[{"given":"Michael","family":"Freyberger","sequence":"first","affiliation":[{"name":"Princeton University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Warren","family":"He","sequence":"additional","affiliation":[{"name":"UC Berkeley"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Devdatta","family":"Akhawe","sequence":"additional","affiliation":[{"name":"Dropbox"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michelle L.","family":"Mazurek","sequence":"additional","affiliation":[{"name":"University of Maryland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prateek","family":"Mittal","sequence":"additional","affiliation":[{"name":"Princeton University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2018,2,20]]},"reference":[{"key":"2021040916532676663_j_popets-2018-0012_ref_001_w2aab3b7b4b1b6b1ab1ab1Aa","unstructured":"[1] Company info | facebook. http:\/\/newsroom.fb.com\/company-info\/."},{"key":"2021040916532676663_j_popets-2018-0012_ref_002_w2aab3b7b4b1b6b1ab1ab2Aa","unstructured":"[2] Dom attributes now on the prototype chain. https:\/\/goo.gl\/DEitmJ."},{"key":"2021040916532676663_j_popets-2018-0012_ref_003_w2aab3b7b4b1b6b1ab1ab3Aa","unstructured":"[3] Html5 input types. http:\/\/goo.gl\/oDbNhf."},{"key":"2021040916532676663_j_popets-2018-0012_ref_004_w2aab3b7b4b1b6b1ab1ab4Aa","unstructured":"[4] Priv.ly project homepage. https:\/\/priv.ly\/."},{"key":"2021040916532676663_j_popets-2018-0012_ref_005_w2aab3b7b4b1b6b1ab1ab5Aa","unstructured":"[5] Todos | build a collaborative task app with meteor. https:\/\/www.meteor.com\/todos."},{"key":"2021040916532676663_j_popets-2018-0012_ref_006_w2aab3b7b4b1b6b1ab1ab6Aa","unstructured":"[6] Webapps\/web components april2015 meeting. https:\/\/goo.gl\/NZ0he2."},{"key":"2021040916532676663_j_popets-2018-0012_ref_007_w2aab3b7b4b1b6b1ab1ab7Aa","doi-asserted-by":"crossref","unstructured":"[7] A. Afanasyev, J. A. Halderman, S. Ruoti, K. Seamons, Y. Yu, D. Zappala, and L. Zhang. Content-based security for the web. In Proceedings of the 2016 New Security Paradigms Workshop, pages 49\u201360. ACM, 2016.","DOI":"10.1145\/3011883.3011890"},{"key":"2021040916532676663_j_popets-2018-0012_ref_008_w2aab3b7b4b1b6b1ab1ab8Aa","unstructured":"[8] Anthony. Best practices for modal windows. http:\/\/uxmovement.com\/forms\/best-practices-for-modal-windows\/, March 2011."},{"key":"2021040916532676663_j_popets-2018-0012_ref_009_w2aab3b7b4b1b6b1ab1ab9Aa","doi-asserted-by":"crossref","unstructured":"[9] A. Bianchi, J. Corbetta, L. Invernizzi, Y. Fratantonio, C. Kruegel, and G. Vigna. What the app is that? deception and countermeasures in the android user interface. In Security and Privacy (SP), 2015 IEEE Symposium on, pages 931\u2013948. IEEE, 2015.","DOI":"10.1109\/SP.2015.62"},{"key":"2021040916532676663_j_popets-2018-0012_ref_010_w2aab3b7b4b1b6b1ab1ac10Aa","doi-asserted-by":"crossref","unstructured":"[10] S. Chen, J. Meseguer, R. Sasse, H. J. Wang, and Y. M. Wang. A systematic approach to uncover security flaws in gui logic. In 2007 IEEE Symposium on Security and Privacy (SP \u201907), pages 71\u201385, May 2007.","DOI":"10.1109\/SP.2007.6"},{"key":"2021040916532676663_j_popets-2018-0012_ref_011_w2aab3b7b4b1b6b1ab1ac11Aa","unstructured":"[11] K. Collins. Google collects Android users\u2019 locations even when location services are disabled. https:\/\/qz.com\/1131515\/google-collects-android-users-locations-even-when-location-services-are-disabled\/, November 2017."},{"key":"2021040916532676663_j_popets-2018-0012_ref_012_w2aab3b7b4b1b6b1ab1ac12Aa","unstructured":"[12] D. Cooney. Shadow dom 101, January 2013. http:\/\/goo.gl\/Rbu0w."},{"key":"2021040916532676663_j_popets-2018-0012_ref_013_w2aab3b7b4b1b6b1ab1ac13Aa","unstructured":"[13] P. De Ryck, N. Nikiforakis, L. Desmet, F. Piessens, and W. Joosen. Protected web components: Hiding sensitive information in the shadows. IT Professional, 17(1):36\u201343, 2015."},{"key":"2021040916532676663_j_popets-2018-0012_ref_014_w2aab3b7b4b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"[14] R. Dhamija and J. D. Tygar. The battle against phishing: Dynamic security skins. In Proceedings of the 2005 symposium on Usable privacy and security, pages 77\u201388. ACM, 2005.","DOI":"10.1145\/1073001.1073009"},{"key":"2021040916532676663_j_popets-2018-0012_ref_015_w2aab3b7b4b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] X. Dong, Z. Chen, H. Siadati, S. Tople, P. Saxena, and Z. Liang. Protecting sensitive web content from client-side vulnerabilities with cryptons. In Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security, pages 1311\u20131324. ACM, 2013.","DOI":"10.1145\/2508859.2516743"},{"key":"2021040916532676663_j_popets-2018-0012_ref_016_w2aab3b7b4b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] S. Egelman, L. F. Cranor, and J. Hong. You\u2019ve been warned: An empirical study of the effectiveness of web browser phishing warnings. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI \u201908, pages 1065\u20131074, New York, NY, USA, 2008. ACM.","DOI":"10.1145\/1357054.1357219"},{"key":"2021040916532676663_j_popets-2018-0012_ref_017_w2aab3b7b4b1b6b1ab1ac17Aa","doi-asserted-by":"crossref","unstructured":"[17] S. Fahl, M. Harbach, T. Muders, M. Smith, and U. Sander. Helping johnny 2.0 to encrypt his facebook conversations. In Proceedings of the Eighth Symposium on Usable Privacy and Security, page 11. ACM, 2012.","DOI":"10.1145\/2335356.2335371"},{"key":"2021040916532676663_j_popets-2018-0012_ref_018_w2aab3b7b4b1b6b1ab1ac18Aa","unstructured":"[18] E. W. Felten, D. Balfanz, D. Dean, and D. S. Wallach. Web spoofing: An internet con game. Software World, 28(2):6\u20138, 1997."},{"key":"2021040916532676663_j_popets-2018-0012_ref_019_w2aab3b7b4b1b6b1ab1ac19Aa","doi-asserted-by":"crossref","unstructured":"[19] B. Fuhry, W. Tighzert, and F. Kerschbaum. Encrypting analytical web applications. In Proceedings of the 2016 ACM on Cloud Computing Security Workshop, pages 35\u201346. ACM, 2016.","DOI":"10.1145\/2996429.2996438"},{"key":"2021040916532676663_j_popets-2018-0012_ref_020_w2aab3b7b4b1b6b1ab1ac20Aa","unstructured":"[20] D. Glazkov and H. Ito. Shadow dom w3c working draft 15 december 2015, December 2015. https:\/\/goo.gl\/JgL7e8."},{"key":"2021040916532676663_j_popets-2018-0012_ref_021_w2aab3b7b4b1b6b1ab1ac21Aa","doi-asserted-by":"crossref","unstructured":"[21] C. Grier, S. Tang, and S. T. King. Secure web browsing with the op web browser. In 2008 IEEE Symposium on Security and Privacy (sp 2008), pages 402\u2013416, May 2008.","DOI":"10.1109\/SP.2008.19"},{"key":"2021040916532676663_j_popets-2018-0012_ref_022_w2aab3b7b4b1b6b1ab1ac22Aa","unstructured":"[22] D. Guarini. Experts say facebook leak of 6 million users\u2019 data might be bigger than we thought, June 2013. http:\/\/www.huffingtonpost.com\/2013\/06\/27\/facebook-leak-data_n_3510100.html."},{"key":"2021040916532676663_j_popets-2018-0012_ref_023_w2aab3b7b4b1b6b1ab1ac23Aa","doi-asserted-by":"crossref","unstructured":"[23] W. He, D. Akhawe, S. Jain, E. Shi, and D. Song. Shadowcrypt: Encrypted web applications for everyone. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201914, pages 1028\u20131039, New York, NY, USA, 2014. ACM.","DOI":"10.1145\/2660267.2660326"},{"key":"2021040916532676663_j_popets-2018-0012_ref_024_w2aab3b7b4b1b6b1ab1ac24Aa","unstructured":"[24] L.-S. Huang, A. Moshchuk, H. J. Wang, S. Schecter, and C. Jackson. Clickjacking: Attacks and defenses. In Presented as part of the 21st USENIX Security Symposium (USENIX Security 12), pages 413\u2013428, Bellevue, WA, 2012. USENIX."},{"key":"2021040916532676663_j_popets-2018-0012_ref_025_w2aab3b7b4b1b6b1ab1ac25Aa","unstructured":"[25] D. Kaminsky. Want these * bugs off my * internet. def con 23, August 2015. https:\/\/youtu.be\/9wx2TnaRSGs."},{"key":"2021040916532676663_j_popets-2018-0012_ref_026_w2aab3b7b4b1b6b1ab1ac26Aa","unstructured":"[26] D. Kaminsky. Want these * bugs off my * internet. def con 23. slide 71-72, August 2015. http:\/\/www.slideshare.net\/dakami\/i-want-these-bugs-off-my-internet-51423044."},{"key":"2021040916532676663_j_popets-2018-0012_ref_027_w2aab3b7b4b1b6b1ab1ac27Aa","unstructured":"[27] F. Lardinois. Gmail now has more than 1b monthly active users, February 2016. https:\/\/techcrunch.com\/2016\/02\/01\/gmail-now-has-more-than-1b-monthly-active-users\/."},{"key":"2021040916532676663_j_popets-2018-0012_ref_028_w2aab3b7b4b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"[28] S. Liang, Y. Zhang, B. Li, X. Guo, H. Guo, X. He, Z. Liu, and C. Jia. Shadowpwd: practical browser-based password manager with a security token. In Proceedings of the ACM Turing 50th Celebration Conference-China, page 30. ACM, 2017.","DOI":"10.1145\/3063955.3063985"},{"key":"2021040916532676663_j_popets-2018-0012_ref_029_w2aab3b7b4b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] J.-S. L\u00e9gar\u00e9, R. Sumi, and W. Aiello. Beeswax: a platform for private web apps. In Proceedings on Privacy Enhancing Technologies, pages 24\u201340. PETS, 2016.","DOI":"10.1515\/popets-2016-0014"},{"key":"2021040916532676663_j_popets-2018-0012_ref_030_w2aab3b7b4b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] A. T. Ozcan, C. Gemicioglu, K. Onarlioglu, M. Weissbacher, C. Mulliner, W. Robertson, and E. Kirda. Babelcrypt: The universal encryption layer for mobile messaging applications. In International Conference on Financial Cryptography and Data Security, pages 355\u2013369. Springer, 2015.","DOI":"10.1007\/978-3-662-47854-7_21"},{"key":"2021040916532676663_j_popets-2018-0012_ref_031_w2aab3b7b4b1b6b1ab1ac31Aa","unstructured":"[31] G. Petracca, A.-A. Reineh, Y. Sun, J. Grossklags, and T. Jaeger. Aware: Preventing abuse of privacy-sensitive sensors via operation bindings. In 26th USENIX Security Symposium, pages 379\u2013396. USENIX, 2017."},{"key":"2021040916532676663_j_popets-2018-0012_ref_032_w2aab3b7b4b1b6b1ab1ac32Aa","doi-asserted-by":"crossref","unstructured":"[32] R. A. Popa, C. M. S. Redfield, N. Zeldovich, and H. Balakrishnan. Cryptdb: Protecting confidentiality with encrypted query processing. In Proceedings of the Twenty-Third ACM Symposium on Operating Systems Principles, SOSP \u201911, pages 85\u2013100, New York, NY, USA, 2011. ACM.","DOI":"10.1145\/2043556.2043566"},{"key":"2021040916532676663_j_popets-2018-0012_ref_033_w2aab3b7b4b1b6b1ab1ac33Aa","unstructured":"[33] R. A. Popa, E. Stark, S. Valdez, J. Helfer, N. Zeldovich, and H. Balakrishnan. Building web applications on top of encrypted data using mylar. In 11th USENIX Symposium on Networked Systems Design and Implementation (NSDI 14), pages 157\u2013172, Seattle, WA, Apr. 2014. USENIX Association."},{"key":"2021040916532676663_j_popets-2018-0012_ref_034_w2aab3b7b4b1b6b1ab1ac34Aa","unstructured":"[34] C. Reber. Our future: Wunderlist joins microsoft, June 2015. https:\/\/www.wunderlist.com\/blog\/our-future-wunderlist-joins-microsoft\/."},{"key":"2021040916532676663_j_popets-2018-0012_ref_035_w2aab3b7b4b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"[35] C. Reis and S. D. Gribble. Isolating web programs in modern browser architectures. In Proceedings of the 4th ACM European Conference on Computer Systems, EuroSys \u201909, pages 219\u2013232, New York, NY, USA, 2009. ACM.","DOI":"10.1145\/1519065.1519090"},{"key":"2021040916532676663_j_popets-2018-0012_ref_036_w2aab3b7b4b1b6b1ab1ac36Aa","unstructured":"[36] S. Ruoti, D. Zappala, and K. Seamons. Messageguard: Retrofitting the web with user-to-user encryption. interface, 9:6."},{"key":"2021040916532676663_j_popets-2018-0012_ref_037_w2aab3b7b4b1b6b1ab1ac37Aa","doi-asserted-by":"crossref","unstructured":"[37] J. H. Saltzer and M. D. Schroeder. The protection of information in computer systems. Proceedings of the IEEE, 63(9):1278\u20131308, 1975.","DOI":"10.1109\/PROC.1975.9939"},{"key":"2021040916532676663_j_popets-2018-0012_ref_038_w2aab3b7b4b1b6b1ab1ac38Aa","doi-asserted-by":"crossref","unstructured":"[38] M. Wu, R. C. Miller, and S. L. Garfinkel. Do security toolbars actually prevent phishing attacks? In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI \u201906, pages 601\u2013610, New York, NY, USA, 2006. ACM.","DOI":"10.1145\/1124772.1124863"},{"key":"2021040916532676663_j_popets-2018-0012_ref_039_w2aab3b7b4b1b6b1ab1ac39Aa","doi-asserted-by":"crossref","unstructured":"[39] Z. E. Ye, S. Smith, and D. Anthony. Trusted paths for browsers. ACM Transactions on Information and System Security (TISSEC), 8(2):153\u2013186, 2005.","DOI":"10.1145\/1065545.1065546"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/content.sciendo.com\/view\/journals\/popets\/2018\/2\/article-p47.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/article\/10.1515\/popets-2018-0012","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:30:04Z","timestamp":1658334604000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2018\/popets-2018-0012.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,2,20]]},"references-count":39,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2018,2,20]]},"published-print":{"date-parts":[[2018,4,1]]}},"alternative-id":["10.1515\/popets-2018-0012"],"URL":"https:\/\/doi.org\/10.1515\/popets-2018-0012","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,2,20]]}}}