<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:iweb="http://www.apple.com/iweb" version="2.0">
  <channel>
    <title>Konstantin (Kosta) Beznosov news</title>
    <link>http://konstantin.beznosov.net/professional/news/news.html</link>
    <description> </description>
    <generator>iWeb 3.0.1</generator>
    <item>
      <title>SOUPS Features LERSSE Research</title>
      <link>http://konstantin.beznosov.net/professional/news/Entries/2010/7/16_SOUPS_Features_LERSSE_Research.html</link>
      <guid isPermaLink="false">6112597a-e452-4428-8044-e6b211cde8f6</guid>
      <pubDate>Fri, 16 Jul 2010 09:33:19 -0700</pubDate>
      <description>&lt;a href=&quot;http://konstantin.beznosov.net/professional/news/Entries/2010/7/16_SOUPS_Features_LERSSE_Research_files/droppedImage.jpg&quot;&gt;&lt;img src=&quot;http://konstantin.beznosov.net/professional/news/Media/object001.png&quot; style=&quot;float:left; padding-right:10px; padding-bottom:10px; width:128px; height:144px;&quot;/&gt;&lt;/a&gt;LERSSE graduate students presented their research at the &lt;a href=&quot;http://cups.cs.cmu.edu/soups/2010/&quot;&gt;Symposium on Usable Security Privacy and Security (SOUPS)&lt;/a&gt;. &lt;br/&gt;&lt;br/&gt;We had posters on &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/240&quot;&gt;OpenIDemail Enabled Browser&lt;/a&gt;, &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/241&quot;&gt;Expectations, Perceptions, and Misconceptions of Personal Firewalls&lt;/a&gt;, and &lt;a href=&quot;http://livepage.apple.com/&quot;&gt;Validating and Extending a Study on the Effectiveness of SSL Warnings&lt;/a&gt;. &lt;br/&gt;&lt;br/&gt;At &lt;a href=&quot;http://cups.cs.cmu.edu/soups/2010/user.html&quot;&gt;SOUPS Workshop on Usable Security Experiment Reports (USER)&lt;/a&gt;, &lt;a href=&quot;http://www.ece.ubc.ca/~andreass/&quot;&gt;Andreas Sotirakopoulos&lt;/a&gt; discussed &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/238&quot;&gt;how study environment biases participant behaviours&lt;/a&gt;, &lt;a href=&quot;http://www.ece.ubc.ca/~motiee/&quot;&gt;Sara Motiee&lt;/a&gt; explained &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/242&quot;&gt;challenges in understanding users’ security-related knowledge, behaviour, and motivations&lt;/a&gt;, and &lt;a href=&quot;http://www.ece.ubc.ca/~hawkey/&quot;&gt;Kirstie Hawkey&lt;/a&gt; presented (for &lt;a href=&quot;http://www.ece.ubc.ca/~pooya/&quot;&gt;Pooya Jaferian&lt;/a&gt;, who could not attend SOUPS) &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/243&quot;&gt;challenges in evaluating complex IT security management systems&lt;/a&gt;. &lt;br/&gt;&lt;br/&gt;In SOUPS technical papers session, &lt;a href=&quot;http://www.ece.ubc.ca/~motiee/&quot;&gt;Sara Motiee&lt;/a&gt; &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/237&quot;&gt;presented her study of support (through LUA and UAC) for the principle of least privilege in Windows Vista and Windows 7&lt;/a&gt;.</description>
      <enclosure url="http://konstantin.beznosov.net/professional/news/Entries/2010/7/16_SOUPS_Features_LERSSE_Research_files/droppedImage.jpg" length="15651" type="image/jpeg"/>
    </item>
    <item>
      <title>LERSSE work on usable security at CHI ’10</title>
      <link>http://konstantin.beznosov.net/professional/news/Entries/2010/2/16_LERSSE_work_on_usable_security_at_CHI_10.html</link>
      <guid isPermaLink="false">3ae161d6-0b0e-403b-8c3e-0e9fbc3087c5</guid>
      <pubDate>Tue, 16 Feb 2010 15:07:36 -0800</pubDate>
      <description>&lt;a href=&quot;http://konstantin.beznosov.net/professional/news/Entries/2010/2/16_LERSSE_work_on_usable_security_at_CHI_10_files/poster.jpg&quot;&gt;&lt;img src=&quot;http://konstantin.beznosov.net/professional/news/Media/object003.png&quot; style=&quot;float:left; padding-right:10px; padding-bottom:10px; width:128px; height:144px;&quot;/&gt;&lt;/a&gt;Two posters about the research by my students Fahimeh Raja and Sara Motiee will be featured at CHI ’10. &lt;br/&gt;&lt;br/&gt;Fahimeh continued her work on the usability of personal firewalls. She interviewed participants to understand participants’ knowledge, requirements, expectations, and misconceptions for personal firewalls. &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/228&quot;&gt;Details are in the preprint of the corresponding paper&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;Sara conducted a user study and contextual interviews to understand the motives and challenges participants face when using different user accounts and the UAC approach. Most participants were not aware of or motivated to employ low-privileged accounts. Moreover, most did not understand or carefully consider the prompts. &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/229&quot;&gt;Details are in the preprint of the corresponding paper&lt;/a&gt;.</description>
      <enclosure url="http://konstantin.beznosov.net/professional/news/Entries/2010/2/16_LERSSE_work_on_usable_security_at_CHI_10_files/poster.jpg" length="237821" type="image/jpeg"/>
    </item>
    <item>
      <title>EECE 412 students star in security analysis</title>
      <link>http://konstantin.beznosov.net/professional/news/Entries/2010/1/8_EECE_412_students_star_in_security_analysis.html</link>
      <guid isPermaLink="false">277b2c6d-03aa-4efc-96d0-a729c61a2005</guid>
      <pubDate>Fri, 8 Jan 2010 13:49:32 -0800</pubDate>
      <description>&lt;a href=&quot;http://konstantin.beznosov.net/professional/news/Entries/2010/1/8_EECE_412_students_star_in_security_analysis_files/412_webpage.jpg&quot;&gt;&lt;img src=&quot;http://konstantin.beznosov.net/professional/news/Media/object001_2.jpg&quot; style=&quot;float:left; padding-right:10px; padding-bottom:10px; width:128px; height:131px;&quot;/&gt;&lt;/a&gt;Several student projects teams in my &lt;a href=&quot;http://courses.ece.ubc.ca/412/&quot;&gt;undergraduate course in computer security&lt;/a&gt; have done anexcellent job analyzing real systems and finding vulnerabilities in them. &lt;br/&gt;	•	Adnan Jiwani, Arash Malekzadeh, Neeraj Prashar, and Cloud Shao found that “Terra: Battle for the Outlands” is weak against online dictionary attacks, password snooping, denial of service, API hooks, and unauthorized e-mail sending. Their term project report provides details and suggests countermeasures.&lt;br/&gt;	•	Maxime Perreault, David Rosberg, Peter Vautour, and David Wang found a glaring vulnerability in the misconfiguration of &lt;a href=&quot;http://www.EASports.com/&quot;&gt;EASports.com&lt;/a&gt;, which would allow an attacker to gain admin access to the portal. Their term project report provides details and suggests countermeasures.&lt;br/&gt;	•	Milad Mesbah and Nima Hosseinikhah discovered vulnerabilities that allow an adversary to do game fixing at PokerStars, online dictionary attack on passwords at and denial of service attacks on accounts of Casino-On-Net, phishing attacks on the users of Rushmore. Their term project report provides details and suggests countermeasures.&lt;br/&gt;	•	Neil Gentleman, William Wong, Insoo Kwon, and Yan Yau (Keith) Kam discovered vulnerabilities in the UBC’s deployment of WPA-PEAP for ubcsecure WiFi network that would allow the adversary to recover user names and passwords of the network users. Their term project report provides details and suggests countermeasures.&lt;br/&gt;	•	Frank Ip, Ken Ho, Jonathan Wong, and Jonathan Chau discovered vulnerabilities in XT3.com web site that would allow an adversary to perform cross-site scripting attacks. Their term project report provides details and suggests countermeasures.&lt;br/&gt;	•	Jon Lee, Niel Paul, Choon-Sean (Steven) Cheong, and Dicky Bratawijaya discovered vulnerabilities in the protocol between the payment card and the reader of the UBC’s residence laundry that would allow the adversary to use the system without payment. Their term project report provides details and suggests countermeasures.&lt;br/&gt;&lt;br/&gt;The &lt;a href=&quot;http://courses.ece.ubc.ca/412/previous_years/2009/mini-conference/schedule.html&quot;&gt;web page of the course mini-conference&lt;/a&gt; contains links to the corresponding reports and video-clips summarizing the projects.</description>
      <enclosure url="http://konstantin.beznosov.net/professional/news/Entries/2010/1/8_EECE_412_students_star_in_security_analysis_files/412_webpage.jpg" length="73430" type="image/jpeg"/>
    </item>
    <item>
      <title>Security Research Advances in 2009</title>
      <link>http://konstantin.beznosov.net/professional/news/Entries/2009/11/30_Security_Research_Advances_in_2009.html</link>
      <guid isPermaLink="false">dcf697c3-bb9d-4b1f-a1e2-e31219bd40c5</guid>
      <pubDate>Mon, 30 Nov 2009 12:45:11 -0800</pubDate>
      <description>&lt;a href=&quot;http://konstantin.beznosov.net/professional/news/Entries/2009/11/30_Security_Research_Advances_in_2009_files/droppedImage.jpg&quot;&gt;&lt;img src=&quot;http://konstantin.beznosov.net/professional/news/Media/object002_1.jpg&quot; style=&quot;float:left; padding-right:10px; padding-bottom:10px; width:133px; height:15px;&quot;/&gt;&lt;/a&gt;I presented a 2009 review of academic research in computer security at &lt;a href=&quot;http://www.rebootconference.com/security2009/&quot;&gt;Vancouver International Security Conference&lt;/a&gt;. This &lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/223&quot;&gt;presentation&lt;/a&gt; reviewed latest scientific conference reports on the cutting edge research in computer security. It presented and explained 2009 highlights from IEEE Symposium in Security and Privacy, ACM Conference in Computer and Communications Security (CCS), Symposium on Network and Distributed Systems Security (NDSS), and Symposium on Usable Privacy and Security (SOUPS). </description>
      <enclosure url="http://konstantin.beznosov.net/professional/news/Entries/2009/11/30_Security_Research_Advances_in_2009_files/droppedImage.jpg" length="34455" type="image/jpeg"/>
    </item>
    <item>
      <title>Secure Web 2.0 Content Sharing Beyond Walled Gardens</title>
      <link>http://konstantin.beznosov.net/professional/news/Entries/2009/11/12_Secure_Web_2.0_Content_Sharing_Beyond_Walled_Gardens.html</link>
      <guid isPermaLink="false">0bb23c06-39da-432c-a5a9-ec0512e89d54</guid>
      <pubDate>Thu, 12 Nov 2009 06:48:52 -0800</pubDate>
      <description>&lt;a href=&quot;http://konstantin.beznosov.net/professional/news/Entries/2009/11/12_Secure_Web_2.0_Content_Sharing_Beyond_Walled_Gardens_files/system_architecture.jpg&quot;&gt;&lt;img src=&quot;http://konstantin.beznosov.net/professional/news/Media/object003_2.jpg&quot; style=&quot;float:left; padding-right:10px; padding-bottom:10px; width:129px; height:45px;&quot;/&gt;&lt;/a&gt;My Ph.D. student &lt;a href=&quot;http://www.ece.ubc.ca/~santsais/&quot;&gt;San-Tsai Sun&lt;/a&gt; will be presenting at &lt;a href=&quot;http://www.acsac.org/&quot;&gt;ACSAC&lt;/a&gt; an architecture, design, and implementation of a proposed system for Web 2.0 content sharing across content service providers (CSPs). With our approach, users use their existing email account to login to CSPs, and content owners use their email-based contact-lists to specify access policies. Users are assumed to be equipped only with a Web browser and CSPs do not need to change their existing access-control mechanisms. In addition, policy statements are URI-addressable, and the same access policies can be reused and enforced across CSPs. &lt;br/&gt;&lt;br/&gt;&lt;a href=&quot;http://lersse-dl.ece.ubc.ca/record/215&quot;&gt;Full text of the paper is available.&lt;/a&gt;&lt;br/&gt;More information can be found on &lt;a href=&quot;https://lersse.ece.ubc.ca/tiki-index.php?page=Project_MyShares&quot;&gt;the project page&lt;/a&gt;.</description>
      <enclosure url="http://konstantin.beznosov.net/professional/news/Entries/2009/11/12_Secure_Web_2.0_Content_Sharing_Beyond_Walled_Gardens_files/system_architecture.jpg" length="76721" type="image/jpeg"/>
    </item>
  </channel>
</rss>
