Sebastian Roth

47 posts

Sebastian Roth

Sebastian Roth

@s3br0th

PostDoctoral Researcher @ TU Wien Playing CTF @ saarsec (saarsec|steg1).

Katılım Ekim 2017
138 Takip Edilen220 Takipçiler
Sebastian Roth
Sebastian Roth@s3br0th·
So if you are interested in the deployment roadblocks and strategies for Trusted Types don't forget to drop by at the User Studies VII Session on Friday!
English
0
0
0
57
Sebastian Roth retweetledi
Valeriy M., PhD, MBA, CQF
Valeriy M., PhD, MBA, CQF@predict_addict·
Conformal Prediction for predicting and prioritizing anti-cancer drug responses. 'Reliable anti-cancer drug sensitivity prediction and prioritization' Nature paper . #conformalprediction
Valeriy M., PhD, MBA, CQF tweet media
English
2
3
15
2.2K
Sebastian Roth
Sebastian Roth@s3br0th·
With the identified roadblocks and possible improvement suggestions for the mechanism, we hope to ease the deployment of Trusted Types for Web developers such that we might gain a mechanism that is both easy to use and secure! (follow-up work in progress)
English
0
0
1
90
Sebastian Roth
Sebastian Roth@s3br0th·
The biggest roadblock seems to be the sanitization of JavaScript as there is (currently) no proper way of doing so. Many ideas from the participants are bypassable. The only secure but hard-to-maintain solution would be hashes, but WebCrypto is not available in sync. contexts.
English
1
0
1
127
Sebastian Roth
Sebastian Roth@s3br0th·
It was one of the most informative and entertaining projects I ever had the opportunity to be part of. If you want to learn more about ethical and legal implications of server-side scans, read this. And if you ever get the chance to work with @fh4ntke, seize it!
Florian@fh4ntke

Can server-side scanning research be legal and ethical? For our upcoming @IEEESSP paper "Where are the red lines?" we talked to experts on law and ethics, and web operators. We discussed challenges, solutions and various fictional research scenarios. swag.cispa.saarland/papers/hantke2…

English
0
0
7
596
Sebastian Roth retweetledi
Florian
Florian@fh4ntke·
Can server-side scanning research be legal and ethical? For our upcoming @IEEESSP paper "Where are the red lines?" we talked to experts on law and ethics, and web operators. We discussed challenges, solutions and various fictional research scenarios. swag.cispa.saarland/papers/hantke2…
Florian tweet media
English
4
14
46
30.9K
Ben Stock
Ben Stock@kcotsneb·
Congratulations to my former PhD student and recent graduate Dr. @s3br0th! It has been a pleasure to accompany you on your way. Best of luck with the next career step with @matteo_maffei
Ben Stock tweet media
English
6
2
67
4.1K
Sebastian Roth retweetledi
Florian
Florian@fh4ntke·
Hey 👋 Are you responsible for a website as an operator, CISO, ..? What do you think about researchers hacking your website - OK or a no-go? Help us make security research more beneficial for operators! Learn more and sign up for an interview at server-side-study.cispa.de. Retweet🙏
Florian tweet media
English
3
11
23
58.8K
Sebastian Roth
Sebastian Roth@s3br0th·
You are a Web developer, want to learn something new, and get 50€? We are conducting a study to understand the challenges of deploying a mechanism to defend against client-side XSS. So, if you are interested, please visit survey.swag.cispa.saarland and/or share this invitation.
Sebastian Roth tweet media
English
1
10
12
0
Sebastian Roth
Sebastian Roth@s3br0th·
This security lottery does not only affect the security of end-users because attackers might choose only to attack the vulnerable population, or they succeed by pure chance due to randomness; it also sheds light on measurement inaccuracies that this randomness can cause.
English
0
0
0
0
Sebastian Roth
Sebastian Roth@s3br0th·
With our analysis, we not only found Web applications that responded with seemingly random levels of protection, but we also have seen cases where we could deterministically get less protection based on our geolocation, language setting, or the browser that we used.
English
2
0
2
0