activity
20182020
collaborators

6 papers

cs.CR2020

Exploring HTTPS Security Inconsistencies: A Cross-Regional Perspective

Eman Salem Alashwali, Pawel Szalachowski, Andrew Martin

If two or more identical HTTPS clients, located at different geographic locations (regions), make an HTTPS request to the same domain (e.g. example.com), on the same day, will they…

cs.CR2019

Towards Forward Secure Internet Traffic

Eman Salem Alashwali, Pawel Szalachowski, Andrew Martin

Forward Secrecy (FS) is a security property in key-exchange algorithms which guarantees that a compromise in the secrecy of a long-term private-key does not compromise the secrecy…

cs.CR2019

Does "www." Mean Better Transport Layer Security?

Eman Salem Alashwali, Pawel Szalachowski, Andrew Martin

Experience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with "www" sub-domains, e.g. "example.com") as synonyms for their equ…

cs.CR2018

On the Feasibility of Fine-Grained TLS Security Configurations in Web Browsers Based on the Requested Domain Name

Eman Salem Alashwali, Kasper Rasmussen

Most modern web browsers today sacrifice optimal TLS security for backward compatibility. They apply coarse-grained TLS configurations that support (by default) legacy versions of…

cs.CR2018

DSTC: DNS-based Strict TLS Configurations

Eman Salem Alashwali, Pawel Szalachowski

Most TLS clients such as modern web browsers enforce coarse-grained TLS security configurations. They support legacy versions of the protocol that have known design weaknesses, and…

cs.CR2018

What's in a Downgrade? A Taxonomy of Downgrade Attacks in the TLS Protocol and Application Protocols Using TLS

Eman Salem Alashwali, Kasper Rasmussen

A number of important real-world protocols including the Transport Layer Security (TLS) protocol have the ability to negotiate various security-related choices such as the protocol…