3 papers
cs.CR2026
Half-Moon Cookie: Private, Similarity-Based Blocklisting with TOCTOU-Attack Resilience
Xinyuan Zhang, Anrin Chakraborti, Michael K. Reiter
Blocklisting is a common technique for preventing the use of known malicious content. However, conventional blocklisting infrastructures require either the blocklist to be public o…
cs.CR2026
Incentivizing Collaboration for Detection of Credential Database Breaches
Mridu Nanda, Michael K. Reiter
Decoy passwords, or ``honeywords,'' alert a site to its breach if entered in a login attempt on that site. However, an attacker can identify a user-chosen password from among the d…
cs.CR2025
Blocklisted Oblivious Pseudorandom Functions
Xinyuan Zhang, Anrin Chakraborti, Michael Reiter
An oblivious pseudorandom function (OPRF) is a protocol by which a client and server interact to evaluate a pseudorandom function on a key provided by the server and an input provi…