Public list by greenonion

Security engineering papers

Based on https://twitter.com/grittygrease/status/1028769194643353600

Singularity - Microsoft Research (2003)

https://www.microsoft.com/en-us/research/project/singularity/

Nick Sullivan: "A series of works derived from the Midori advanced development OS project."

almost 8 years ago

Ceremony Design and Analysis - Carl Ellison (2007)

https://eprint.iacr.org/2007/399.pdf

Nick Sullivan: "This paper introduces the idea of a ceremony as a generalization of a security protocol, formalizing the often overlooked human element."

almost 8 years ago

Format String Attacks - Tim Newsham (2000)

http://forum.ouah.org/FormatString.PDF

Nick Sullivan: "Still one of the most pervasive security issues, format string vulnerabilities demonstrate the dangers of mixing abstractions."

almost 8 years ago

This World of Ours - James Mickens (2014)

https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Nick Sullivan: "A comedic article that helps emphasize the difference between targeted attacks by well-resourced adversaries and the more pedestrian threats faced by the general populace."

almost 8 years ago

Improving SSL Warnings: Comprehension and Adherence - Adrienne Porter Felt et al. (2015)

http://delivery.acm.org/10.1145/2710000/2702442/p2893-felt.pdf?__acm__=1535698623_eb2e8a306c72900fa54b16429e2ce945&acc=OA&id=2702442&ip=185.6.78.166&key=4D4702B0C3E38B35.4D4702B0C3E38B35.4D4702B0C3E38B35.5945DC2EABF3343C

Nick Sullivan: "A data-driven study of how well/poorly user interfaces express security features to users in web browsers."

almost 8 years ago

Reflections on Trusting Trust - Ken Thompson (1984)

https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf

Nick Sullivan: "This paper succinctly describes the concept that it's not enough to trust software, you also need to trust the software that compiles the software, and the software that compiles the compiler, and so on."

almost 8 years ago