SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Dietmar Winkler, Bernhard Brenner and Matthias Eckhart represented the Christian Doppler Laboratory for Security and Quality Improvement in the Production System Lifecycle (CDL-SQI) at the Software Quality Days 2019.
“Früher war Sicherheit einfach Firewalls, und fertig.” Thomas Konrad berichtet im DigitalMondayBlog über einfache Fehler mit tausendfacher Auswirkung und die Verschmelzung zweier Welten. Ganzer Artikel sec4dev: Konferenz und Bootcamp Um sich genau diesen Themen zu widmen, hat SBA Research, die sec4dev für Softwareentwickler*Innen geschaffen: Von… Read More
What better way to start the New Year than with three new Bridge Projects. Wellfort is about secure storage, a trusted analysis environment, and combining data from different companies for analysis while respecting user privacy. KnoP-2D (lead SCCH) is about creativity and… Read More
“If HTTPS Were Secure, I Wouldn’t Need 2FA – End User and Administrator Mental Models of HTTPS” by Katharina Krombholz (CISPA Helmholtz Center (i.G.)), Karoline Busse (University of Bonn), Katharina Pfeffer (SBA Research), Matthew Smith (University of Bonn) and Emanuel von Zezschwitz (University of Bonn) has been accepted at the… Read More
Looking back upon the past year, we would like to acknowledge those who have helped us transform ideas into projects and shape our business. Thank you for a successful year! We wish you all the best as you embark on 2019!… Read More
While everyone seeks to be on the cutting edge of hacks and bugs, the number of rather basic issues remaining unsolved appears to flat line. The SBA Security Meetup on January 17, 2019 strives to explain why basic security measures have the potential to solve a good number of existing… Read More
“Measuring Cookies and Web Privacy in a Post-GDPR World” by Adrian Dabrowski, Georg Merzdovnik, Johanna Ullrich, Gerald Sendera and Edgar Weippl has been accepted at the 20th Passive and Active Measurements Conference (PAM). The paper investigates the impact of the General Data Protection Regulation (GDPR) on the use… Read More
SBA is partner of the Women&Code Hackathon 2019. The initiative launched by Barbara Ondrisek and Eva Lettner offers free programming courses for starters with the main objective to bring more women into IT. Read more… Read More
Manuel Leithner (MaTRIS Research Group) presented his paper titled “DOMdiff: Identification and Classification of Inter-DOM Modifications” (Joint work with Dimitris E. Simos) at the IEEE/WIC/ACM International Conference on Web Intelligence 2018 (WI2018), which took place in Santiago, Chile, from 2nd to 5th of December. The paper was published… Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. ∞
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. ∞