Research

My research broadly lies in web and mobile security, with a particular focus on how real-world systems deviate from the intended security model and how these gaps can be measured and exploited.

Certificate validation in mobile and in-app browsers Link to heading

Measurement of the phishing ecosystem Link to heading

Privacy leakage in the Android ecosystem Link to heading

Security of web infrastructure Link to heading