<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Light Blue Touchpaper &#187; Awards</title>
	<atom:link href="http://www.lightbluetouchpaper.org/category/awards/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Mon, 30 Jan 2012 10:06:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The PET Award: Nominations wanted for prestigious privacy award</title>
		<link>http://www.lightbluetouchpaper.org/2011/04/01/the-pet-award-nominations-wanted-for-prestigious-privacy-award/</link>
		<comments>http://www.lightbluetouchpaper.org/2011/04/01/the-pet-award-nominations-wanted-for-prestigious-privacy-award/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 13:56:10 +0000</pubDate>
		<dc:creator>Steven J. Murdoch</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Call for papers]]></category>
		<category><![CDATA[Internet censorship]]></category>
		<category><![CDATA[Privacy technology]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=2846</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=The+PET+Award%3A+Nominations+wanted+for+prestigious+privacy+award&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Call+for+papers&amp;rft.subject=Internet+censorship&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2011-04-01&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2011/04/01/the-pet-award-nominations-wanted-for-prestigious-privacy-award/&amp;rft.language=English"></span>
The PET Award is presented annually to researchers who have made an outstanding contribution to the theory, design, implementation, or deployment of privacy enhancing technology. It is awarded at the annual Privacy Enhancing Technologies Symposium (PETS).
The PET Award carries a prize of 3000 USD thanks to the generous support of Microsoft. The crystal prize itself [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=The+PET+Award%3A+Nominations+wanted+for+prestigious+privacy+award&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Call+for+papers&amp;rft.subject=Internet+censorship&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2011-04-01&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2011/04/01/the-pet-award-nominations-wanted-for-prestigious-privacy-award/&amp;rft.language=English"></span>
<p>The PET Award is presented annually to researchers who have made an outstanding contribution to the theory, design, implementation, or deployment of privacy enhancing technology. It is awarded at the annual Privacy Enhancing Technologies Symposium (PETS).</p>
<p>The PET Award carries a prize of 3000 USD thanks to the generous support of Microsoft. The crystal prize itself is offered by the Office of the Information and Privacy Commissioner of Ontario, Canada.</p>
<p>Any paper by any author written in the area of privacy enhancing technologies is eligible for nomination. However, the paper must have appeared in a refereed journal, conference, or workshop with proceedings published in the period from August 8, 2009 until April 15, 2011.</p>
<p>The complete award rules including eligibility requirements can be found under the <a href="http://petsymposium.org/award/rules.php">award rules</a> section of the PET Symposium website.</p>
<p>Anyone can nominate a paper by sending an email message containing the following to <a href="mailto:award-chair11@petsymposium.org">award-chair11@petsymposium.org</a>.</p>
<ul>
<li>Paper title</li>
<li>Author(s)</li>
<li>Author(s) contact information</li>
<li>Publication venue and full reference</li>
<li>Link to an available online version of the paper</li>
<li>A nomination statement of no more than 500 words.</li>
</ul>
<p>All nominations must be submitted by April 15th, 2011. The Award Committee will select one or two winners among the nominations received. Winners must be present at the PET Symposium in order to receive the Award. This requirement can be waived only at the discretion of the PET Advisory board.</p>
<p>More information about the PET award (including past winners) is available at <a href="http://petsymposium.org/award/">http://petsymposium.org/award/</a></p>
<p>More information about the 2011 PET Symposium is available at <a href="http://petsymposium.org/2011">http://petsymposium.org/2011</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2011/04/01/the-pet-award-nominations-wanted-for-prestigious-privacy-award/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Capsicum: practical capabilities for UNIX</title>
		<link>http://www.lightbluetouchpaper.org/2010/08/12/capsicum-practical-capabilities-for-unix/</link>
		<comments>http://www.lightbluetouchpaper.org/2010/08/12/capsicum-practical-capabilities-for-unix/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 02:57:37 +0000</pubDate>
		<dc:creator>Robert N. M. Watson</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Operating systems]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=2349</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Capsicum%3A+practical+capabilities+for+UNIX&amp;rft.aulast=Watson&amp;rft.aufirst=Robert&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Operating+systems&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2010-08-12&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2010/08/12/capsicum-practical-capabilities-for-unix/&amp;rft.language=English"></span>
Today, Jonathan Anderson, Ben Laurie, Kris Kennaway, and I presented Capsicum: practical capabilities for UNIX at the 19th USENIX Security Symposium in Washington, DC; the slides can be found on the Capsicum web site. We argue that capability design principles fill a gap left by discretionary access control (DAC) and mandatory access control (MAC) in [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Capsicum%3A+practical+capabilities+for+UNIX&amp;rft.aulast=Watson&amp;rft.aufirst=Robert&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Operating+systems&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2010-08-12&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2010/08/12/capsicum-practical-capabilities-for-unix/&amp;rft.language=English"></span>
<p>Today, Jonathan Anderson, Ben Laurie, Kris Kennaway, and I presented <a href="http://www.cl.cam.ac.uk/research/security/capsicum/papers/2010usenix-security-capsicum-website.pdf">Capsicum: practical capabilities for UNIX</a> at the <a href="http://www.usenix.org/events/sec10/">19th USENIX Security Symposium</a> in Washington, DC; the <a href="http://www.cl.cam.ac.uk/research/security/capsicum/slides/20100811-usenix-capsicum.pdf">slides</a> can be found on the <a href="http://www.cl.cam.ac.uk/research/security/capsicum/">Capsicum web site</a>. We argue that capability design principles fill a gap left by discretionary access control (DAC) and mandatory access control (MAC) in operating systems when supporting security-critical and security-aware applications.</p>
<p>Capsicum responds to the trend of application compartmentalisation (sometimes called privilege separation) by providing strong and well-defined isolation primitives, and by facilitating rights delegation driven by the application (and eventually, user). These facilities prove invaluable, not just for traditional security-critical programs such as tcpdump and OpenSSH, but also complex security-aware applications that map distributed security policies into local primitives, such as Google&#8217;s Chromium web browser, which implement the same-origin policy when sandboxing JavaScript execution.</p>
<p>Capsicum extends POSIX with a new <i>capability mode</i> for processes, and <i>capability</i> file descriptor type, as well as supporting primitives such as <i>process descriptors</i>. Capability mode denies access to global operating system namespaces, such as the file system and IPC namespaces: only delegated rights (typically via file descriptors or more refined capabilities) are available to sandboxes. We prototyped Capsicum on FreeBSD 9.x, and have extended a variety of applications, including Google&#8217;s Chromium web browser, to use Capsicum for sandboxing. Our paper discusses design trade-offs, both in Capsicum and in applications, as well as a performance analysis. Capsicum is available under a BSD license.</p>
<p>Capsicum is collaborative research between the University of Cambridge and Google, and has been sponsored by Google, and will be a foundation for future work on application security, sandboxing, and security usability at Cambridge and Google. Capsicum has also been backported to FreeBSD 8.x, and Heradon Douglas at Google has an in-progress port to Linux.</p>
<p>We&#8217;re also pleased to report the Capsicum paper won Best Student Paper award at the conference!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2010/08/12/capsicum-practical-capabilities-for-unix/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>IEEE best paper award</title>
		<link>http://www.lightbluetouchpaper.org/2010/05/18/ieee-best-paper-award/</link>
		<comments>http://www.lightbluetouchpaper.org/2010/05/18/ieee-best-paper-award/#comments</comments>
		<pubDate>Tue, 18 May 2010 20:05:19 +0000</pubDate>
		<dc:creator>Ross Anderson</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Banking security]]></category>
		<category><![CDATA[News coverage]]></category>
		<category><![CDATA[Protocols]]></category>
		<category><![CDATA[Security engineering]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=2089</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=IEEE+best+paper+award&amp;rft.aulast=Anderson&amp;rft.aufirst=Ross&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.subject=News+coverage&amp;rft.subject=Protocols&amp;rft.subject=Security+engineering&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2010-05-18&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2010/05/18/ieee-best-paper-award/&amp;rft.language=English"></span>
Steven Murdoch, Saar Drimer, Mike Bond and I have just won the IEEE Security and Privacy Symposium&#8217;s Best Practical Paper award for our paper Chip and PIN is Broken. This was an unexpected pleasure, given the very strong competition this year (especially from this paper). We won this award once before, in 2008, for a [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=IEEE+best+paper+award&amp;rft.aulast=Anderson&amp;rft.aufirst=Ross&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.subject=News+coverage&amp;rft.subject=Protocols&amp;rft.subject=Security+engineering&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2010-05-18&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2010/05/18/ieee-best-paper-award/&amp;rft.language=English"></span>
<p>Steven Murdoch, Saar Drimer, Mike Bond and I have just won the IEEE Security and Privacy Symposium&#8217;s Best Practical Paper award for our paper <a href="http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/">Chip and PIN is Broken</a>. This was an unexpected pleasure, given the very strong competition this year (especially from <a href="http://www.autosec.org/pubs/cars-oakland2010.pdf">this paper</a>). We won this award once before, in 2008, for a paper on a <a href="http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/">similar topic</a>.</p>
<p><img src="/wp-content/uploads/2010/05/ross_mike_saar_steven1-mod1.jpg" alt="Ross, Mike, Saar, Steven (photo by Joseph Bonneau)" /></p>
<p><strong>Update</strong> (2010-05-28): The photo now includes the full team (<a href="/wp-content/uploads/2010/05/steven_ross.jpg">original version</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2010/05/18/ieee-best-paper-award/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>PET Award 2008</title>
		<link>http://www.lightbluetouchpaper.org/2008/07/24/pet-award-2008/</link>
		<comments>http://www.lightbluetouchpaper.org/2008/07/24/pet-award-2008/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 10:50:23 +0000</pubDate>
		<dc:creator>Steven J. Murdoch</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Privacy technology]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=349</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=PET+Award+2008&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-07-24&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/07/24/pet-award-2008/&amp;rft.language=English"></span>
At last year&#8217;s Privacy Enhancing Technologies Symposium (PETS), I presented the paper &#8220;Sampled Traffic Analysis by Internet-Exchange-Level Adversaries&#8221;, co-authored with Piotr Zieliński. In it, we discussed the risk of traffic-analysis at Internet exchanges (IXes). We then showed that given even a small fraction of the data passing through an IX it was still possible to [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=PET+Award+2008&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-07-24&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/07/24/pet-award-2008/&amp;rft.language=English"></span>
<p>At last year&#8217;s <a href="http://www.petsymposium.org/">Privacy Enhancing Technologies Symposium (PETS)</a>, I presented the paper &#8220;Sampled Traffic Analysis by Internet-Exchange-Level Adversaries&#8221;, co-authored with <a href="http://www.cl.cam.ac.uk/~pz215/">Piotr Zieliński</a>. In it, we discussed the risk of traffic-analysis at Internet exchanges (IXes). We then showed that given even a small fraction of the data passing through an IX it was still possible to track a substantial proportion of anonymous communications. Our results are summarized in a previous <a href="http://www.lightbluetouchpaper.org/2007/05/28/sampled-traffic-analysis-by-internet-exchange-level-adversaries/">blog post</a> and full details are in the <a href="http://www.cl.cam.ac.uk/~sjm217/papers/pet07ixanalysis.pdf">paper</a>.</p>
<p>Our paper has now been announced as a runner-up for the <a href="http://petworkshop.org/award/">Privacy Enhancing Technologies Award</a>. The prize is presented annually, for research which makes an outstanding contribution to the field. Microsoft, the sponsor of the award, have further details and summaries of the papers in their <a href="http://www.microsoft.com/emea/presscentre/pressreleases/23072008_PETSFS.mspx">press release</a>.</p>
<p>Congratulations to the winners, Arvind Narayanan and Vitaly Shmatikov, for <a href="http://www.cs.utexas.edu/~shmat/shmat_oak08netflix.pdf">&#8220;Robust De-Anonymization of Large Sparse Datasets&#8221;</a>; and the other runner-ups, Mira Belenkiy, Melissa Chase, C. Chris Erway, John Jannotti, Alptekin Küpçü, Anna Lysyanskaya and Erich Rachlin, for <a href="http://www.cs.brown.edu/~mira/papers/wpes07.pdf">&#8220;Making P2P Accountable without Losing Privacy&#8221;</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2008/07/24/pet-award-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Covert channel vulnerabilities in anonymity systems&#8221; wins best thesis award</title>
		<link>http://www.lightbluetouchpaper.org/2008/06/03/covert-channel-vulnerabilities-in-anonymity-systems-wins-best-thesis-award/</link>
		<comments>http://www.lightbluetouchpaper.org/2008/06/03/covert-channel-vulnerabilities-in-anonymity-systems-wins-best-thesis-award/#comments</comments>
		<pubDate>Tue, 03 Jun 2008 09:57:41 +0000</pubDate>
		<dc:creator>Steven J. Murdoch</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Hardware & signals]]></category>
		<category><![CDATA[Privacy technology]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=334</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=%26%238220%3BCovert+channel+vulnerabilities+in+anonymity+systems%26%238221%3B+wins+best+thesis+award&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Hardware+%26%23038%3B+signals&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-06-03&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/06/03/covert-channel-vulnerabilities-in-anonymity-systems-wins-best-thesis-award/&amp;rft.language=English"></span>
My PhD thesis &#8220;Covert channel vulnerabilities in anonymity systems&#8221; has been awarded this year&#8217;s best thesis prize by the ERCIM security and trust management working group. The announcement can be found on the working group homepage and I&#8217;ve been invited to give a talk at their upcoming workshop, STM 08, Trondheim, Norway, 16&#8211;17 June 2008.
Update [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=%26%238220%3BCovert+channel+vulnerabilities+in+anonymity+systems%26%238221%3B+wins+best+thesis+award&amp;rft.aulast=Murdoch&amp;rft.aufirst=Steven+J.&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Hardware+%26%23038%3B+signals&amp;rft.subject=Privacy+technology&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-06-03&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/06/03/covert-channel-vulnerabilities-in-anonymity-systems-wins-best-thesis-award/&amp;rft.language=English"></span>
<p>My <a href="http://www.lightbluetouchpaper.org/2007/12/10/covert-channel-vulnerabilities-in-anonymity-systems/">PhD thesis</a> &#8220;Covert channel vulnerabilities in anonymity systems&#8221; has been awarded this year&#8217;s best thesis prize by the <a href="http://www.ercim.org/">ERCIM</a> security and trust management working group. The announcement can be found on the <a href="http://www.iit.cnr.it/STM-WG/">working group homepage</a> and I&#8217;ve been invited to give a talk at their upcoming workshop, <a href="http://www.isac.uma.es/stm08/">STM 08</a>, Trondheim, Norway, 16&#8211;17 June 2008.</p>
<p><strong>Update</strong> 2007-07-07: ERCIM have also published a <a href="http://www.ercim.org/content/view/196/60/">press release</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2008/06/03/covert-channel-vulnerabilities-in-anonymity-systems-wins-best-thesis-award/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PED vulnerability paper receives &#8220;Most Practical Paper&#8221; award at Oakland</title>
		<link>http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/</link>
		<comments>http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/#comments</comments>
		<pubDate>Wed, 21 May 2008 09:56:48 +0000</pubDate>
		<dc:creator>Saar Drimer</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Banking security]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=327</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=PED+vulnerability+paper+receives+%26%238220%3BMost+Practical+Paper%26%238221%3B+award+at+Oakland&amp;rft.aulast=Drimer&amp;rft.aufirst=Saar&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-05-21&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/&amp;rft.language=English"></span>
In February, Steven Murdoch, Ross Anderson and I reported our findings on system-level failures of widely deployed PIN Entry Devices (PED) and the Chip and PIN scheme as a whole. Steven is in Oakland presenting the work described in our paper at the IEEE Symposium on Security and Privacy (slides).
We are very pleased that we [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=PED+vulnerability+paper+receives+%26%238220%3BMost+Practical+Paper%26%238221%3B+award+at+Oakland&amp;rft.aulast=Drimer&amp;rft.aufirst=Saar&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-05-21&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/&amp;rft.language=English"></span>
<p>In February, Steven Murdoch, Ross Anderson and I <a href="http://www.lightbluetouchpaper.org/2008/02/26/chip-pin-terminals-vulnerable-to-simple-attacks/">reported our findings</a> on system-level failures of widely deployed PIN Entry Devices (PED) and the Chip and PIN scheme as a whole. Steven is in Oakland presenting the work described in our <a href="http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-711.pdf">paper</a> at the <a href="http://www.ieee-security.org/TC/SP2008/oakland08.html">IEEE Symposium on Security and Privacy</a> (<a href="http://www.cl.cam.ac.uk/~sjm217/talks/oakland08tamper.pdf">slides</a>).</p>
<p>We are very pleased that we are the recipients of the new &#8220;<a href="http://www.ieee-security.org/TC/SP2008/oakland08-cfp.html">Most Practical Paper</a>&#8221; award of the conference, given to &#8220;the paper most likely to immediately improve the security of current environments and systems&#8221;. Thanks to everyone who supported this work!</p>
<p style="text-align: center;"><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/06/award.jpg" alt="IEEE Security &#038; Privacy Magazine Award" width="290" height="360" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2008/05/21/ped-vulnerability-paper-receives-most-practical-paper-award-at-oakland/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Award Winners #2</title>
		<link>http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/</link>
		<comments>http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 23:30:00 +0000</pubDate>
		<dc:creator>Richard Clayton</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Award+Winners+%232&amp;rft.aulast=Clayton&amp;rft.aufirst=Richard&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-03-31&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/&amp;rft.language=English"></span>
Two years ago, almost exactly, I wrote:

Congratulations to Steven J. Murdoch and George Danezis who were recently awarded the Computer Laboratory Lab Ring (the local alumni association) award for the “most notable publication” (that’s notable as in jolly good) for the past year, written by anyone in the whole lab.

Well this year, it&#8217;s the turn [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Award+Winners+%232&amp;rft.aulast=Clayton&amp;rft.aufirst=Richard&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2008-03-31&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/&amp;rft.language=English"></span>
<p>Two years ago, almost exactly, <a href="http://www.lightbluetouchpaper.org/2006/03/31/award-winners/">I wrote</a>:</p>
<blockquote><p>
Congratulations to Steven J. Murdoch and George Danezis who were recently awarded the Computer Laboratory Lab Ring (the local alumni association) award for the “most notable publication” (that’s notable as in jolly good) for the past year, written by anyone in the whole lab.
</p></blockquote>
<p>Well this year, it&#8217;s the turn of <a href="http://www.cl.cam.ac.uk/~twm29/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a> to win, for our <a href="http://www.apwg.org/ecrimeresearch/2007/program.html">APWG paper</a>: <a href="http://www.cl.cam.ac.uk/~rnc1/ecrime07.pdf">Examining the Impact of Website Take-down on Phishing</a>.</p>
<p>The obligatory posed photo, showing that we both own ties (!), is courtesy of the Science Editor of the Economist.</p>
<p><img width="420" src='http://www.lightbluetouchpaper.org/wp-content/uploads/2008/03/award2008.jpg' alt='Tyler Moore and Richard Clayton, most notable publication 2008' /><br />
<strong>Tyler Moore and Richard Clayton, most notable publication 2008</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2008/03/31/award-winners-2/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>A conspicuous contribution !</title>
		<link>http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/</link>
		<comments>http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 17:40:46 +0000</pubDate>
		<dc:creator>Richard Clayton</dc:creator>
				<category><![CDATA[Awards]]></category>
		<category><![CDATA[News coverage]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=A+conspicuous+contribution+%21&amp;rft.aulast=Clayton&amp;rft.aufirst=Richard&amp;rft.subject=Awards&amp;rft.subject=News+coverage&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-12-04&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/&amp;rft.language=English"></span>
When people are up for an award at the Oscars or some other prestigious event, they generally know all about it beforehand. So they turn up on the day with an impromptu speech tucked away in a pocket and they&#8217;ve a glassy smile to hand when it turns out that they&#8217;ve been overlooked for yet [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=A+conspicuous+contribution+%21&amp;rft.aulast=Clayton&amp;rft.aufirst=Richard&amp;rft.subject=Awards&amp;rft.subject=News+coverage&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-12-04&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/&amp;rft.language=English"></span>
<p>When people are up for an award at the <a href="http://www.oscars.org">Oscars</a> or <a href="http://www.razzies.com">some other prestigious event</a>, they generally know all about it beforehand. So they turn up on the day with an <a href="http://www.myvillage.com/pages/celebs-oscars-worst-speeches.htm">impromptu speech</a> tucked away in a pocket and they&#8217;ve a <a href="http://goldderby.latimes.com/awards_goldderby/2007/11/oscars-poll---6.html">glassy smile</a> to hand when it turns out that they&#8217;ve been overlooked for yet another year&#8230;</p>
<p>&#8230; <a href="https://www.linx.net">LINX</a>, the London Internet Exchange, doesn&#8217;t work that way, so I&#8217;d no previous inkling when they recently gave me their 2007 award for a &#8220;conspicuous contribution&#8221;.</p>
<p><img src='http://www.lightbluetouchpaper.org/wp-content/uploads/2007/12/linxaward.jpg' alt='LINX conspicuous contribution award 2007' /></p>
<p>This award was first given in 2006 to <a href="http://www.zoominfo.com/Search/PersonDetail.aspx?PersonID=18174730">Nigel Titley</a>, who was a LINX council member from its 1994 formation through to 2006, and his contribution is crystal clear to all. My own was perhaps a little less obvious. I have regularly attended LINX general meetings from 1998 onwards &#8212; even after I became <a href="http://www.cl.cam.ac.uk/~rnc1/">an academic</a>, because attending LINX meetings is one of the ways that I continue to consult for <a href="http://www.thus.net">THUS plc</a> (aka <a href="http://www.demon.net">Demon Internet</a>), my previous employer. I&#8217;ve often given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/index.html">talks at meetings</a>, or just asked awkward questions of the LINX board from the floor.</p>
<p>But I suspect that the main reason that I got the award is because of my contribution to many of <a href="https://www.linx.net/good/bcpindex.html">LINX&#8217;s Best Current Practice (BCP) documents</a>, on everything from traceability to spam. These documents are hugely influential. They show the industry the best ways to do things &#8212; spreading knowledge to all of the companies, not keeping it within the largest and most competent. They show Government and the regulators that the industry is responsible and can explain why it works the way it does. They educate end-users to the best way of doing things and &#8212; when there&#8217;s a dispute with an abuse@ team &#8212; that other ISPs will take the same dim view of their spamming as their current provider (which reduces <a href="http://www.netlingo.com/lookup.cfm?term=churn">churn</a> and helps everyone to work things out sensibly).</p>
<p>Of course I haven&#8217;t worked on these documents in isolation &#8212; the whole point is that they&#8217;re a distillation of Best Practice from across the whole industry, and so there&#8217;s been dozens of people from dozens of companies attending meetings, contributing text, reading drafts, and then eventually voting for their adoption at formal LINX meetings.</p>
<p>When you step back and think about it, it&#8217;s quite remarkable that so many companies from within a fiercely competitive industry are prepared, like THUS, to put their resources into co-operation in this way. I think it&#8217;s partly far-sightedness (a belief that self-regulation is much to be preferred to the imposition of standards from outside), and partly the inherent culture of the Internet, where you cannot stand alone but have to co-operate with other companies so that your customers can interwork.</p>
<p>Anyway, when I was given the award, I should have pulled out a <a href="http://www.loc.gov/exhibits/gadd/">neat little speech</a> along the above lines, and said thank you to the whole industry, and thank you to THUS, and thank you to colleagues and particularly thank you to <a href="http://www.thus.net/aboutus/biographies.shtml#pm">Phil Male</a> who had faith that my consultancy would be of ongoing value&#8230;   but it was all a surprise and I stammered out something far less eloquent.  I&#8217;m really pleased to try and fix that now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2007/12/04/a-conspicuous-contribution/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Phishing take-down paper wins &#8216;Best Paper Award&#8217; at APWG eCrime Researcher&#8217;s Summit</title>
		<link>http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/</link>
		<comments>http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/#comments</comments>
		<pubDate>Thu, 04 Oct 2007 17:50:36 +0000</pubDate>
		<dc:creator>Tyler Moore</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Security economics]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Phishing+take-down+paper+wins+%26%238216%3BBest+Paper+Award%26%238217%3B+at+APWG+eCrime+Researcher%26%238217%3Bs+Summit&amp;rft.aulast=Moore&amp;rft.aufirst=Tyler&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Security+economics&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-10-04&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/&amp;rft.language=English"></span>
Richard Clayton and I have been tracking phishing sites for  some time.  Back in May, we reported on how quickly phishing websites are removed.  Subsequently, we have also compared the performance of banks in removing websites and found evidence that ISPs and registrars are initially slow to remove malicious websites.  
We [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Phishing+take-down+paper+wins+%26%238216%3BBest+Paper+Award%26%238217%3B+at+APWG+eCrime+Researcher%26%238217%3Bs+Summit&amp;rft.aulast=Moore&amp;rft.aufirst=Tyler&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Security+economics&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-10-04&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/&amp;rft.language=English"></span>
<p><a href="http://www.cl.cam.ac.uk/~rnc1/">Richard Clayton</a> and I have been tracking phishing sites for  some time.  Back in May, we reported on <a href="http://www.lightbluetouchpaper.org/2007/05/16/how-quickly-are-phishing-websites-taken-down/">how quickly phishing websites are removed</a>.  Subsequently, we have also <a href="http://www.lightbluetouchpaper.org/2007/08/24/phishing-website-removal-comparing-banks/">compared the performance of banks in removing websites</a> and <a href="http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/">found evidence that ISPs and registrars are initially slow to remove malicious websites</a>.  </p>
<p>We have published our updated results at <a href="http://www.ecrimeresearch.org">eCrime 2007</a>, sponsored by the <a href="http://www.antiphishing.org">Anti-Phishing Working Group</a>.  The paper, <a href="http://www.cl.cam.ac.uk/~twm29/ecrime07.pdf">&#8216;Examining the Impact of Website Take-down on Phishing&#8217;</a> (slides <a href="http://www.cl.cam.ac.uk/~twm29/ecrime07-pres.pdf">here</a>), was selected for the &#8216;Best Paper Award&#8217;.  </p>
<p>A high-level abridged description of this work also appeared in the September issue of <a href="http://www.infosecurity-magazine.com">Infosecurity Magazine</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2007/10/04/phishing-take-down-paper-wins-best-paper-award-at-apwg-ecrime-researchers-summit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Chip-and-PIN relay attack paper wins &#8220;Best Student Paper&#8221; at USENIX Security 2007</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/</link>
		<comments>http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/#comments</comments>
		<pubDate>Wed, 08 Aug 2007 20:31:01 +0000</pubDate>
		<dc:creator>Robert N. M. Watson</dc:creator>
				<category><![CDATA[Academic papers]]></category>
		<category><![CDATA[Awards]]></category>
		<category><![CDATA[Banking security]]></category>
		<category><![CDATA[Hardware & signals]]></category>

		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Chip-and-PIN+relay+attack+paper+wins+%26%238220%3BBest+Student+Paper%26%238221%3B+at+USENIX+Security+2007&amp;rft.aulast=Watson&amp;rft.aufirst=Robert&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.subject=Hardware+%26%23038%3B+signals&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-08-08&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/&amp;rft.language=English"></span>
In May 2007, Saar Drimer and Steven Murdoch posted about &#8220;Distance bounding against smartcard relay attacks&#8221;.  Today their paper won the &#8220;Best Student Paper&#8221; award at USENIX Security 2007 and their slides are now online. You can read more about this work on the Security Group&#8217;s banking security web page.

]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=Chip-and-PIN+relay+attack+paper+wins+%26%238220%3BBest+Student+Paper%26%238221%3B+at+USENIX+Security+2007&amp;rft.aulast=Watson&amp;rft.aufirst=Robert&amp;rft.subject=Academic+papers&amp;rft.subject=Awards&amp;rft.subject=Banking+security&amp;rft.subject=Hardware+%26%23038%3B+signals&amp;rft.source=Light+Blue+Touchpaper&amp;rft.date=2007-08-08&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/&amp;rft.language=English"></span>
<p>In May 2007, Saar Drimer and Steven Murdoch posted about &#8220;<a href="http://www.lightbluetouchpaper.org/2007/05/21/distance-bounding-against-smartcard-relay-attacks/">Distance bounding against smartcard relay attacks</a>&#8221;.  Today their <a href="http://www.cl.cam.ac.uk/research/security/projects/banking/relay/bounding.pdf">paper</a> won the &#8220;Best Student Paper&#8221; award at <a href="http://www.usenix.org/events/sec07/">USENIX Security 2007</a> and their <a href="http://www.cl.cam.ac.uk/~sd410/pres/usenix07_relay.pdf">slides</a> are now online. You can read more about this work on the <a href="http://www.cl.cam.ac.uk/research/security/projects/banking/">Security Group&#8217;s banking security web page</a>.</p>
<p style="text-align: center;"><a href="http://www.lightbluetouchpaper.org/wp-content/uploads/2007/08/usenix-sec07-large.jpg"><img src='http://www.lightbluetouchpaper.org/wp-content/uploads/2007/08/usenix-sec07.jpg' title='Steven and Saar at USENIX Security 2007' alt='Steven and Saar at USENIX Security 2007' /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

