SearcharxivSearch

arXiv subjects

David Malone

Publications and source records attributed to David Malone.

17 recordsLinked to original sources

Staying at the Roach Motel: Cross-Country Analysis of Manipulative Subscription and Cancellation Flows

Subscribing to online services is typically a straightforward process, but cancelling them can be arduous and confusing -- causing many to resign and continue paying for services they no longer use. Making the cancellation intentionally difficult is recognized as a dark pattern called Roach Motel. This paper characterizes the subscription and cancellation flows of popular news websites from four different countries, and discusses them in the context of recent regulatory changes. We study the design features that make it difficult to cancel a subscription and find several cancellation flows that feature intentional barriers, such as forcing users to type in a phrase or call a representative. Further, we find many subscription flows that do not adequately inform users about recurring charges. Our results point to a growing need for effective regulation of designs that trick, coerce, or manipulate users into paying for subscriptions they do not want.

cs.HC

A Supervised Learning Approach to Rankability

The rankability of data is a recently proposed problem that considers the ability of a dataset, represented as a graph, to produce a meaningful ranking of the items it contains. To study this concept, a number of rankability measures have recently been proposed, based on comparisons to a complete dominance graph via combinatorial and linear algebraic methods. In this paper, we review these measures and highlight some questions to which they give rise before going on to propose new methods to assess rankability, which are amenable to efficient estimation. Finally, we compare these measures by applying them to both synthetic and real-life sports data.

math.CO

Quantum multi-factor authentication

We present a quantum multi-factor authentication mechanism based on the hidden-matching quantum communication complexity problem. It offers step-up graded authentication for users via a quantum token. In this paper, we outline the protocol, demonstrate that it can be used in a largely classical setting, explain how it can be implemented in SASL, and discuss arising security features. We also offer a comparison between our mechanism and current state-of-the-art multi-factor authentication mechanisms.

cs.CR

Optimal age-specific vaccination control for COVID-19: an Irish case study

The outbreak of a novel coronavirus causing severe acute respiratory syndrome in December 2019 has escalated into a worldwide pandemic. In this work, we propose a compartmental model to describe the dynamics of transmission of infection and use it to obtain the optimal vaccination control. The model accounts for the various stages of the vaccination and the optimisation is focused on minimising the infections to protect the population and relieve the healthcare system. As a case study we selected the Republic of Ireland. We use data provided by Ireland's COVID-19 Data-Hub and simulate the evolution of the pandemic with and without the vaccination in place for two different scenarios, one representative of a national lockdown situation and the other indicating looser restrictions in place. One of the main findings of our work is that the optimal approach would involve a vaccination programme where the older population is vaccinated in larger numbers earlier while simultaneously part of the younger population also gets vaccinated to lower the risk of transmission between groups. We compare our simulated results with that of the vaccination policy taken by the Irish government to explore the advantages of our optimisation method. Our comparison suggests that a similar reduction in cases may have been possible even with a reduced set of vaccinations being available for use.

math.OC

Costs and benefits of authentication advice

Authentication security advice is given with the goal of guiding users and organisations towards secure actions and practices. In this paper, we demonstrate that security advice can be ambiguous, contradictory and at times may not even have any clear benefits. We expand on current work by defining a formal approach to identifying costs of security advice and instigate a user study to identify the costs that apply to a large range of authentication advice. We also apply a simple framework for analysing the authentication related security benefits of advice. This allows us to identify costs and benefits for all classes of security advice.

cs.CR

Multi-armed bandit approach to password guessing

The multi-armed bandit is a mathematical interpretation of the problem a gambler faces when confronted with a number of different machines (bandits). The gambler wants to explore different machines to discover which machine offers the best rewards, but simultaneously wants to exploit the most profitable machine. A password guesser is faced with a similar dilemma. They have lists of leaked password sets, dictionaries of words, and demographic information about the users, but they don't know which dictionary will reap the best rewards. In this paper we provide a framework for using the multi-armed bandit problem in the context of the password guesser and use some examples to show that it can be effective.

cs.CR

Implementing a Quantum Coin Scheme

Quantum computing has the power to break current cryptographic systems, disrupting online banking, shopping, data storage and communications. Quantum computing also has the power to support stronger more resistant technologies. In this paper, we describe a digital cash scheme created by Dmitry Gavinsky, which utilises the capability of quantum computing. We contribute by setting out the methods for implementing this scheme. For both the creation and verification of quantum coins we convert the algebraic steps into computing steps. As part of this, we describe the methods used to convert information stored on classical bits to information stored on quantum bits.

quant-ph

Exploring the Impact of Password Dataset Distribution on Guessing

Leaks from password datasets are a regular occurrence. An organization may defend a leak with reassurances that just a small subset of passwords were taken. In this paper we show that the leak of a relatively small number of text-based passwords from an organizations' stored dataset can lead to a further large collection of users being compromised. Taking a sample of passwords from a given dataset of passwords we exploit the knowledge we gain of the distribution to guess other samples from the same dataset. We show theoretically and empirically that the distribution of passwords in the sample follows the same distribution as the passwords in the whole dataset. We propose a function that measures the ability of one distribution to estimate another. Leveraging this we show that a sample of passwords leaked from a given dataset, will compromise the remaining passwords in that dataset better than a sample leaked from another source.

cs.CR

Evaluating Password Advice

Password advice is constantly circulated by standards agencies, companies, websites and specialists. But there appears to be great diversity in terms of the advice that is given. Users have noticed that different websites are enforcing different restrictions. For example, requiring different combinations of uppercase and lowercase letters, numbers and special characters. We collected password advice and found that the advice distributed by one organization can directly contradict advice given by another. Our paper aims to illuminate interesting characteristics for a sample of the password advice distributed. We also create a framework for identifying the costs associated with implementing password advice. In doing so we identify a reason for why password advice is often both derided and ignored.

cs.CR

State-of-the-art in Power Line Communications: from the Applications to the Medium

In recent decades, power line communication has attracted considerable attention from the research community and industry, as well as from regulatory and standardization bodies. In this article we provide an overview of both narrowband and broadband systems, covering potential applications, regulatory and standardization efforts and recent research advancements in channel characterization, physical layer performance, medium access and higher layer specifications and evaluations. We also identify areas of current and further study that will enable the continued success of power line communication technology.

cs.NI

Rigorous and Practical Proportional-fair Allocation for Multi-rate Wi-Fi

Recent experimental studies confirm the prevalence of the widely known performance anomaly problem in current Wi-Fi networks, and report on the severe network utility degradation caused by this phenomenon. Although a large body of work addressed this issue, we attribute the refusal of prior solutions to their poor implementation feasibility with off-the-shelf hardware and their imprecise modelling of the 802.11 protocol. Their applicability is further challenged today by very high throughput enhancements (802.11n/ac) whereby link speeds can vary by two orders of magnitude. Unlike earlier approaches, in this paper we introduce the first rigorous analytical model of 802.11 stations' throughput and airtime in multi-rate settings, without sacrificing accuracy for tractability. We use the proportional-fair allocation criterion to formulate network utility maximisation as a convex optimisation problem for which we give a closed-form solution. We present a fully functional light-weight implementation of our scheme on commodity access points and evaluate this extensively via experiments in a real deployment, over a broad range of network conditions. Results demonstrate that our proposal achieves up to 100\% utility gains, can double video streaming goodput and reduces TCP download times by 8x.

cs.NI

On Efficiency and Validity of Previous Homeplug MAC Performance Analysis

The Medium Access Control protocol of Power Line Communication networks (defined in Homeplug and IEEE 1901 standards) has received relatively modest attention from the research community. As a consequence, there is only one analytic model that complies with the standardised MAC procedures and considers unsaturated conditions. We identify two important limitations of the existing analytic model: high computational expense and predicted results just prior to the predicted saturation point do not correspond to long-term network performance. In this work, we present a simplification of the previously defined analytic model of Homeplug MAC able to substantially reduce its complexity and demonstrate that the previous performance results just before predicted saturation correspond to a transitory phase. We determine that the causes of previous misprediction are common analytical assumptions and the potential occurrence of a transitory phase, that we show to be of extremely long duration under certain circumstances. We also provide techniques, both analytical and experimental, to correctly predict long-term behaviour and analyse the effect of specific Homeplug/IEEE 1901 features on the magnitude of misprediction errors.

cs.NI

Modeling, Analysis and Impact of a Long Transitory Phase in Random Access Protocols

In random access protocols, the service rate depends on the number of stations with a packet buffered for transmission. We demonstrate via numerical analysis that this state-dependent rate along with the consideration of Poisson traffic and infinite (or large enough to be considered infinite) buffer size may cause a high-throughput and extremely long (in the order of hours) transitory phase when traffic arrivals are right above the stability limit. We also perform an experimental evaluation to provide further insight into the characterisation of this transitory phase of the network by analysing statistical properties of its duration. The identification of the presence as well as the characterisation of this behaviour is crucial to avoid misprediction, which has a significant potential impact on network performance and optimisation. Furthermore, we discuss practical implications of this finding and propose a distributed and low-complexity mechanism to keep the network operating in the high-throughput phase.

cs.NI

On the Distributed Construction of a Collision-Free Schedule in WLANs

In wireless local area networks (WLANs), a media access protocol arbitrates access to the channel. In current IEEE 802.11 WLANs, carrier sense multiple access with collision avoidance (CSMA/CA) is used. Carrier sense multiple access with enhanced collision avoidance (CSMA/ECA) is a subtle variant of the well-known CSMA/CA algorithm that offers substantial performance benefits. CSMA/ECA significantly reduces the collision probability and, under certain conditions, leads to a completely collision-free schedule. The only difference between CSMA/CA and CSMA/ECA is that the latter uses a deterministic backoff after successful transmissions. This deterministic backoff is a constant and is the same for all the stations. The first part of the paper is of tutorial nature, offering an introduction to the basic operation of CSMA/ECA and describing the benefits of this approach in a qualitative manner. The second part of the paper surveys related contributions, briefly summarizing the main challenges and potential solutions, and also introducing variants and derivatives of CSMA/ECA.

cs.NI

Investigating the Distribution of Password Choices

In this paper we will look at the distribution with which passwords are chosen. Zipf's Law is commonly observed in lists of chosen words. Using password lists from four different on-line sources, we will investigate if Zipf's law is a good candidate for describing the frequency with which passwords are chosen. We look at a number of standard statistics, used to measure the security of password distributions, and see if modelling the data using Zipf's Law produces good estimates of these statistics. We then look at the the similarity of the password distributions from each of our sources, using guessing as a metric. This shows that these distributions provide effective tools for cracking passwords. Finally, we will show how to shape the distribution of passwords in use, by occasionally asking users to choose a different password.

cs.CR

Decentralised Learning MACs for Collision-free Access in WLANs

By combining the features of CSMA and TDMA, fully decentralised WLAN MAC schemes have recently been proposed that converge to collision-free schedules. In this paper we describe a MAC with optimal long-run throughput that is almost decentralised. We then design two \changed{schemes} that are practically realisable, decentralised approximations of this optimal scheme and operate with different amounts of sensing information. We achieve this by (1) introducing learning algorithms that can substantially speed up convergence to collision free operation; (2) developing a decentralised schedule length adaptation scheme that provides long-run fair (uniform) access to the medium while maintaining collision-free access for arbitrary numbers of stations.

cs.NI

Buffer Sizing for 802.11 Based Networks

We consider the sizing of network buffers in 802.11 based networks. Wireless networks face a number of fundamental issues that do not arise in wired networks. We demonstrate that the use of fixed size buffers in 802.11 networks inevitably leads to either undesirable channel under-utilization or unnecessary high delays. We present two novel dynamic buffer sizing algorithms that achieve high throughput while maintaining low delay across a wide range of network conditions. Experimental measurements demonstrate the utility of the proposed algorithms in a production WLAN and a lab testbed.

cs.NI