Our work is helping inform industry best practices. For example, we are referenced in the Cloud Security Alliance's cloud security guide
and the European Network and Information Security Agency's report on cloud security.
We discovered (and helped fix) security vulnerabilities in a widely used smartphone-based point-of-sale system (used to process credit card transactions).
See the vulnerability report here.
We uncovered a new attack against the TLS record layer, uncovered weak key pairs in HMAC, and provided the first formal security analysis for PKCS#5 (password-based
cryptography).
Privacy-preserving device tracking for helping locate lost or stolen mobile devices