Real-World Deployments of Advanced Cryptography

Speaker

Kevin Yeo

Host

Henry Corrigan-Gibbs
MIT CSAIL
In this talk, I will present two real-world deployments of advanced cryptographic techniques that help improve user privacy. The first is password leak check that enables end users to determine whether their credentials appeared in a data breach without revealing any information about the queried password. By warning end users to migrate to a new password, we protect their accounts from credential stuffing attacks. The second is privacy-preserving enrollment that protects device information during the enrollment phase. When a device is first opened, a series of membership checks are performed to determine the correct end state of your device. Our deployed private set membership protocols guarantee that devices can perform these checks without revealing sensitive information about their devices.