{"id":"https://openalex.org/W4401753099","doi":"https://doi.org/10.1109/eurosp60621.2024.00051","title":"Share with Care: Breaking E2EE in Nextcloud","display_name":"Share with Care: Breaking E2EE in Nextcloud","publication_year":2024,"publication_date":"2024-07-08","ids":{"openalex":"https://openalex.org/W4401753099","doi":"https://doi.org/10.1109/eurosp60621.2024.00051"},"language":"en","primary_location":{"id":"doi:10.1109/eurosp60621.2024.00051","is_oa":false,"landing_page_url":"https://doi.org/10.1109/eurosp60621.2024.00051","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 IEEE 9th European Symposium on Security and Privacy (EuroS&amp;amp;P)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://kclpure.kcl.ac.uk/ws/files/265989527/nextcloud-main.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066696423","display_name":"M. Albrecht","orcid":"https://orcid.org/0000-0003-1835-052X"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Martin R. Albrecht","raw_affiliation_strings":["King&#x0027;s College London,London,UK"],"affiliations":[{"raw_affiliation_string":"King&#x0027;s College London,London,UK","institution_ids":["https://openalex.org/I183935753"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052939319","display_name":"Matilda Backendal","orcid":"https://orcid.org/0000-0002-8677-8301"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Matilda Backendal","raw_affiliation_strings":["ETH Zurich, Switzerland,Zurich,Switzerland"],"affiliations":[{"raw_affiliation_string":"ETH Zurich, Switzerland,Zurich,Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054153175","display_name":"Daniele Coppola","orcid":null},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Daniele Coppola","raw_affiliation_strings":["ETH Zurich, Switzerland,Zurich,Switzerland"],"affiliations":[{"raw_affiliation_string":"ETH Zurich, Switzerland,Zurich,Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5072987600","display_name":"Kenneth G. Paterson","orcid":"https://orcid.org/0000-0002-5145-4489"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Kenneth G. Paterson","raw_affiliation_strings":["ETH Zurich, Switzerland,Zurich,Switzerland"],"affiliations":[{"raw_affiliation_string":"ETH Zurich, Switzerland,Zurich,Switzerland","institution_ids":["https://openalex.org/I35440088"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5066696423"],"corresponding_institution_ids":["https://openalex.org/I183935753"],"apc_list":null,"apc_paid":null,"fwci":1.0825,"has_fulltext":true,"cited_by_count":3,"citation_normalized_percentile":{"value":0.78702976,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"828","last_page":"840"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13999","display_name":"Digital Rights Management and Security","score":0.991100013256073,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9837999939918518,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5294587016105652}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5294587016105652}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/eurosp60621.2024.00051","is_oa":false,"landing_page_url":"https://doi.org/10.1109/eurosp60621.2024.00051","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 IEEE 9th European Symposium on Security and Privacy (EuroS&amp;amp;P)","raw_type":"proceedings-article"},{"id":"pmh:oai:kclpure.kcl.ac.uk:publications/6584bef2-5c52-473f-9917-608539cbb1b5","is_oa":true,"landing_page_url":"https://kclpure.kcl.ac.uk/portal/en/publications/6584bef2-5c52-473f-9917-608539cbb1b5","pdf_url":"https://kclpure.kcl.ac.uk/ws/files/265989527/nextcloud-main.pdf","source":{"id":"https://openalex.org/S4306400216","display_name":"Research Portal (King's College London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I183935753","host_organization_name":"King's College London","host_organization_lineage":["https://openalex.org/I183935753"],"host_organization_lineage_names":[],"type":"repository"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Albrecht, M, Backendal, M, Coppola, D & Paterson, K G 2024, Share with Care : Breaking E2EE in Nextcloud. in Euro S &P 2024. pp. 828-840. https://doi.org/10.1109/EuroSP60621.2024.00051","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"pmh:oai:kclpure.kcl.ac.uk:publications/6584bef2-5c52-473f-9917-608539cbb1b5","is_oa":true,"landing_page_url":"https://kclpure.kcl.ac.uk/portal/en/publications/6584bef2-5c52-473f-9917-608539cbb1b5","pdf_url":"https://kclpure.kcl.ac.uk/ws/files/265989527/nextcloud-main.pdf","source":{"id":"https://openalex.org/S4306400216","display_name":"Research Portal (King's College London)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I183935753","host_organization_name":"King's College London","host_organization_lineage":["https://openalex.org/I183935753"],"host_organization_lineage_names":[],"type":"repository"},"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Albrecht, M, Backendal, M, Coppola, D & Paterson, K G 2024, Share with Care : Breaking E2EE in Nextcloud. in Euro S &P 2024. pp. 828-840. https://doi.org/10.1109/EuroSP60621.2024.00051","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4401753099.pdf"},"referenced_works_count":20,"referenced_works":["https://openalex.org/W1516512945","https://openalex.org/W1516634197","https://openalex.org/W1552695147","https://openalex.org/W1561907855","https://openalex.org/W1855109561","https://openalex.org/W2082437395","https://openalex.org/W2513374167","https://openalex.org/W2546510801","https://openalex.org/W2753555060","https://openalex.org/W2765700031","https://openalex.org/W2806424702","https://openalex.org/W3083633640","https://openalex.org/W3087873898","https://openalex.org/W4289038676","https://openalex.org/W4308391724","https://openalex.org/W4365934937","https://openalex.org/W4367663818","https://openalex.org/W4384948645","https://openalex.org/W6630806230","https://openalex.org/W6722760890"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W4402327032","https://openalex.org/W2382290278"],"abstract_inverted_index":{"Nextcloud":[0,13,46,86,189],"is":[1,21,67,137],"a":[2,37,95,187,229],"leading":[3],"cloud":[4],"storage":[5],"platform":[6],"with":[7,88],"more":[8],"than":[9],"20":[10],"million":[11],"users.":[12,108],"offers":[14],"an":[15],"end-to-end":[16],"encryption":[17,71],"(E2EE)":[18],"feature":[19,227,233],"that":[20,44,51,75,81,98,242],"claimed":[22],"to":[23,56,85,106,164,191,204],"be":[24,165,235,244],"able":[25],"\u201cto":[26],"keep":[27],"extremely":[28],"sensitive":[29],"data":[30,60],"fully":[31,171],"secure":[32],"even":[33],"in":[34,63,130,150],"case":[35],"of":[36,58,118,160,231,248],"full":[38],"server":[39,47,135,190],"breach\u201d.":[40],"They":[41],"also":[42],"claim":[43],"the":[45,59,107,111,128,131,134,146,156,201,225,232],"\u201chas":[48],"Zero":[49],"Knowledge,":[50],"is,":[52],"never":[53],"has":[54],"access":[55,192],"any":[57],"or":[61],"keys":[62,80,91],"unencrypted":[64],"form\u201d.":[65],"This":[66],"achieved":[68],"by":[69,94,219],"having":[70],"and":[72,115,158,173,193,209],"decryption":[73],"operations":[74],"are":[76,82,170],"done":[77],"using":[78],"file":[79,90,222],"only":[83],"available":[84],"clients,":[87],"those":[89],"being":[92],"protected":[93],"key":[96],"hierarchy":[97],"ultimately":[99],"relies":[100],"on":[101,239],"long":[102],"passphrases":[103],"known":[104],"exclusively":[105],"We":[109,140,197,237],"provide":[110],"first":[112,216],"detailed":[113],"documentation":[114],"security":[116,124,148],"analysis":[117,129],"Nextcloud's":[119,122],"E2EE":[120,147,226,249],"feature.":[121],"strong":[123],"claims":[125],"motivate":[126],"conducting":[127],"setting":[132],"where":[133],"itself":[136],"considered":[138],"malicious.":[139],"present":[141],"three":[142,168,202],"distinct":[143],"attacks":[144,169],"against":[145],"guarantees":[149],"this":[151],"setting.":[152],"Each":[153],"one":[154],"enables":[155],"confidentiality":[157],"integrity":[159],"all":[161],"user":[162],"files":[163],"compromised.":[166],"All":[167],"practical":[172],"we":[174],"have":[175,198,212],"built":[176],"proof-of-concept":[177],"implementations":[178],"for":[179,186,246],"each.":[180],"The":[181,207,215],"vulnerabilities":[182,203,211],"make":[183],"it":[184],"trivial":[185],"malicious":[188],"manipulate":[194],"users'":[195],"data.":[196],"responsibly":[199],"disclosed":[200],"N":[205],"extcloud.":[206],"second":[208],"third":[210],"been":[213],"remediated.":[214],"was":[217],"addressed":[218],"temporarily":[220],"disabling":[221],"sharing":[223],"from":[224],"until":[228],"redesign":[230],"can":[234,243],"made.":[236],"reflect":[238],"broader":[240],"lessons":[241],"learned":[245],"designers":[247],"systems.":[250]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-17T17:19:04.345684","created_date":"2025-10-10T00:00:00"}
