PhD. student in Security & Privacy
- Website Fingerprinting and Defenses2020
- Rubato: Metadata-Private Messaging for Mobile Devices2020
- Decentralized Privacy-Preserving Proximity Tracing (DP3T)2020
My contribution to this large team project mostly consists of: security analysis (of the initial project PEPP-PT, then of DP3T), reviews of alternative protocols (ROBERT, DESIRE, etc), and some work on interoperability.
website, paper, some press articles: Reuters, BBC, Financial Times, Blick, Le Temps
- Traffic-Analysis of Wearable Devices over Bluetooth Classic and BLE 2019
- PriFi: Low-Latency Metadata Protection for Organizational Networks 2018
L. Barman, I. Dacosta, M. Zamani, E. Zhai, B. Ford, J. Feigenbaum, J-P. Hubaux. PETS 2020
paper, website, code
- Reducing Metadata Leakage from Encrypted Files and Communication with PURBs 2018
K. Nikitin & L. Barman, M. Underwood, W. Lueks, B. Ford, J-P. Hubaux. PETS 2019
paper, website, press article, presentation, code
- Drand & LeagueOfEntropy.com: Provable Distributed Randomness 2017
My contribution to this team project is mostly code.
website, code, various press articles
- PriFi: A Low-Latency [...] Protocol for Local-Area Anonymous Communication 2016
L. Barman, M. Zamani, I. Dacosta, J. Feigenbaum, B. Ford, J-P. Hubaux, D. Wolinsky. WPES 2016
- Mirror: Enabling Proofs of Data Replication and Retrievability in the Cloud 2015
F. Armknecht, L. Barman, J-M. Bohli, G. Karame. USENIX Security 2016
- Privacy Threats and Practical Solutions for Genetic Risk Tests 2015
L. Barman, E. Graini, J-L. Raisaro, E. Ayday, J-P. Hubaux. GenoPri 2015
Non-peer-reviewed posts, highlights on personal projects & random discussions.
- Padmé: Efficiently hiding file sizes read it 2020
An inexpensive padding function to protect the size metadata
- IoT Home Automation with 3D-Printing read it 2019
Keeping my fish and plants alive while I'm away
- A TLS downgrade attack with NetFilter's Queues and Docker read it 2017
Try your very own MitM and downgrade attack now !
- A Journey into Stack Smashing read it 2017
A first attempt at crackme's
- Should I trust the GitHub activity summary ? read it 2016
A «hello world» on GitHub
- Escaping the PyJail read it 2016
Getting out of a python sandbox
- Hunting Aurora Borealis : a Cookbook read it 2016
A step-by-step guide to finding Northern Lights
- EPFL, Lausanne : PhD in Security and Privacy, with Jean-Pierre Hubaux and Bryan Ford
started in 2015
- EPFL, Lausanne : Master in Communications Systems, specialized in Security
2013 - 2015
- NUS, Singapore : one-year exchange in Electrical Engineering & Computer Science
2012 - 2013
- EPFL, Lausanne : Bachelor in Communications Systems
2010 - 2013
Selected Past Positions
- Research Intern at Cloudflare, London
Website Fingerprinting and Defenses
- Teaching Assistant at EPFL (part of the PhD program)
In the class "Information Security and Privacy", I rebuilt the aging infrastructure in favor of a more reliable setup with dockers and Continuous Integration. I also designed several exercises such as a TLS downgrade attack & implementation of a PAKE protocol.
In the class "Mobile Networks", I helped building hands-on exercises about Wireless networks and their security/privacy aspects. I gave a lecture about Tor and the anonymity on the Web.
- Intern at NEC Laboratories Europe, Heidelberg
Master Thesis, NEC Laboratories Europe, Heidelberg
Supervised by G. Karame (NEC Laboratories Europe) and P. Oechslin (LASEC, EPFL)
- Teaching assistant at EPFL
For the class "System-oriented Programming", where students learn about SH, C, Perl, Unix.
Supervision of semester projects for students in Java, involving cryptography and networking.
- various Web Developer positions (Sunergic, CJ Online Works, JE EPFL, Intemporare)
2008 - 2019
At Sunergic, I created a Web application for monitoring Siemens solar panels. In addition, it enabled clients to design a roof (through a graphical wizard) and estimate the expected efficiency and profit of a solar installation. This application has been used by several partners of Sunergic and Romande Energie.
Note: these demos have not been updated since early 2020.
- Vaultage : a self-hosted, in-browser password manager with client-side encryption 2015-2020
Technologies: Express/Typescript, SJCL (crypto), Jest/Jasmine+Pupeteer (testing)
- TuringWars : A game where small programs fight on a shared computer! (reboot of CoreWars)2017-2019
Technologies: Scala+ScalaJS (backend), Express/Typescript/TypeORM/React/Redux (backend + frontend), Webpack/Docker. Made in 24h @ Lauzhack, then improved for a while.