High Exposure ledge, Gunks, NY. 2019. The Dangler, Gunks, NY. 2020.

My thesis work focued on human authentication on the web, though I've also published on social networking privacy, crypto protocols, side-channel attacks, software obfuscation, and reverse engineering. I try to make full text available for all publications accepted into academic conferences and workshops as soon as possible.

My Google Scholar and Microsoft Academic pages have bibliometric data and links to citations of my papers.

Sort by year Sort by topic

2025

  • SoK: Trusted setups for powers-of-tau strings (to appear)
    Faxing Wang, Shanaan Cohney and Joseph Bonneau. FC 2025. Miyakojima, Japan.
    Citation

2024

  • NOPE: Strengthening domain authentication with zero-knowledge proofs
    Zachary DeStefano, Jeff J. Ma, Joseph Bonneau and Michael Walfish. SOSP 2024. Austin, TX, USA.
    Abstract Citation
  • How Much Public Randomness Do Modern Consensus Protocols Need? (working draft)
    Joseph Bonneau, Benedikt Bünz, Miranda Christ and Yuval Efron.
    Abstract Citation
  • Good things come to those who wait: Dishonest-Majority Coin-Flipping Requires Delay Functions (working draft)
    Joseph Bonneau, Benedikt Bünz, Miranda Christ and Yuval Efron.
    Abstract Citation
  • Atomic and Fair Data Exchange via Blockchain
    Ertem Nusret Tas, István András Seres, Yinou Zhang, Márk Melczer, Mahimna Kelkar, Joseph Bonneau and Valeria Nikolaenko. ACM CCS 2024. Salt Lake City, UT, USA.
    Abstract Citation
  • Cornucopia: Distributed randomness beacons at scale
    Miranda Christ, Kevin Choi and Joseph Bonneau. AFT 2024. Vienna, Austria.
    Abstract Citation
  • Accountable Secret Leader Election
    Walter McKelvie, Miranda Christ, Kevin Choi, Tal Malkin and Joseph Bonneau. AFT 2024. Vienna, Austria.
    Abstract Citation
  • NOTRY: Deniable messaging with retroactive avowal
    Faxing Wang, Shaanan Cohney, Riad Wahby and Joseph Bonneau. PETS 2024. Bristol, England, UK.
    Abstract Citation
  • Zombie: Middleboxes that Don’t Snoop
    Collin Zhang, Zachary DeStefano, Arasu Arun, Joseph Bonneau, Paul Grubbs and Michael Walfish. NSDI 2024. Santa Clara, CA, USA.
    Abstract Citation
  • Powers-of-Tau to the People: Decentralizing Setup Ceremonies
    Valeria Nikolaenko, Sam Ragsdale, Joseph Bonneau and Dan Boneh. ACNS 2023. Abu Dhabi, UAE.
    Abstract Citation
  • Naysayer proofs
    István András Seres, Noemi Glaeser and Joseph Bonneau. FC 2024. Willemstad, Curaçao.
    Abstract Citation

2023

  • Riggs: Decentralized Sealed-Bid Auctions
    Nirvan Tyagi, Arasu Arun, Cody Freitag, Riad Wahby, Joseph Bonneau and David Mazières. ACM CCS 2023. Copenhagen, Denmark.
    Abstract Citation
  • Cicada: Efficient tally-private elections and sealed-bid auctions from homomorphic time-lock puzzles (working draft)
    Noemi Glaeser, István András Seres, Michael Zhu and Joseph Bonneau.
    Abstract Citation
  • High Performance, Low Energy, and Trustworthy Blockchains Using Satellites
    Dennis Shasha, Taegyun Kim, Joseph Bonneau, Yan Michalevsky,, Gil Shotan and Yonatan Winetraub. Foundations and Trends in Networking.
    Abstract Citation
  • SoK: Distributed Randomness Beacons
    Kevin Choi, Aathira Manoj and Joseph Bonneau. IEEE Security & Privacy (Oakland) 2023. San Francisco, CA, USA.
    Abstract Citation
  • Proof of Necessary Work: Succinct State Verification with Fairness Guarantees
    Assimakis Kattis and Joseph Bonneau. FC 2023. Bol, Brač, Croatia.
    Abstract Citation
  • Limits on revocable proof systems, with applications to stateless blockchains
    Miranda Christ and Joseph Bonneau. FC 2023. Bol, Brač, Croatia.
    Abstract Citation
  • Bicorn: An optimistically efficient distributed randomness beacon
    Kevin Choi, Arasu Arun, Nirvan Tyagi and Joseph Bonneau. FC 2023. Bol, Brač, Croatia.
    Abstract Citation
  • Transparency, Trust, and Security Needs for the Design of Digital News Authentication Tools
    Bernat Ivancsics, Eve Washington, Errol Francis II, Ayana Monroe, Emily Sidnam-Mauch, Joseph Bonneau, Kelly Caine and Susan E. McGregor. CSCW 2023.
    Abstract Citation

2022

  • Short-lived zero-knowledge proofs and signatures
    Arasu Arun, Joseph Bonneau and Jeremy Clark. Asiacrypt 2022. Taipei, Taiwan.
    Abstract Citation
  • VeRSA: Verifiable Registries with Efficient Client Audits from RSA Authenticated Dictionaries
    Nirvan Tyagi, Ben Fisch, Andrew Zitek, Joseph Bonneau and Stefano Tessaro. ACM CCS 2022. Los Angeles, CA, USA.
    Abstract Citation
  • Zero-Knowledge Middleboxes
    Paul Grubbs, Arasu Arun, Ye Zhang, Joseph Bonneau and Michael Walfish. USENIX Security 2022. Boston, MA, USA.
    Abstract Citation
  • Usable Cryptographic Provenance Systems to Proactively Mitigate Misinformation Creation and Spread
    Emily Sidnam-Mauch, Bernat Ivancsics, Ayana Monroe, Eve Washington, Errol Francis II, Kelly Caine, Joseph Bonneau and Susan E. McGregor. MEDIATE.
    Abstract Citation
  • The Invisible Infrastructures of Online Visibility: An Analysis of the Platform-Facing Markup Used by U.S.-Based Digital News Organizations
    Bernat Ivancsics, Eve Washington, Errol Francis II, Ayana Monroe, Emily Sidnam-Mauch, Joseph Bonneau, Kelly Caine and Susan E. McGregor. Digital Journalism 2022.
    Abstract Citation

2020

  • Mina: Decentralized Cryptocurrency at Scale
    Joseph Bonneau, Izaak Meckler, Vanishree Rao and Evan Shapiro.
    Abstract Citation

2019

  • “I was told to buy a software or lose my computer. I ignored it”: A study of ransomware
    Camelia Simoiu, Christopher Gates, Joseph Bonneau and Sharad Goel. SOUPS 2019: The 15th Symposium On Usable Privacy and Security. Santa Clara, CA, USA.
    Abstract Citation
  • Scaling Proof-of-Replication for Filecoin Mining
    Ben Fisch, Joseph Bonneau, Nicola Greco and Juan Benet.
    Abstract Citation

2018

  • Verifiable Delay Functions
    Dan Boneh, Joseph Bonneau, Benedikt Bünz and Ben Fisch. CRYPTO 2018. Santa Barbara, CA, USA.
    Abstract Citation
  • Hostile blockchain takeovers
    Joseph Bonneau. BITCOIN 2018. Curaçao.
    Abstract Citation

2017

  • Certificate Transparency with Privacy
    (arXiv entry)
    Saba Eskandarian, Eran Messeri, Joseph Bonneau and Dan Boneh. PETS 2017. Minneapolis, MN, USA.
    Abstract Citation
  • Obstacles to the Adoption of Secure Communication Tools
    Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova, Alena Naiakshina and Matthew Smith. IEEE Security & Privacy (Oakland) 2017. San Francisco, CA, USA.
    Abstract Citation
  • Can Unicorns Help Users Compare Crypto Key Fingerprints?
    (supporting material)
    Joshua Tan, Lujo Bauer, Joseph Bonneau, Lorrie Faith Cranor, Jeremy Thomas and Blase Ur. CHI 2017. Denver, CO, USA.
    Abstract Citation
  • Proofs-of-delay and randomness beacons in Ethereum
    Benedikt Bünz, Steven Goldfeder and Joseph Bonneau. S&B '17: IEEE Security & Privacy on the Blockchain. Paris, France.
    Abstract Citation
  • Escrow protocols for cryptocurrencies: How to buy physical goods using Bitcoin
    Steven Goldfeder, Joseph Bonneau, Rosario Gennaro and Arvind Narayanan. FC '17: The 21st International Conference on Financial Cryptography. Silema, Malta.
    Abstract Citation

2016

  • Bitcoin and Cryptocurrency Technologies
    Arvind Narayanan, Joseph Bonneau, Edward W. Felten, Andrew Miller and Steven Goldfeder.
    Citation
  • Why buy when you can rent? Bribery attacks on Bitcoin consensus
    Joseph Bonneau. BITCOIN '16: 3rd Workshop on Bitcoin and Blockchain Research. Barbados.
    Abstract Citation
  • EthIKS: Using Ethereum to audit a CONIKS key transparency log
    Joseph Bonneau. BITCOIN '16: 3rd Workshop on Bitcoin and Blockchain Research. Barbados.
    Abstract Citation
  • Incentive Compatibility of Bitcoin Mining Pool Reward Functions
    Okke Schrijvers, Joseph Bonneau, Dan Boneh and Tim Roughgarden. FC '16: The 20th International Conference on Financial Cryptography. Barbados.
    Abstract Citation
  • The Bitcoin Brain Drain: Examining the Use and Abuse of Bitcoin Brain Wallets
    Marie Vasek, Joseph Bonneau, Ryan Castellucci, Cameron Keith and Tyler Moore. FC '16: The 20th International Conference on Financial Cryptography. Barbados.
    Abstract Citation
  • Differentially Private Password Frequency Lists
    (dataset)
    Jeremiah Blocki, Anupam Datta and Joseph Bonneau. NDSS 2016. San Diego, CA, USA.
    Abstract Citation

2015

  • On Bitcoin as a public randomness source
    Joseph Bonneau, Jeremy Clark and Steven Goldfeder .
    Abstract Citation
  • Secure Chat for the Masses? User-centered Security to the Rescue (poster)
    Ruba Abu-Salma, M. Angela Sasse and Joseph Bonneau. ACM CCS 2015. Denver, CO, USA.
    Abstract Citation
  • Provisions: Privacy-preserving proofs of solvency for Bitcoin exchanges
    (ePrint entry)
    Gaby G. Dagher, Benedikt Bünz, Joseph Bonneau, Jeremy Clark and Dan Boneh. ACM CCS 2015. Denver, CO, USA.
    Abstract Citation
  • CONIKS: Bringing Key Transparency to End Users
    Marcela S. Melara, Aaron Blankstein, Joseph Bonneau, Michael J. Freedman and Edward W. Felten. USENIX Security 2015. Washington, DC, USA.
    Abstract Citation
  • Learning Assigned Secrets for Unlocking Mobile Devices
    Stuart Schechter and Joseph Bonneau. SOUPS '15: The 11th Symposium On Usable Privacy and Security. Ottawa, Canada.
    Abstract Citation
  • Passwords and the Evolution of Imperfect Authentication
    Joseph Bonneau, Cormac Herley, Paul C. van Oorschot and Frank Stajano. Communications of the ACM.
    Abstract Citation
  • An empirical study of Namecoin and lessons for decentralized namespace design
    Harry Kalodner, Miles Carlsten, Paul Ellenbogen, Joseph Bonneau and Arvind Narayanan. WEIS '15: The 14th Workshop on the Economics of Information Security. Delft, Netherlands.
    Abstract Citation
  • Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google
    Joseph Bonneau, Elie Bursztein, Ilan Caron, Rob Jackson and Mike Williamson. 25th International World Wide Web Conference (WWW).
    Abstract Citation
  • SoK: Secure Messaging
    (abridged paper)
    Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg and Matthew Smith. Security & Privacy (Oakland) 2015. San Francisco, CA, USA.
    Abstract Citation
  • Research Perspectives and Challenges for Bitcoin and Cryptocurrencies
    Joseph Bonneau, Andrew Miller, Jeremy Clark, Arvind Narayanan, Joshua A. Kroll and Edward W. Felten. Security & Privacy (Oakland) 2015. San Francisco, CA, USA.
    Abstract Citation
  • Cracking-Resistant Password Vaults using Natural Language Encoders
    Rahul Chatterjee, Joseph Bonneau, Ari Juels and Thomas Ristenpart. Security & Privacy (Oakland) 2015. San Francisco, CA, USA.
    Abstract Citation
  • Upgrading HTTPS in Mid-Air: An Empirical Study of Strict Transport Security and Key Pinning
    Michael Kranch and Joseph Bonneau. NDSS 2015. San Diego, CA, USA.
    Abstract Citation

2014

  • Cognitive Disconnect: Understanding Facebook Connect Login Permissions
    (abridged version)
    Nicky Robinson and Joseph Bonneau. COSN '14: ACM Conference on Online Social Networks. Dublin, Ireland.
    Abstract Citation
  • Towards reliable storage of 56-bit secrets in human memory
    (abridged version)
    Joseph Bonneau and Stuart Schechter. USENIX Security 2014. San Diego, CA, USA.
    Abstract Citation
  • Clarity of Facebook Connect login permissions (poster)
    Nicky Robinson and Joseph Bonneau. SOUPS 2014: The 10th Symposium On Usable Privacy and Security. Menlo Park, CA, USA.
    Abstract Citation
  • Privacy concerns of implicit secondary factors for web authentication
    Joseph Bonneau, Edward W. Felten, Prateek Mittal and Arvind Narayanan. WAY 2014: Who are you?! Adventures in Authentication Workshop. Menlo Park, CA, USA.
    Citation
  • On Decentralizing Prediction Markets and Order Books
    Jeremy Clark, Joseph Bonneau, Edward W. Felten, Joshua A. Kroll, Andrew Miller and Arvind Narayanan. WEIS '14: The 13th Workshop on the Economics of Information Security. State College, PA, USA.
    Abstract Citation
  • Fawkescoin: A cryptocurrency without public-key cryptography
    Joseph Bonneau and Andrew Miller. 22nd International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation
  • Mixcoin: Anonymity for Bitcoin with accountable mixes
    (abridged version) (ePrint entry)
    Joseph Bonneau, Arvind Narayanan, Andrew Miller, Jeremy Clark, Joshua A. Kroll and Edward W. Felten. FC '14: The 18th International Conference on Financial Cryptography. Barbados.
    Abstract Citation
  • The Tangled Web of Password Reuse
    Anupam Das, Joseph Bonneau, Matthew Caesar, Nikita Borisov and XiaoFeng Wang. NDSS 2014. San Diego, CA, USA.
    Abstract Citation

2013

  • S-links: Why distributed security policy requires secure introduction
    Joseph Bonneau. Web 2.0 Security & Privacy. San Francisco, CA, USA.
    Abstract Citation

2012

  • Of contraseñas, סיסמאות, and 密码: Character encoding issues for web passwords
    Joseph Bonneau and Rubin Xu. Web 2.0 Security & Privacy. San Francisco, CA, USA.
    Abstract Citation
  • The science of guessing: analyzing an anonymized corpus of 70 million passwords
    (source code)
    Joseph Bonneau. Security & Privacy (Oakland) 2012. San Francisco, CA, USA.
    Abstract Citation
  • The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes
    (full-length technical report)
    Joseph Bonneau, Cormac Herley, Paul C. van Oorschot and Frank Stajano. Security & Privacy (Oakland) 2012. San Francisco, CA, USA.
    Abstract Citation
  • Guessing human-chosen secrets (PhD dissertation)
    (bindable version) (tech report version) (DSpace version) (source code)
    Joseph Bonneau.
    Abstract Citation
  • Statistical metrics for individual password strength
    Joseph Bonneau. Twentieth International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation
  • Linguistic properties of multi-word passphrases
    Joseph Bonneau and Ekaterina Shutova. USEC '12: Workshop on Usable Security. Kralendijk, Bonaire, Netherlands.
    Abstract Citation
  • A birthday present every eleven wallets? The security of customer-chosen banking PINs
    (RockYou PIN plot) (iPhone PIN plot)
    Joseph Bonneau, Sören Preibusch and Ross Anderson. FC '12: The 16th International Conference on Financial Cryptography. Kralendijk, Bonaire, Netherlands.
    Abstract Citation

2011

  • The privacy landscape: product differentiation on data collection
    Sören Preibusch and Joseph Bonneau. WEIS '11: The 10th Workshop on the Economics of Information Security. Washington, DC, USA.
    Abstract Citation
  • Getting web authentication right: a best-case protocol for the remaining life of passwords
    Joseph Bonneau. 19th International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation
  • Scrambling for lightweight censorship resistance
    Joseph Bonneau and Rubin Xu. 19th International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation

2010

  • The Password Game: negative externalities from weak password practices
    Sören Preibusch and Joseph Bonneau. GameSec 2010: Conference on Decision and Game Theory for Security. Berlin, Germany.
    Abstract Citation
  • The password thicket: technical and market failures in human authentication on the web
    Joseph Bonneau and Sören Preibusch. WEIS '10: The 9th Workshop on the Economics of Information Security. Boston, MA, USA.
    Abstract Citation
  • Inglourious Installers: Security in the Application Marketplace
    Jonathan Anderson, Joseph Bonneau and Frank Stajano. WEIS '10: The 9th Workshop on the Economics of Information Security. Boston, MA, USA.
    Abstract Citation
  • Don't Tread on Me: Moderating Access to OSN Data with SpikeStrip
    Christo Wilson, Alessandra Sala, Joseph Bonneau, Robert Zablit and Ben Zhao. WOSN 2010: The 3rd Workshop on Online Social Networks. Boston, Massachussets.
    Abstract Citation
  • Digital immolation: new directions in online protest
    Joseph Bonneau. 18th International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation
  • What's in a Name? Evaluating Statistical Attacks on Personal Knowledge Questions
    (dataset)
    Joseph Bonneau, Mike Just and Greg Matthews. FC '10: The 14th International Conference on Financial Cryptography. Tenerife, Spain.
    Abstract Citation

2009

  • Privacy-Enhanced Public View for Social Graphs
    Hyoungshick Kim and Joseph Bonneau. SWSM '09: The 2nd Workshop on Social Web Search and Mining. Hong Kong, China.
    Abstract Citation
  • Privacy Preserving Social Networking Over Untrusted Networks
    Jonathan Anderson, Claudia Diaz, Joseph Bonneau and Frank Stajano. WOSN 2009: The 2nd ACM SIGCOMM Workshop on Online Social Networks. Barcelona, Spain.
    Abstract Citation
  • Prying Data out of a Social Network
    Joseph Bonneau, Jonathan Anderson and George Danezis. ASONAM 09: The 1st International Conference on Advances in Social Networks Analysis and Mining. Athens, Greece.
    Abstract Citation
  • Privacy Stories: Confidence in Privacy Behaviors through End User Programming (poster)
    (abstract)
    Luke Church, Jonathan Anderson, Joseph Bonneau and Frank Stajano. SOUPS 2009: The 5th Symposium On Usable Privacy and Security. Mountain View, CA, USA.
    Abstract Citation
  • Privacy Suites: Shared Privacy for Social Networks (poster)
    (abstract)
    Joseph Bonneau, Jonathan Anderson and Luke Church. SOUPS 2009: The 5th Symposium On Usable Privacy and Security. Mountain View, CA, USA.
    Abstract Citation
  • Security APIs for Online Applications
    Jonathan Anderson, Joseph Bonneau and Frank Stajano. 3rd International Workshop on Analysis of Security APIs. Port Jefferson, NY, USA.
    Abstract Citation
  • The Privacy Jungle: On the Market for Privacy in Social Networks
    (abridged paper)
    Joseph Bonneau and Sören Preibusch. WEIS '09: The 8th Workshop on the Economics of Information Security. London, UK.
    Abstract Citation
  • Alice and Bob's life stories: Cryptographic communication using shared experiences
    Joseph Bonneau. 17th International Workshop on Security Protocols. Cambridge, UK.
    Abstract Citation
  • Eight Friends Are Enough: Social Graph Approximation via Public Listings
    Joseph Bonneau, Jonathan Anderson, Frank Stajano and Ross Anderson. SNS '09: The 2nd ACM Workshop on Social Network Systems. Nuremberg, Germany.
    Abstract Citation

2006

  • Robust Final-Round Cache-Trace Attacks Against AES
    Joseph Bonneau.
    Abstract Citation
  • Cache Collision Timing Attacks Against AES
    (source code)
    Joseph Bonneau and Ilya Mironov. CHES '06: Workshop on Cryptographic Hardware and Embedded Systems. Boston, MA, USA.
    Abstract Citation
  • Finite State Security Analysis of OTR Version 2
    Joseph Bonneau and Andrew Morrison.
    Abstract Citation