Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. DELF: Safeguarding deletion correctness in Online Social Networks
 
conference paper

DELF: Safeguarding deletion correctness in Online Social Networks

Cohn-Gordon, Katriel
•
Damaskinos, Georgios  
•
Neto, Divino
Show more
January 1, 2020
Proceedings Of The 29Th Usenix Security Symposium
29th USENIX Security Symposium

Deletion is a core facet of Online Social Networks (OSNs). For users, deletion is a tool to remove what they have shared and control their data. For OSNs, robust deletion is both an obligation to their users and a risk when developer mistakes inevitably occur. While developers are effective at identifying high-level deletion requirements in products (e.g., users should be able to delete posted photos), they are less effective at mapping high-level requirements into concrete operations (e.g., deleting all relevant items in data stores). Without framework support, developer mistakes lead to violations of users' privacy, such as retaining data that should be deleted, deleting the wrong data, and exploitable vulnerabilities.

We propose DELF, a deletion framework for modem OSNs. In DELF, developers specify deletion annotations on data type definitions, which the framework maps into asynchronous, reliable and temporarily reversible operations on backing data stores. DELF validates annotations both statically and dynamically, proactively flagging errors and suggesting fixes.

We deployed DELF in three distinct OSNs, showing the feasibility of our approach. DELF detected, surfaced, and helped developers correct thousands of omissions and dozens of mistakes, while also enabling timely recovery in tens of incidents where user data was inadvertently deleted.

  • Details
  • Metrics
Type
conference paper
Web of Science ID

WOS:000668146200060

Author(s)
Cohn-Gordon, Katriel
Damaskinos, Georgios  
Neto, Divino
Cordova, Shi
Reitz, Benoit
Strahs, Benjamin
Obenshain, Daniel
Pearce, Paul
Papagiannis, Loannis
Date Issued

2020-01-01

Publisher

USENIX ASSOC

Publisher place

Berkeley

Published in
Proceedings Of The 29Th Usenix Security Symposium
ISBN of the book

978-1-939133-17-5

Start page

1057

End page

1074

Subjects

Computer Science, Information Systems

•

Computer Science

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
DCL  
Event nameEvent placeEvent date
29th USENIX Security Symposium

ELECTR NETWORK

Aug 12-14, 2020

Available on Infoscience
August 14, 2021
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/180639
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés