2012 Poster Sessions : Hails: Protecting Data Privacy in Untrusted Web Apps

Student Name : Amit Levy
Advisor : David Mazières
Research Areas: Computer Systems
Web applications are increasingly becoming the primary curators of personal and corporate data. Much of the success of such Web applications is due to the flexibility in allowing third-party vendors to extend user experiences. However, today’s web application APIs provide too little extensibility at too high a privacy cost for the next generation of web application extensions. Commonly, web application platforms find a middle ground between restricting access to data by third-party applications and requiring users to disclose private information: sacrific ing both extensibility and privacy.

Hails is a web platform that uses information flow control (IFC) to enforce policies on untrusted code. IFC allows users to specify policies in terms of where data can flow instead of what code is privileged to access it.

Amit Levy is a first year Ph.D. student in Computer Science. His research interest are in computer security, distributed systems and cloud storage. Prior to Stanford he obtained a BSc in Computer Science and Economics and MSc in Computer Science at University of Washington.