Bibliographic record
Abstract
Software installation and updates have become simpler for end users in recent years.The commoditization of the internet has enabled users to obtain more software than ever before from more developers than ever before.Additionally, software installation now requires less input from users, allowing installation with merely a single click or tap.At the same time, different software installation models with varying levels of security, usability and freedom have emerged.In centralized environments, available software is limited by an authority, whereas decentralized environments allow users and developers to interact freely.Decentralized software installation ecosystems pose the most significant security challenges due to the lack of centralized control.In this thesis we identify, through the systematic evaluation of prominent systems, limitations in the way operating systems provide security guarantees (including verification of integrity and authentication, and establishment of trust) in decentralized software installation environments.We address these limitations by designing tools and protocols that help secure software installation and updates at each of the three installation stages (software discovery, initial install and updates, and enforcing security policies).Specifically, we propose a cryptographically verifiable protocol for developers to delegate digital signature privileges to other certificates (possibly owned by other developers) without requiring a centrally trusted public key infrastructure.Our proposal allows trust to be delegated during software updates without user involvement.We also propose a flexible policy for developers to authenticate and share privileges amongst applications being executed simultaneously on a device.We evaluate these proposals and show that they are direct improvements over currently deployed real-world systems.We discuss the design and implementation of an install-time architecture that allows users to query crowdsourced expert information sources to gain trust in software they are about to install.We motivate the requirements for such a system, designed to mirror the security semantics provided by centralized environments.The proposed protocols and tools have been implemented as proofs-of-concept using Google's Android mobile operating system.We leverage a large application dataset to inform our design decisions and demonstrate backward compatibility with existing applications.While the implementations are specific to Android, we discuss how our general proposals extend to other decentralized environments.iii I owe thanks to my wife Elizabeth for her love and patience during the many (and often stressful) milestones of my doctorate.Elizabeth was a constant reminder that there was life outside the university walls.I'd like to thank my mom for always checking in on me despite living 3600 Km away.It is always comforting to know that my mom is thinking about me, no matter how far I am.I also owe thanks to my father (the other Dr. Barrera) for always asking about the details of my research and showing great interest in my progress as an academic.And of course to my sisters who always provided their unconditional support.I'm grateful to Daniel McCarney, Jeremy Clark, and William Enck who helped with the papers that eventually made up this dissertation.I could not have produced this document without their hard work, insight, and discussion.A special mention to Glenn Wurster and Mohammad
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.007 | 0.038 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.002 | 0.002 |
| Scholarly communication | 0.004 | 0.009 |
| Open science | 0.002 | 0.007 |
| Research integrity | 0.002 | 0.003 |
| Insufficient payload (model declined to judge) | 0.003 | 0.005 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".