{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:234GYUPPPO7VAXR73QHPWQMNFW","short_pith_number":"pith:234GYUPP","canonical_record":{"source":{"id":"1809.04774","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T04:54:45Z","cross_cats_sorted":[],"title_canon_sha256":"fb2ac6c0503fbac746383aada0129d67d4fa5d1cebb8e3ee0a0fbe69602eae04","abstract_canon_sha256":"54347f79ea18bde68c4420e1b4eedcb21f7e588ee4f90b3025601e8ee5944ed8"},"schema_version":"1.0"},"canonical_sha256":"d6f86c51ef7bbf505e3fdc0efb418d2d92699317586c31e5756a479335dae34c","source":{"kind":"arxiv","id":"1809.04774","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.04774","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"arxiv_version","alias_value":"1809.04774v3","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.04774","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"pith_short_12","alias_value":"234GYUPPPO7V","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"234GYUPPPO7VAXR7","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"234GYUPP","created_at":"2026-05-18T12:31:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:234GYUPPPO7VAXR73QHPWQMNFW","target":"record","payload":{"canonical_record":{"source":{"id":"1809.04774","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T04:54:45Z","cross_cats_sorted":[],"title_canon_sha256":"fb2ac6c0503fbac746383aada0129d67d4fa5d1cebb8e3ee0a0fbe69602eae04","abstract_canon_sha256":"54347f79ea18bde68c4420e1b4eedcb21f7e588ee4f90b3025601e8ee5944ed8"},"schema_version":"1.0"},"canonical_sha256":"d6f86c51ef7bbf505e3fdc0efb418d2d92699317586c31e5756a479335dae34c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:14.329243Z","signature_b64":"E8vFSIHAs/rz6t08h0gI4zp8iNO+IDSG4E3A2R0BiNoLUP2KynGZHCKWhKZ36KxrScz8xmJFX5Hmn+F8yf15DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d6f86c51ef7bbf505e3fdc0efb418d2d92699317586c31e5756a479335dae34c","last_reissued_at":"2026-05-17T23:59:14.328749Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:14.328749Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.04774","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eCCiZmNwSRKfc/HQvUaqQSr0sLj2TC/khun0S5UqKS+g254Xe6tK5gWI7GUnK+YLc+cBrAG1SSdJDUVgGSpaDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-21T23:14:15.683769Z"},"content_sha256":"86f1666bab3c2a9e306316e90b89605962ba1512d01605b64a5788c067296b61","schema_version":"1.0","event_id":"sha256:86f1666bab3c2a9e306316e90b89605962ba1512d01605b64a5788c067296b61"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:234GYUPPPO7VAXR73QHPWQMNFW","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Fidelius: Protecting User Secrets from Compromised Browsers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dan Boneh, Dillon Franke, Eric Gong, Forest Fraser, Gaspar Garcia Jr., Giancarlo Pellegrino, Hung T. Nguyen, Jonathan Cogan, Michael Backes, Peh Chang Wei Brandon, Saba Eskandarian, Sawyer Birnbaum, Taresh K. Sethi, Vishal Subbiah","submitted_at":"2018-09-13T04:54:45Z","abstract_excerpt":"Users regularly enter sensitive data, such as passwords, credit card numbers, or tax information, into the browser window. While modern browsers provide powerful client-side privacy measures to protect this data, none of these defenses prevent a browser compromised by malware from stealing it. In this work, we present Fidelius, a new architecture that uses trusted hardware enclaves integrated into the browser to enable protection of user secrets during web browsing sessions, even if the entire underlying browser and OS are fully controlled by a malicious attacker.\n  Fidelius solves many challe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.04774","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yt3N0itXWTErL76MfAeo1Po1+Dj9Bw+qxmwuQZf2HLkkq9xiPtCd58fGw75/p0Tz183oG1+hfziJbxfzqBHWAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-21T23:14:15.684107Z"},"content_sha256":"16f3672de0a7ea296ee76fe1c04d0a7ffa3b36160b0fda2eae35223185c8dc00","schema_version":"1.0","event_id":"sha256:16f3672de0a7ea296ee76fe1c04d0a7ffa3b36160b0fda2eae35223185c8dc00"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/234GYUPPPO7VAXR73QHPWQMNFW/bundle.json","state_url":"https://pith.science/pith/234GYUPPPO7VAXR73QHPWQMNFW/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/234GYUPPPO7VAXR73QHPWQMNFW/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-21T23:14:15Z","links":{"resolver":"https://pith.science/pith/234GYUPPPO7VAXR73QHPWQMNFW","bundle":"https://pith.science/pith/234GYUPPPO7VAXR73QHPWQMNFW/bundle.json","state":"https://pith.science/pith/234GYUPPPO7VAXR73QHPWQMNFW/state.json","well_known_bundle":"https://pith.science/.well-known/pith/234GYUPPPO7VAXR73QHPWQMNFW/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:234GYUPPPO7VAXR73QHPWQMNFW","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"54347f79ea18bde68c4420e1b4eedcb21f7e588ee4f90b3025601e8ee5944ed8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T04:54:45Z","title_canon_sha256":"fb2ac6c0503fbac746383aada0129d67d4fa5d1cebb8e3ee0a0fbe69602eae04"},"schema_version":"1.0","source":{"id":"1809.04774","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.04774","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"arxiv_version","alias_value":"1809.04774v3","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.04774","created_at":"2026-05-17T23:59:14Z"},{"alias_kind":"pith_short_12","alias_value":"234GYUPPPO7V","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"234GYUPPPO7VAXR7","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"234GYUPP","created_at":"2026-05-18T12:31:59Z"}],"graph_snapshots":[{"event_id":"sha256:16f3672de0a7ea296ee76fe1c04d0a7ffa3b36160b0fda2eae35223185c8dc00","target":"graph","created_at":"2026-05-17T23:59:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Users regularly enter sensitive data, such as passwords, credit card numbers, or tax information, into the browser window. While modern browsers provide powerful client-side privacy measures to protect this data, none of these defenses prevent a browser compromised by malware from stealing it. In this work, we present Fidelius, a new architecture that uses trusted hardware enclaves integrated into the browser to enable protection of user secrets during web browsing sessions, even if the entire underlying browser and OS are fully controlled by a malicious attacker.\n  Fidelius solves many challe","authors_text":"Dan Boneh, Dillon Franke, Eric Gong, Forest Fraser, Gaspar Garcia Jr., Giancarlo Pellegrino, Hung T. Nguyen, Jonathan Cogan, Michael Backes, Peh Chang Wei Brandon, Saba Eskandarian, Sawyer Birnbaum, Taresh K. Sethi, Vishal Subbiah","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T04:54:45Z","title":"Fidelius: Protecting User Secrets from Compromised Browsers"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.04774","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:86f1666bab3c2a9e306316e90b89605962ba1512d01605b64a5788c067296b61","target":"record","created_at":"2026-05-17T23:59:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"54347f79ea18bde68c4420e1b4eedcb21f7e588ee4f90b3025601e8ee5944ed8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T04:54:45Z","title_canon_sha256":"fb2ac6c0503fbac746383aada0129d67d4fa5d1cebb8e3ee0a0fbe69602eae04"},"schema_version":"1.0","source":{"id":"1809.04774","kind":"arxiv","version":3}},"canonical_sha256":"d6f86c51ef7bbf505e3fdc0efb418d2d92699317586c31e5756a479335dae34c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d6f86c51ef7bbf505e3fdc0efb418d2d92699317586c31e5756a479335dae34c","first_computed_at":"2026-05-17T23:59:14.328749Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:14.328749Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"E8vFSIHAs/rz6t08h0gI4zp8iNO+IDSG4E3A2R0BiNoLUP2KynGZHCKWhKZ36KxrScz8xmJFX5Hmn+F8yf15DA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:14.329243Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.04774","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:86f1666bab3c2a9e306316e90b89605962ba1512d01605b64a5788c067296b61","sha256:16f3672de0a7ea296ee76fe1c04d0a7ffa3b36160b0fda2eae35223185c8dc00"],"state_sha256":"a6bbc8d7c246b125e06a20048c1867475a879f2e41225e80e445406e3b4797fe"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hK7rTROHn1F8F/GfmHuTpLCL3i+WqPbimnkTw57X/wTE77xnpXv+hbCl38Y2fQaifQ4j8+su3/Rg0o8sSqaqBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-21T23:14:15.685960Z","bundle_sha256":"ad145e93bf83a48ae4feefeff2d6f1399f345e6710c7a3c8b8b1d7455cc41889"}}