cv
A brief overview of my curriculum vitae.
Contact Information
| Name | Christian Mainka |
| Professional Title | Professor Dr.-Ing. |
| [email protected] | |
| Location | University of Wuppertal, Robust, Secure and Privacy-Preserving Smart Systems, Rainer-Gruenter-Str. 21, Building FME/1.03c, 42119 Wuppertal, Germany |
| Website | https://christianmainka.de |
Research Topics
-
Web Security
- Browser security: Cross-Site Leaks, Same-Origin Policy
- Web protocol security: Single Sign-On, OAuth, OpenID Connect, REST
- Focusing on vulnerability detection, attack development, and flow analyses
-
Data Security
- Document security: PDF, ODF, OOXML
- Data-format security: JSON, XML
- Focusing on signatures, encryption, information leakage, and code execution
Experience
-
2025 - present Wuppertal, Germany
Professor
University of Wuppertal — Chair for Robust, Secure and Privacy-Preserving Smart Systems
School of Electrical, Information and Media Engineering.
-
2018 - 2025 Bochum, Germany
Tenured researcher, student councilor (Studienrat i.H.)
Ruhr University Bochum — Chair for Network and Data Security
Faculty of Computer Science.
-
2017 - 2018 Bochum, Germany
Postdoctoral researcher
Ruhr University Bochum
-
2014 - 2026 Bochum, Germany
Co-Founder & CTO
Hackmanit GmbH
-
2012 - present Germany
Freelancer
Penetration Tests, Training, Threat Analysis
-
2012 - 2017 Bochum, Germany
PhD Candidate
Ruhr University Bochum
Education
-
2012 - 2017 Bochum, Germany
PhD
Ruhr University Bochum
Dissertation: "On Message-Level Security"
-
2010 - 2012 Bochum, Germany
Master IT Security
Ruhr University Bochum
Thesis: "Automatic Penetration Test Tool for Detection of XML Signature Wrapping Attacks in Web Services"
-
2010 - 2013 Bochum, Germany
Bachelor Applied Computer Science
Ruhr University Bochum
Thesis: "Developing a Security Analysis Tool for OpenID-Based Single Sign-on Systems"
-
2007 - 2010 Bochum, Germany
Bachelor IT Security
Ruhr University Bochum
Thesis: "Automatic Penetration Test Tool for Detection of XML Signature Wrapping Attacks in Web Services"
Awards
-
2024 Excellent Teaching Award
For the lecture Message-Level Security. Teaching Award of the Faculty of Computer Science.
-
2022 Best Paper Award on CSAW (2nd place)
For “Oops… Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument Signatures”. Awarded with 500 EUR at the Cyber Security Awareness Week (CSAW), Applied Research Competition.
-
2022 5x5000 Competition: "Online or presence teaching - it fits!"
Winner with the project e-Hacking. Awarded by the Centre for Teaching and Learning (ZfW) at Ruhr University Bochum.
-
2021 ACM CCS Best Paper Award
For “XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers”. Awarded at the ACM SIGSAC Conference on Computer and Communications Security.
-
2019 Best Paper Award on CSAW (1st place)
For “1 Trillion Dollar Refund: How To Spoof PDF Signatures”. Awarded with 700 EUR at the Cyber Security Awareness Week (CSAW), Applied Research Competition.
Networks
-
2021 - 2023 Member of the Global Young Faculty VII
Applied Science Communication working group. Initiative of Stiftung Mercator in cooperation with the University Alliance Ruhr.
-
2019 - 2025 Associate Principal Investigator of DFG CASA
Research Hub C: Secure Systems (Cluster of Excellence: Cyber Security in the Age of Large-Scale Adversaries).
-
IETF IETF OAuth Working Group
RFC 9700 (OAuth 2.0 Security Best Current Practice), RFC 9207 (Authorization Server Issuer Identification), OAuth 2.0 for Browser-Based Apps.
-
ISO ISO Technical Committee PDF Specification
Working Group Securing PDF.
-
DIN DIN Working Group PDF
Services
-
2023 - 2025 Senate: Status Group Scientific Staff
Substitute member, Status Group Scientific Staff (Ruhr University Bochum).
-
2021 - 2025 Faculty Council
Full member of the Faculty Council of Computer Science (Ruhr University Bochum).
-
2022 - 2025 Quality Improvement Commission
Member of the commission for improving teaching and studies (full member since 2023).
-
PC Program Committees
ACM CCS 2026, USENIX Security 2024 & 2025, RAID 2024, RuhrSec 2017–2025, ICICS 2021–2023, MetaCom 2023.
-
Reviews Reviewer and Sub-Reviewer
ACNS, AsiaCCS, CCS, EuroS&P, IJIS, S&P, …
Publications: 14 × A✱
-
2026 XSS-over-DoH: On the Adverse Side Effects of DoH on Web Security
Matthias Gierlings, Lukas Knittel, Jorg Schwenk, Christian Mainka, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2026 The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web
Louis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
USENIX Security Symposium
-
2025 "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web
Tommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov, Engin Kirda
IEEE Symposium on Security and Privacy (S&P)
-
2023 Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers
Dominik Noß, Lukas Knittel, Christian Mainka, Marcus Niemietz, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2023 Every Signature Is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures
Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger, Jörg Schwenk
USENIX Security Symposium
-
2022 DISTINCT: Identity Theft Using In-Browser Communications in Dual-Window Single Sign-On
Louis Jannett, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2022 Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument Signatures
Simon Rohlmann, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
USENIX Security Symposium
-
2021 XSinator.Com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers
Lukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Noß, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2021 Breaking the Specification: PDF Certification
Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
IEEE Symposium on Security and Privacy (S&P)
-
2021 Shadow Attacks: Hiding and Replacing Content in Signed PDFs
Christian Mainka, Vladislav Mladenov, Simon Rohlmann
Network and Distributed System Security Symposium
-
2021 Processing Dangerous Paths - On Security and Privacy of the Portable Document Format
Jens Müller, Dominik Noß, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
Network and Distributed System Security Symposium
-
2019 Practical Decryption exFiltration: Breaking PDF Encryption
Jens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2019 1 Trillion Dollar Refund: How To Spoof PDF Signatures
Vladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe, Jörg Schwenk
ACM SIGSAC Conference on Computer and Communications Security
-
2017 Same-Origin Policy: Evaluation in Modern Browsers
Jörg Schwenk, Marcus Niemietz, Christian Mainka
USENIX Security Symposium
Publications: 7 × A
-
2024 SoK: SSO-MONITOR — The Current State and Future Research Directions in Single Sign-On Security Measurements
Louis Jannett, Maximilian Westers, Tobias Wich, Christian Mainka, Andreas Mayer, Vladislav Mladenov
European Symposium on Security and Privacy (Euro S&P)
-
2018 More Is Less: On the End-to-End Security of Group Chats in Signal, WhatsApp, and Threema
Paul Rösler, Christian Mainka, Jörg Schwenk
European Symposium on Security and Privacy (Euro S&P)
-
2017 SECRET: On the Feasibility of a Secure, Efficient, and Collaborative Real-Time Web Editor
Dennis Felsch, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
ACM Asia Conference on Computer and Communications Security (ASIACCS)
-
2017 SoK: Single Sign-On Security – An Evaluation of OpenID Connect
Christian Mainka, Vladislav Mladenov, Tobias Wich, Jörg Schwenk
European Symposium on Security and Privacy (Euro S&P)
-
2016 How Secure Is TextSecure?
Tilman Frosch, Christian Mainka, Christoph Bader, Florian Bergsma, Jörg Schwenk, Thorsten Holz
European Symposium on Security and Privacy (Euro S&P)
-
2016 Do Not Trust Me: Using Malicious IdPs for Analyzing and Attacking Single Sign-On
Christian Mainka, Vladislav Mladenov, Jörg Schwenk
European Symposium on Security and Privacy (Euro S&P)
-
2013 A New Approach towards DoS Penetration Testing on Web Services
Andreas Falkenberg, Christian Mainka, Juraj Somorovsky, Jörg Schwenk
International Conference on Web Services (ICWS)
Publications: 13 × Other Peer Reviewed
-
2020 Office Document Security and Privacy
Jens Müller, Fabian Ising, Christian Mainka, Vladislav Mladenov, Sebastian Schinzel
USENIX Workshop on Offensive Technologies (WOOT)
-
2017 On the (in-)Security of JavaScript Object Signing and Encryption
Dennis Detering, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
ROOTS: Proceedings of the 1st Reversing and Offensive-Oriented Trends Symposium
-
2016 Your Cloud in My Company: Modern Rights Management Services Revisited
Martin Grothe, Paul Rösler, Johanna Jupke, Jan Kaiser, Christian Mainka, Jörg Schwenk
International Conference on Availability, Reliability and Security (ARES)
-
2016 How to Break Microsoft Rights Management Services
Martin Grothe, Christian Mainka, Paul Rösler, Jörg Schwenk
USENIX Workshop on Offensive Technologies (WOOT)
-
2016 SoK: XML Parser Vulnerabilities
Christopher Späth, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
USENIX Workshop on Offensive Technologies (WOOT)
-
2015 Automatic Recognition, Processing and Attacking of Single Sign-on Protocols with Burp Suite
Christian Mainka, Vladislav Mladenov, Tim Guenther, Jörg Schwenk
Open Identity Summit
-
2015 AdIDoS – Adaptive and Intelligent Fully-Automatic Detection of Denial-of-Service Weaknesses in Web Services
Christian Altmeier, Christian Mainka, Juraj Somorovsky, Jörg Schwenk
International Workshop on Quantitative Aspects of Security Assurance (QASA)
-
2015 Not so Smart: On Smart TV Apps
Marcus Niemietz, Juraj Somorovsky, Christian Mainka, Jörg Schwenk
International Workshop on Secure Internet of Things (SIoT)
-
2015 How to Break XML Encryption – Automatically
Dennis Kupser, Christian Mainka, Juraj Somorovsky, Jörg Schwenk
USENIX Workshop on Offensive Technologies (WOOT)
-
2014 Your Software at My Service: Security Analysis of SaaS Single Sign-on Solutions in the Cloud
Christian Mainka, Vladislav Mladenov, Florian Feldmann, Julian Krautwald, Jörg Schwenk
Proceedings of the 6th Edition of the ACM Workshop on Cloud Computing Security
-
2013 A New Approach for WS-Policy Intersection Using Partial Ordered Sets
Abeer Elsafie, Christian Mainka, Jörg Schwenk
Services and Their Composition (ZEUS)
-
2012 Penetration Testing Tool for Web Services Security
Christian Mainka, Juraj Somorovsky, Jörg Schwenk
World Congress on Services (SERVICES)
-
2012 XSpRES: Robust and Effective XML Signatures for Web Services
Christian Mainka, Meiko Jensen, Luigi Lo Iacono, Jörg Schwenk
International Conference on Cloud Computing and Services Science (CLOSER)