Gwendal Patat

Assistant Professor. Ph.D. in Cybersecurity, IRISA.

gpatat.jpg

Office F401, IRISA


Campus de Beaulieu


Rennes, France

I am an Assistant Professor at the University of Rennes and IRISA in the SPICY team, where I work on vulnerability research through reverse engineering. My work focuses on analyzing and understanding closed-source software and protocols to identify and exploit security flaws.

Previously, I was a Postdoc at Fraunhofer SIT in the SSE department directed by Steven Arzt, where I worked on binary lifting and native code analysis for security applications, and contributed my expertise to industry projects as a security researcher.

In December 2023, I completed my PhD at IRISA, under the supervision of Pierre-Alain Fouque and Mohamed Sabt. My research focused on the security of cryptographic implementations in mobile devices. I employed various reverse engineering techniques to uncover cryptographic vulnerabilities, providing Proof-of-Concept exploits to ensure these issues are addressed in future implementations, with a specific focus on Digital Rights Management (DRM) systems with the Widevine DRM.

Beyond my professional interests, I enjoy training my bookbinding and lockpicking skills by creating custom tools and attempting to open various locks and padlocks (that I purchase first, of course). Additionally, I enjoy hacking retro games for fun.

news

Jun 14, 2024 I’ve received the 2nd prize PhD Thesis award from the University of Rennes Foundation.
Dec 15, 2023 I have defended my PhD! You can found my manuscript here.
Mar 01, 2023 Rewarded by Mozilla Bug Bounty program.
Apr 02, 2021 Rewarded by Netflix Bug Bounty program and Google BugHunter program. Related CVE and Android Security Bulletin have been published.

latest posts

selected publications

  1. A*
    Formal Security Analysis of Widevine through the W3C EME Standard
    Stéphanie Delaune, Joseph Lallemand, Gwendal Patat, Florian Roudot, and Mohamed Sabt
    In 33rd USENIX Security Symposium (USENIX Security 24), Aug 2024
  2. A
    Your DRM Can Watch You Too: Exploring the Privacy Implications of Browsers (mis)Implementations of Widevine EME
    Gwendal Patat, Mohamed Sabt, and Pierre-Alain Fouque
    In 23rd Proceedings on Privacy Enhancing Technologies, PETS 2023, Lausanne, Switzerland, July 10-15, Aug 2023
  3. Workshop
    Exploring Widevine for Fun and Profit
    Gwendal Patat, Mohamed Sabt, and Pierre-Alain Fouque
    In 43rd IEEE Security and Privacy, SP Workshops 2022, San Francisco, CA, USA, May 22-26, Aug 2022