VLDB 2026 Research / reviewers in the wild / expert
Florian Schaub
dblp:08/7562
· DBLP profile ↗
85ranked-venue papers
9as first author
37since 2021 · last 2026
0000-0003-1039-7155ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 51 · 8 first-author · 20 since 2021Security and privacy · 29 · 2 first-author · 17 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 2Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Caring for the Furry Friends in the Smart Home: An Initial Exploration of a Child-Centered Approach to Designing for PetsabstractSmart home technologies are often designed to meet the needs of adults, yet children and pets also live with these systems without being meaningfully considered in their design. Child-Computer Interaction (CCI) researchers have shown the value of studying children's experiences and ideation of technologies used in the domestic space. In this pictorial, we explore experiences at the intersection of children, pets, and smart home technologies by analyzing data from an in-home study with 6-to-11-year-olds. Our analysis identifies five themes in how children perceive smart home technologies in the context of pet care: convenience, presence, physical comfort, emotional wellbeing, and responsibility. Grounded in children's everyday routines of playing with and looking after their pets, this work offers design directions for domestic technologies that account for non-human household members. Jade Xiaoyi Li, Jason C. Yip 0001, Katie Davis 0001, Florian Schaub, Christopher Brooks 0001, Jenny S. Radesky, Kaiwen Sun 0001 |
IDC | 4 |
| 2026 | Designing Workbook Probes for Families: A Smart Home Case Study of Intergenerational Co-Speculation
Kaiwen Sun 0001, Jade Xiaoyi Li, Irene Chung, Jenny S. Radesky, Jason C. Yip 0001, Christopher Brooks 0001, Florian Schaub |
IDC | 7 |
| 2026 | "Families are messy": From Parent-Child Tensions to Family-Centered Design of Smart Home TechnologiesabstractSmart home technologies have become common in family homes, making even young children inevitable users of these technologies. However, these systems are typically designed for individual adults, creating family tensions and conflicts over children’s access, safety, and appropriate smart home use. To investigate children’s and parents’ individual and joint smart home needs and dynamics, we conducted an in-home study with nine families (children aged 6-11). We identify four key parent-child tensions with smart home technologies, including struggles over parental protection versus children’s autonomy, differing views on technology’s purpose, disagreements over technology-enforced routines, and children’s vulnerability to embedded commercialism. Our work reconceptualizes parental mediation as a process of “tension management” rather than the application of static rules. This research challenges the dominant individual-centric choice architecture in smart home design, calling for a family-centered approach that acknowledges and adapts to the fluid, complex, and negotiated reality of modern family life. Kaiwen Sun 0001, Jade Xiaoyi Li, Irene Chung, Jenny S. Radesky, Jason C. Yip 0001, Christopher Brooks 0001, Florian Schaub |
CHI | 7 |
| 2026 | Privacy and Trust vs. Utility: Adoption of Commercial vs. Institutional AI assistants Among University UsersabstractGenerative AI assistants are being rapidly adopted in universities, supporting students in coursework and faculty in academic tasks. To address privacy concerns, some institutions introduced institutional AI assistants, typically wrappers around commercial models (e.g., ChatGPT) with added governance and data protections. However, university-affiliated users appear to rely more on commercial tools (e.g., ChatGPT, Gemini). We conducted a survey (n=260) at one U.S. university to examine preferences, usage scenarios, and perceptions of trust, privacy, and experience with institutional and commercial AI. Participants trusted institutional tools more and considered them more privacy protective, nevertheless commercial tools were often favored for writing, programming, and learning due to their features and utility. Findings reveal a trade-off between privacy and trust versus utility, highlighting complementary adoption patterns and design opportunities for both institutional and commercial AI in higher education. Rongjun Ma, Florian Schaub |
CHI | 4 |
| 2026 | Nice to Know You're Not Alone: Co-designing Community-centered Online Safety and Privacy Education with Librarians
Tanisha Afnan, Sheza Naveed, Griffin Christie, Jackie Hu, Byron Lowens, Allison McDonald, Florian Schaub |
SOUPS | 7 |
| 2026 | How We Define Privacy Literacy: Teaching Experiences & Challenges of Community-Engaged Privacy EducatorsabstractThis study examines the pedagogical approaches and experiences of community-engaged educators—individuals who teach privacy, online safety, or security to specific communities through community organizations, companies, or local institutions, such as libraries. We draw on interviews with 21 such educators across the United States and find that, unlike some privacy and security advice that may emphasize knowledge retention of common skills and strategies, these educators prioritized teaching for independent decision-making. Our participants conceptualized privacy literacy as a process for taking informed action, and, from their insights, we identified five core competencies of privacy literacy: (1) data fluency, (2) account security, (3) fraud detection, (4) information vetting, and (5) surveillance capitalism. Notably, these competencies integrate privacy, security, and online safety concepts into privacy literacy—reflecting an increasingly integrated threat landscape. Embedded within the communities they serve, these educators shared their deep understanding of their students’ needs, which varied dramatically, and shared ways in which they tailored their programming accordingly. However, educators also shared significant teaching constraints, including limited time, resources, and organizational support. We discuss the implications of our findings for privacy literacy and for supporting community-engaged privacy literacy efforts. Tanisha Afnan, Sheza Naveed, Griffin Christie, Jackie Hu, Byron Lowens, Allison McDonald, Florian Schaub |
Proc. Priv. Enhancing Technol. | 7 |
| 2025 | Layered, Overlapping, and Inconsistent: A Large-Scale Analysis of the Multiple Privacy Policies and Controls of U.S. BanksabstractPrivacy policies are often complex. An exception is the two-page standardized notice that U.S. financial institutions must provide under the Gramm-Leach-Bliley Act (GLBA). However, banks now operate websites, mobile apps, and other services that involve complex data sharing practices that require additional privacy notices and do-not-sell opt-outs. We conducted a large-scale analysis of how U.S. banks implement privacy policies and controls in response to GLBA; other federal privacy policy requirements; and the California Consumer Privacy Act (CCPA), a key example for U.S. state privacy laws. We focused on the disclosure and control of a set of especially privacy-invasive practices: third-party data sharing for marketing-related purposes. We collected privacy policies for the 2,067 largest U.S. banks, 45.2% of which provided multiple policies. Across disclosures and controls for the same bank, we identified frequent, concerning inconsistencies---53.8% of banks with multiple privacy policies indicated in GLBA notices that they do not share with third parties but disclosed sharing in other policies. This multiplicity of policies, with the inconsistencies it causes, may create consumer confusion and undermine the transparency goals of the very laws that require them. Our findings call into question whether current policy requirements, such as the GLBA notice, are achieving their intended goals in today's online banking landscape. We discuss potential avenues for reforming and harmonizing privacy policies and control requirements across federal and state laws. Lu Xian, Van Hong Tran, Lauren Lee, Meera Kumar, Florian Schaub |
CCS | 6 |
| 2025 | Intriguing, Concerning, and Questioning the Impact on Immersion: An Exploration of VR Users' Advertising Experiences and AttitudesabstractPeer Reviewed Abraham H. Mhaidli, Selin Fidan, Florian Schaub |
CHI | 3 |
| 2025 | Transparency in Usable Privacy and Security Research: Scholars' Perspectives, Practices, and RecommendationsabstractTransparent reporting of research is a crucial aspect of good scientific practice and contributes to trustworthy science. Transparency helps to understand research processes, assess the validity of research contributions, and facilitates replication of studies and reported results. In the face of reproducibility crises in other fields, the security and privacy (SP) research community in general and the usable privacy and security (UPS) community in particular lack clear standards for transparent research reporting. To gain insights into current research transparency practices and associated challenges and obstacles in the UPS community, we report findings from 24 semi-structured interviews with UPS researchers. We find that researchers value research transparency and already apply several transparency reporting practices. However, an implicit community standard without incentives that outweigh challenges and drawbacks appears to prevent further advances in research transparency. Based on our findings, we conclude with recommendations for transparency practices and guidance for publication venues to better incentivize research transparency (e.g., adapting artifact evaluation to typical UPS artifacts like study materials) and to alleviate constraints that hinder transparency (e.g., removing page limits on appendices). We hope our findings can spur community discussion and effort to improve research quality through more transparent research reporting. Jan H. Klemmer, Juliane Schmüser, Byron Lowens, Fabian Fischer 0009, Lea Schmüser, Florian Schaub, Sascha Fahl |
SP | 6 |
| 2025 | Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessabstractPhishing warning researchers have proposed two forms of hyperlink restrictions for reducing phishing click-through rates: focused attention, which prevents users from proceeding to a suspicious URL until they click the uncovered link inside the warning; and time delay, which disables link clicking for a short period of time. Both measures aim to draw user attention to the warning and nudge them to carefully evaluate the respective link's URL. However, the effectiveness of these measures has so far not been comparatively evaluated. We conducted a mixed-methods online experiment (n=1,320) to understand differences in the effectiveness of focused attention and time delay both independently and together. Our study used an instrumented email inbox environment, in which participants were asked to assess emails and email hyper-links. We found that, while both focused attention and time delay reduced click-through rates independently, the strength of these effects were significantly different from each other with focused attention being more effective than time delay. Combining both measures reduced CTR even further. We also found that participants who saw a warning with a time delay were more likely to hover over hyperlinks for longer than those who saw a focused attention warning. We discuss the implications of our findings for the design of anti-phishing warnings. Justin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer, Florian Schaub |
SP | 5 |
| 2025 | How Transparent is Usable Privacy and Security Research? A Meta-Study on Current Research Transparency Practices
Jan H. Klemmer, Juliane Schmüser, Fabian Fischer 0009, Jacques Suray, Jan-Ulrich Holtgrave, Simon Lenau, Byron Lowens, Florian Schaub, Sascha Fahl |
USENIX Security Symposium | 8 |
| 2025 | Misalignments and Demographic Differences in Expected and Actual Privacy Settings on FacebookabstractSocial media platforms pose privacy risks when data is used in unexpected ways (e.g., for advertising or data sharing with partners). Using a custom browser extension and an online survey with 195 Facebook users, we investigated (1) whether participants’ expected values of their Facebook privacy settings were (mis)aligned with their actual settings; (2) demographic differences in privacy expectation-setting mismatches; and (3) participants' privacy concerns and trust towards Facebook.Our study presents a current and comprehensive analysis of Facebook users' privacy settings. We find that expectation-setting mismatches are prevalent: all participants had at least one mismatch; many had multiple, often expecting their settings to be more restrictive than they were. We also found that Facebook's default values are not aligned with people's expectations and/or actual settings, which suggests that those defaults are ineffective. Furthermore, mismatches differed along certain demographic variables.Participants' trust in Facebook decreased after they became aware of mismatches and their actual settings. Our empirical findings indicate that, despite increased public awareness, media scrutiny, and regulatory attention regarding privacy issues, there is still a substantial and concerning disconnect between how private people perceive their social media data to be and how exposed their data actually is, opening them up to both interpersonal and institutional privacy risks. We discuss design and public policy implications of our findings. Byron Lowens, Sean Scarnecchia, Jane Im, Tanisha Afnan, Annie Chen, Yixin Zou, Florian Schaub |
Proc. Priv. Enhancing Technol. | 7 |
| 2025 | User-Centric Textual Descriptions of Privacy-Enhancing Technologies for Ad Tracking and AnalyticsabstractDescribing Privacy Enhancing Technologies (PETs) to the general public is challenging but essential to convey the privacy protections they provide. Existing research has explored the explanation of differential privacy in health contexts. Our study adapts well-performing textual descriptions of local differential privacy from prior work to a new context and broadens the investigation to the descriptions of additional PETs. Specifically, we develop user-centric textual descriptions for popular PETs in ad tracking and analytics, including local differential privacy, federated learning with and without local differential privacy, and Google's Topics. We examine the applicability of previous findings to these expanded contexts, and evaluate the PET descriptions with quantitative and qualitative survey data (n=306). We find that adapting a process- and implications-focused approach to the ad tracking and analytics context achieved similar effects in facilitating user understanding compared to health contexts, and that our descriptions developed with this process+implications approach for the additional, understudied PETs help users understand PETs' processes. We also find that incorporating an implications statement into PET descriptions did not hurt user comprehension but also did not achieve a significant positive effect, which contrasts prior findings in health contexts. We note that the use of technical terms as well as the machine learning aspect of PETs, even without delving into specifics, led to confusion for some respondents. Based on our findings, we offer recommendations and insights for crafting effective user-centric descriptions of privacy-enhancing technologies. Lu Xian, Song Mi Lee-Kan, Jane Im, Florian Schaub |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | "Why is Everything in the Cloud?": Co-Designing Visual Cues Representing Data Processes with ChildrenabstractChildren struggle to understand hidden data processes (e.g., inferences) and related privacy implications (e.g., profiling). Children use visual cues to reason about technical processes in digital products, sometimes drawing inaccurate conclusions when interface cues are vague or absent. We conducted five consecutive participatory design sessions with children (ages 7–12), probing their perceptions of visual cues and data processes; and iteratively designed and reviewed new visual cues with them. We found that children conceptualized data collection concretely, lacked awareness of its pervasive nature, expressed limited understanding of data inferences, and recognized certain visual cues (e.g., loading, cloud) but unable to explain their meanings. We designed visual cues in “symbolic” and “concrete” styles using icons and metaphors, which helped children understand data flows. Our work contributes to developing comprehensible visual cues for children to support their data and privacy literacy. We discuss design and policy implications of our findings. Kaiwen Sun 0001, Ritesh Kanchi, Frances Marie Tabio Ello, Li-Neishin Co, Mandy Wu, Susan A. Gelman, Jenny S. Radesky, Florian Schaub, Jason C. Yip 0001 |
IDC | 8 |
| 2024 | Better Together: The Interplay Between a Phishing Awareness Video and a Link-centric Phishing Support ToolabstractTwo popular approaches for helping consumers avoid phishing threats are phishing awareness videos and tools supporting users in identifying phishing emails. Awareness videos and tools have each been shown on their own to increase people’s phishing detection rate. Videos have been shown to be a particularly effective awareness measure; link-centric warnings have been shown to provide effective tool support. However, it is unclear how these two approaches compare to each other. We conducted a between-subjects online experiment (n=409) in which we compared the effectiveness of the NoPhish video and the TORPEDO tool and their combination. Our main findings suggest that the TORPEDO tool outperformed the NoPhish video and that the combination of both performs significantly better than just the tool. We discuss the implications of our findings for the design and deployment of phishing awareness measures and support tools. Benjamin Berens, Florian Schaub, Mattia Mossano, Melanie Volkamer |
CHI | 2 |
| 2024 | Unfulfilled Promises of Child Safety and Privacy: Portrayals and Use of Children in Smart Home MarketingabstractSmart home technologies are making their way into families. Parents' and children's shared use of smart home technologies has received growing attention in CSCW and related research communities. Families and children are also frequently featured as target audiences in smart home product marketing. However, there is limited knowledge of how exactly children and family interactions are portrayed in smart home product marketing, and to what extent those portrayals align with the actual consideration of children and families in product features and resources for child safety and privacy. We conducted a content analysis of product websites and online resources of 102 smart home products, as these materials constitute a main marketing channel and information source about products for consumers. We found that despite featuring children in smart home marketing, most analyzed product websites did not mention child safety features and lacked sufficient information on how children's data is collected and used. Specifically, our findings highlight misalignments in three aspects: (1) children are depicted as users of smart home products but there are insufficient child-friendly product features; (2) harmonious child-product co-presence is portrayed but potential child safety issues are neglected; and (3) children are shown as the subject of monitoring and datafication but there is limited information on child data collection and use. We discuss how parent-child relationships and parenting may be negatively impacted by such marketing depictions, and we provide design and policy recommendations for better incorporating child safety and privacy considerations into smart home products. Kaiwen Sun 0001, Yixin Zou, Jenny S. Radesky, Christopher Brooks 0001, Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2024 | Cross-Contextual Examination of Older Adults' Privacy Concerns, Behaviors, and VulnerabilitiesabstractA growing body of research has examined the privacy concerns and behaviors of older adults, often within specific contexts. It remains unclear to what extent older adults' privacy concerns and behaviors vary across contexts and whether old age is the primary factor influencing privacy vulnerabilities. To address this gap, we conducted semi-structured interviews with 43 older adults (aged 65 to 89) in the United States. Our interviews were grounded in five scenarios: account and device sharing, healthcare, online advertising, social networking, and cybercrime. Our cross-contextual analysis showed that cybercrime was a recurring and pressing concern across scenarios; privacy concerns and protective behaviors were rarely mentioned in the healthcare scenario. Across all scenarios, participants' threat models and strategies revolved around data collection rather than other stages in which privacy harms may occur; they employed various active strategies to safeguard their privacy while trusting service providers to protect their information. Our findings underscore the need to revisit the discussion around privacy vulnerability and aging. Vulnerability levels among our participants varied widely and were often influenced by factors beyond age, such as tech savviness and income. We discuss opportunities for privacy interventions, technologies, and education that promote positive aging and recognize diversity among older adults. Yixin Zou, Kaiwen Sun 0001, Tanisha Afnan, Ruba Abu-Salma, Robin Brewer, Florian Schaub |
Proc. Priv. Enhancing Technol. | 6 |
| 2024 | Encouraging Users to Change Breached Passwords Using the Protection Motivation TheoryabstractWe draw on the Protection Motivation Theory (PMT) to design interventions that encourage users to change breached passwords. Our online experiment ( \(n=1{,}386\) ) compared the effectiveness of a threat appeal (highlighting the negative consequences after passwords were breached) and a coping appeal (providing instructions on changing the breached password) in a 2 \(\times\) 2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords. Participants’ password change behaviors are further associated with other factors, such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based interventions are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT’s application in security research and provides concrete design implications for improving compromised credential notifications. Yixin Zou, Khue Le, Peter Mayer 0001, Alessandro Acquisti, Adam J. Aviv, Florian Schaub |
ACM Trans. Comput. Hum. Interact. | 6 |
| 2023 | Less is Not More: Improving Findability and Actionability of Privacy Controls for Online Behavioral AdvertisingabstractTech companies that rely on ads for business argue that users have control over their data via ad privacy settings. However, these ad settings are often hidden. This work aims to inform the design of findable ad controls and study their impact on users’ behavior and sentiment. We iteratively designed ad control interfaces that varied in the setting’s (1) entry point (within ads, at the feed’s top) and (2) level of actionability, with high actionability directly surfacing links to specific advertisement settings, and low actionability pointing to general settings pages (which is reminiscent of companies’ current approach to ad controls). We built a Chrome extension that augments Facebook with our experimental ad control interfaces and conducted a between-subjects online experiment with 110 participants. Results showed that entry points within ads or at the feed’s top, and high actionability interfaces, both increased Facebook ad settings’ findability and discoverability, as well as participants’ perceived usability of them. High actionability also reduced users’ effort in finding ad settings. Participants perceived high and low actionability as equally usable, which shows it is possible to design more actionable ad controls without overwhelming users. We conclude by emphasizing the importance of regulation to provide specific and research-informed requirements to companies on how to design usable ad controls. Jane Im, Ruiyi Wang, Weikun Lyu, Nick Cook, Hana Habib, Lorrie Faith Cranor, Nikola Banovic 0001, Florian Schaub |
CHI | 8 |
| 2023 | Emotion AI at Work: Implications for Workplace Surveillance, Emotional Labor, and Emotional PrivacyabstractWorkplaces are increasingly adopting emotion AI, promising benefits to organizations. However, little is known about the perceptions and experiences of workers subject to emotion AI in the workplace. Our interview study with (n=15) US adult workers addresses this gap, finding that (1) participants viewed emotion AI as a deep privacy violation over the privacy of workers’ sensitive emotional information; (2) emotion AI may function to enforce workers’ compliance with emotional labor expectations, and that workers may engage in emotional labor as a mechanism to preserve privacy over their emotions; (3) workers may be exposed to a wide range of harms as a consequence of emotion AI in the workplace. Findings reveal the need to recognize and define an individual right to what we introduce as emotional privacy, as well as raise important research and policy questions on how to protect and preserve emotional privacy within and beyond the workplace. Kat Roemmich, Florian Schaub, Nazanin Andalibi |
CHI | 2 |
| 2023 | Privacy Now or Never: Large-Scale Extraction and Analysis of Dates in Privacy Policy TextabstractThe General Data Protection Regulation (GDPR) and other recent privacy laws require organizations to post their privacy policies, and place specific expectations on organisations' privacy practices. Privacy policies take the form of documents written in natural language, and one of the expectations placed upon them is that they remain up to date. To investigate legal compliance with this recency requirement at a large scale, we create a novel pipeline that includes crawling, regex-based extraction, candidate date classification and date object creation to extract updated and effective dates from privacy policies written in English. We then analyze patterns in policy dates using four web crawls and find that only about 40% of privacy policies online contain a date, thereby making it difficult to assess their regulatory compliance. We also find that updates in privacy policies are temporally concentrated around passage of laws regulating digital privacy (such as the GDPR), and that more popular domains are more likely to have policy dates as well as more likely to update their policies regularly. Mukund Srinath, Lee Matheson, Pranav Venkit, Gabriela Zanfir-Fortuna, Florian Schaub, C. Lee Giles, Shomir Wilson |
DocEng | 5 |
| 2023 | "It's up to the Consumer to be Smart": Understanding the Security and Privacy Attitudes of Smart Home Users on RedditabstractSmart home technologies offer many benefits to users. Yet, they also carry complex security and privacy implications that users often struggle to assess and account for during adoption. To better understand users’ considerations and attitudes regarding smart home security and privacy, in particular how users develop them progressively, we conducted a qualitative content analysis of 4,957 Reddit comments in 180 security- and privacy-related discussion threads from /r/homeautomation, a major Reddit smart home forum. Our analysis reveals that users’ security and privacy attitudes, manifested in the levels of concern and degree to which they incorporate protective strategies, are shaped by multi-dimensional considerations. Users’ attitudes evolve according to changing contextual factors, such as adoption phases, and how they become aware of these factors. Further, we describe how online discourse about security and privacy risks and protections contributes to individual and collective attitude development. Based on our findings, we provide recommendations to improve smart home designs, support users’ attitude development, facilitate information exchange, and guide future research regarding smart home security and privacy. Kaiwen Sun 0001, Brittany Skye Huff, Anna Marie Bierley, Younghyun Kim 0001, Florian Schaub, Kassem Fawaz |
SP | 6 |
| 2023 | "Would I Feel More Secure With a Robot?": Understanding Perceptions of Security Robots in Public SpacesabstractRobots are increasingly being deployed as security agents helping law enforcement in spaces such as streets, parks, or shopping malls. Unfortunately, the deployment of security robots is not without problems and controversies. For example, the New York Police Department canceled its contract with Boston Dynamics in response to backlash from their use of Digidog, an autonomous robotic dog, which sparked fears in the public. However, it is unclear to what extent affected communities have been involved in the design and deployment process of robots. This is problematic because, without input from community members in the processes of design and deployment, security robots are likely to not satisfy the concerns or safety needs of real communities. To gain deeper insight into people's perceptions of security robots - including both potential benefits and concerns - we conducted 17 semi-structured interviews addressing the following research questions: RQ1. What characteristics do people ascribe to security robots? RQ2. What expectations do people have about the function and role of security robots? RQ3. What are people's attitudes toward the use of security robots? Our study offers several contributions to the existing literature on security robots. Gabriela Marcu, Iris Lin, Brandon Williams, Lionel P. Robert Jr., Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2023 | Researchers' Experiences in Analyzing Privacy Policies: Challenges and OpportunitiesabstractCompanies' privacy policies and their contents are being analyzed for many reasons, including to assess the readability, usability, and utility of privacy policies; to extract and analyze data practices of apps and websites; to assess compliance of companies with relevant laws and their own privacy policies, and to develop tools and machine learning models to summarize and read policies. Despite the importance and interest in studying privacy policies from researchers, regulators, and privacy activists, few best practices or approaches have emerged and infrastructure and tool support is scarce or scattered. In order to provide insight into how researchers study privacy policies and the challenges they face when doing so, we conducted 26 interviews with researchers from various disciplines who have conducted research on privacy policies. We provide insights on a range of challenges around policy selection, policy retrieval, and policy content analysis, as well as multiple overarching challenges researchers experienced across the research process. Based on our findings, we discuss opportunities to better facilitate privacy policy research, including research directions for methodologically advancing privacy policy analysis, potential structural changes around privacy policies, and avenues for fostering an interdisciplinary research community and maturing the field. Abraham H. Mhaidli, Selin Fidan, An Doan, Gina Herakovic, Mukund Srinath, Lee Matheson, Shomir Wilson, Florian Schaub |
Proc. Priv. Enhancing Technol. | 8 |
| 2023 | Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by WebsitesabstractModern websites frequently use and embed third-party services to facilitate web development, connect to social media, or for monetization. This often introduces privacy issues as the inclusion of third-party services on a website can allow the third party to collect personal data about the website's visitors. While the prevalence and mechanisms of third-party web tracking have been widely studied, little is known about the decision processes that lead to websites using third-party functionality and whether efforts are being made to protect their visitors' privacy. We report results from an online survey with 395 participants involved in the creation and maintenance of websites. For ten common website functionalities we investigated if privacy has played a role in decisions about how the functionality is integrated, if specific efforts for privacy protection have been made during integration, and to what degree people are aware of data collection through third parties. We find that ease of integration drives third-party adoption but visitor privacy is considered if there are legal requirements or respective guidelines. Awareness of data collection and privacy risks is higher if the collection is directly associated with the purpose for which the third-party service is used. Christine Utz, Sabrina Klivan, Martin Degeling, Thorsten Holz, Sascha Fahl, Florian Schaub |
Proc. Priv. Enhancing Technol. | 6 |
| 2023 | Awareness, Intention, (In)Action: Individuals' Reactions to Data BreachesabstractData breaches are prevalent. We provide novel insights into individuals’ awareness, perception, and responses to breaches that affect them through two online surveys: a main survey (n= 413) in which we presented participants with up to three breaches that affected them, and a follow-up survey (n= 108) in which we investigated whether the main study participants followed through with their intentions to act. Overall, 73% of participants were affected by at least one breach, but participants were unaware of 74% of breaches affecting them. Although some reported intention to take action, most participants believed the breach would not impact them. We also found a sizable intention-behavior gap. Participants did not follow through with their intention when they were apathetic about breaches, considered potential costs, forgot, or felt resigned about taking action. Our findings suggest that breached organizations should be held accountable for more proactively informing and protecting affected consumers. Peter Mayer 0001, Yixin Zou, Byron Lowens, Hunter A. Dyer, Khue Le, Florian Schaub, Adam J. Aviv |
ACM Trans. Comput. Hum. Interact. | 6 |
| 2022 | Trauma-Informed Computing: Towards Safer Technology Experiences for AllabstractTrauma is the physical, emotional, or psychological harm caused by deeply distressing experiences. Research with communities that may experience high rates of trauma has shown that digital technologies can create or exacerbate traumatic experiences. Via three vignettes, we discuss how considering the possible effects of trauma and traumatic stress reactions provides an explanatory lens with new insights into people’s technology experiences. Then, we present a framework—trauma-informed computing—in which we adapt and show how to apply six key principles of trauma-informed approaches to computing: safety, trust, peer support, collaboration, enablement, and intersectionality. Through specific examples, we describe how to apply trauma-informed computing in four areas of computing research and practice: user experience research & design, security & privacy, artificial intelligence & machine learning, and organizational culture in tech companies. We conclude by discussing how adopting trauma-informed computing will lead to benefits for all users, not only those experiencing trauma. Janet X. Chen, Allison McDonald, Yixin Zou, Emily Tseng, Kevin A. Roundy, Acar Tamersoy, Florian Schaub, Thomas Ristenpart, Nicola Dell |
CHI | 7 |
| 2022 | Increasing Adoption of Tor Browser Using Informational and Planning NudgesabstractAbstract Browsing privacy tools can help people protect their digital privacy. However, tools which provide the strongest protections—such as Tor Browser—have struggled to achieve widespread adoption. This may be due to usability challenges, misconceptions, behavioral biases, or mere lack of awareness. In this study, we test the effectiveness of nudging interventions that encourage the adoption of Tor Browser. First, we test an informational nudge based on protection motivation theory (PMT), designed to raise awareness of Tor Browser and help participants form accurate perceptions of it. Next, we add an action planning implementation intention, designed to help participants identify opportunities for using Tor Browser. Finally, we add a coping planning implementation intention, designed to help participants overcome challenges to using Tor Browser, such as extreme website slowness. We test these nudges in a longitudinal field experiment with 537 participants. We find that our PMT-based intervention increased use of Tor Browser in both the short- and long-term. Our coping planning nudge also increased use of Tor Browser, but only in the week following our intervention. We did not find statistically significant evidence of our action planning nudge increasing use of Tor Browser. Our study contributes to a greater understanding of factors influencing the adoption of Tor Browser, and how nudges might be used to encourage the adoption of Tor Browser and similar privacy enhancing technologies. Peter Story, Daniel Smullen, Rex Chen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
Proc. Priv. Enhancing Technol. | 8 |
| 2021 | Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link TextsabstractIncreasingly, icons are being proposed to concisely convey privacy-related information and choices to users. However, complex privacy concepts can be difficult to communicate. We investigate which icons effectively signal the presence of privacy choices. In a series of user studies, we designed and evaluated icons and accompanying textual descriptions (link texts) conveying choice, opting-out, and sale of personal information — the latter an opt-out mandated by the California Consumer Privacy Act (CCPA). We identified icon-link text pairings that conveyed the presence of privacy choices without creating misconceptions, with a blue stylized toggle icon paired with “Privacy Options” performing best. The two CCPA-mandated link texts (“Do Not Sell My Personal Information” and “Do Not Sell My Info”) accurately communicated the presence of do-not-sell opt-outs with most icons. Our results provide insights for the design of privacy choice indicators and highlight the necessity of incorporating user testing into policy making. Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Joel R. Reidenberg, Norman M. Sadeh, Florian Schaub |
CHI | 8 |
| 2021 | The Annoying, the Disturbing, and the Weird: Challenges with Phone Numbers as Identifiers and Phone Number RecyclingabstractPhone numbers are intimately connected to our digital lives. People are increasingly required to disclose their phone number in digital spaces, both commercial and personal. While convenient for companies, the pervasive use of phone numbers as user identifiers also poses privacy, security, and access risks for individuals. In order to understand these risks, we present findings from a qualitative online elicitation study with 195 participants about their negative experiences with phone numbers, the consequences they faced, and how those consequences impacted their behavior. Our participants frequently reported experiencing phone number recycling, unwanted exposure, and temporary loss of access to a phone number. Resulting consequences they faced included harassment, account access problems, and privacy invasions. Based on our findings, we discuss service providers’ faulty assumptions in the use of phone numbers as user identifiers, problems arising from phone number recycling, and provide design and public policy recommendations for mitigating these issues with phone numbers. Allison McDonald, Carlo Sugatan, Tamy Guberek, Florian Schaub |
CHI | 4 |
| 2021 | Identifying Manipulative Advertising Techniques in XR Through Scenario ConstructionabstractAs Extended Reality (XR) devices and applications become more mainstream, so too will XR advertising — advertising that takes place in XR mediums. Due to the defining features of XR devices, such as the immersivity of the medium and the ability of XR devices to simulate reality, there are fears that these features could be exploited to create manipulative XR ads that trick consumers into buying products they do not need or might harm them. Using scenario construction, we investigate potential future incarnations of manipulative XR advertising and their harms. We identify five key mechanisms of manipulative XR advertising: misleading experience marketing; inducing artificial emotions in consumers; sensing and targeting people when they are vulnerable; emotional manipulation through hyperpersonalization; and distortion of reality. We discuss research challenges and questions in order to address and mitigate manipulative XR advertising risks. Abraham H. Mhaidli, Florian Schaub |
CHI | 2 |
| 2021 | "They See You're a Girl if You Pick a Pink Robot with a Skirt": A Qualitative Study of How Children Conceptualize Data Processing and Digital Privacy RisksabstractAs children become frequent digital technology users, concerns about their digital privacy are increasing. To better understand how young children conceptualize data processing and digital privacy risks, we interviewed 26 children, 4 to 10 years old, from families with higher educational attainment recruited in a college town. Our child participants construed apps’ and services’ data collection and storage practices in terms of their benefits, both to themselves and for user safety, and characterized both data tracking and privacy violations as interpersonal rather than considering automated processes or companies as privacy threats. We identify four factors shaping these mental models and privacy risk perceptions: (1) surface-level visual cues, (2) past digital interactions involving data collection, (3) age and cognitive development, and (4) privacy-related experiences in non-digital contexts. We discuss our findings’ design, educational, and public policy implications toward better supporting children in identifying and reasoning about digital privacy risks. Kaiwen Sun 0001, Carlo Sugatan, Tanisha Afnan, Hayley Simon, Susan A. Gelman, Jenny S. Radesky, Florian Schaub |
CHI | 7 |
| 2021 | "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them
Peter Mayer 0001, Yixin Zou, Florian Schaub, Adam J. Aviv |
USENIX Security Symposium | 3 |
| 2021 | "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices Online
Allison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub, Elissa M. Redmiles |
USENIX Security Symposium | 4 |
| 2021 | The Role of Computer Security Customer Support in Helping Survivors of Intimate Partner Violence
Yixin Zou, Allison McDonald, Julia Narakornpichit, Nicola Dell, Thomas Ristenpart, Kevin A. Roundy, Florian Schaub, Acar Tamersoy |
USENIX Security Symposium | 7 |
| 2021 | Child Safety in the Smart Home: Parents' Perceptions, Needs, and Mitigation StrategiesabstractConcerns about child physical and digital safety are emerging with families' adoption of smart home technologies such as robot vacuums and smart speakers. To better understand parents' definitions and perceptions of child safety regarding smart home technologies, we interviewed 23 parents who are smart home adopters. We contribute insights into parents' perceptions of the physical and digital safety risks smart home technologies pose to children, and how such perceptions formed and changed across three phases. In acquiring smart home devices, parents already considered whether the device could cause physical harm to their children or pose privacy and security risks. Once children become active users of smart home technologies, parents however reported encountering unanticipated physical safety risks and digital safety issues (e.g., exposure to unsuitable content) that required their mitigation strategies. As their children grow up, parents further expressed the need to shift attention from physical safety to digital safety. Parents' safety perceptions influence how they involve children in smart home interactions and implement mitigation strategies, such as restricting access to certain devices and using parental controls. We identify six factors that shape parents' perception and evaluation of smart home safety risks to children, including parenting style, parents' tech-savviness, parents' trust in tech companies, children's age and developmental differences, news media, and device characteristics. We provide design and policy recommendations to better protect children's safety in the smart home environment. Kaiwen Sun 0001, Yixin Zou, Jenny S. Radesky, Christopher Brooks 0001, Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2021 | Awareness, Adoption, and Misconceptions of Web Privacy ToolsabstractAbstract Privacy and security tools can help users protect themselves online. Unfortunately, people are often unaware of such tools, and have potentially harmful misconceptions about the protections provided by the tools they know about. Effectively encouraging the adoption of privacy tools requires insights into people’s tool awareness and understanding. Towards that end, we conducted a demographically-stratified survey of 500 US participants to measure their use of and perceptions about five web browsing-related tools: private browsing, VPNs, Tor Browser, ad blockers, and antivirus software. We asked about participants’ perceptions of the protections provided by these tools across twelve realistic scenarios. Our thematic analysis of participants’ responses revealed diverse forms of misconceptions. Some types of misconceptions were common across tools and scenarios, while others were associated with particular combinations of tools and scenarios. For example, some participants suggested that the privacy protections offered by private browsing, VPNs, and Tor Browser would also protect them from security threats – a misconception that might expose them to preventable risks. We anticipate that our findings will help researchers, tool designers, and privacy advocates educate the public about privacy- and security-enhancing technologies. Peter Story, Daniel Smullen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
Proc. Priv. Enhancing Technol. | 7 |
| 2020 | "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesabstractWe conducted an in-lab user study with 24 participants to explore the usefulness and usability of privacy choices offered by websites. Participants were asked to find and use choices related to email marketing, targeted advertising, or data deletion on a set of nine websites that differed in terms of where and how these choices were presented. They struggled with several aspects of the interaction, such as selecting the correct page from a site's navigation menu and understanding what information to include in written opt-out requests. Participants found mechanisms located in account settings pages easier to use than options contained in privacy policies, but many still consulted help pages or sent email to request assistance. Our findings indicate that, despite their prevalence, privacy choices like those examined in this study are difficult for consumers to exercise in practice. We provide design and policy recommendations for making these website opt-out and deletion choices more useful and usable for consumers. Hana Habib, Sarah Pearman, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub |
CHI | 8 |
| 2020 | Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection PracticesabstractUsers struggle to adhere to expert-recommended security and privacy practices. While prior work has studied initial adoption of such practices, little is known about the subsequent implementation and abandonment. We conducted an online survey (n=902) examining the adoption and abandonment of 30 commonly recommended practices. Security practices were more widely adopted than privacy and identity theft protection practices. Manual and fully automatic practices were more widely adopted than practices requiring recurring user interaction. Participants' gender, education, technical background, and prior negative experience are correlated with their levels of adoption. Furthermore, practices were abandoned when they were perceived as low-value, inconvenient, or when users overrode them with subjective judgment. We discuss how security, privacy, and identity theft protection recommendations and tools can be better aligned with user needs. Yixin Zou, Kevin A. Roundy, Acar Tamersoy, Saurabh Shintre, Johann Roturier, Florian Schaub |
CHI | 6 |
| 2020 | "They Like to Hear My Voice": Exploring Usage Behavior in Speech-Based Mobile Instant MessagingabstractAdoption and use of smartphone-based asynchronous voice messaging has increased substantially in recent years. However, this communication channel has a strong tendency to polarize. To provide an understanding of this modality, we started by conducting an online survey (n=1,003) exploring who is using voice messages, their motives, and utilization. In a consecutive field study (n=6), we analyzed voice messaging behavior of six avid voice message users in a two-week field study, followed by semi-structured interviews further exploring themes uncovered in our survey. Conducting a thematic analysis, we identified four themes driving voice messaging usage: convenience, para-linguistic features, situational constraints and the receiver. Voice messaging helps to overcome issues of mobile communication, through ease of use, asynchronous implementation, and voices’ rich emotional context. It also was perceived as enabling more efficient communication, helps to handle secondary occupations, and better facilitates maintenance of close relationships. Despite the increased effort required to listen to a voice message, they complement communication with people we care about. Gabriel Haas 0001, Jan Gugenheimer, Jan Rixen, Florian Schaub, Enrico Rukzio |
MobileHCI | 4 |
| 2020 | Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy TextabstractWebsite privacy policies sometimes provide users the option to opt-out of certain collections and uses of their personal data. Unfortunately, many privacy policies bury these instructions deep in their text, and few web users have the time or skill necessary to discover them. We describe a method for the automated detection of opt-out choices in privacy policy text and their presentation to users through a web browser extension. We describe the creation of two corpora of opt-out choices, which enable the training of classifiers to identify opt-outs in privacy policies. Our overall approach for extracting and classifying opt-out choices combines heuristics to identify commonly found opt-out hyperlinks with supervised machine learning to automatically identify less conspicuous instances. Our approach achieves a precision of 0.93 and a recall of 0.9. We introduce Opt-Out Easy, a web browser extension designed to present available opt-out choices to users as they browse the web. We evaluate the usability of our browser extension with a user study. We also present results of a large-scale analysis of opt-outs found in the text of thousands of the most popular websites. Vinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng, Hana Habib, Peter Story, Sushain Cherivirala, Margaret Hagan, Lorrie Faith Cranor, Shomir Wilson, Florian Schaub, Norman M. Sadeh |
WWW | 11 |
| 2020 | Listen Only When Spoken To: Interpersonal Communication Cues as Smart Speaker Privacy ControlsabstractAbstract Internet of Things and smart home technologies pose challenges for providing effective privacy controls to users, as smart devices lack both traditional screens and input interfaces. We investigate the potential for leveraging interpersonal communication cues as privacy controls in the IoT context, in particular for smart speakers. We propose privacy controls based on two kinds of interpersonal communication cues – gaze direction and voice volume level – that only selectively activate a smart speaker’s microphone or voice recognition when the device is being addressed, in order to avoid constant listening and speech recognition by the smart speaker microphones and reduce false device activation. We implement these privacy controls in a smart speaker prototype and assess their feasibility, usability and user perception in two lab studies. We find that privacy controls based on interpersonal communication cues are practical, do not impair the smart speaker’s functionality, and can be easily used by users to selectively mute the microphone. Based on our findings, we discuss insights regarding the use of interpersonal cues as privacy controls for smart speakers and other IoT devices. Abraham H. Mhaidli, Manikandan Kandadai Venkatesh, Yixin Zou, Florian Schaub |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | (Un)informed Consent: Studying GDPR Consent Notices in the FieldabstractSince the adoption of the General Data Protection Regulation (GDPR) in May 2018 more than 60 % of popular websites in Europe display cookie consent notices to their visitors. This has quickly led to users becoming fatigued with privacy notifications and contributed to the rise of both browser extensions that block these banners and demands for a solution that bundles consent across multiple websites or in the browser. In this work, we identify common properties of the graphical user interface of consent notices and conduct three experiments with more than 80,000 unique users on a German website to investigate the influence of notice position, type of choice, and content framing on consent. We find that users are more likely to interact with a notice shown in the lower (left) part of the screen. Given a binary choice, more users are willing to accept tracking compared to mechanisms that require them to allow cookie use for each category or company individually. We also show that the wide-spread practice of nudging has a large effect on the choices users make. Our experiments show that seemingly small implementation decisions can substantially impact whether and how people interact with consent notices. Our findings demonstrate the importance for regulation to not just require consent, but also provide clear requirements or guidance for how this consent has to be obtained in order to ensure that users can make free and informed choices. Christine Utz, Martin Degeling, Sascha Fahl, Florian Schaub, Thorsten Holz |
CCS | 4 |
| 2019 | Put Your Warning Where Your Link Is: Improving and Evaluating Email Phishing WarningsabstractPhishing emails often disguise a link's actual URL. Thus, common anti-phishing advice is to check a link's URL before clicking, but email clients do not support this well. Automated phishing detection enables email clients to warn users that an email is suspicious, but current warnings are often not specific. We evaluated the effects on phishing susceptibility of (1) moving phishing warnings close to the suspicious link in the email, (2) displaying the warning on hover interactions with the link, and (3) forcing attention to the warning by deactivating the original link, forcing users to click the URL in the warning. We assessed the effectiveness of such link-focused phishing warning designs in a between-subjects online experiment (n=701). We found that link-focused phishing warnings reduced phishing click-through rates compared to email banner warnings; forced attention warnings were most effective. We discuss the implications of our findings for phishing warning design. Justin Petelka, Yixin Zou, Florian Schaub |
CHI | 3 |
| 2019 | It's My Data! Tensions Among Stakeholders of a Learning Analytics DashboardabstractEarly warning dashboards in higher education analyze student data to enable early identification of underperforming students, allowing timely interventions by faculty and staff. To understand perceptions regarding the ethics and impact of such learning analytics applications, we conducted a multi-stakeholder analysis of an early-warning dashboard deployed at the University of Michigan through semi-structured interviews with the system's developers, academic advisors (the primary users), and students. We identify multiple tensions among and within the stakeholder groups, especially with regard to awareness, understanding, access and use of the system. Furthermore, ambiguity in data provenance and data quality result in differing levels of reliance and concerns about the system among academic advisors and students. While students see the system's benefits, they argue for more involvement, control, and informed consent regarding the use of student data. We discuss our findings' implications for the ethical design and deployment of learning analytics applications in higher education. Early warning dashboards in higher education analyze student data to enable early identification of underperforming students, allowing timely interventions by faculty and staff. To understand perceptions regarding the ethics and impact of such learning analytics applications, we conducted a multi-stakeholder analysis of an early-warning dashboard deployed at the University of Michigan through semi-structured interviews with the system's developers, academic advisors (the primary users), and students. We identify multiple tensions among and within the stakeholder groups, especially with regard to awareness, understanding, access, and use of the system. Furthermore, ambiguity in data provenance and data quality result in differing levels of reliance and concerns about the system among academic advisors and students. While students see the system's benefits, they argue for more involvement, control, and informed consent regarding the use of student data. We discuss our findings' implications for the ethical design and deployment of learning analytics applications in higher education. Kaiwen Sun 0001, Abraham H. Mhaidli, Sonakshi Watel, Christopher Brooks 0001, Florian Schaub |
CHI | 5 |
| 2019 | You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach NotificationsabstractData breaches place affected individuals at significant risk of identity theft. Yet, prior studies have shown that many consumers do not take protective actions after receiving a data breach notification from a company. We analyzed 161 data breach notifications sent to consumers with respect to their readability, structure, risk communication, and presentation of potential actions. We find that notifications are long and require advanced reading skills. Many companies downplay or obscure the likelihood of the receiver being affected by the breach and associated risks. Moreover, potential actions and offered compensations are frequently described in lengthy paragraphs instead of clearly listed. Little information is provided regarding an action's urgency and effectiveness; little guidance is provided on which actions to prioritize. Based on our findings, we provide recommendations for designing more usable and informative data breach notifications that could help consumers better mitigate the consequences of being affected by a data breach. Yixin Zou, Shawn Danino, Kaiwen Sun 0001, Florian Schaub |
CHI | 4 |
| 2019 | The Impact of Student Opt-Out on Educational Predictive ModelsabstractPrivacy concerns may lead people to opt-in or opt-out of having their educational data collected. These decisions may impact the performance of educational predictive models. To understand this, we conducted a survey to determine the propensity of students to withhold or grant access to their data for the purposes of training predictive models. We simulated the effects of opt-out on the accuracy of educational predictive models by dropping a random sample of data over a range of increments, and then contextualize our findings using the survey results. We find that grade predictive models are fairly robust and that kappa scores do not decrease unless there is signiicant opt-out, but when there is, the deteriorating performance disproportionately affects certain subpopulations. Warren Li, Christopher Brooks 0001, Florian Schaub |
LAK | 3 |
| 2019 | We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy
Martin Degeling, Christine Utz, Christopher Lentzsch, Henry Hosseini, Florian Schaub, Thorsten Holz |
NDSS | 5 |
| 2019 | Analyzing Privacy Policies at Scale: From Crowdsourcing to Automated AnnotationsabstractWebsite privacy policies are often long and difficult to understand. While research shows that Internet users care about their privacy, they do not have the time to understand the policies of every website they visit, and most users hardly ever read privacy policies. Some recent efforts have aimed to use a combination of crowdsourcing, machine learning, and natural language processing to interpret privacy policies at scale, thus producing annotations for use in interfaces that inform Internet users of salient policy details. However, little attention has been devoted to studying the accuracy of crowdsourced privacy policy annotations, how crowdworker productivity can be enhanced for such a task, and the levels of granularity that are feasible for automatic analysis of privacy policies. In this article, we present a trajectory of work addressing each of these topics. We include analyses of crowdworker performance, evaluation of a method to make a privacy-policy oriented task easier for crowdworkers, a coarse-grained approach to labeling segments of policy text with descriptive themes, and a fine-grained approach to identifying user choices described in policy text. Together, the results from these efforts show the effectiveness of using automated and semi-automated methods for extracting from privacy policies the data practice details that are salient to Internet users’ interests. Shomir Wilson, Florian Schaub, Frederick Liu, Kanthashree Mysore Sathyendra, Daniel Smullen, Sebastian Zimmeck, Rohan Ramanath, Peter Story, Fei Liu 0004, Norman M. Sadeh, Noah A. Smith |
ACM Trans. Web | 2 |
| 2018 | Keeping a Low Profile?: Technology, Risk and Privacy among Undocumented ImmigrantsabstractUndocumented immigrants in the United States face risks of discrimination, surveillance, and deportation. We investigate their technology use, risk perceptions, and protective strategies relating to their vulnerability. Through semi-structured interviews with Latinx undocumented immigrants, we find that while participants act to address offline threats, this vigilance does not translate to their online activities. Their technology use is shaped by needs and benefits rather than risk perceptions. While our participants are concerned about identity theft and privacy generally, and some raise concerns about online harassment, their understanding of government surveillance risks is vague and met with resignation. We identify tensions among self-expression, group privacy, and self-censorship related to their immigration status, as well as strong trust in service providers. Our findings have implications for digital literacy education, privacy and security interfaces, and technology design in general. Even minor design decisions can substantially affect exposure risks and well-being for such vulnerable communities. Tamy Guberek, Allison McDonald, Sylvia Simioni, Abraham H. Mhaidli, Kentaro Toyama, Florian Schaub |
CHI | 6 |
| 2018 | Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep Learning
Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G. Shin, Karl Aberer |
USENIX Security Symposium | 4 |
| 2018 | Alexa, Are You Listening?: Privacy Perceptions, Concerns and Privacy-seeking Behaviors with Smart SpeakersabstractSmart speakers with voice assistants, like Amazon Echo and Google Home, provide benefits and convenience but also raise privacy concerns due to their continuously listening microphones. We studied people's reasons for and against adopting smart speakers, their privacy perceptions and concerns, and their privacy-seeking behaviors around smart speakers. We conducted a diary study and interviews with seventeen smart speaker users and interviews with seventeen non-users. We found that many non-users did not see the utility of smart speakers or did not trust speaker companies. In contrast, users express few privacy concerns, but their rationalizations indicate an incomplete understanding of privacy risks, a complicated trust relationship with speaker companies, and a reliance on the socio-technical context in which smart speakers reside. Users trade privacy for convenience with different levels of deliberation and privacy resignation. Privacy tensions arise between primary, secondary, and incidental users of smart speakers. Finally, current smart speaker privacy controls are rarely used, as they are not well-aligned with users' needs. Our findings can inform future smart speaker designs; in particular we recommend better integrating privacy controls into smart speaker interaction. Josephine Lau, Benjamin Zimmerman, Florian Schaub |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2017 | The Impact of Assistive Technology on Communication Quality Between Deaf and Hearing IndividualsabstractDeaf individuals often experience communication difficulties in face-to-face interactions with hearing people. In order to support deaf individuals in such situations, an active stream of assistive technology (AT) research focuses on real-time translation of sign language. We investigate the impact of real-time translation-based ATs on communication quality between deaf and hearing individuals. We conducted a focus group and aWizard of Oz study in which deaf and hearing participants jointly interacted with different assistive technologies. We find that while ATs facilitate communication, communication quality is degraded by to breaks in the conversation. Using Co-Cultural Theory, we identify deaf people as a subordinate group inside a hearing society. Our results indicate that current ATs reinforce this subordination by emphasizing deficiency of mastering the dominant form of communication. Based on our findings, we propose a change in design perspective by enabling the hearing to sign rather than the deaf to "hear". We argue that ATs should not be seen as "just" a tool for the Deaf but rather as a collaborative technology. Jan Gugenheimer, Katrin Plaumann, Florian Schaub, Patrizia Di Campli San Vito, Saskia Duck, Melanie Rabus, Enrico Rukzio |
CSCW | 3 |
| 2017 | Identifying the Provision of Choices in Privacy Policy TextabstractWebsites' and mobile apps' privacy policies, written in natural language, tend to be long and difficult to understand. Information privacy revolves around the fundamental principle of Notice and choice, namely the idea that users should be able to make informed decisions about what information about them can be collected and how it can be used. Internet users want control over their privacy, but their choices are often hidden in long and convoluted privacy policy texts. Moreover, little (if any) prior work has been done to detect the provision of choices in text. We address this challenge of enabling user choice by automatically identifying and extracting pertinent choice language in privacy policies. In particular, we present a two-stage architecture of classification models to identify opt-out choices in privacy policy text, labelling common varieties of choices with a mean F1 score of 0.735. Our techniques enable the creation of systems to help Internet users to learn about their choices, thereby effectuating notice and choice and improving Internet privacy. Kanthashree Mysore Sathyendra, Shomir Wilson, Florian Schaub, Sebastian Zimmeck, Norman M. Sadeh |
EMNLP | 3 |
| 2017 | Automated Analysis of Privacy Requirements for Mobile Apps
Sebastian Zimmeck, Ziqi Wang 0007, Lieyong Zou, Roger Iyengar, Bin Liu 0017, Florian Schaub, Shomir Wilson, Norman M. Sadeh, Steven M. Bellovin, Joel R. Reidenberg |
NDSS | 6 |
| 2017 | On the Use of Emojis in Mobile Authentication
Lydia Kraus, Robert Schmidt 0005, Marcel Walch, Florian Schaub, Sebastian Möller 0001 |
SEC | 4 |
| 2017 | Exploring End User Programming Needs in Home AutomationabstractHome automation faces the challenge of providing ubiquitous, unobtrusive services while empowering users with approachable configuration interfaces. These interfaces need to provide sufficient expressiveness to support complex automation, and notations need to be devised that enable less tech-savvy users to express such scenarios. Rule-based and process-oriented paradigms have emerged as opposing ends of the spectrum; however, their underlying concepts have not been studied comparatively. We report on a contextual inquiry study in which we collected qualitative data from 18 participants in 12 households on the current potential and acceptance of home automation, as well as explored the respective benefits and drawbacks of these two notation paradigms for end users. Results show that rule-based notations are sufficient for simple automation tasks but not flexible enough for more complex use cases. The resulting insights can inform the design of interfaces for smart homes to enable usable real-world home automation for end users. Julia Brich, Marcel Walch, Michael Rietzler, Michael Weber 0001, Florian Schaub |
ACM Trans. Comput. Hum. Interact. | 5 |
| 2016 | The Creation and Analysis of a Website Privacy Policy CorpusabstractShomir Wilson, Florian Schaub, Aswarth Abhilash Dara, Frederick Liu, Sushain Cherivirala, Pedro Giovanni Leon, Mads Schaarup Andersen, Sebastian Zimmeck, Kanthashree Mysore Sathyendra, N. Cameron Russell, Thomas B. Norton, Eduard Hovy, Joel Reidenberg, Norman Sadeh. Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2016. Shomir Wilson, Florian Schaub, Aswarth Abhilash Dara, Frederick Liu, Sushain Cherivirala, Pedro Giovanni Leon, Mads Schaarup Andersen, Sebastian Zimmeck, Kanthashree Mysore Sathyendra, N. Cameron Russell, Thomas B. Norton, Eduard H. Hovy, Joel R. Reidenberg, Norman M. Sadeh |
ACL (1) | 2 |
| 2016 | Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions
Bin Liu 0017, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Zhang, Norman M. Sadeh, Yuvraj Agarwal, Alessandro Acquisti |
SOUPS | 3 |
| 2016 | How Short Is Too Short? Implications of Length and Framing on the Effectiveness of Privacy Notices
Joshua Gluck, Florian Schaub, Amy Friedman, Hana Habib, Norman M. Sadeh, Lorrie Faith Cranor, Yuvraj Agarwal |
SOUPS | 2 |
| 2016 | Expecting the Unexpected: Understanding Mismatched Privacy Expectations Online
Ashwini Rao, Florian Schaub, Norman M. Sadeh, Alessandro Acquisti, Ruogu Kang |
SOUPS | 2 |
| 2016 | Crowdsourcing Annotations for Websites' Privacy Policies: Can It Really Work?abstractWebsite privacy policies are often long and difficult to understand. While research shows that Internet users care about their privacy, they do not have time to understand the policies of every website they visit, and most users hardly ever read privacy policies. Several recent efforts aim to crowdsource the interpretation of privacy policies and use the resulting annotations to build more effective user interfaces that provide users with salient policy summaries. However, very little attention has been devoted to studying the accuracy and scalability of crowdsourced privacy policy annotations, the types of questions crowdworkers can effectively answer, and the ways in which their productivity can be enhanced. Prior research indicates that most Internet users often have great difficulty understanding privacy policies, suggesting limits to the effectiveness of crowdsourcing approaches. In this paper, we assess the viability of crowdsourcing privacy policy annotations. Our results suggest that, if carefully deployed, crowdsourcing can indeed result in the generation of non-trivial annotations and can also help identify elements of ambiguity in policies. We further introduce and evaluate a method to improve the annotation process by predicting and highlighting paragraphs relevant to specific data practices. Shomir Wilson, Florian Schaub, Rohan Ramanath, Norman M. Sadeh, Fei Liu 0004, Noah A. Smith, Frederick Liu |
WWW | 2 |
| 2016 | Mining Privacy Goals from Privacy Policies Using Hybridized Task RecompositionabstractPrivacy policies describe high-level goals for corporate data practices; regulators require industries to make available conspicuous, accurate privacy policies to their customers. Consequently, software requirements must conform to those privacy policies. To help stakeholders extract privacy goals from policies, we introduce a semiautomated framework that combines crowdworker annotations, natural language typed dependency parses, and a reusable lexicon to improve goal-extraction coverage, precision, and recall. The framework evaluation consists of a five-policy corpus governing web and mobile information systems, yielding an average precision of 0.73 and recall of 0.83. The results show that no single framework element alone is sufficient to extract goals; however, the overall framework compensates for elemental limitations. Human annotators are highly adaptive at discovering annotations in new texts, but those annotations can be inconsistent and incomplete; dependency parsers lack sophisticated, tacit knowledge, but they can perform exhaustive text search for prospective requirements indicators; and while the lexicon may never completely saturate, the lexicon terms can be reliably used to improve recall. Lexical reuse reduces false negatives by 41%, increasing the average recall to 0.85. Last, crowd workers were able to identify and remove false positives by around 80%, which improves average precision to 0.93. Jaspreet Bhatia, Travis D. Breaux, Florian Schaub |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2015 | Your Location has been Shared 5, 398 Times!: A Field Study on Mobile App Privacy NudgingabstractSmartphone users are often unaware of the data collected by apps running on their devices. We report on a study that evaluates the benefits of giving users an app permission manager and sending them nudges intended to raise their awareness of the data collected by their apps. Our study provides both qualitative and quantitative evidence that these approaches are complementary and can each play a significant role in empowering users to more effectively control their privacy. For instance, even after a week with access to the permission manager, participants benefited from nudges showing them how often some of their sensitive data was being accessed by apps, with 95% of participants reassessing their permissions, and 58% of them further restricting some of their permissions. We discuss how participants interacted both with the permission manager and the privacy nudges, analyze the effectiveness of both solutions, and derive some recommendations. Hazim Almuhimedi, Florian Schaub, Norman M. Sadeh, Idris Adjerid, Alessandro Acquisti, Joshua Gluck, Lorrie Faith Cranor, Yuvraj Agarwal |
CHI | 2 |
| 2015 | A Design Space for Effective Privacy Notices
Florian Schaub, Rebecca Balebako, Adam L. Durity, Lorrie Faith Cranor |
SOUPS | 1 |
| 2014 | User Authentication for Rotary Knob Controlled In-car ApplicationsabstractIn recent years, the automobile has become more connected and has started offering drivers a variety of services and applications for in-car use, such as Facebook, Twitter, and mobile payment. Many such services require user authentication. We have investigated the requirements and potential of authenticating users with a rotary control knob, which constitutes the central control entity (CCE) in many modern cars. In a user-centered design approach we adapted three established authentication schemes for in-car usage with consideration to driver distraction. We performed extensive user experiments in a driving simulator focusing on usability, security and driver distraction. The results of our experiments provide relevant insights for integrating user authentication methods into the automotive context solely based on present hardware components. Jan Gugenheimer, Florian Schaub, Gregory M. Neiswander, Eromi Guneratne, Michael Weber 0001 |
AutomotiveUI | 2 |
| 2014 | Broken display = broken interface': the impact of display damage on smartphone interactionabstractThis paper is the first to assess the impact of touchscreen damage on smartphone interaction. We gathered a dataset consisting of 95 closeup images of damaged smartphones and extensive information about a device's usage history, damage severity, and impact on use. 88% of our participants continued to use their damaged smartphone for at least three months; 32% plan to use it for another year or more, mainly due to high repair and replacement costs. From the dataset, we identified three categories of damaged smartphone displays. Reading and text input were most affected. Further interviews (n=11) revealed that users adapt to damage with diverse coping strategies, closely tailored to specific interaction issues. In total, we identified 23 different strategies. Based on our results, we proposed guidelines for interaction design in order to provide a positive user experience when display damage occurs. Florian Schaub, Julian Seifert, Frank Honold, Enrico Rukzio, Michael Weber 0001 |
CHI | 1 |
| 2014 | Identifying Relevant Text Fragments to Help Crowdsource Privacy Policy AnnotationsabstractIn today's age of big data, websites are collecting an increasingly wide variety of information about their users. The texts of websites' privacy policies, which serve as legal agreements between service providers and users, are often long and difficult to understand. Automated analysis of those texts has the potential to help users better understand the implications of agreeing to such policies. In this work, we present a technique that combines machine learning and crowdsourcing to semi-automatically extract key aspects of website privacy policies that is scalable, fast, and cost-effective. Rohan Ramanath, Florian Schaub, Shomir Wilson, Fei Liu 0004, Norman M. Sadeh, Noah A. Smith |
HCOMP | 2 |
| 2014 | Crowdsourcing the Extraction of Data Practices from Privacy PoliciesabstractWebsite and mobile application privacy policies are intended to describe the system’s data practices. However, they are often written in non-standard formats and contain ambiguities that make it difficult for users to read and comprehend these documents. We propose a crowdsourcing approach to extract data practices from privacy policies to provide more concise and useable privacy notices to users and support the analysis of stated data practices. To that end, we designed a hierarchical task workflow for crowdsourcing the extraction of data practices from privacy policies. We discuss our workflow design and report preliminary results. Florian Schaub, Travis D. Breaux, Norman M. Sadeh |
HCOMP | 1 |
| 2014 | PriCal: context-adaptive privacy in ambient calendar displaysabstractPriCal is an ambient calendar display that shows a user's schedule similar to a paper wall calendar. PriCal provides context-adaptive privacy to users by detecting present persons and adapting event visibility according to the user's privacy preferences. We present a detailed privacy impact assessment of our system, which provides insights on how to leverage context to enhance privacy without being intrusive. PriCal is based on a decentralized architecture and supports the detection of registered users as well as unknown persons. In a three-week deployment study with seven displays, ten participants used PriCal in their real work environment with their own digital calendars. Our results provide qualitative insights on the implications, acceptance, and utility of context-adaptive privacy in the context of a calendar display system, indicating that it is a viable approach to mitigate privacy implications in ubicomp applications. Florian Schaub, Bastian Könings, Peter Lang, Björn Wiedersheim, Christian Winkler 0001, Michael Weber 0001 |
UbiComp | 1 |
| 2014 | Privacy implications of presence sharing in mobile messaging applicationsabstractMobile messaging applications, such as WhatsApp, provide a free alternative for mobile texting on smartphones. Mobile messengers typically also share presence information about users to indicate when a user is online. We investigated the privacy implications of such presence updates, using WhatsApp as an example. We conducted a user study with two independent groups (19 participants in total), in which we collected and analyzed their presence information over four weeks of regular WhatsApp use and conducted follow-up interviews. Our results show that presence information alone is sufficient to accurately identify, for example, daily routines, deviations, times of inappropriate mobile messaging, or conversation partners. We discuss resulting privacy implications of presence information and potential solutions to mitigate these issues. Andreas Buchenscheit, Bastian Könings, Andreas Neubert, Florian Schaub, Frank Kargl |
MUM | 4 |
| 2014 | PriPref broadcaster: enabling users to broadcast privacy preferences in their physical proximityabstractWhile privacy is often treated as an information centric issue, privacy issues in ubiquitous and mobile computing also encompass physical or territorial aspects, i.e., the right to be left alone or undisturbed. Disturbances that affect privacy often stem from persons nearby and their mobile devices, e.g., ringing phones, loud phone calls, or sounds of mobile games. We propose PriPref Broadcaster, a smartphone-based approach for communicating personal privacy preferences to persons in physical proximity. Our approach further supports automatic adaptation of mobile device settings based on the dominating preferences in the current environment. Results from a usability study and a five-day field trial with 28 participants show that broadcasting privacy preferences is perceived as meaningful and has the potential to support privacy signaling in many everyday situations. Bastian Könings, Sebastian Thoma, Florian Schaub, Michael Weber 0001 |
MUM | 3 |
| 2014 | Scaling requirements extraction to the crowd: Experiments with privacy policiesabstractNatural language text sources have increasingly been used to develop new methods and tools for extracting and analyzing requirements. To validate these new approaches, researchers rely on a small number of trained experts to perform a labor-intensive manual analysis of the text. The time and resources needed to conduct manual extraction, however, has limited the size of case studies and thus the generalizability of results. To begin to address this issue, we conducted three experiments to evaluate crowdsourcing a manual requirements extraction task to a larger number of untrained workers. In these experiments, we carefully balance worker payment and overall cost, as well as worker training and data quality to study the feasibility of distributing requirements extraction to the crowd. The task consists of extracting descriptions of data collection, sharing and usage requirements from privacy policies. We present results from two pilot studies and a third experiment to justify applying a task decomposition approach to requirements extraction. Our contributions include the task decomposition workflow and three metrics for measuring worker performance. The final evaluation shows a 60% reduction in the cost of manual extraction with a 16% increase in extraction coverage. Travis D. Breaux, Florian Schaub |
RE | 2 |
| 2014 | Hover Pad: interacting with autonomous and self-actuated displays in spaceabstractHandheld displays enable flexible spatial exploration of information spaces -- users can physically navigate through three-dimensional space to access information at specific locations. Having users constantly hold the display, however, has several limitations: (1) inaccuracies due to natural hand tremors; (2) fatigue over time; and (3) limited exploration within arm's reach. We investigate autonomous, self-actuated displays that can freely move and hold their position and orientation in space without users having to hold them at all times. We illustrate various stages of such a display's autonomy ranging from manual to fully autonomous, which -- depending on the tasks -- facilitate the interaction. Further, we discuss possible motion control mechanisms for these displays and present several interaction techniques enabled by such displays. Our Hover Pad toolkit enables exploring five degrees of freedom of self-actuated and autonomous displays and the developed control and interaction techniques. We illustrate the utility of our toolkit with five prototype applications, such as a volumetric medical data explorer. Julian Seifert, Sebastian Boring, Christian Winkler 0001, Florian Schaub, Fabian Schwab, Steffen Herrdum, Fabian Maier, Daniel Mayer, Enrico Rukzio |
UIST | 4 |
| 2013 | Find my stuff: supporting physical objects search with relative positioningabstractSearching for misplaced keys, phones, or wallets is a common nuisance. Find My Stuff (FiMS) provides search support for physical objects inside furniture, on room level, and in multiple locations, e.g., home and office. Stuff tags make objects searchable while all other localization components are integrated into furniture. FiMS requires minimal configuration and automatically adapts to the user's furniture arrangement. Object search is supported with relative position cues, such as "phone is inside top drawer" or "the wallet is between couch and table," which do not require exact object localization. Functional evaluation of our prototype shows the approach's practicality with sufficient accuracy in realistic environments and low energy consumption. We also conducted two user studies, which showed that objects can be retrieved significantly faster with FiMS than manual search and that our relative position cues provide better support than map-based cues. Combined with audiovisual feedback, FiMS also outperforms spotlight-based cues. Jens Nickels, Pascal Knierim, Bastian Könings, Florian Schaub, Björn Wiedersheim, Steffen Musiol, Michael Weber 0001 |
UbiComp | 4 |
| 2013 | Device Names in the Wild: Investigating Privacy Risks of Zero Configuration NetworkingabstractZero configuration networking aims to support users in seamlessly connecting devices and services. However, in public networks associated service announcements pose substantial privacy risks. A major issue is the inclusion of identifying information in device names, often automatically set or suggested by devices upon initial configuration. Focusing on mDNS, we assess this issue by studying its actual extent, awareness about the problem, and potential consequences for privacy. We collected a one-week dataset of mDNS announcements in a semi-public Wi-Fi network at a university. Of 2,957 unique device names, 59% contained real names of users, with 17.6% containing first and last name. An online survey (n=137) revealed that 29% of the participants did not know the current device name of their smartphone, but that the vast majority considered periodic announcement of their full names worrisome. We further discuss specific potential privacy threats and attack scenarios stemming from mDNS device names. Bastian Könings, Christoph Bachmaier, Florian Schaub, Michael Weber 0001 |
MDM (2) | 3 |
| 2013 | Exploring the design space of graphical passwords on smartphonesabstractSmartphones have emerged as a likely application area for graphical passwords, because they are easier to input on touchscreens than text passwords. Extensive research on graphical passwords and the capabilities of modern smartphones result in a complex design space for graphical password schemes on smartphones. We analyze and describe this design space in detail. In the process, we identify and highlight interrelations between usability and security characteristics, available design features, and smartphone capabilities. We further show the expressiveness and utility of the design space in the development of graphical passwords schemes by implementing five different existing graphical password schemes on one smartphone platform. We performed usability and shoulder surfing experiments with the implemented schemes to validate identified relations in the design space. From our results, we derive a number of helpful insights and guidelines for the design of graphical passwords. Florian Schaub, Marcel Walch, Bastian Könings, Michael Weber 0001 |
SOUPS | 1 |
| 2013 | On credibility improvements for automotive navigation systemsabstractAutomotive navigation systems are becoming ubiquitous as driver assistance systems. Vendors continuously aim to enhance route guidance by adding new features to their systems. However, we found in an analysis of current navigation systems that many share interaction weaknesses, which can damage the system’s credibility. Such issues are most prevalent when selecting a route, deviating from the route intentionally, or when systems react to dynamic traffic warnings. In this work, we analyze the impact on credibility and propose improved interaction mechanisms to enhance perceived credibility of navigation systems. We improve route selection and the integration of dynamic traffic warnings by optimizing route comparability with relevance-based information display. Further, we show how bidirectional communication between driver and device can be enhanced to achieve a better mapping between device behavior and driver intention. We evaluated the proposed mechanisms in a comparative user study and present results that confirm positive effects on perceived credibility. Florian Schaub, Markus Hipp, Frank Kargl, Michael Weber 0001 |
Pers. Ubiquitous Comput. | 1 |
| 2012 | Privacy context model for dynamic privacy adaptation in ubiquitous computingabstractUbiquitous computing is characterized by the merger of physical and virtual worlds as physical artifacts gain digital sensing, processing, and communication capabilities. Maintaining an appropriate level of privacy in the face of such complex and often highly dynamic systems is challenging. We argue that context awareness not only enables novel UbiComp applications but can also support dynamic regulation and configuration of privacy mechanisms. We propose a higher level context model that abstracts from low level details and contains only privacy relevant context features. Context changes in our model can trigger reconfiguration of privacy mechanisms or facilitate context-specific privacy recommendations to the user. Based on our model, we analyze potential privacy implications of context changes and discuss how these results could inform actual reconfiguration of privacy mechanisms. Florian Schaub, Bastian Könings, Stefan Dietzel, Michael Weber 0001, Frank Kargl |
UbiComp | 1 |
| 2012 | Find my stuff: a search engine for everyday objectsabstractSearching for lost keys, wallets or mobile phones is a common nuisance. Compared to digital information, search support for physical objects is very limited. We propose Find My Stuff (FiMS) as a search engine for physical objects. We built a fully functional Arduino-based prototype. FiMS offers the users a simple search interface to locate tagged physical items in different indoor environments. A hierarchical search process ensures energy efficient and effective searches. Instead of a fixed search infrastructure, the localization system is based on SmartFurniture equipped with RFID readers and ZigBee modules. Search results provide intuitive search cues based on relative positioning to support users in the physical retrieval of their lost objects. The system requires no manual calibration and is robust against rearrangement of SmartFurniture. Safety mechanisms prevent abuse of the system and protect user privacy. Pascal Knierim, Jens Nickels, Steffen Musiol, Bastian Könings, Florian Schaub, Björn Wiedersheim, Michael Weber 0001 |
MUM | 5 |
| 2012 | Password entry usability and shoulder surfing susceptibility on different smartphone platformsabstractVirtual keyboards of different smartphone platforms seem quite similar at first glance, but the transformation from a physical to a virtual keyboard on a small-scale display results in user experience variations that cause significant differences in usability as well as shoulder surfing susceptibility, i.e., the risk of a bystander observing what is being typed. In our work, we investigate the impact of both aspects on the security of text-based password entry on mobile devices. In a between subjects study with 80 participants, we analyzed usability and shoulder surfing susceptibility of password entry on different mobile platforms (iOS, Android, Windows Phone, Symbian, MeeGo). Our results show significant differences in the usability of password entry (required password entry time, typing accuracy) and susceptibility to shoulder surfing. Our results provide insights for security-aware design of on-screen keyboards and for password composition strategies tailored to entry on smartphones. Florian Schaub, Ruben Deyhle, Michael Weber 0001 |
MUM | 1 |
| 2012 | Ginger: An Access Control Framework for Telematics ApplicationsabstractTelematics applications in automobiles have attracted considerable attention for their promise of value-added services. However, new challenges arise from the integration of telematics applications that require a multitude of vehicular data. The safety-critical context of the automotive domain calls for reliable access control mechanisms, especially when applications access sensitive data. However, those mechanisms must also respect the requirement of minimal driver distraction. To cope with these issues we propose Ginger -- an access control framework for telematics applications. Ginger is context aware, provides enhanced privacy protection, and realizes advanced access control paradigms. We demonstrate Ginger's feasibility with an Android-based implementation in a functional evaluation consisting of two representative use cases and in a comparative analysis with related approaches. David Herges, Naim Asaj, Bastian Könings, Florian Schaub, Michael Weber 0001 |
TrustCom | 4 |
| 2010 | Interaction weaknesses of personal navigation devicesabstractAutomotive navigation systems, especially portable navigation devices (PNDs), are gaining popularity worldwide. Drivers increasingly rely on these devices to guide them to their destination. Some follow them almost blindly, with devastating consequences if the routing goes wrong. Wrong messages as well as superfluous and unnecessary messages can potentially reduce the credibility of those devices. We performed a comparative study with current PNDs from different vendors and market segments, in order to assess the extent of this problem and how it is related to the interaction between device and driver. In this paper, we report the corresponding results and identify multiple interaction weaknesses that are prevalent throughout all tested device classes. Markus Hipp, Florian Schaub, Frank Kargl, Michael Weber 0001 |
AutomotiveUI | 2 |
| 2010 | V-Tokens for Conditional Pseudonymity in VANETsabstractPrivacy is an important requirement in vehicle networks, because vehicles broadcast detailed location information. Also of importance is accountability due to safety critical applications. Conditional pseudonymity, i.e., usage of resolvable pseudonyms, is a common approach to address both. Often, resolvability of pseudonyms is achieved by authorities maintaining pseudonym- identity mappings. However, these mappings are privacy sensitive and require strong protection to prevent abuse or leakage. We present a new approach that does not rely on pseudonym-identity mappings to be stored by any party. Resolution information is directly embedded in pseudonyms and can only be accessed when multiple authorities cooperate. Our privacy-preserving pseudonym issuance protocol ensures that pseudonyms contain valid resolution information but prevents issuing authorities from creating pseudonym-identity mappings. Florian Schaub, Frank Kargl, Zhendong Ma, Michael Weber 0001 |
WCNC | 1 |
| 2009 | Channel switch and quiet attack: New DoS attacks exploiting the 802.11 standardabstractNetwork communication using unprotected air as a medium leads to unique challenges ensuring confidentiality, integrity and availability. While newer amendments of IEEE 802.11 provide acceptable confidentiality and integrity, availability is still questionable despite broad usage of Wi-Fi technologies for tasks where availability is critical. We will present new security weaknesses that we have identified in the 802.11 standard and especially the 802.11h amendment. Our results are underlined by an extensive analysis of attacks addressing the quiet information element and channel switch announcement in management frames. For some stations a complete DoS effect can be achieved with a single packet for more than one minute. This shows that the newly identified attacks are more efficient than earlier approaches like a deauthentication attack. Tests were performed with a large variety of network interface cards, mobile devices, and operating systems. Bastian Könings, Florian Schaub, Frank Kargl, Stefan Dietzel |
LCN | 2 |