VLDB 2026 Research / reviewers in the wild / expert
Mahdi N. Al-Ameen
dblp:119/5033 · also Mahdi Nasrullah Al-Ameen
· DBLP profile ↗
40ranked-venue papers
12as first author
25since 2021 · last 2026
0000-0002-5764-2253ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 26 · 5 first-author · 20 since 2021Security and privacy · 13 · 7 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "We listen, we don't judge": Exploring Design Opportunities for Emotional Literacy and Normalization in Parent-Child InteractionsabstractWe focus on emotional literacy and normalization to foster safe space in parent-child communication. To this end, we conceptualized our designs through two focus group sessions; first with three child experts, followed by a session with four UX experts. We then created storyboards accommodating our designs, which we used as interview stimuli in a study with 16 parent-child dyads in the USA, aimed at understanding the usefulness and applicability of our designs. Our findings show promise in creating safe space in parent-child interaction through offering ease and flexibility in expression, allowing opportunities for situational appraisal, cultivating reassurance of judgment-free space, and fostering accountability towards collaborative activity. Rizu Paudel, Mahdi N. Al-Ameen |
IDC | 2 |
| 2026 | "...Anything My Friend Shares, I Would Want to Support Them by Clicking on It": Co-Designing Story-Based Interventions Against Clickbait for TeenagersabstractTeenagers’ lack of digital sophistication makes them vulnerable to social engineering attacks. Clickbait, one of such attacks, is primarily performed through social media to trick users into clicking on malicious links. With teenagers’ increasing use of social media, clickbait poses a substantial threat to their online safety. The existing online safety measures for teens mainly focus on parental mediation, which can be perceived as restrictive. Here, researchers recommended empowering teens to deal with online risks. To that end, we conducted co-design sessions with 27 teenagers aimed at understanding their perceptions and designing countermeasures against clickbait. Our findings suggest that teenagers are vulnerable to clickbait due to relevance and peer influence, where co-design revealed interventions with unique teen perspectives through storytelling. Overall, our study provides valuable insights into understanding teenagers’ needs around clickbait and interventions against it. We offer guidelines for future research in these directions based on our findings. Ankit Shrestha, Audrey Flood, Bryson D. Hackler, Mahdi N. Al-Ameen |
Int. J. Hum. Comput. Interact. | 4 |
| 2025 | Understanding Teen's Expectations and Challenges to Seek Help in Social Media
Rizu Paudel, Mahdi N. Al-Ameen |
IDC | 2 |
| 2025 | One Size Doesn't Fit All: Towards Design and Evaluation of Developmentally Appropriate Parental Control ToolabstractAs children progress through developmental stages, they undergo substantial biological, cognitive, and social changes, creating unique needs for online safety across different age groups (e.g., young children, tweens, teens). The existing parental control tools fail to account for these differences, leaving a notable gap in the literature on parental mediation. To this end, we conducted 10 focus group sessions with a total of 20 parents to understand their preferences for age-appropriate design components that promote self-regulation and open communication, followed by an ideation workshop with four UX design experts to translate these preferences into customized features. We then evaluated these designs (presented as storyboards) through semi-structured interviews with 25 parents. Our study joins the body of work on parental mediation, providing valuable insights into customizing parental control settings as children transition through the developmental stages. Based on our findings, we offer guidelines for future research in these directions. Prakriti Dumaru, Mahdi N. Al-Ameen |
CHI | 2 |
| 2025 | Mental Model-Based Designs: The Study in Privacy Policy LandscapeabstractUsers’ mental models influence secure and privacy-preserving behavior in a computing environment. Prior studies on users’ mental models of Internet, security tools, and digital privacy show that there is no one-size-fits-all solution when it comes to security and privacy design. However, little study to date has explored the ways to translate users’ mental models into interactive security and privacy designs. As we begin to address this gap, we focus on privacy policy in this paper. The typical text-based privacy policy suffers from poor readability and usability. A recent study proposed a Visual Interactive Privacy Policy (VIPP), showing promise to offer a better user experience as compared to prior designs – we used VIPP as a control condition and compared that with our mental model (MM)-based designs, inspired by users’ privacy mental models explored in the existing literature. We iteratively improved our MM-based designs through a series of user studies in the lab setting. We evaluated our updated designs in an online study with 182 participants over Amazon Mechanical Turk. The participants rated MM-based designs significantly better than the control in most of our evaluation parameters. Furthermore, we found that when a design is centered around the mental model of participants, study participants rated it higher in terms of personal connection to the design, perspicuity, attractiveness, being stimulated towards privacy protection, as well as the propensity for real-life adoption. Based on our findings, we discussed the successes and challenges of MM-based designs and provided guidelines on the scope of leveraging mental models in the broader area of privacy and security designs. Hanieh Atashpanjeh, Rizu Paudel, Mahdi N. Al-Ameen |
Int. J. Hum. Comput. Interact. | 3 |
| 2025 | "It's Definitely New and Different...It's Really Engaging": Understanding the Power of Storytelling Towards Secure Password CreationabstractThere is a dearth in existing literature to attain systematic understanding of leveraging digital storytelling in security designs. As we begin to address this gap, we focused on user authentication where the existing password composition policies and password meters often fail to help users around creating a strong and memorable password. To this end, we conducted a lab study with 19 participants, where we updated our initial designs in an iterative manner based on their feedback. We then conducted a between-subject online study with 104 participants over Amazon Mechanical Turk to evaluate our designs. We found that all of our designs received positive ratings from participants in terms of how they felt confident, and capable in password creation upon interacting with our design. Taken together, the findings from our studies unpacked users’ perceptions and preferences in using storytelling around password creation, where we provide guideline for future research in these directions. Rizu Paudel, Mahdi N. Al-Ameen |
Int. J. Hum. Comput. Interact. | 2 |
| 2025 | "It is Luring You to Click on the Link With False Advertising" - Mental Models of Clickbait and Its Impact on User's Perceptions and Behavior Towards Clickbait WarningsabstractClickbait, a social engineering attack performed through social media, tricks users through sensationalized or misleading posts into clicking on links that direct them to malicious websites. With the recent boom in social media, clickbait has become a substantial security concern, necessitating efforts from platforms and academia to control it. Despite these attempts, clickbait is effective due to the lack of users’ knowledge. Therefore, we explore user mental models (thought processes about how something works) about clickbait to analyze their deficiencies and their influences on users’ behavior towards clickbait warnings. To this end, we conducted an online study with 770 participants over MTurk to generate user mental models about clickbait and to evaluate the clickbait warnings conveying harm. Our findings suggest that a large portion of users have a simple mental model that fails to comprehend the dangers of clickbait, indicating the importance of warnings in supporting and educating users. Overall, our studies provide valuable insights into understanding the impact of clickbait mental models on users’ online security behavior in social media and offer guidelines for future research in these directions. Ankit Shrestha, Arezou Behfar, Mahdi N. Al-Ameen |
Int. J. Hum. Comput. Interact. | 3 |
| 2025 | This One Weird Trick Gets Users to Stop Clicking on ClickbaitabstractClickbait, masked behind interesting headlines and thumbnails, is often used to spread misinformation and trick users into clicking on social media posts or links that direct them to malicious websites. To help users protect against clickbait, we examined interventions based on persuasion theories including designs that used social consequence, personal consequence, and badges. To this end, we first conducted a preliminary study to translate the participants’ feedback into improving our initial designs, followed by a lab study with 20 participants (60% Male, 40% Female; 18–44 years old) aimed at understanding their perceptions of the improved interventions; we further updated our designs based on their feedback. We then conducted an online study with 773 participants (56% Male, 42% Female; 18 to above 65 years old) over MTurk to evaluate the impact of persuasion techniques leveraged in our designs. Our findings suggest that persuasion can be an effective strategy to warn users against clickbait, specifically ones that use incentives such as revealing mystery of clickbait. Overall, our studies provide valuable insights into understanding users’ needs and expectations around interventions against clickbait, and offer guidelines for future research in these directions. Ankit Shrestha, Arezou Behfar, Sovantharith Seng, Matthew Wright 0001, Mahdi N. Al-Ameen |
Int. J. Hum. Comput. Interact. | 5 |
| 2025 | "Synchronized parenting is like mixing oil and water": Reimagining Parental Control for Co-parenting in the Divorced HouseholdsabstractChildren from divorced households are granted access to devices (e.g., smartphones, tablets), helping them to maintain meaningful contact with both parents. However, regulating their device usage across two households presents unique co-parenting challenges, which are little studied in the existing literature on parental mediation. As we begin to address this gap, we used low-fidelity prototype designs, guided by the principles of fostering open communication and instilling self-regulation. We evaluated those designs (presented in the form of storyboards) through semi-structured interviews with 23 divorced parents, whose children are active Internet users and aged 13 years or below. Based on our analysis, we identified six distinct personas under four co-parenting types: conflicted, cooperative, parallel, and uninvolved. We then validated these personas through three focus group sessions with seven divorced parents. Within the context of these personas, we delve into diverse co-parenting challenges, shed light on the perceived benefits of the design in addressing those challenges, and outline design modifications suggested by parents to suit various co-parenting situations. The insights from our studies offer recommendations and guidelines for future research in the sphere of dynamic co-parenting. Prakriti Dumaru, Audrey Flood, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | "I feel like he's looking in the computer world to be social, but I can't trust his judgement": Reimagining Parental Control for Children with ASDabstractChildren with Autism Spectrum Disorder (ASD) often seek comfort from devices (e.g., smartphones) to deal with social overstimulation. However, such reliance exposes them to inappropriate digital content and increases susceptibility to mimicry and social vulnerability. Thus, parents having children with ASD encounter unique challenges in regulating their device usage, which are little addressed in the existing literature on parental mediation. As we begin to address this gap, we designed low-fidelity prototypes centered around open communication and self-regulation, which we refined based on the feedback from six ASD experts in two focus groups. We evaluated updated designs (presented in form of storyboards) through semi-structured interviews with 25 parents whose children with ASD (aged below 14) are active Internet users. Our study joins the body of work on parental mediation; our findings provide insights into inclusive parental control tools for children with ASD, and offer guidelines for future research in these directions. Prakriti Dumaru, Bryson D. Hackler, Audrey Flood, Mahdi N. Al-Ameen |
CHI | 4 |
| 2024 | A First Look into Targeted Clickbait and its Countermeasures: The Power of StorytellingabstractClickbait headlines work through superlatives and intensifiers, creating information gaps to increase the relevance of their associated links that direct users to time-wasting and sometimes even malicious websites. This approach can be amplified using targeted clickbait that takes publicly available information from social media to align clickbait to users’ preferences and beliefs. In this work, we first conducted preliminary studies to understand the influence of targeted clickbait on users’ clicking behavior. Based on our findings, we involved 24 users in the participatory design of story-based warnings against targeted clickbait. Our analysis of user-created warnings led to four design variations, which we evaluated through an online survey over Amazon Mechanical Turk. Our findings show the significance of integrating information with persuasive narratives to create effective warnings against targeted clickbait. Overall, our studies provide valuable insights into understanding users’ perceptions and behaviors towards targeted clickbait, and the efficacy of story-based interventions. Ankit Shrestha, Audrey Flood, Saniat Javid Sohrawardi, Matthew Wright 0001, Mahdi N. Al-Ameen |
CHI | 5 |
| 2024 | "...I have my dad, sister, brother, and mom's password": unveiling users' mental models of security and privacy-preserving toolsabstractPurpose The purpose of this study is to understand user perceptions and misconceptions regarding security tools. Security and privacy-preserving tools (for brevity, the authors term them as “security tools” in this paper, unless otherwise specified) are designed to protect the security and privacy of people in the digital environment. However, inappropriate use of these tools can lead to unexpected consequences that are preventable. Hence, it is significant to examine why users do not understand the security tools. Design/methodology/approach The authors conducted a qualitative study with 40 participants in the USA to investigate the prevalent misconceptions of people regarding security tools, their perceptions of data access and the corresponding impact on their usage behavior and data protection strategies. Findings While security vulnerabilities are often rooted in people’s internet usage behavior, this study examined user’s mental models of the internet and unpacked how the misconceptions about security tools relate to those mental models. Originality/value Based on the findings, this study offers recommendations highlighting the design aspects of security tools that need careful attention from researchers and industry practitioners, to alleviate users’ misconceptions and provide them with accurate conceptual models toward the desired use of security tools. Prakriti Dumaru, Ankit Shrestha, Rizu Paudel, Cassity Haverkamp, Maryellen Brunson McClain, Mahdi N. Al-Ameen |
Inf. Comput. Secur. | 6 |
| 2024 | "It's hard for him to make choices sometimes and he needs guidance": Re-orienting Parental Control for ChildrenabstractWith access to devices and online platforms at an increasingly younger age, it is essential to protect children from potential online risks. In our studies, we particularly focused the parents who have a child under 13 years of age. To this end, deriving from developmental psychology, we base our low-fidelity prototype design (termed as 'treatment') on a set of design principles focusing on open communication, instilling self-regulation, and availing granularity along with designs of existing Google's parental control as a baseline. First, we conducted semi-structured interviews with 21 parents to understand their perceptions, including suggestions for design improvement within our prototype. Then, we conducted an online study over MTurk with 156 participants to compare and evaluate the treatment condition against the baseline in the realm of our design principles. As reflected in our results, parents appreciated the insights into the children's activities to have a meaningful discussion with them, the significance of nudges in instilling self-regulation, and the usefulness of granularity in a wide range of contexts, including shielding the children from inappropriate content and defining purpose-specific device usage. The findings from our studies lead to the recommendations, and the guideline for future research in the sphere of developmental parenting and inclusiveness. Prakriti Dumaru, Hanieh Atashpanjeh, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | Priming through Persuasion: Towards Secure Password BehaviorabstractUsers tend to create weak passwords even for the important accounts. The prior research shed light on user's insecure password behavior, and why the interventions, including requirement specification (e.g., password composition policies) and feedback systems (e.g., password meters) fail in practice. To this end, we propose and evaluate the concept: priming-through-persuasion in the realm of secure password creation. In particular, we created visual designs, aimed at priming users about the repercussions of weak passwords before their password creation. We base our designs on two forms of persuasion methods: pathos and logos. Pathos appeals to people's emotion in order to persuade them towards an expected behavior, where logos-based rhetoric appeals to a person's sense of reason. We conducted a lab study including participatory design and semi-structured interview with 20 participants. We updated our designs in an iterative manner based on the feedback from our participants in the lab study. To evaluate our updated designs, we conducted a between-subject online study with 131 participants over Amazon Mechanical Turk. Our study provides insight into how the use of persuasion techniques contributed to user attachment and engagement with the design, as well as the comprehension of the conveyed message about password vulnerabilities. Our findings lead to the guideline for future research on leveraging the priming-through-persuasion to complement the existing techniques in encouraging users towards secure behavior. Rizu Paudel, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2024 | Leveraging the Power of Storytelling to Encourage and Empower Children towards Strong PasswordsabstractWith the increasing use of computer and smartphones by children, their online safety has been of major concern due to their limited security knowledge and skills. User authentication is pivotal for their security protection, where a body of work focused on children's password practices. The insights from these studies highlight children's lack of awareness and skills in creating a strong password. However, there is a dearth in existing literature to understand the scopes of designs for encouraging and empowering children towards strong passwords. As we begin to address this gap, we leveraged the power of storytelling to foster user attachment, encouragement, and empowerment. To this end, we adopted a systematic approach through a series of studies. First, a focus group session with three experts whose research primarily focuses on children contributed to build the narrative of a story, followed by a participatory design study with 20 children (aged between 8 and 12) to understand their preferences and perceptions of design components for the visual depiction of that narrative. The insights from focus group and participatory design led to the design of 'Story', a digital storytelling based design representing password advice for children. We also created the baseline designs and compared them with Story in a within-subject survey with 44 children aged between 8 and 12. The findings from our study unpack the efficacy of storytelling, leading us to offer guidelines for future research in these directions. Rizu Paudel, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2023 | A Deep Dive into User's Preferences and Behavior around Mobile Phone SharingabstractUsers share their personal devices with different entities in various circumstances. While prior research shed light on the broad reasons behind the sharing of mobile phones, there is a dearth of systematic study to understand the user's decision-making process and the underlying preferences and concerns in the context of phone sharing. To address these gaps, we designed a prototype that we leveraged to investigate the interplay between a user's relationship with sharees, preferences of sharing a subset of apps with a certain entity, perceived sensitivity of the apps being shared, and how these factors relate to their authentication behavior. We conducted a multi-session study with 50 participants from three countries (USA, Turkey, and Nepal), where the participants interacted with our prototype and took part in semi-structured interviews. The findings from our study revealed the need for phone sharing at a granular level, where we identified the factors that could influence a user's decision-making process in sharing. Our analysis unpacked the relation between a user's perceived sensitivity of apps being shared, and authentication behavior to protect information from unauthorized access. Overall, our findings advance the CSCW community's understanding of how the user attains a balance between privacy protection and the need for phone sharing. Rizu Paudel, Prakriti Dumaru, Ankit Shrestha, Huzeyfe Kocabas, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2022 | The Role of Intermediaries, Terrorist Assemblage, and Re-skilling in the Adoption of Cashless Transaction Systems in BangladeshabstractThis work addresses the challenges associated with cashless transactions and Mobile Financial Services (MFS) in the Global South. In our 19-months long interview study in Dhaka, Bangladesh, we engaged with 38 participants, including everyday users, bank employees, and policymakers, and investigated their experiences and perspectives associated with financial services. Our findings reveal a wide range of factors, naming intermediaries, terrorist assemblage, and re-skilling the existing employees that impede the mass adoption of cashless transaction services in Bangladesh. The findings from this study contribute to the ongoing discourse on the challenges and opportunities offered by the digitization of financial systems in Bangladesh. Our recommendations aim to improve the integration of the cashless systems within the societal context of Bangladesh and, more broadly, the Global South. Yasaman Rohanifar, Sharifa Sultana, Swapnil Nandy, Pratyasha Saha, Md. Jonayed Hossain Chowdhury, Mahdi N. Al-Ameen, Syed Ishtiaque Ahmed |
COMPASS | 6 |
| 2022 | On improving the memorability of system-assigned recognition-based passwordsabstractUser-chosen passwords reflecting common strategies and patterns ease memorisation but offer uncertain and often weak security, while system-assigned passwords provide higher security guarantee but suffer from poor memorability. We thus examine the technique to enhance password memorability that incorporates a scientific understanding of long-term memory. In particular, we examine the efficacy of providing users with verbal cues—real-life facts corresponding to system-assigned keywords. We also explore the usability gain of including images related to the keywords along with verbal cues. In our multi-session lab study with 52 participants, textual recognition-based scheme offering verbal cues had a significantly higher login success rate (94.23%) compared to the control condition, i.e. textual recognition without verbal cues (61.54%). When users were provided with verbal cues, adding images contributed to faster recognition of the assigned keywords, and thus had an overall improvement in usability. So, we conducted a field study with 54 participants to further examine the usability of graphical recognition-based scheme offering verbal cues, which showed an average login success rate of 98% in a real-life setting and an overall improvement in login performance with more login sessions. These findings show a promising research direction to gain high memorability for system-assigned passwords. Mahdi N. Al-Ameen, Sonali Tukaram Marne, Kanis Fatema, Matthew Wright 0001, Shannon Scielzo |
Behav. Inf. Technol. | 1 |
| 2022 | Understanding the Behavior, Challenges, and Privacy Risks in Digital Technology Use by Nursing ProfessionalsabstractWith the growing adoption of digital technology in healthcare organizations, it is important to understand nursing professionals' behavior and challenges, and the corresponding privacy implications around digital technology use. To this end, we conducted semi-structured interviews with 21 participants (16 nursing professionals, and five nursing faculties) in the USA. In our study with nursing professionals, we explored how they used digital technology and protected sensitive health data at their workplace. We investigated their understanding of privacy breaches and possible consequences, the challenges they encountered to maintaining privacy, and their workarounds to deal with such issues. We looked into the support that professional nurses receive in the form of organizational training, and how they collaborate with the IT department at their institution to address technical issues. In addition, we shed light on the gap between their academic preparation and professional needs in the context of digital technology use and privacy protection, where we also interviewed five nursing faculties to get more in-depth understanding of this issue from the point of view of academia. Overall, our findings provide valuable insights for the CSCW community to better understand the challenges and privacy risks in digital technology use by nursing professionals, and lead to our recommendations to address these issues. Ankit Shrestha, Danielle M. Graham, Prakriti Dumaru, Rizu Paudel, Kristin A. Searle, Mahdi N. Al-Ameen |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2022 | Imagined Online Communities: Communionship, Sovereignty, and Inclusiveness in Facebook GroupsabstractThrough Facebook "Group" feature, users often sensitize communionships, join different Facebook groups, and establish imagined communities with known people and strangers. In our interview study with 32 admins and users of Facebook groups, we explored the influential factors of such communionships, the challenges the Facebook group admins face while managing these communities, and how they resolve those. Our findings show that admins set rules for the entry and maintenance of the groups, monitor members' activities, and often limit their actions or mute them during conflicts. Thus, the members and admins of the groups together grow a sensibility of sovereignty within the community on Facebook. While the imagined sovereignty in Facebook groups is empowering, this empowerment may not be perceived and experienced evenly by everyone in such online communities. To explain this, we build on the concept of "Imagined Communities' by Benedict Anderson [16 ] and argue that there is a tension between Facebook admins' perceived sovereignty and other users' empowerment in practice. Our work joins the body of CSCW literature that aims at designing more sustainable and collaborative tools for specific communities on Facebook groups and other similar platforms. Sharifa Sultana, Pratyasha Saha, Shaid Hasan, S. M. Raihanul Alam, Rokeya Akter, Md. Mirajul Islam, Raihan Islam Arnob, A. K. M. Najmul Islam, Mahdi N. Al-Ameen, Syed Ishtiaque Ahmed |
Proc. ACM Hum. Comput. Interact. | 9 |
| 2021 | Purdah, Amanah, and Gheebat: Understanding Privacy in Bangladeshi "pious" Muslim CommunitiesabstractHCI has a dearth of knowledge in understanding how religiosity, spirituality, and ideological values and practices shape the notion of privacy and guide information practices worldwide. In this paper, we fill this gap by reporting our findings from an eight-month-long ethnographically informed study in Bangladeshi Islamic communities. We report how the Islamic spirit of purdah, amanah, gheebat, riya, and buhtan represent the notion of privacy and guide privacy practices among “pious” Bangladeshi Muslims. We further discuss how sacred values generate norms and customs associated with privacy and surveillance. Finally, we recommend how a nuanced understanding of divine interests, identity performance, family surveillance, and spatial privacy norms help designing for inclusive privacy in the Global South. This paper makes a novel contribution to HCI by providing a new analytical perspective to understand privacy and design privacy-preserving technologies and tools for regions where religiosity, spirituality, and sacred values play a dominant role. Md. Rashidujjaman Rifat, Mahiratul Jannat, Mahdi N. Al-Ameen, S. M. Taiabul Haque, Muhammad Ashad Kabir, Syed Ishtiaque Ahmed |
COMPASS | 3 |
| 2021 | A first look into users' perceptions of facial recognition in the physical world
Sovantharith Seng, Mahdi N. Al-Ameen, Matthew Wright 0001 |
Comput. Secur. | 2 |
| 2021 | A look into user's privacy perceptions and data practices of IoT devicesabstractPurpose With the rapid deployment of internet of things (IoT) technologies, it has been essential to address the security and privacy issues through maintaining transparency in data practices. The prior research focused on identifying people's privacy preferences in different contexts of IoT usage and their mental models of security threats. However, there is a dearth in existing literature to understand the mismatch between user's perceptions and the actual data practices of IoT devices. Such mismatches could lead users unknowingly sharing their private information, exposing themselves to unanticipated privacy risks. The paper aims to identify these mismatched privacy perceptions in this work. Design/methodology/approach The authors conducted a lab study with 42 participants, where they compared participants’ perceptions with the data practices stated in the privacy policy of 28 IoT devices from different categories, including health and exercise, entertainment, smart homes, toys and games and pets. Findings The authors identified the mismatched privacy perceptions of users in terms of data collection, sharing, protection and storage period. The findings revealed the mismatches between user's perceptions and the data practices of IoT devices for various types of information, including personal, contact, financial, heath, location, media, connected device, online social media and IoT device usage. Originality/value The findings from this study lead to the recommendations on designing simplified privacy notice by highlighting the unexpected data practices, which in turn, would contribute to the secure and privacy-preserving use of IoT devices. Mahdi N. Al-Ameen, Apoorva Chauhan, M. A. Manazir Ahsan, Huzeyfe Kocabas |
Inf. Comput. Secur. | 1 |
| 2021 | A look into user privacy andthird-party applications in FacebookabstractPurpose A huge amount of personal and sensitive data are shared on Facebook, which makes it a prime target for attackers. Adversaries can exploit third-party applications connected to a user’s Facebook profiles (i.e. Facebook apps) to gain access to this personal information. Users’ lack of knowledge and the varying privacy policies of these apps make them further vulnerable to information leakage. However, little has been done to identify mismatches between users’ perceptions and the privacy policies of Facebook apps. This paper aims to address this challenge in the work. Design/methodology/approach The authors conducted a lab study with 31 participants, where the authors received data on how they share information on Facebook, their Facebook-related security and privacy practices and their perceptions on the privacy aspects of 65 frequently-used Facebook apps in terms of data collection, sharing and deletion. The authors then compared participants’ perceptions with the privacy policy of each reported app. Participants also reported their expectations about the types of information that should not be collected or shared by any Facebook app. Findings The analysis reveals significant mismatches between users’ privacy perceptions and reality (i.e. privacy policies of Facebook apps), where the authors identified over-optimism not only in users’ perceptions of information collection but also in their self-efficacy in protecting their information in Facebook despite experiencing negative incidents in the past. Originality/value To the best of the knowledge, this is the first study on the gap between users’ privacy perceptions around Facebook apps and reality. The findings from this study offer direction for future research to address that gap through designing usable, effective and personalized privacy notices to help users to make informed decisions about using Facebook apps. Sovantharith Seng, Mahdi N. Al-Ameen, Matthew Wright 0001 |
Inf. Comput. Secur. | 2 |
| 2021 | "We, three brothers have always known everything of each other": A Cross-cultural Study of Sharing Digital Devices and Online AccountsabstractAbstract Although many technologies assume that a device or an account would be used by a single user, prior research has found that this assumption may not hold true in everyday life. Most studies conducted to date focused on sharing a device or account with the members in a household. However, there is a dearth in existing literature to understand the contexts of sharing devices and accounts, which may extend to a wide range of personal, social, and professional settings. Further, people’s sharing behavior could be impacted by their social background. To this end, our paper presents a qualitative study with 59 participants from three different countries: Bangladesh, Turkey, and USA, where we investigated the sharing of digital devices (e.g., computer, mobile phone) and online accounts, in particular, financial and identity accounts (e.g., email, social networking) in various contexts, and with different entities - not limited to the members in a household. Our study reveals users’ perceptions of risks while sharing a device or account, and their access control strategies to protect privacy and security. Based on our analysis, we shed light on the interplay between users’ sharing behavior and their demographics, social background, and cultural values. Taken together, our findings have broad implications that advance the PETS community’s situated understanding of sharing devices and accounts. Mahdi N. Al-Ameen, Huzeyfe Kocabas, Swapnil Nandy, Tanjina Tamanna |
Proc. Priv. Enhancing Technol. | 1 |
| 2020 | We Don't Give a Second Thought Before Providing Our Information: Understanding Users' Perceptions of Information Collection by Apps in Urban BangladeshabstractWith a rapid increase in the use of digital technologies, people in the Global South including Bangladesh are exposed to a wide-range of smartphone applications (termed as apps in this paper), which offer a variety of features and services. However, privacy leakage through apps has increasingly become a major concern in Bangladesh, where the app collecting users' sensitive information without their consent was reported in news media for privacy violation. Our study with 32 participants from varying age, literacy level, and profession in Dhaka, Bangladesh unveils the perceptions of people around data collection and sharing by the app reported in privacy leakage news. All of our participants were aware of information leakage through the app they use, where they possess varying perceptions around providing personal information, like a sense of benefit, necessity and contribution, indifference, fear, or (no) authority over data collection. Our analysis reveals the relation between users' privacy perceptions, local infrastructure, and social practices in Bangladesh, where we identify the situated challenges that interfere with people's understanding of privacy notice. Our results lead to a discussion on how people's privacy perceptions are influenced by rapid urbanization and the opportunities offered by digitization in Bangladesh. Based on our findings, we provide recommendations to develop situated and sustainable strategies to enhance privacy awareness and practices in the social setting of Bangladesh, and Global South. Mahdi N. Al-Ameen, Tanjina Tamanna, Swapnil Nandy, M. A. Manazir Ahsan, Priyank Chandra, Syed Ishtiaque Ahmed |
COMPASS | 1 |
| 2020 | Understanding the Sensibility of Social Media Use and Privacy with Bangladeshi Facebook Group UsersabstractFacebook users often join Facebook groups to connect to the people with the same interest regardless of the fact that the other members take the same standing with them. Our study aims to investigate Bangladeshi users' motivation to join and strategies to manage their Facebook groups and identify the relevant challenges. In our ongoing work, we are conducting a survey and interviewing Facebook-group users to understand how Facebook groups are bringing the users of similar interest and agenda together on Facebook and providing the admins with imagined sovereignty. This poster presents some of our crucial findings. This set of findings will be useful in designing better tools for managing Facebook groups for empowering the admins and the users. Sharifa Sultana, Pratyasha Saha, Shaid Hasan, S. M. Raihanul Alam, Rokeya Akter, Md. Mirajul Islam, Raihan Islam Arnob, Mahdi N. Al-Ameen, Syed Ishtiaque Ahmed |
COMPASS | 8 |
| 2020 | Privacy Vulnerabilities in Public Digital Service Centers in Dhaka, BangladeshabstractThis paper joins a growing body of work within ICTD and related fields studying the privacy challenges in the Global South. While most of the existing work in this area has focused on uses of technology in personal and home settings, a large part of computing in the Global South centers around public places, such as commercial Digital Service Centers (DSCs). In this paper, we present the findings from a six-month-long ethnography studying 19 Digital Service Centers in Dhaka, Bangladesh. We find that infrastructural limitations, local power politics, lack of knowledge, and insufficient protection mechanisms lead to privacy vulnerabilities for the customers of these centers. We apply the lens of informal markets to analyze these vulnerabilities and connect our findings to the broader concerns of ICTD around development, ethics, and postcolonial computing and discuss potential design and policy implications around these issues. S. M. Taiabul Haque, Md. Romael Haque, Swapnil Nandy, Priyank Chandra, Mahdi N. Al-Ameen, Shion Guha, Syed Ishtiaque Ahmed |
ICTD | 5 |
| 2019 | Poster: Understanding User's Decision to Interact with Potential Phishing Posts on Facebook using a Vignette StudyabstractFacebook remains the largest social media platform on the Internet with over one billion active monthly users. A variety of personal and sensitive data is shared on the platform, which makes it a prime target for attackers. Increasingly, we see phishing attacks that take advantage of users' lack of security knowledge, deceiving victims by using fake or compromised accounts to share malicious posts. These attacks may slip undetected by the Facebook defense system, exposing users to potentially be phished or have their devices infected with drive-by downloads and malware. Only a few studies have been conducted to date to understand how users interact with attacks like this in Facebook. In our prior work, we conducted a study to address this challenge using a simulated interface and think-aloud protocol. In this study, we aim to make further progress in understanding the impact of different factors on users' clicking decision in social media through a vignette study that encourages participants to think about realistic scenarios that they might face. Sovantharith Seng, Huzeyfe Kocabas, Mahdi N. Al-Ameen, Matthew Wright 0001 |
CCS | 3 |
| 2017 | Learning System-assigned Passwords: A Preliminary Study on the People with Learning Disabilities
Sonali Tukaram Marne, Mahdi N. Al-Ameen, Matthew Wright 0001 |
SOUPS | 2 |
| 2017 | When the Weakest Link is Strong: Secure Collaboration in the Case of the Panama Papers
Susan E. McGregor, Elizabeth Anne Watkins, Mahdi N. Al-Ameen, Kelly Caine, Franziska Roesner |
USENIX Security Symposium | 3 |
| 2017 | Exploring the Potential of GeoPass: A Geographic Location-Password SchemeabstractPassword schemes based on online map locations are an emerging topic in authentication research. GeoPass is a promising such scheme, as it provides satisfactory resilience against online guessing and showed high memorability (97%) in a single-password laboratory study. In this article, we investigate more deeply into the potential of GeoPass through four separate studies. First, in a 2-month-long field study, we found that users in a real-world setting remembered their location passwords 96.1% of the time and showed improvement with more login sessions. Then, in a study of interference effects in Geopass, in which each participant had to remember four separate location passwords, we found that memorability was <70%, with 41.5% of login failures due to interference. Based on these findings, we propose to address interference issues in GeoPass with mental stories, where users are asked to create a meaningful association between their location password and the corresponding account. We tested the efficacy of this approach through a second interference study, where the memorability rate for GeoPass was >97%, with only 3.4% of login attempts failing due to interference. We also conducted a shoulder-surfing study to examine the resilience of GeoPass against this attack. Based on our results, we identify the promising aspects of location passwords that should be further studied in future research. Mahdi N. Al-Ameen, Matthew Wright 0001 |
Interact. Comput. | 1 |
| 2016 | Leveraging autobiographical memory for two-factor online authenticationabstractPurpose Two-factor authentication is being implemented more broadly to improve security against phishing, shoulder surfing, keyloggers and password guessing attacks. Although passwords serve as the first authentication factor, a common approach to implementing the second factor is sending a one-time code, either via e-mail or text message. The prevalence of smartphones, however, creates security risks in which a stolen phone leads to user’s accounts being accessed. Physical tokens such as RSA’s SecurID create extra burdens for users and cannot be used on many accounts at once. This study aims to improve the usability and security for two-factor online authentication. Design/methodology/approach The authors propose a novel second authentication factor that, similar to passwords, is also based on something the user knows but operates similarly to a one-time code for security purposes. The authors design this component to provide higher security guarantee with minimal memory burden and does not require any additional communication channels or hardware. Motivated by psychology research, the authors leverage users’ autobiographical memory in a novel way to create a secure and memorable component for two-factor authentication. Findings In a multi-session lab study, all of the participants were able to log in successfully on the first attempt after a one-week delay from registration and reported satisfaction on the usability of the scheme. Originality/value The results indicate that the proposed approach to leverage autobiographical memory is a promising direction for further research on second authentication factor based on something the user knows. Mahdi N. Al-Ameen, S. M. Taiabul Haque, Matthew Wright 0001 |
Inf. Comput. Secur. | 1 |
| 2016 | iPersea: Towards improving the Sybil-resilience of social DHT
Mahdi N. Al-Ameen, Matthew Wright 0001 |
J. Netw. Comput. Appl. | 1 |
| 2015 | Towards Making Random Passwords Memorable: Leveraging Users' Cognitive Ability Through Multiple CuesabstractGiven the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. System-assigned passwords provide measurable security but suffer from poor memorability. To address this usability-security tension, we argue that systems should assign random passwords but also help with memorization and recall. We investigate the feasibility of this approach with CuedR, a novel cued-recognition authentication scheme that provides users with multiple cues (visual, verbal, and spatial) and lets them choose the cues that best fit their learning process for later recognition of system-assigned keywords. In our lab study, all 37 of our participants could log in within three attempts one week after registration (mean login time: 38.0 seconds). A pilot study on using multiple CuedR passwords also showed 100% recall within three attempts. Based on our results, we suggest appropriate applications for CuedR, such as financial and e-commerce accounts. Mahdi N. Al-Ameen, Matthew Wright 0001, Shannon Scielzo |
CHI | 1 |
| 2015 | Leveraging Real-Life Facts to Make Random Passwords More Memorable
Mahdi N. Al-Ameen, Kanis Fatema, Matthew Wright 0001, Shannon Scielzo |
ESORICS (2) | 1 |
| 2015 | The Impact of Cues and User Interaction on the Memorability of System-Assigned Recognition-Based Graphical Passwords
Mahdi N. Al-Ameen, Kanis Fatema, Matthew Wright 0001, Shannon Scielzo |
SOUPS | 1 |
| 2014 | Design and evaluation of persea, a sybil-resistant DHTabstractP2P systems are inherently vulnerable to Sybil attacks, in which an attacker creates a large number of identities and uses them to control a substantial fraction of the system. We propose Persea, a novel P2P system that derives its Sybil resistance by assigning IDs through a bootstrap tree, the graph of how nodes have joined the system through invitations. Unlike prior Sybil-resistant P2P systems based on social networks, Persea does not rely on two key assumptions: (1) that the social network is fast mixing and (2) that there is a small ratio of attack edges to honest nodes. Both assumptions have been shown to be unreliable in real social networks. A node joins Persea when it gets an invitation from an existing node in the system. The inviting node assigns a node ID to the joining node and gives it a chunk of node IDs for further distribution. For each chunk of ID space, the attacker needs to socially engineer a connection to another node already in the system. The hierarchical distribution of node IDs confines a large attacker botnet to a considerably smaller region of the ID space than in a normal P2P system. We then build upon this hierarchical ID space to make a distributed hash table (DHT) based on the Kad network. The Persea DHT uses a replication mechanism in which each (key, value) pair is stored in nodes that are evenly spaced over the network. Thus, even if a given region is occupied by attackers, the desired (key, value pair can be retrieved from other regions. We evaluate Persea in analysis and in simulations with social network datasets and show that it provides better lookup success rates than prior work with modest overheads. Mahdi N. Al-Ameen, Matthew Wright 0001 |
AsiaCCS | 1 |
| 2014 | ReDS: A Framework for Reputation-Enhanced DHTsabstractDistributed hash tables (DHTs), such as Chord and Kademlia, offer an efficient means to locate resources in peer-to-peer networks. Unfortunately, malicious nodes on a lookup path can easily subvert such queries. Several systems, including Halo (based on Chord) and Kad (based on Kademlia), mitigate such attacks by using redundant lookup queries. Much greater assurance can be provided; we present Reputation for Directory Services (ReDS), a framework for enhancing lookups in redundant DHTs by tracking how well other nodes service lookup requests. We describe how the ReDS technique can be applied to virtually any redundant DHT including Halo and Kad. We also study the collaborative identification and removal of bad lookup paths in a way that does not rely on the sharing of reputation scores, and we show that such sharing is vulnerable to attacks that make it unsuitable for most applications of ReDS. Through extensive simulations, we demonstrate that ReDS improves lookup success rates for Halo and Kad by 80 percent or more over a wide range of conditions, even against strategic attackers attempting to game their reputation scores and in the presence of node churn. Ruj Akavipat, Mahdi N. Al-Ameen, Apu Kapadia, Zahid Rahman, Roman Schlegel, Matthew Wright 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Persea: a sybil-resistant social DHTabstractP2P systems are inherently vulnerable to Sybil attacks, in which an attacker can have a large number of identities and use them to control a substantial fraction of the system. We propose Persea, a novel P2P system that is more robust against Sybil attacks than prior approaches. Persea derives its Sybil resistance by assigning IDs through a bootstrap tree, the graph of how nodes have joined the system through invitations. More specifically, a node joins Persea when it gets an invitation from an existing node in the system. The inviting node assigns a node ID to the joining node and gives it a chunk of node IDs for further distribution. For each chunk of ID space, the attacker needs to socially engineer a connection to another node already in the system. This hierarchical distribution of node IDs confines a large attacker botnet to a considerably smaller region of the ID space than in a normal P2P system. Persea uses a replication mechanism in which each (key,value) pair is stored in nodes that are evenly spaced over the network. Thus, even if a given region is occupied by attackers, the desired (key,value) pair can be retrieved from other regions. We compare our results with Kad, Whanau, and X-Vine and show that Persea is a better solution against Sybil attacks. Mahdi N. Al-Ameen, Matthew Wright 0001 |
CODASPY | 1 |