Martin Ukrop

dblp:136/6756 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0001-8110-8926ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2024 What Johnny thinks about using two-factor authentication on GitHub: A survey among open-source developers
abstract
Several security issues in open-source projects demonstrate that developer accounts get misused or stolen if weak authentication is used. Many services have started to enforce second-factor authentication (2FA) for their users. This is also the case for GitHub, the largest open-source development platform. We surveyed 110 open-source developers using GitHub to explore how they perceive the importance of authentication on GitHub. Our participants perceived secure authentication as important as other security mechanisms (e.g., commit signing) to improve open-source security. 2FA usage of the project owner was perceived as one of the most important mechanisms. Around half of the participants (51%) were aware of the planned 2FA enforcement on GitHub. Their perception of this enforcement was rather positive. They agreed to enforce 2FA for new devices and new locations, but they were slightly hesitant to use it after some time. They also rather agreed to enforce various user groups on GitHub to use 2FA. Our participants also perceived GitHub authentication methods positively with respect to their usability and security. Most of our participants (68%) reported that they had enabled 2FA on their GitHub accounts.
Agata Kruzikova, Jakub Suchanek, Milan Broz, Martin Ukrop, Vashek Matyas
ARES4
2022 Experience with Abrupt Transition to Remote Teaching of Embedded Systems
abstract
Due to the pandemic of COVID-19, many university courses had to abruptly transform to enable remote teaching. Adjusting courses on embedded systems and micro-controllers was extra challenging since interaction with real hardware is their integral part. We start by comparing our experience with four basic alternatives of teaching embedded systems: 1) interacting with hardware at school, 2) having remote access to hardware, 3) lending hardware to students for at-home work and 4) virtualizing hardware. Afterward, we evaluate in detail our experience of the fast transition from traditional, offline at-school hardware programming course to using remote access to real hardware present in the lab. The somewhat unusual remote hardware access approach turned out to be a fully viable alternative for teaching embedded systems, enabling a relatively low-effort transition. Our setup is based on existing solutions and stable open technologies without the need for custom-developed applications that require high maintenance. We evaluate the experience of both the students and teachers and condense takeaways for future courses. The specific environment setup is available online as an inspiration for others.
Jan Koniarik, Daniel Dlhopolcek, Martin Ukrop
ITiCSE (1)3
2022 Usability Insights from Establishing TLS Connections
Lydia Kraus, Matej Grabovský, Martin Ukrop, Katarína Galanská, Vashek Matyas
SEC3
2021 Challenges Faced by Teaching Assistants in Computer Science Education Across Europe
abstract
Teaching assistants (TAs) are heavily used in computer science courses as a way to handle high enrollment and still being able to offer students individual tutoring and detailed assessments. TAs are themselves students who take on this additional role in parallel with their own studies at the same institution. Previous research has shown that being a TA can be challenging but has mainly been conducted on TAs from a single institution or within a single course. This paper offers a multi-institutional, multi-national perspective of challenges that TAs in computer science face. This has been done by conducting a thematic analysis of 180 reflective essays written by TAs from three institutions across Europe. The thematic analysis resulted in five main challenges: becoming a professional TA, student focused challenges, assessment, defining and using best practice, and threats to best practice. In addition, these challenges were all identified within the essays from all three institutions, indicating that the identified challenges are not particularly context-dependent. Based on these findings, we also outline implications for educators involved in TA training and coordinators of computer science courses with TAs.
Emma Riese, Madeleine Lorås, Martin Ukrop, Tomás Effenberger
ITiCSE (1)3
2021 The Stack: Unplugged Activities for Teaching Computer Science
abstract
The Stack is a free open repository of learning activities for adults that illustrate computing principles without a computer. We explain the rationale behind its development, describe its content with an example, and discuss its applications in university teaching practice.
Valdemar Svábenský, Martin Ukrop
SIGCSE2
2020 Teaching Lab: Training Novice Computer Science Teachers
abstract
Student teaching assistants are not uncommon in computer science. However, their pedagogical training is often only superficial. This poster presents the Teaching Lab - a mature and fully developed training course for novice teachers (mostly undergraduate teaching assistants), its core principles, content and unique features as it evolved over five years. Our experience can be helpful to others intending to create or adjust a training program for novice teachers.
Martin Ukrop, Valdemar Svábenský, Imrich Nagy
ITiCSE1
2019 Will you trust this TLS certificate?: perceptions of people working in IT
abstract
Flawed TLS certificates are not uncommon on the Internet. While they signal a potential issue, in most cases they have benign causes (e.g., misconfiguration or even deliberate deployment). This adds fuzziness to the decision on whether to trust a connection or not. Little is known about perceptions of flawed certificates by IT professionals, even though their decisions impact high numbers of end users. Moreover, it is unclear how much does the content of error messages and documentation influence these perceptions.
Martin Ukrop, Lydia Kraus, Vashek Matyas, Heider A. M. Wahsheh
ACSAC1
2019 Reflective Diary for Professional Development of Novice Teachers
abstract
Many starting teachers of computer science have great professional skill but often lack pedagogical training. Since providing expert mentorship directly during their lessons would be quite costly, institutions usually offer separate teacher training sessions for novice instructors. However, the reflection on teaching performed with a significant delay after the taught lesson limits the possible impact on teachers. To bridge this gap, we introduced a weekly semi-structured reflective practice to supplement the teacher training sessions at our faculty. We created a paper diary that guides the starting teachers through the process of reflection. Over the course of the semester, the diary poses questions of increasing complexity while also functioning as a reference to the topics covered in teacher training. Piloting the diary on a group of 25 novice teaching assistants resulted in overwhelmingly positive responses and provided the teacher training sessions with valuable input for discussion. The diary also turned out to be applicable in a broader context: it was appreciated and used by several experienced university teachers from multiple faculties and even some high-school teachers. The diary is freely available online, including source and print versions.
Martin Ukrop, Valdemar Svábenský, Jan Nehyba
SIGCSE1
2018 Why Johnny the Developer Can't Work with Public Key Certificates - An Experimental Study of OpenSSL Usability
Martin Ukrop, Vashek Matyas
CT-RSA1
2018 Experimental large-scale review of attractors for detection of potentially unwanted applications
Vlasta Stavova, Lenka Dedkova, Vashek Matyas, Mike Just, David Smahel, Martin Ukrop
Comput. Secur.6
2014 Constructing Empirical Tests of Randomness
abstract
In this paper we introduce a general framework for automatic construction of empirical tests of randomness. Our new framework generalises and improves a previous approach (Svenda et al., 2013) and it also provides a clear statistical interpretation of its results. This new approach was tested on selected stream ciphers from the eSTREAM competition. Results show that our approach can lay foundations to randomness testing and it is comparable to the Statistical Test Suite developed by NIST. Additionally, the proposed approach is able to perform randomness analysis even when presented with sequences shorter by several orders of magnitude than required by the NIST suite. Although the Dieharder battery still provides a slightly better randomness analysis, our framework is able to detect non-randomness for stream ciphers with limited number of rounds (Hermes, Fubuki) where both above-mentioned batteries fail.
Marek Sýs, Petr Svenda, Martin Ukrop, Vashek Matyas
SECRYPT3
2013 Towards Cryptographic Function Distinguishers with Evolutionary Circuits
Petr Svenda, Martin Ukrop, Vashek Matyas
SECRYPT2