VLDB 2026 Research / reviewers in the wild / expert
Noura Alomar
dblp:151/6443
· DBLP profile ↗
9ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0002-9052-999XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AIabstractFor mobile developers to comply with privacy regulations, they must create privacy policies that accurately describe their apps’ data practices. This requires a complete understanding of their apps’ behaviors, including those of embedded third-party SDKs. Despite the complexity of this process, little is known about how privacy policies are created and validated. To investigate, we interviewed 20 developers from around the world about their processes, also observing them use a large language model (LLM) to prepare privacy policies for their apps. We found that developers struggle with collecting information about third-party SDKs, even when they use LLMs, and feel uncertain about the legal validity of LLM outputs. Many developers do not seek legal assistance and believe that, as long as app stores accept their privacy policies, they are protected. Our findings suggest that reliance on LLMs and developers’ desire to externalize validation may result in increasingly unreliable privacy policies. Shiva Mayahi, Noura Alomar, Nathan Malkin |
CHI | 2 |
| 2025 | The Effect of Platform Policies on App Privacy Compliance: A Study of Child-Directed AppsabstractOver the past few years, the two dominant app platforms made major improvements to their policies surrounding child-directed apps. While prior work repeatedly demonstrated that privacy issues were prevalent in child-directed apps, it is unclear whether platform policies can lead child-directed apps to comply with privacy requirements, when laws alone have not. To understand the effect of recent changes in platform policies (e.g., whether they result in greater levels of compliance with applicable privacy laws), we conducted a large-scale measurement study of the privacy behaviors of 7,377 child-directed Android apps, as well as a follow-up survey with some of their developers. We observed a drastic decrease in the number of apps that transmitted personal data without verifiable parental consent and an increase in the number of apps that encrypted their transmissions using TLS. However, improper use of third-party SDKs still led to privacy issues (e.g., inaccurate disclosures in apps’ privacy labels). Our analysis of apps’ privacy practices over a period of a few months in 2023 and a comparison of our results with those observed a few years ago demonstrate gradual improvements in apps’ privacy practices over time. We discuss how app platforms can further improve their policies and emphasize the role of enforcement in making such policies effective. Noura Alomar, Joel Reardon, Aniketh Girish, Narseo Vallina-Rodriguez, Serge Egelman |
Proc. Priv. Enhancing Technol. | 1 |
| 2023 | Security and Privacy Failures in Popular 2FA Apps
Conor Gilsenan, Fuzail Shakir, Noura Alomar, Serge Egelman |
USENIX Security Symposium | 3 |
| 2023 | Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)abstractThe California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights. Our research investigated the extent to which Android app developers comply with the provisions of the CCPA that require them to provide consumers with accurate privacy notices and respond to "verifiable consumer requests" (VCRs) by disclosing personal information that they have collected, used, or shared about consumers for a business or commercial purpose. We compared the actual network traffic of 109 apps that we believe must comply with the CCPA to the data that apps state they collect in their privacy policies and the data contained in responses to "right to know" requests that we submitted to the app's developers. Of the 69 app developers who substantively replied to our requests, all but one provided specific pieces of personal data (as opposed to only categorical information). However, a significant percentage of apps collected information that was not disclosed, including identifiers (55 apps, 80%), geolocation data (21 apps, 30%), and sensory data (18 apps, 26%) among other categories. We discuss improvements to the CCPA that could help app developers comply with "right to know" requests and other related regulations. Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Jay Hoofnagle, Serge Egelman |
Proc. Priv. Enhancing Technol. | 7 |
| 2022 | Developers Say the Darnedest Things: Privacy Compliance Processes Followed by Developers of Child-Directed AppsabstractWe investigate the privacy compliance processes followed by developers of child-directed mobile apps. While children’s online privacy laws have existed for decades in the US, prior research found relatively low rates of compliance. Yet, little is known about how compliance issues come to exist and how compliance processes can be improved to address them. Our results, based on surveys (n = 127) and interviews (n = 27), suggest that most developers rely on app markets to identify privacy issues, they lack complete understandings of the third-party SDKs they integrate, and they find it challenging to ensure that these SDKs are kept upto-date and privacy-related options are configured correctly. As a result, we find that well-resourced app developers outsource most compliance decisions to auditing services, and that smaller developers follow “best-effort” models, by assuming that their apps are compliant so long as they have not been rejected by app markets. We highlight the need for usable tools that help developers identify and fix mobile app privacy issues. Noura Alomar, Serge Egelman |
Proc. Priv. Enhancing Technol. | 1 |
| 2019 | Uncovering the predictors of unsafe computing behaviors in online crowdsourcing contexts
Noura Alomar, Mansour Alsaleh, Abdulrahman Alarifi |
Comput. Secur. | 1 |
| 2017 | Performance-Based Comparative Assessment of Open Source Web Vulnerability ScannersabstractThe widespread adoption of web vulnerability scanners and the differences in the functionality provided by these tool-based vulnerability detection approaches increase the demand for testing their detection effectiveness. Despite the advantages of dynamic testing approaches, the literature lacks studies that systematically evaluate the performance of open source web vulnerability scanners. The main objectives of this study are to assess the performance of open source scanners from multiple perspectives and to examine their detection capability. This paper presents the results of a comparative evaluation of the security features as well as the performance of four web vulnerability detection tools. We followed this comparative assessment with a case study in which we evaluate the level of agreement between the results reported by two open source web vulnerability scanners. Given that the results of our comparative evaluation did not show significant performance differences among the scanners while the results of the conducted case study revealed high level of disagreement between the reports generated by different scanners, we conclude that the inconsistencies between the reports generated by different scanners might not necessarily correlate with their performance properties. We also present some recommendations for helping developers of web vulnerabilities scanners to improve their tools’ capabilities. Mansour Alsaleh, Noura Alomar, Monirah Alshreef, Abdulrahman Alarifi, AbdulMalik Al-Salman |
Secur. Commun. Networks | 2 |
| 2017 | Someone in Your Contact List: Cued Recall-Based Textual PasswordsabstractTextual passwords remain the most commonly employed user authentication mechanism, and potentially will continue to be so for years to come. Despite the well-known security and usability issues concerning textual passwords, none of the numerous proposed authentication alternatives appear to have achieved a sufficient level of adoption to dominate in the foreseeable future. Password hints, consisting of a user generated text saved at the account setup stage, are employed in several authentication systems to help users to recall forgotten passwords. However, users are often unable to create hints that jog the memory without revealing too much information regarding the passwords themselves. We propose a rethink of password hints by introducing SỲNTHIMA, a novel cued recall-based textual password method that reveals no information regarding the password, requires no modifications to authentication servers, and requires no additional setup or registration steps. SỲNTHIMA makes use of users' contact lists, so that mapped password hints extracted from a user's contacts are automatically generated while the user is typing the password. We create formal models for relevant aspects of the password hint mechanism, define its threat model, and analyze the security and usability of SỲNTHIMA. We also present the results of an in-lab user study of SỲNTHIMA on 30 participants to evaluate its effectiveness and usability. The results demonstrate that SỲNTHIMA minimizes the number of incorrect login attempts and improves long-term password recall, with acceptable login times and positive user feedback. We summarize the lessons learned from the user study, with the hope of provoking further insights regarding the design of effective cued recall-based textual password schemes. Noura Alomar, Mansour Alsaleh, Abdulrahman Alarifi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | SECDEP: Software engineering curricula development and evaluation process using SWEBOK
Abdulrahman Alarifi, Mohammad Zarour, Noura Alomar, Ziyad Alshaikh, Mansour Alsaleh |
Inf. Softw. Technol. | 3 |