Jessica Colnago

dblp:174/9189 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
2since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Trust-Enabled Privacy: Social Media Designs to Support Adolescent User Boundary Regulation
Jaewon Kim 0002, Robert Wolfe, Ramya Bhagirathi Subramanian, Mei-Hsuan Lee, Jessica Colnago, Alexis Hiniker
SOUPS5
2023 Is There a Reverse Privacy Paradox? An Exploratory Analysis of Gaps Between Privacy Perspectives and Privacy-Seeking Behaviors
abstract
Privacy scholars have long studied, and argued about, a so-called privacy paradox---the alleged gap between individuals' claims of caring about privacy and their actual behaviors. This manuscript explores whether a different type of mismatch occurs in an online sample of US participants: a mismatch between participants' dismissive perspectives on privacy and their privacy-protective behaviors. In a series of online studies with Prolific US participants we tackle two research questions: is there evidence of mismatches between (dismissive) privacy perspectives, and (protective) privacy behaviors? If so, what can explain those mismatches? In a Behavior Elicitation study, we collect a corpus of privacy-regulating and privacy-protective behaviors. Next, in Study 1, we find evidence that engagement in a broad array of privacy behaviors is, in fact, very common in our sample. We also find that mismatches between dismissive privacy perspectives and protective behaviors emerge in a large proportion of participants. Finally, in Study 2, we uncover several common but distinct reasons for those mismatches, including construing seemingly protective behaviors as motivated by reasons other than privacy, and nuanced stances on when to express privacy concern. Collectively, the results indicate that individuals who are seemingly dismissive of privacy concerns engage in behaviors that can be construed as privacy-seeking. The findings highlight the nuances of individual privacy decision-making and suggest that public policy related to privacy should account for the evidence for widespread privacy-seeking behaviors.
Jessica Colnago, Lorrie Faith Cranor, Alessandro Acquisti
Proc. Priv. Enhancing Technol.1
2020 Choice of Voices: A Large-Scale Evaluation of Text-to-Speech Voice Quality for Long-Form Content
abstract
The advancement of text-to-speech (TTS) voices and a rise of commercial TTS platforms allow people to easily experience TTS voices across a variety of technologies, applications, and form factors. As such, we evaluated TTS voices for long-form content: not individual words or sentences, but voices that are pleasant to listen to for several minutes at a time. We introduce a method using a crowdsourcing platform and an online survey to evaluate voices based on listening experience, perception of clarity and quality, and comprehension. We evaluated 18 TTS voices, three human voices, and a text-only control condition. We found that TTS voices are close to rivaling human voices, yet no single voice outperforms the others across all evaluation dimensions. We conclude with considerations for selecting text-to-speech voices for long-form content.
Julia Cambre, Jessica Colnago, Jim Maddock, Janice Y. Tsai, Joseph Kaye
CHI2
2020 Informing the Design of a Personalized Privacy Assistant for the Internet of Things
abstract
Internet of Things (IoT) devices create new ways through which personal data is collected and processed by service providers. Frequently, end users have little awareness of, and even less control over, these devices' data collection. IoT Personalized Privacy Assistants (PPAs) can help overcome this issue by helping users discover and, when available, control the data collection practices of nearby IoT resources. We use semi-structured interviews with 17 participants to explore user perceptions of three increasingly more autonomous potential implementations of PPAs, identifying benefits and issues associated with each implementation. We find that participants weigh the desire for control against the fear of cognitive overload. We recommend solutions that address users' differing automation preferences and reduce notification overload. We discuss open issues related to opting out from public data collections, automated consent, the phenomenon of user resignation, and designing PPAs with at-risk communities in mind.
Jessica Colnago, Yuanyuan Feng, Tharangini Palanivel, Sarah Pearman, Megan Ung, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh
CHI1
2018 "It's not actually that horrible": Exploring Adoption of Two-Factor Authentication at a University
abstract
Despite the additional protection it affords, two-factor authentication (2FA) adoption reportedly remains low. To better understand 2FA adoption and its barriers, we observed the deployment of a 2FA system at Carnegie Mellon University (CMU). We explore user behaviors and opinions around adoption, surrounding a mandatory adoption deadline. Our results show that (a) 2FA adopters found it annoying, but fairly easy to use, and believed it made their accounts more secure; (b) experience with CMU Duo often led to positive perceptions, sometimes translating into 2FA adoption for other accounts; and, (c) the differences between users required to adopt 2FA and those who adopted voluntarily are smaller than expected. We also explore the relationship between different usage patterns and perceived usability, and identify user misconceptions, insecure practices, and design issues. We conclude with recommendations for large-scale 2FA deployments to maximize adoption, focusing on implementation design, use of adoption mandates, and strategic messaging.
Jessica Colnago, Summer Devlin, Maggie Oates, Chelse Swoopes, Lujo Bauer, Lorrie Faith Cranor, Nicolas Christin
CHI1
2017 Design and Evaluation of a Data-Driven Password Meter
abstract
Despite their ubiquity, many password meters provide inaccurate strength estimates. Furthermore, they do not explain to users what is wrong with their password or how to improve it. We describe the development and evaluation of a data-driven password meter that provides accurate strength measurement and actionable, detailed feedback to users. This meter combines neural networks and numerous carefully combined heuristics to score passwords and generate data-driven text feedback about the user's password. We describe the meter's iterative development and final design. We detail the security and usability impact of the meter's design dimensions, examined through a 4,509-participant online study. Under the more common password-composition policy we tested, we found that the data-driven meter with detailed feedback led users to create more secure, and no less memorable, passwords than a meter with only a bar as a strength indicator.
Blase Ur, Felicia Alfieri, Maung Aung, Lujo Bauer, Nicolas Christin, Jessica Colnago, Lorrie Faith Cranor, Henry Dixon, Pardis Emami Naeini, Hana Habib, Noah Johnson, William Melicher
CHI6