VLDB 2026 Research / reviewers in the wild / expert
Jacob Abbott
dblp:177/4489
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0002-7173-6643ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Comparing the Use and Usefulness of Four IoT Security LabelsabstractThere are currently multiple proposed security label designs for consumer products, with each prioritizing different security and privacy factors. These differences risk making product comparisons more confusing than informative. Standardized labels could potentially resolve this by informing consumers of a product's security features at the point of purchase. But which standard? This survey, of 500 participants, studied four label designs and measured comprehension, response time, acceptability, and cognitive load. We gauged understanding of participant perception and preferences using three smart devices: light bulbs, cameras, and thermostats. We identified preferences and behaviors before, during, and after label use for product selection. At first, participants believed more information-dense labels would better support their purchasing behavior; however, after they evaluated and compared products, participants gravitated towards less cognitively demanding designs. We identified how participants utilized and prioritized label elements to provide recommendations for US label design efforts. Peter J. Caven, Zitao Zhang, Jacob Abbott, Xinyao Ma, L. Jean Camp |
CHI | 3 |
| 2023 | Tips, Tricks, and Training: Supporting Anti-Phishing Awareness among Mid-Career Office Workers Based on Employees' Current PracticesabstractPreventing workplace phishing depends on the actions of every employee, regardless of cybersecurity expertise. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old) at two U.S. universities, we found that less than 21% of our participants had any formal anti-phishing training. Much of what our participants know about phishing comes from informal sources that emphasize “tips” and "tricks" like those found in conversations with friends, news stories, newsletters, social media, and podcasts. These informal channels provide opportunities for IT professionals wishing to enhance employees’ anti-phishing awareness by better aligning the delivery of expert advice with employees’ current practices and desires. We provide four recommendations designed to embrace "guerrilla learning" by distributing anti-phishing educational resources across the workplace and workday in part to encourage the delivery of more accurate information in more informal and incidental ways, and greater dialogue between anti-phishing training instructors and learners. Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng |
CHI | 2 |
| 2023 | What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsabstractPhishing attacks, in which deceptive messages purporting to be from a legitimate contact are used to trick recipients and acquire sensitive information for the purposes of committing fraud, are a substantial and growing problem for organizations. IT departments and professionals may put in place a variety of institutional responses to thwart such attacks, but an organization's susceptibility to phishing also depends on the decisions and actions of individual employees. These employees may have little phishing expertise but still need to react to such attempts on a daily basis. Based on 24 semi-structured interviews with mid-career office workers (70.8% women, averaging 44 years old, with a bachelor's degree or more) at two universities in the midwestern United States, we find that employees self-describe a wide range of levels of awareness of, and confidence, competency and investment in, the organization's proscribed anti-phishing policies and practices. These employees also describe variation in the ways they would prefer to increase their perceived performance levels in all of these areas. In this paper, we argue that in order to empower employees to be better collaborators in an organization's anti-phishing efforts, organizations should embrace a range of efforts akin to the range of expertise among the users themselves. We make four such empowering recommendations for organizations to consider incorporating into their existing anti-phishing policies and practices, including suggestions to 1) embrace educating non-expert users more fully on organizational processes and consequences, 2) provide employees with a standing one-to-one communication channel between them and an IT phishing point-of-contact, 3) keep employees in the loop once phishing reports are made, and 4) avoid testing employees with "gotcha" assessments. Anne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 0001, Christena Nippert-Eng |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2022 | Identifying an Aurally Distinct Phrase Set for Text Entry TechniquesabstractIn the last decade, interest in accessible and eyes-free text entry has continued to grow. However, little research has been done to explore the feasibility of using audibly distinct phrases for text entry tasks. To better understand whether preexisting phrases used in text entry research are sufficiently distinct for eyes-free text entry tasks, we used Microsoft’s and Apple’s desktop text-to-speech systems to generate all 500 phrases from MacKenzie and Soukoreff’s set [32] using the default male and female voices. We then asked 392 participants recruited through Amazon’s Mechanical Turk to transcribe the generated audio clips. We report participant transcription errors and present the 96 phrases that were observed with no comprehension errors. These phrases were further tested with 80 participants who identified as low-vision and/or blind recruited through Twitter. We contribute the 92 phrases that were observed to maintain no comprehension errors across both experiments. Jacob Abbott, Joseph Kaye, James Clawson |
CHI | 1 |
| 2021 | The importance of social identity on password formulations
Marthie Grobler, Mahawaga Arachchige Pathum Chamikara, Jacob Abbott, Jongkil Jeong, Surya Nepal, Cécile Paris |
Pers. Ubiquitous Comput. | 3 |
| 2020 | How Mandatory Second Factor Affects the Authentication User ExperienceabstractRecent years have seen growing organizational adoption of two-factor authentication as organizations seek to limit the damage caused by password breaches. However, research on the user experience of two-factor authentication in a real-world setting is relatively scant. To fill this gap, we conducted multiple waves of an online survey of users at a large public university during its multi-phase rollout of mandatory two-factor authentication for faculty, staff, and students. In addition, we examined multiple months of logs of all authentication events at the university. We found no significant changes in user experience and acceptance of two-factor authentication when it was mandatory for select systems that dealt with sensitive information. However, these factors degraded when users were forced to use two-factor authentication for logging into every single university resource. Our findings can serve as important guidance for the implementation of two-factor authentication in organizations in a way that can help achieve a balance between security and user experience. Jacob Abbott, Sameer Patil 0001 |
CHI | 1 |
| 2019 | Local Standards for Anonymization Practices in Health, Wellness, Accessibility, and Aging Research at CHIabstractWhen studying technologies pertaining to health, wellness, accessibility, and aging, researchers are often required to perform a balancing act between controlling and sharing sensitive data of the people in their studies and protecting the privacy of these participants. If the data can be anonymized and shared, it can boost the impact of the research by facilitating replication and extension. Despite anonymization, data reporting and sharing may lead to re-identification of participants, which can be particularly problematic when the research deals with sensitive topics, such as health. We analyzed 509 CHI papers in the domains of health, wellness, accessibility, and aging to examine data reporting and sharing practices. Our analysis revealed notable patterns and trends regarding the reporting of age, gender, participant types, sample sizes, methodology, ethical considerations, anonymization techniques, and data sharing. Based on our findings, we propose several suggestions for community standards and practices that could facilitate data reporting and sharing while limiting the privacy risks for study participants. Jacob Abbott, Haley MacLeod, Novia Nurain, Gustave Ekobe, Sameer Patil 0001 |
CHI | 1 |