VLDB 2026 Research / reviewers in the wild / expert
Nina Gerber
dblp:181/7338
· DBLP profile ↗
16ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0001-9669-7276ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unpacking the Social and Emotional Dimensions of Security and Privacy User Engagement
Nina Gerber, Verena Zimmermann, Alexandra von Preuschen, Karen Renaud |
SOUPS | 1 |
| 2025 | Let's Get Visual - Testing Visual Analogies and Metaphors for Conveying Privacy Policies and Data Handling InformationabstractWith EU-GDPR and related regulations, the respon-sibility to make privacy-related decisions such as to provide informed consent to data handling practices mainly rests with the user. However, current lengthy privacy policies and often deceptive cookie notices rarely facilitate truly informed consent. Related work on privacy icons or structuring privacy policies aims to enhance users' understanding but achieve mixed results. In a between-subjects study with N=379 participants we thus explored the potential of embedding privacy information in visual metaphors and analogies to support informed decision-making. Additionally, we explored whether dynamic feedback helped users understand the implications of their decisions. While both visual and textual information and feedback appeared to support users' understanding of data handling practices and alignment with personal preferences, with no significant differences between conditions, users per-ceived visualizations as more suitable and aesthetically pleasing than text. This indicates potential for using visual contexts to enhance informed consent not only within existing cookie notices but also in emerging tools such as privacy assistants or related privacy-enhancing technologies. Future work should investigate differences to currently deployed solutions and the effect of perceived pleasantness of design variants on users' understanding and decisions. Verena Zimmermann, Adrienn Toth, Hannah Sievers, Linda Fanconi, Yanis Isenring, Mona Henz, Alina Stöver, Nina Gerber |
SP | 8 |
| 2025 | I Have Not Understood but Agree: Studying Informed Consent in the Context of the German COVID-19 Contact Tracing AppabstractMany EU data collectors rely on informed consent for data processing, requiring users to consent after being informed. To do so, it is necessary for users to have at least partially correct assumptions about what the software does. The introduction of the official German contact tracing app, the Corona-Warn-App (CWA), provides an interesting use case to explore whether potential users are capable of being informed with a reasonable amount of effort by the publishers of software. We captured CWA users’ and non-users’ mental models of data collection and processing in the app in interviews (N = 20) and a survey study (N = 352). We investigated whether users have enough correct assumptions to be considered informed. Our findings show that the participants had misconceptions. Therefore, we argue that user consent might often lack the required level of informedness and may be replaced by a more rigorous privacy-by-design principle. Maximilian Häring, Eva Tiefenau, Christian Tiefenau, Felix Kretschmer-Pietralla, Alina Stöver, Nina Gerber |
ACM Trans. Comput. Hum. Interact. | 6 |
| 2024 | Investigating Voter Perceptions of Printed Physical Audit Trails for Online VotingabstractOnline elections come with security challenges since digital votes do not produce physical audit trails that are easily verifiable. We present and investigate a hybrid online voting system that combines the benefits of voting from home via the internet with those of physical ballots, such as risk-limiting audits and verifiability. After voting online, the system generates a tracking code and a physical printout – either paper or 3D-printed – of the encrypted vote that can be visually verified by the voters through live video-broadcasts. Through an online experiment (N=150), we compared hybrid voting with paper and 3D-printed votes to a baseline (digitally stored votes), investigating perceived trust, UX, usability, and security readiness. Among our results, we show that paper printouts enhance trust without negatively impacting UX. 3D-printouts enhance perceived privacy, yet impact usability and UX. We conclude with recommendations and practical considerations to inform the implementation of hybrid online voting schemes. Karola Marky, Nina Gerber, Henry John Krumb, Mohamed Khamis, Max Mühlhäuser |
SP | 2 |
| 2024 | Don't Accept All and Continue: Exploring Nudges for More Deliberate Interaction with Tracking Consent NoticesabstractLegal frameworks rely on users to make an informed decision about data collection, e.g., by accepting or declining the use of tracking technologies. In practice, however, users hardly interact with tracking consent notices on a deliberate website per website level, but usually accept or decline optional tracking technologies altogether in a habituated behavior. We explored the potential of three different nudge types (color highlighting, social cue, timer) and default settings to interrupt this auto-response in an experimental between-subject design with 167 participants. We did not find statistically significant differences regarding the buttons clicked. Our results showed that opt-in default settings significantly decrease tracking technology use acceptance rates. These results are a first step towards understanding the effects of different nudging concepts on users’ interaction with tracking consent notices. Nina Gerber, Alina Stöver, Justin Peschke, Verena Zimmermann |
ACM Trans. Comput. Hum. Interact. | 1 |
| 2023 | How Website Owners Face Privacy Issues: Thematic Analysis of Responses from a Covert Notification Study Reveals Diverse Circumstances and ChallengesabstractMany websites contain services from third parties. Misconfigurations of these services can lead to missing compliance with legal obligations and privacy risks for website users. Previous research indicates that one cause for such privacy issues is missing awareness. However, reasons for the missing awareness and other reasons for the prevalence of privacy issues are not widely researched; that includes website owners’ dealing with those issues. To shed light on the issue, we analyze 1043 responses from website owners to a notification about a privacy issue on their website using thematic analysis, following an exploratory and qualitative approach. Our analysis shows that, next to unawareness of the issue, incorrect technical implementation and ambiguous responsibilities are among the reasons for privacy issues. Also, website owners face different challenges, such as a lack of knowledge or slow organizational coordination and processes. In addition, our results show that the circumstances in which they operate their website influences how they act and what challenges they face. To illustrate these differences in website owners, we derive three personas from our thematic analysis: (1) the Ignorant Hobbyist, (2) the Busy Self-Employed, and (3) the Informed Multi-Stakeholder. These personas cover the majority of the aspects of the analyzed responses and represent the diversity of website owners and their backgrounds. Given the challenges and backgrounds of website owners, we discuss which prerequisites must be fulfilled to remediate privacy issues on websites. Finally, we present measures that support website owners in remediating privacy issues and show how to adapt these measures to the needs of different website owners. We hope that better support for website owners will also lead to better privacy for website visitors. Alina Stöver, Nina Gerber, Henning Pridöhl, Max Maaß, Sebastian Bretthauer, Indra Spiecker genannt Döhmann, Matthias Hollick, Dominik Herrmann |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Investigating how Users Imagine their Personal Privacy AssistantabstractPersonal Privacy Assistants (PPAs) can support users in managing their privacy. Conducting a user study, we provide qualitative and quantitative insights into how users imagine their PPA and how PPAs designs can appear for different user groups. We highlight five aspects derived from the literature that are essential when designing a PPA: What features should the PPA have? How should the PPA learn the users’ preferences? What level of user involvement in its decisions should the PPAs have? Which vendor should offer the PPA? What data are users willing to disclose to their PPA? Our results provide a holistic view of user perceptions of PPAs. We identify two user groups that differ in their characteristics, such as technology affinity and privacy concerns, and have different ideas of a PPA in terms of automation level and provider, for example. We discuss our results in relation to the literature and derive recommendations for designing PPAs to fulfill user needs. Alina Stöver, Sara Hahn, Felix Kretschmer, Nina Gerber |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | "You offer privacy like you offer tea": Investigating Mechanisms for Improving Guest Privacy in IoT-Equipped HouseholdsabstractIoT devices are becoming more common and prevalent in private households. Since guests can be present in IoT-equipped households, IoT devices can pose considerable privacy risks to them. In this paper, we present an in-depth evaluation of privacy protection for guests considering the perspectives of hosts and guests. First, we interviewed 21 IoT device owners about four classes of mechanisms obtained from the literature and social aspects. Second, we conducted an online survey (N=264) that investigates the perspective of guests in IoT-equipped households. From our results, we learn that protection mechanisms should not introduce privacy threats and require low resources. Further, hosts should keep control over their devices and the aesthetics of their living spaces. Guests, however, value feedback about the status of privacy protection which can interfere with aesthetics. Privacy protection should rather foster collaboration and not impact the visit of the guest too severely. We use our results to identify a design space for guest privacy protection in IoT-equipped households. Karola Marky, Nina Gerber, Michelle Gabriela Pelzer, Mohamed Khamis, Max Mühlhäuser |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | The password is dead, long live the password - A laboratory study on user perceptions of authentication schemes
Verena Zimmermann, Nina Gerber |
Int. J. Hum. Comput. Stud. | 2 |
| 2019 | I (Don't) See What You Typed There! Shoulder-surfing Resistant Password Entry on GamepadsabstractUsing gamepad-driven devices like games consoles is an activity frequently shared with others. Thus, shoulder-surfing is a serious threat. To address this threat, we present the first investigation of shoulder-surfing resistant text password entry on gamepads by (1) identifying the requirements of this context; (2) assessing whether shoulder-surfing resistant authentication schemes proposed in non-gamepad contexts can be viably adapted to meet these requirements; (3) proposing "Colorwheels", a novel shoulder-surfing resistant authentication scheme specifically geared towards this context; (4) using two different methodologies proposed in the literature for evaluating shoulder-surfing resistance to compare "Colorwheels", on-screen keyboards (the de facto standard in this context), and an existing shoulder-surfing resistant scheme which we identified during our assessment and adapted for the gamepad context; (5) evaluating all three schemes regarding their usability. Having applied different methodologies to measure shoulder-surfing resistance, we discuss their strengths and pitfalls and derive recommendations for future research. Peter Mayer 0001, Nina Gerber, Benjamin Reinheimer, Philipp Rack, Kristoffer Braun, Melanie Volkamer |
CHI | 2 |
| 2019 | Keep on rating - on the systematic rating and comparison of authentication schemesabstractPurpose Six years ago, Bonneau et al. (2012) proposed a framework to compare authentication schemes to the ubiquitous text password. Even though their work did not reveal an alternative outperforming the text password on every criterion, the framework can support decision makers in finding suitable solutions for specific authentication contexts. The purpose of this paper is to extend and update the database, thereby discussing benefits, limitations and suggestions for continuing the development of the framework. Design/methodology/approach This paper revisits the rating process and describes the application of an extended version of the original framework to an additional 40 authentication schemes identified in a literature review. All schemes were rated in terms of 25 objective features assigned to the three main criteria: usability, deployability and security. Findings The rating process and results are presented along with a discussion of the benefits and pitfalls of the rating process. Research limitations/implications While the extended framework, in general, proves suitable for rating and comparing authentication schemes, ambiguities in the rating could be solved by providing clearer definitions and cut-off values. Further, the extension of the framework with subjective user perceptions that sometimes differ from objective ratings could be beneficial. Originality/value The results of the rating are made publicly available in an authentication choice support system named ACCESS to support decision makers and researchers and to foster the further extension of the knowledge base and future development of the extended rating framework. Verena Zimmermann, Nina Gerber, Peter Mayer 0001, Marius Kleboth, Alexandra von Preuschen, Konstantin Schmidt |
Inf. Comput. Secur. | 2 |
| 2019 | Investigating People's Privacy Risk PerceptionabstractAbstract Although media reports often warn about risks associated with using privacy-threatening technologies, most lay users lack awareness of particular adverse consequences that could result from this usage. Since this might lead them to underestimate the risks of data collection, we investigate how lay users perceive different abstract and specific privacy risks. To this end, we conducted a survey with 942 participants in which we asked them to rate nine different privacy risk scenarios in terms of probability and severity. The survey included abstract risk scenarios as well as specific risk scenarios, which describe specifically how collected data can be abused, e.g., to stalk someone or to plan burglaries. To gain broad insights into people’s risk perception, we considered three use cases: Online Social Networks (OSN), smart home, and smart health devices. Our results suggest that abstract and specific risk scenarios are perceived differently, with abstract risk scenarios being evaluated as likely, but only moderately severe, whereas specific risk scenarios are considered to be rather severe, but only moderately likely. People, thus, do not seem to be aware of specific privacy risks when confronted with an abstract risk scenario. Hence, privacy researchers or activists should make people aware of what collected and analyzed data can be used for when abused (by the service or even an unauthorized third party). Nina Gerber, Benjamin Reinheimer, Melanie Volkamer |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | Finally Johnny Can Encrypt: But Does This Make Him Feel More Secure?abstractEnd-to-end (E2E) encryption is an effective measure against privacy infringement. In 2016, it was introduced by WhatsApp for all users (of the latest app version) quasi overnight. However, it is unclear how non-expert users perceived this change, whether they trust WhatsApp as a provider of E2E encryption, and how their communication behavior changed. We conducted semi-structured interviews with twenty WhatsApp users to answer these questions. We found that about half of the participants perceived that even with E2E encryption, their messages could still be eavesdropped, for example by hackers and other criminals, governmental institutions, or WhatsApp's employees and cooperation partners. Many participants correctly identified sender and recipient as weakest points after the introduction of E2E encryption, but misconceptions were still present. For instance, users thought that messages were transmitted directly between two devices without being forwarded or stored on a server, or interpreted 'end-to-end' as a temporally end of communication. The majority of users stated to mistrust WhatsApp and its E2E encryption and presumed image-related reasons for the cost-free implementation. While most participants did not change their communication behavior, they reported to use protection strategies such as sending sensitive content via alternative channels even after the introduction of E2E encryption. Nina Gerber, Verena Zimmermann, Birgit Henhapl, Sinem Emeröz, Melanie Volkamer |
ARES | 1 |
| 2018 | Developing and Evaluating a Five Minute Phishing Awareness Video
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Philipp Rack, Marco Ghiglieri, Peter Mayer 0001, Alexandra Kunz, Nina Gerber |
TrustBus | 8 |
| 2018 | Explaining the privacy paradox: A systematic review of literature investigating privacy attitude and behavior
Nina Gerber, Paul Gerber, Melanie Volkamer |
Comput. Secur. | 1 |
| 2017 | Productivity vs security: mitigating conflicting goals in organizationsabstractPurpose This paper aims to contribute to the understanding of goal setting in organizations, especially regarding the mitigation of conflicting productivity and security goals. Design/methodology/approach This paper describes the results of a survey with 200 German employees regarding the effects of goal setting on employees’ security compliance. Based on the survey results, a concept for setting information security goals in organizations building on actionable behavioral recommendations from information security awareness materials is developed. This concept was evaluated in three small- to medium-sized organizations (SMEs) with overall 90 employees. Findings The survey results revealed that the presence of rewards for productivity goal achievement is strongly associated with a decrease in security compliance. The evaluation of the goal setting concept indicates that setting their own information security goals is welcomed by employees. Research limitations/implications Both studies rely on self-reported data and are, therefore, likely to contain some kind of bias. Practical implications Goal setting in organizations has to accommodate for situations, where productivity goals constrain security policy compliance. Introducing the proposed goal setting concept based on relevant actionable behavioral recommendations can help mitigate issues in such situations. Originality/value This work furthers the understanding of the factors affecting employee security compliance. Furthermore, the proposed concept can help maximizing the positive effects of goal setting in organizations by mitigating the negative effects through the introduction of meaningful and actionable information security goals. Peter Mayer 0001, Nina Gerber, Ronja McDermott, Melanie Volkamer, Joachim Vogt 0002 |
Inf. Comput. Secur. | 2 |