VLDB 2026 Research / reviewers in the wild / expert
Rick Wash
dblp:20/5611
· DBLP profile ↗
30ranked-venue papers
14as first author
3since 2021 · last 2025
0000-0003-4266-975XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 25 · 11 first-author · 3 since 2021Security and privacy · 7 · 6 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 2 first-authorDatabases, data management, data science and information retrieval · 3 · 1 first-authorArtificial intelligence and machine learning · 2Systems, architecture and hardware · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Achieving Resilience: Data Loss and Recovery on Devices for Personal Use in Three Countries
Julia Wunder, Rick Wash, Karen Renaud, Daniela A Oliveira, Zinaida Benenson |
CHI | 2 |
| 2021 | How Potential New Members Approach an Online CommunityabstractAbstract Online communities, socio-technical systems where people interact with others, depend on new members coming to the community. While the majority of research in online communities relation to the recruitment of new members has focused on new members’ socialization and retention, little work has focused on howpotential new memberswho are not yet a member of the community make the decision on whether they are willing to join in the online community. To understand this initial decision process, we investigated how potential new members build mental models of the online community from their first experience within the community, and how this process impacts the decision to continue participating in the community. We interviewed 31 potential new members of the online communities, Quora and Reddit, to better understand how they evaluate a new community. We found that the process of understanding a community involves orienting toward multiple different aspects of the community, including the content available on the community, the people who are already part of the community, and the technology interface and mechanisms that control the community. Participants who focused on consuming and enjoying content were much more likely to express an interest in future participation in these communities than participants who just evaluated the community, looking at the people in the community or the technology of the community. This extends previous considerations for recruiting new members in online communities. We conclude by discussing how our findings can have broad implications in developing successful online communities and suggesting future research efforts that could help understand potential new members. Janghee Cho, Rick Wash |
Comput. Support. Cooperative Work. | 2 |
| 2021 | Anyone else have this experience: Sharing the Emotional Labor of Tracking Data About MeabstractSelf-tracking technologies, ranging from digital thermometers to wearable fitness trackers, allow users to use personal data accumulated from their everyday activities. But, to use these data, people have to make sense of how these numbers and figures are relevant to their lives in some way in order to make decisions and gain new insight. This process is impacted by people's emotional reactions to their data. While seeking support from others can be an effective strategy for overcoming these emotional challenges, self-trackers face unique barriers in sharing their personal data. Our study investigates 1) how users seek out support online for emotional barriers elicited by their self-tracking data and 2) what self-described impact this sharing has on their self-tracking practices. To investigate these topics, we analyzed discussions in two online communities on Reddit.com centered around infertility and trying to conceive that consistently describe self-tracking experiences. We found that community members described three distinct driving emotional tensions with their self-tracking data. In seeking community input, users were focused on support for understanding and acting upon their feelings and emotions. Even when data was uncertain, frustrating, or viewed as inaccurate, comparing and learning with others benefited users through feelings of connection, control, and humor this collective sense-making provided. Additionally, we found that users taking breaks from self-tracking in whole or part appeared to support their emotional well-being and long-term motivation to track. Based on these findings, we conclude that self-tracking data has social and emotional value beyond perceived accuracy and individual treatment goals. Megan L. Knittel, Faye Kollig, Abrielle Mason, Rick Wash |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2020 | How Experts Detect Phishing Scam EmailsabstractPhishing scam emails are emails that pretend to be something they are not in order to get the recipient of the email to undertake some action they normally would not. While technical protections against phishing reduce the number of phishing emails received, they are not perfect and phishing remains one of the largest sources of security risk in technology and communication systems. To better understand the cognitive process that end users can use to identify phishing messages, I interviewed 21 IT experts about instances where they successfully identified emails as phishing in their own inboxes. IT experts naturally follow a three-stage process for identifying phishing emails. In the first stage, the email recipient tries to make sense of the email, and understand how it relates to other things in their life. As they do this, they notice discrepancies: little things that are "off'' about the email. As the recipient notices more discrepancies, they feel a need for an alternative explanation for the email. At some point, some feature of the email --- usually, the presence of a link requesting an action --- triggers them to recognize that phishing is a possible alternative explanation. At this point, they become suspicious (stage two) and investigate the email by looking for technical details that can conclusively identify the email as phishing. Once they find such information, then they move to stage three and deal with the email by deleting it or reporting it. I discuss ways this process can fail, and implications for improving training of end users about phishing. Rick Wash |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2019 | "The Most Trustworthy Coin": How Ideological Tensions Drive Trust in BitcoinabstractBitcoin is an innovative technological network, a new, non-governmental currency, and a worldwide group of users. In other words, Bitcoin is a complex sociotechnical system with a complex set of risks and challenges for anyone using it. We investigated how everyday users of Bitcoin develop trust in Bitcoin on one of the largest online communities devoted to Bitcoin: the Reddit.com r/bitcoin forum. Using qualitative content analysis, we examined how trust in Bitcoin develops based on contributions to this community. On r/bitcoin, trust in Bitcoin is driven by a pervasive ideology we call the "True Bitcoiner" ideology. This ideological viewpoint in centered on the interpretation of Bitcoin as functionally "trustless" and risk-free. Despite widespread evidence of emerging individual and system-level risks with using Bitcoin, participants continue to maintain this ideological perspective. This ideology consists of three primary beliefs: viewing Bitcoin's technology as more trustworthy than its people; rejecting 'corrupt' social hierarchies related to money; and the importance of accumulating or 'HODLing' quantities of Bitcoin as a strategy to create an ideal future. We conclude that this "True Bitcoiner" ideology is maintained despite contradictory evidence in the world because it allows participants to more easily interpret Bitcoin and make decisions by reducing perceived risk and uncertainty in the system. The role of this ideology on r/bitcoin demonstrates an expanded conceptualization of how trust is created and socially-mediated in socio-technical contexts. Megan L. Knittel, Shelby Pitts, Rick Wash |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2018 | Who Provides Phishing Training?: Facts, Stories, and People Like MeabstractHumans represent one of the most persistent vulnerabilities in many computing systems. Since human users are independent agents who make their own choices, closing these vulnerabilities means persuading users to make different choices. Focusing on one specific human choice -- clicking on a link in a phishing email -- we conducted an experiment to identify better ways to train users to make more secure decisions. We compared traditional facts-and-advice training against training that uses a simple story to convey the same lessons. We found a surprising interaction effect: facts-and-advice training works better than not training users, but only when presented by a security expert. Stories don't work quite as well as facts-and-advice, but work much better when told by a peer. This suggests that the perceived origin of training materials can have a surprisingly large effect on security outcomes. Rick Wash, Molly M. Cooper |
CHI | 1 |
| 2017 | Can People Self-Report Security Accurately?: Agreement Between Self-Report and Behavioral MeasuresabstractIt is common for researchers to use self-report measures (e.g. surveys) to measure people's security behaviors. In the computer security community, we don't know what behaviors people understand well enough to self-report accurately, or how well those self-reports correlate with what people actually do. In a six week field study, we collected both behavior data and survey responses from 122 subjects. We found that a relatively small number of behaviors -- mostly related to tasks that require users to take a specific, regular action -- have non-zero correlations. Since security is almost never a user's primary task for everyday computer users, several important security behaviors that we directly measured were not self-reported accurately. These results suggest that security research based on self-report is only reliable for certain behaviors. Additionally, a number of important security behaviors are not sufficiently salient to users that they can self-report accurately. Rick Wash, Emilee Rader, Chris Fennell |
CHI | 1 |
| 2017 | The Rich Get Richer? Limited Learning in Charitable Giving on donorschoose.org
Chankyung Pak, Rick Wash |
ICWSM | 2 |
| 2016 | Highly Successful Projects Inhibit Coordination on Crowdfunding SitesabstractDonors on crowdfunding sites must coordinate their actions to identify and collectively fund projects prior to their deadline. Some projects receive vast support immediately upon launch. Other seemingly worthwhile projects have more modest success or no success at raising funds. We examine how the presence of high-performing "superstar' projects on a crowdfunding site affects donors' ability to coordinate their actions and fund other less popular but still worthwhile projects on the site. In a lab experiment where users simulate the dynamics of a crowdfunding site, we found that superstar projects reduce the likelihood that other projects are funded by the crowd, even when the super project has no opportunity to steal away donations form other projects. We argue that this is due to superstar projects setting too high of a standard of what a "fundable" project looks like, leading donors to underestimate the amount of support within a crowd for less exceptional projects. Jacob Solomon, Wenjuan Ma, Rick Wash |
CHI | 3 |
| 2016 | Understanding Password Choices: How Frequently Entered Passwords Are Re-used across Websites
Rick Wash, Emilee Rader, Ruthie Berman, Zac Wellmer |
SOUPS | 1 |
| 2015 | Don't Wait!: How Timing Affects Coordination of Crowdfunding DonationsabstractCrowdfunding sites often impose deadlines for projects to receive their requested funds. This deadline structure creates a difficult decision for potential donors. Donors can donate early to a project to help it reach its goal and to signal to other donors that the project is worthwhile. But donors may also want to wait for a similar signal from others. We conduct an experimental simulation of a crowdfunding website to explore how potential donors to projects make this decision. We find evidence for both strategies in our experiment; some donate early while others wait till the last second. However, we also find that making an early donation is usually a better strategy for donors because the amount of donations made early in a project's campaign is often the only difference between that project being funded or not. This finding suggests that crowdfunding sites need to develop designs, policies and incentives that encourage people to make immediate donations so that the site can most efficiently fund projects. Jacob Solomon, Wenjuan Ma, Rick Wash |
CSCW | 3 |
| 2015 | Are You Listening?: Social Roles and Perceived Value of Statements in Online Learning CommunitiesabstractAn important part of learning is interactions with peers, mentors, teaching assistants and the instructor. Discussions and group work allow for interactive learning and deeper understanding of class concepts. Online learning environments struggle to replicate this process. This is especially true when the scale of an online class is increased. In order to address this issue a few MOOCs solicit teaching assistants to answer questions, and through their social position, help set academic standards in discussion forums. However, little is know about how different social roles influence the attribution of value to statements in these environments. This study demonstrates that the attitudes expressed by individuals in facilitating roles influence the acceptance of information shared in a discussion board setting. Ruth Shillair, Rick Wash |
L@S | 2 |
| 2015 | Too Much Knowledge? Security Beliefs and Protective Behaviors Among United States Internet Users
Rick Wash, Emilee Rader |
SOUPS | 1 |
| 2014 | Betrayed by updates: how negative experiences affect future securityabstractInstalling security-relevant software updates is one of the best computer protection mechanisms. However, users do not always choose to install updates. Through interviewing non-expert Windows users, we found that users frequently decide not to install future updates, regardless of whether they are important for security, after negative experiences with past updates. This means that even non-security updates (such as user interface changes) can impact the security of a computer. We discuss three themes impacting users' willingness to install updates: unexpected new features in an update, the difficulty of assessing whether an update is ``worth it', and confusion about why an update is necessary. Kami Vaniea, Emilee Rader, Rick Wash |
CHI | 3 |
| 2014 | Coordinating donors on crowdfunding websitesabstractCrowdfunding websites like Kickstarter, Spot.Us and Donor's Choose seek to fund multiple projects simultaneously by soliciting donations from a large number of donors. Crowdfunding site designers must decide what to do with donations to projects that don't reach their goal by the deadline. Some crowdfunding sites use an all-or-nothing return rule in which donations are returned to donors if a project doesn't meet its goal. Other sites use a direct donation structure where all donations are kept by the project even if the total is insufficient. We simulated a crowdfunding site using a threshold public goods game in which a set of donors tries to fund multiple projects that vary in riskiness. We find that the return rule mechanism leads to a marginal improvement in productivity of a site -- more money is donated in total -- by eliciting more donations. However, the return rule also leads to a potential loss in efficiency (percentage of projects funded) because donations become spread across too many projects and are not coordinated to achieve the maximum possible impact. The direct donation model, though, encourages donors to coordinate to creates a more efficient but slightly less productive marketplace. Rick Wash, Jacob Solomon |
CSCW | 1 |
| 2014 | Critical Mass of What? Exploring Community Growth in WikiProjects
Jacob Solomon, Rick Wash |
ICWSM | 2 |
| 2014 | Out of the Loop: How Automated Software Updates Cause Unintended Security Consequences
Rick Wash, Emilee Rader, Kami Vaniea, Michelle Rizor |
SOUPS | 1 |
| 2014 | Latent Users in an Online User-Generated Content Community
Alcides Velasquez, Rick Wash, Cliff Lampe, Torger Bjornrud |
Comput. Support. Cooperative Work. | 2 |
| 2013 | The Value of Completing Crowdfunding Projects
Rick Wash |
ICWSM | 1 |
| 2012 | Bootstrapping wikis: developing critical mass in a fledgling community by seeding contentabstractOnline communities depend on content contributed by their members. However, new communities have not yet achieved critical mass and are vulnerable to inadequate contribution. To encourage contribution, many fledgling communities seed the site with data from 3rd parties. We study the effectiveness of such seeding by looking at how people react to different types of seeded content. We found that people make larger contributions when there is no seeded content. But when there is seeded content, users learn from that content and contribute similar types of content. Therefore, if websites prefer specific types of contributions, seeding that type of contribution can be a valuable way to elicit appropriate contributions. Jacob Solomon, Rick Wash |
CSCW | 2 |
| 2012 | The power of the ask in social mediaabstractSocial computing and social media systems depend on contributions from users. We posit the existence of a latent demand for contribution: many users want to contribute but don't. We then test a simple interface that can induce these users to actually contribute: we display a popup window asking users to contribute. In a real-world randomized field experiment, we found that asking them to contribute right now is ineffective, but reminding the users to contribute actually leads to approximately a 23% increase in contributions with no reduction in quality. However, this effect wanes as users habituate to the popups. Rick Wash, Cliff Lampe |
CSCW | 1 |
| 2012 | Stories as informal lessons about securityabstractNon-expert computer users regularly need to make security-relevant decisions; however, these decisions tend not to be particularly good or sophisticated. Nevertheless, their choices are not random. Where does the information come from that these non-experts base their decisions upon? We argue that much of this information comes from stories they hear from other people. We conducted a survey to ask open- and closed- ended questions about security stories people hear from others. We found that most people have learned lessons from stories about security incidents informally from family and friends. These stories impact the way people think about security, and their subsequent behavior when making security-relevant decisions. In addition, many people retell these stories to others, indicating that a single story has the potential to influence multiple people. Understanding how non-experts learn from stories, and what kinds of stories they learn from, can help us figure out new methods for helping these people make better security decisions. Emilee Rader, Rick Wash, Brandon Brooks |
SOUPS | 2 |
| 2011 | Influencing mental models of security: a research agendaabstractOver 80 million households in the United States have a home computer and an Internet connection. The vast majority of these are administered by people who have little computer security knowledge or training, and many users try to avoid making security decisions because they feel they don't have the knowledge and skills to maintain proper security. Nevertheless, home computer users still make security-related decisions on a regular basis -- for example, whether or not to click on a shady link in an email message -- without even knowing that's what they are doing. Their decisions are guided by how they think about computer security, or their "mental models," which do not have to be technically correct to lead to desirable security behaviors [44]. In other words, sometimes even "wrong" mental models produce good security decisions. By eliminating the constraint that nontechnical users must become more like computer security experts to properly protect themselves, we believe that we can create more effective ways of helping home computer users make good security decisions. To that end, we propose a research agenda that will help us learn how to shape the mental models of regular non-technical computer users. Rick Wash, Emilee Rader |
NSPW | 1 |
| 2010 | Motivations to participate in online communitiesabstractA consistent theoretical and practical challenge in the design of socio-technical systems is that of motivating users to participate in and contribute to them. This study examines the case of Everything2.com users from the theoretical perspectives of Uses and Gratifications and Organizational Commitment to compare individual versus organizational motivations in user participation. We find evidence that users may continue to participate in a site for different reasons than those that led them to the site. Feelings of belonging to a site are important for both anonymous and registered users across different types of uses. Long-term users felt more dissatisfied with the site than anonymous users. Social and cognitive factors seem to be more important than issues of usability in predicting contribution to the site. Cliff Lampe, Rick Wash, Alcides Velasquez, Elif Ozkaya |
CHI | 2 |
| 2010 | Folk models of home computer securityabstractHome computer systems are insecure because they are administered by untrained users. The rise of botnets has amplified this problem; attackers compromise these computers, aggregate them, and use the resulting network to attack third parties. Despite a large security industry that provides software and advice, home computer users remain vulnerable. I identify eight 'folk models' of security threats that are used by home computer users to decide what security software to use, and which expert security advice to follow: four conceptualizations of 'viruses' and other malware, and four conceptualizations of 'hackers' that break into computers. I illustrate how these models are used to justify ignoring expert security advice. Finally, I describe one reason why botnets are so difficult to eliminate: they cleverly take advantage of gaps in these models so that many home computer users do not take steps to protect against them. Rick Wash |
SOUPS | 1 |
| 2008 | Influences on tag choices in del.icio.usabstractCollaborative tagging systems have the potential to produce socially constructed information organization schemes. The effectiveness of tags for finding and re-finding information depends upon how individual users choose tags; however, influences on users' tag choices are poorly understood. We quantitatively test competing hypotheses from the literature concerning these choices, using data from del.icio.us (a collaborative tagging system for organizing web bookmarks) and a computer model of possible tag choice strategies. We find evidence that users choose tags in a pattern consistent with personal information management goals, rather than as a result of social influence. Emilee Rader, Rick Wash |
CSCW | 2 |
| 2007 | Security when people matter: structuring incentives for user behaviorabstractHumans are "smart components" in a system, but cannot be directly programmed to perform; rather, their autonomy must be respected as a design constraint and incentives provided to induce desired behavior. Sometimes these incentives are properly aligned, and the humans don't represent a vulnerability. But often, a misalignment of incentives causes a weakness in the system that can be exploited by clever attackers. Incentive-centered design tools help us understand these problems, and provide design principles to alleviate them. We describe incentive-centered design and some tools it provides. We provide a number of examples of security problems for which Incentive Centered Design might be helpful. We elaborate with a general screening model that offers strong design principles for a class of security problems. Rick Wash, Jeffrey K. MacKie-Mason |
ICEC | 1 |
| 2006 | Incentive-Centered Design for Information Security
Rick Wash, Jeffrey K. MacKie-Mason |
HotSec | 1 |
| 2005 | Design decisions in the RideNow projectabstractThe RideNow Project is designed to help individuals within a group or organization coordinate ad hoc shared rides. This paper describes three design decisions the RideNow team made in order to allow incremental adoption and evolution and to capitalize on local conditions. (1) The system allows users to interact with the system through email or Web, because we anticipate that email will be most convenient when there are few users but the Web interface will be more useful as the number of users increase. (2) The system does not force structure on user-entered data such as dates, times, and locations, instead allowing conventions to emerge. (3) We use the group's shared physical spaces to provide additional information about ride sharing activity. Rick Wash, Libby Hemphill, Paul Resnick |
GROUP | 1 |
| 2004 | An economic answer to unsolicited communicationabstractWe explore an alternative approach to spam based on eco-nomic rather than technological or regulatory screening mech-anisms. We employ a model of email value which sup-ports two intuitive notions: 1) mechanisms designed to pro-mote valuable communication can often outperform those designed merely to block wasteful communication, and 2) designers of such mechanisms should shift focus away from the information in the message to the information known to the sender. We then use principles of information asymme-try to cause people who knowingly misuse communication to incur higher costs than those who do not. In certain cases, though not all, we can show this approach leaves re-cipients better off than even an idealized or “perfect ” filter that costs nothing and makes no mistakes. Our mechanism also accounts for individual differences in opportunity costs, and allows for bi-directional wealth transfers while facilitat-ing both sender signaling and recipient screening. 1 Thede Loder, Marshall W. van Alstyne, Rick Wash |
EC | 3 |