VLDB 2026 Research / reviewers in the wild / expert
Nathan Reitinger
dblp:238/8867
· DBLP profile ↗
8ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0001-8294-9946ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Help Me Help You: Privacy Considerations for Third Party IoT Device RepairabstractSmart home devices are becoming increasingly complex and data-rich. The inevitable repair of these devices will be both difficult and privacy-sensitive. A "HandyTech"—a technician for home Internet of Things (IoT) system repair—has the potential to lower barriers to repair, but privacy questions remain: Are people willing to use a HandyTech to fix a broken home IoT device despite the inherent privacy risk (i.e., allowing a third party to access potentially sensitive IoT data)? We explore this question through a vignette-based, multi-factorial survey with a nationally representative sample of adults in the United States. We further ask whether types of devices (i.e., smart speakers, refrigerators, and CPAP machines) and factors adjacent to privacy and associated with the HandyTech's work (i.e., scope of access, state-based licensing requirements, and transparency provisions) affect decisions to use or not use a HandyTech. We find that some demographic groups are more willing than others to use a HandyTech (e.g., younger age groups, those with children in the home). Current ownership of more types of smart devices increases willingness to use a HandyTech, while greater concerns over general IoT privacy decreases willingness to use a HandyTech. Device-specific perceptions also mattered, such that perceived urgency to fix is strongly associated with willingness to use a HandyTech, but concern over that device's privacy is not. In addition, reduced scope of access and increased transparency by the HandyTech statistically increased willingness to use a HandyTech. In closing, we recommend takeaways that developers and policymakers can engage with to decrease privacy concerns and increase the adoption of third-party IoT repair. Nathan Reitinger, Weijia He, Chelsea Bruno, Susan Landau 0001, Carl A. Gunter, Mounib Khanafer, Ravindra Mangar, Denise L. Anthony |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Understanding and Addressing Online Tracking: Online Privacy's Regulatory TurnabstractComputing and storage breakthroughs over the last few decades have given rise to online tracking abilities that outpace current-day privacy-enhancing tools, social norms, and privacy regulations. Users lack the tools they need to block the types of tracking they cannot see and have very little control over; data stewards (i.e., companies processing user data) lack an understanding of what types of tracking practices users find normatively problematic; and policymakers lack effective feedback on real-world implementations of the data-focused or tracking-adjacent laws they are drafting-at a time when these regulations are in their infancy and feedback is crucial. Users should be able to navigate the web without falling victim to surreptitious tracking technologies; companies should be aware of what types of tracking users find most problematic; and legislators should be able to rely on empirically driven measurement studies to help them understand where the law falls short and where companies need help. My dissertation work focuses on improving online privacy by developing tracker-blocking tools, investigating user perceptions of online tracking, and systematizing knowledge as it relates to the measurement of statutory instruments. I focus here on the last, in-progress piece: a systematization of the measurement of legal compliance-helping researchers produce measurements that are compelling, ethical, and legally robust. Nathan Reitinger |
CCS | 1 |
| 2024 | Contextualizing Interpersonal Data Sharing in Smart HomesabstractA key feature of smart home devices is monitoring the environment and recording data. These devices provide security via motion-detection video alerts, cost-savings via thermostat usage history, and peace of mind via functions like auto-locking doors or water leak detectors. At the same time, the sharing of this information in interpersonal relationships---though necessary---is currently accomplished on an all-or-nothing basis. This can easily lead to oversharing in a multi-user environment. Although prior work has studied people's perceptions of information sharing with vendors or ISPs, the sharing of household data among users who interact personally is less well understood. Interpersonal situations make data sharing much more context-based and, thus, more complicated. In this paper, we use themes from the theory of contextual integrity in an online survey (n=1,992) to study how people perceive data sharing with others in smart homes and inform future designs and research. Our results show that data recipients in a smart home can be reduced to three major groups, and data types matter more than device types. We also found that the types of access control desired by users can vary from scenario to scenario. Depending on whom they are sharing data with and about what data, participants expressed varying levels of comfort when presented with different types of access control (e.g., explicit approval versus time-limited access). Taken together, this provides strong evidence that a more dynamic access control system is needed, and we can design it in a more usable way. Weijia He, Nathan Reitinger, Atheer Almogbil, Yi-Shyuan Chiang, Timothy J. Pierson, David Kotz |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | What Does It Mean to Be Creepy? Responses to Visualizations of Personal Browsing Activity, Online Tracking, and Targeted AdsabstractInternet companies routinely follow users around the web, building profiles for ad targeting based on inferred attributes. Prior work has shown that these practices, generally, are creepy—but what does that mean? To help answer this question, we substantially revised an open-source browser extension built to observe a user's browsing behavior and present them with a tracker's perspective of that behavior. Our updated extension models possible interest inferences far more accurately, integrates data scraped from the user's Google ad dashboard, and summarizes ads the user was shown. Most critically, it introduces ten novel visualizations that show implications of the collected data, both the mundane (e.g., total number of ads you've been served) and the provocative (e.g., your interest in reproductive health, a potentially sensitive topic). We use our extension as a design probe in a week-long field study with 200 participants. We find that users do perceive online tracking as creepy—but that the meaning of creepiness is far from universal. Participants felt differently about creepiness even when their data presented similar visualizations, and even when responding to the most potentially provocative visualizations—in no case did more than 66% of participants agree that any one visualization was creepy. Nathan Reitinger, Bruce Wen, Michelle L. Mazurek, Blase Ur |
Proc. Priv. Enhancing Technol. | 1 |
| 2023 | Is Cryptographic Deniability Sufficientƒ Non-Expert Perceptions of Deniability in Secure MessagingabstractCryptographers have long been concerned with secure messaging protocols threatening deniability. Many messaging protocols—including, surprisingly, modern email— contain digital signatures which definitively tie the author to their message. If stolen or leaked, these signatures make it impossible to deny authorship. As illustrated by events surrounding leaks from Hilary Clinton’s 2016 U.S. presidential campaign, this concern has proven well founded. Deniable protocols are meant to avoid this very outcome, letting politicians and dissidents alike safely disavow authorship. Despite being deployed on billions of devices in Signal and WhatsApp, the effectiveness of such protocols in convincing people remains unstudied. While the absence of cryptographic evidence is clearly necessary for an effective denial, is it sufficientƒWe conduct a survey study (n = 1, 200) to understand how people perceive evidence of deniability related to encrypted messaging protocols. Surprisingly, in a world of "fake news" and Photoshop, we find that simple denials of message authorship, when presented in a courtroom setting without supporting evidence, are not effective. In contrast, participants who were given access to a screenshot forgery tool or even told one exists were much more likely to believe a denial. Similarly, but to a lesser degree, we find an expert cryptographer’s assertion that there is no evidence is also effective. Nathan Reitinger, Nathan Malkin, Omer Akgul, Michelle L. Mazurek, Ian Miers |
SP | 1 |
| 2021 | ML-CB: Machine Learning Canvas BlockabstractAbstract With the aim of increasing online privacy, we present a novel, machine-learning based approach to blocking one of the three main ways website visitors are tracked online—canvas fingerprinting. Because the act of canvas fingerprinting uses, at its core, a JavaScript program, and because many of these programs are reused across the web, we are able to fit several machine learning models around a semantic representation of a potentially offending program, achieving accurate and robust classifiers. Our supervised learning approach is trained on a dataset we created by scraping roughly half a million websites using a custom Google Chrome extension storing information related to the canvas. Classification leverages our key insight that the images drawn by canvas fingerprinting programs have a facially distinct appearance, allowing us to manually classify files based on the images drawn; we take this approach one step further and train our classifiers not on the malleable images themselves, but on the more-difficult-to-change, underlying source code generating the images. As a result, ML-CB allows for more accurate tracker blocking. Nathan Reitinger, Michelle L. Mazurek |
Proc. Priv. Enhancing Technol. | 1 |
| 2020 | What Twitter Knows: Characterizing Ad Targeting Practices, User Perceptions, and Ad Explanations Through Users' Own Twitter Data
Miranda Wei, Madison Stamos, Sophie Veys, Nathan Reitinger, Justin Goodman, Margot Herman, Dorota Filipczuk, Ben Weinshel, Michelle L. Mazurek, Blase Ur |
USENIX Security Symposium | 4 |
| 2018 | Going Dark: A Retrospective on the North American Blackout of 2038abstractFrom March 29, 2038, to April 6, 2038, the world observed the North American Blackout of 2038. The blackout left upwards of 300 million people without power, ravaged the world economy, and devastated the global internet. By many accounts, it was the most devastating blackout ever witnessed. That said, its occurrence should not be surprising. While pundits harp on the technical sophistication of the adversary, debate the merits of a kinetic response, and politicize the blackout, the sad reality is that we have, for years, known we were susceptible to such an event. Moreover, we have had the requisite knowledge and tools to avert the blackout, but failed to use them. Plenty has been written on the wide-reaching societal effects of the blackout; our focus will be on the blackout itself. Prashant Anantharaman, J. Peter Brady, Patrick Flathers, Vijay H. Kothari, Michael C. Millian, Jason Reeves, Nathan Reitinger, William G. Nisen, Sean W. Smith |
NSPW | 7 |