VLDB 2026 Research / reviewers in the wild / expert
Eva Tiefenau
dblp:239/8234 · also Eva Gerlitz
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0003-1251-5629ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 5 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in GermanyabstractTwo-factor authentication is often recommended for increasing online security, and users often follow this by using their phones. If physical items become unavailable, there is a risk of losing access to the account due to missing authentication requirements. In such cases, users need a backup or help from the service. Previous work found no standardized approach to how services address this issue, assist users, or offer backup options. Until now, it is unclear how users handle backups and account recovery and what their expectations towards service providers are. To shed light on this, we conducted 16 interviews and a survey with 95 participants. We found that most had never considered how to access their accounts if the second factor was lost, and only a few had a backup plan. Instead, users often rely on website support, assuming that personal data will help them regain access. We give recommendations for services. Eva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau |
CHI | 1 |
| 2025 | I Have Not Understood but Agree: Studying Informed Consent in the Context of the German COVID-19 Contact Tracing AppabstractMany EU data collectors rely on informed consent for data processing, requiring users to consent after being informed. To do so, it is necessary for users to have at least partially correct assumptions about what the software does. The introduction of the official German contact tracing app, the Corona-Warn-App (CWA), provides an interesting use case to explore whether potential users are capable of being informed with a reasonable amount of effort by the publishers of software. We captured CWA users’ and non-users’ mental models of data collection and processing in the app in interviews (N = 20) and a survey study (N = 352). We investigated whether users have enough correct assumptions to be considered informed. Our findings show that the participants had misconceptions. Therefore, we argue that user consent might often lack the required level of informedness and may be replaced by a more rigorous privacy-by-design principle. Maximilian Häring, Eva Tiefenau, Christian Tiefenau, Felix Kretschmer-Pietralla, Alina Stöver, Nina Gerber |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2023 | Less About Privacy: Revisiting a Survey about the German COVID-19 Contact Tracing AppabstractThe release of COVID-19 contact tracing apps was accompanied by a heated public debate with much focus on privacy concerns, e.g., possible government surveillance. Many papers studied people’s intended behavior to research potential features and uptake of the apps. Studies in Germany conducted before the app’s release, such as that by Häring et al., showed that privacy was an important factor in the intention to install the app. We conducted a follow-up study two months post-release to investigate the intention-behavior-gap, see how attitudes changed after the release, and capture reported behavior. Analyzing a quota sample (n=837) for Germany, we found that fewer participants mentioned privacy concerns post-release, whereas utility now plays a greater role. We provide further evidence that the results of intention-based studies should be handled with care when used for prediction purposes. Maximilian Häring, Eva Tiefenau, Matthew Smith 0001, Christian Tiefenau |
CHI | 2 |
| 2023 | Evolution of Password Expiry in Companies: Measuring the Adoption of Recommendations by the German Federal Office for Information Security
Eva Tiefenau, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau |
SOUPS | 1 |
| 2023 | Adventures in Recovery Land: Testing the Account Recovery of Popular Websites When the Second Factor is Lost
Eva Tiefenau, Maximilian Häring, Charlotte Theresa Mädler, Matthew Smith 0001, Christian Tiefenau |
SOUPS | 1 |
| 2020 | On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company DevelopersabstractEcological validity is a major concern in usable security studies with developers. Many studies are conducted with computer science (CS) students out of convenience, since recruiting professional software developers in sufficient numbers is very challenging. In a password-storage study, Naiakshina et al. (CHI'19) showed that CS students behave similarly to freelance developers recruited online. While this is a promising result for conducting developer studies with students, an open question remains: Do professional developers employed in companies behave similarly as well? To provide more insight into the ecological validity of recruiting students for security developer studies, we replicated the study of Naiakshina et al. with developers from diverse companies in Germany. We found that developers employed in companies performed better than students and freelancers in a direct comparison. However, treatment effects were found to be significant in all groups; the treatment effects on CS students also held for company developers. Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Matthew Smith 0001 |
CHI | 3 |
| 2019 | "If you want, I can store the encrypted password": A Password-Storage Field Study with Freelance DevelopersabstractIn 2017 and 2018, Naiakshina et al. (CCS'17, SOUPS'18) studied in a lab setting whether computer science students need to be told to write code that stores passwords securely. The authors' results showed that, without explicit prompting, none of the students implemented secure password storage. When asked about this oversight, a common answer was that they would have implemented secure storage - if they were creating code for a company. To shed light on this possible confusion, we conducted a mixed-methods field study with developers. We hired freelance developers online and gave them a similar password storage task followed by a questionnaire to gain additional insights into their work. From our research, we offer two contributions. First of all, we reveal that, similar to the students, freelancers do not store passwords securely unless prompted, they have misconceptions about secure password storage, and they use outdated methods. Secondly, we discuss the methodological implications of using freelancers and students in developer studies. Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Emanuel von Zezschwitz, Matthew Smith 0001 |
CHI | 3 |