Eva Tiefenau

dblp:239/8234 · also Eva Gerlitz · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0003-1251-5629ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 5 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in Germany
abstract
Two-factor authentication is often recommended for increasing online security, and users often follow this by using their phones. If physical items become unavailable, there is a risk of losing access to the account due to missing authentication requirements. In such cases, users need a backup or help from the service. Previous work found no standardized approach to how services address this issue, assist users, or offer backup options. Until now, it is unclear how users handle backups and account recovery and what their expectations towards service providers are. To shed light on this, we conducted 16 interviews and a survey with 95 participants. We found that most had never considered how to access their accounts if the second factor was lost, and only a few had a backup plan. Instead, users often rely on website support, assuming that personal data will help them regain access. We give recommendations for services.
Eva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau
CHI1
2025 I Have Not Understood but Agree: Studying Informed Consent in the Context of the German COVID-19 Contact Tracing App
abstract
Many EU data collectors rely on informed consent for data processing, requiring users to consent after being informed. To do so, it is necessary for users to have at least partially correct assumptions about what the software does. The introduction of the official German contact tracing app, the Corona-Warn-App (CWA), provides an interesting use case to explore whether potential users are capable of being informed with a reasonable amount of effort by the publishers of software. We captured CWA users’ and non-users’ mental models of data collection and processing in the app in interviews (N = 20) and a survey study (N = 352). We investigated whether users have enough correct assumptions to be considered informed. Our findings show that the participants had misconceptions. Therefore, we argue that user consent might often lack the required level of informedness and may be replaced by a more rigorous privacy-by-design principle.
Maximilian Häring, Eva Tiefenau, Christian Tiefenau, Felix Kretschmer-Pietralla, Alina Stöver, Nina Gerber
ACM Trans. Comput. Hum. Interact.2
2023 Less About Privacy: Revisiting a Survey about the German COVID-19 Contact Tracing App
abstract
The release of COVID-19 contact tracing apps was accompanied by a heated public debate with much focus on privacy concerns, e.g., possible government surveillance. Many papers studied people’s intended behavior to research potential features and uptake of the apps. Studies in Germany conducted before the app’s release, such as that by Häring et al., showed that privacy was an important factor in the intention to install the app. We conducted a follow-up study two months post-release to investigate the intention-behavior-gap, see how attitudes changed after the release, and capture reported behavior. Analyzing a quota sample (n=837) for Germany, we found that fewer participants mentioned privacy concerns post-release, whereas utility now plays a greater role. We provide further evidence that the results of intention-based studies should be handled with care when used for prediction purposes.
Maximilian Häring, Eva Tiefenau, Matthew Smith 0001, Christian Tiefenau
CHI2
2023 Evolution of Password Expiry in Companies: Measuring the Adoption of Recommendations by the German Federal Office for Information Security
Eva Tiefenau, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau
SOUPS1
2023 Adventures in Recovery Land: Testing the Account Recovery of Popular Websites When the Second Factor is Lost
Eva Tiefenau, Maximilian Häring, Charlotte Theresa Mädler, Matthew Smith 0001, Christian Tiefenau
SOUPS1
2020 On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company Developers
abstract
Ecological validity is a major concern in usable security studies with developers. Many studies are conducted with computer science (CS) students out of convenience, since recruiting professional software developers in sufficient numbers is very challenging. In a password-storage study, Naiakshina et al. (CHI'19) showed that CS students behave similarly to freelance developers recruited online. While this is a promising result for conducting developer studies with students, an open question remains: Do professional developers employed in companies behave similarly as well? To provide more insight into the ecological validity of recruiting students for security developer studies, we replicated the study of Naiakshina et al. with developers from diverse companies in Germany. We found that developers employed in companies performed better than students and freelancers in a direct comparison. However, treatment effects were found to be significant in all groups; the treatment effects on CS students also held for company developers.
Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Matthew Smith 0001
CHI3
2019 "If you want, I can store the encrypted password": A Password-Storage Field Study with Freelance Developers
abstract
In 2017 and 2018, Naiakshina et al. (CCS'17, SOUPS'18) studied in a lab setting whether computer science students need to be told to write code that stores passwords securely. The authors' results showed that, without explicit prompting, none of the students implemented secure password storage. When asked about this oversight, a common answer was that they would have implemented secure storage - if they were creating code for a company. To shed light on this possible confusion, we conducted a mixed-methods field study with developers. We hired freelance developers online and gave them a similar password storage task followed by a questionnaire to gain additional insights into their work. From our research, we offer two contributions. First of all, we reveal that, similar to the students, freelancers do not store passwords securely unless prompted, they have misconceptions about secure password storage, and they use outdated methods. Secondly, we discuss the methodological implications of using freelancers and students in developer studies.
Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Emanuel von Zezschwitz, Matthew Smith 0001
CHI3