VLDB 2026 Research / reviewers in the wild / expert
Sabrina Klivan
dblp:251/3013 · also Sabrina Amft
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2025
0009-0002-2315-8989ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations
Jan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha Fahl |
CHI | 2 |
| 2024 | Passwords To-Go: Investigating Multifaceted Challenges for Password Managers in the Android EcosystemabstractAndroid provides two APIs to help mobile apps and browsers interact with password managers, the Android Autofill framework (AAF) and the Credentials API. Mobile password managers rely on these APIs to insert stored credentials into apps and browsers, limiting user interaction during authentication. However, implementing these APIs correctly can be challenging for app developers. For example, misusing the AAF can lead to insecure authentication, login credential phishing, and decreased usability.In this work, we conduct a mixed-methods study on the use of Android authentication APIs, focusing on their password manager support and impact on authentication security and usability. We first conduct a large-scale analysis of the two authentication APIs in 639,731 Android apps. Secondly, we perform an in-depth qualitative analysis of the AAF with 100 apps, ten browsers, and eleven password managers on Android. The Credentials API has not yet been adopted broadly, illustrating its recent introduction. Regarding Android’s Autofill framework, our qualitative analysis identified various unsupported edge cases like credit card management and password changing. Based on our findings, we make recommendations for improving the AAF and relate them to the Credentials API. We find that while a lot of the partially supported cases will work better in the new API, especially the lesser supported cases in our analysis currently fail for both APIs. Nicolas Huaman Groschopf, Marten Oltrogge, Sabrina Klivan, Yannick Evers, Sascha Fahl |
ACSAC | 3 |
| 2024 | Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game DevelopmentabstractThe video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Philip Klostermeyer, Sabrina Klivan, Sandra Höltervennhoff, Alexander Krause 0002, Niklas Busch, Sascha Fahl |
CCS | 2 |
| 2024 | Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsabstractTo increase open-source software supply chain security, protecting the development environment of contributors against attacks is crucial. For example, contributors must protect authentication credentials for software repositories, code-signing keys, and their systems from malware.Previous incidents illustrated that open-source contributors struggle with protecting their development environment. In contrast to companies, open-source software projects cannot easily enforce security guidelines for development environments. Instead, contributors’ security setups are likely heterogeneous regarding chosen technologies and strategies.To the best of our knowledge, we perform the first in-depth qualitative investigation of the security of open-source software contributors’ individual security setups, their motivation, decision-making, and sentiments, and the potential impact on open-source software supply chain security. Therefore, we conduct 20 semi-structured interviews with a diverse set of experienced contributors to critical open-source software projects.Overall, we find that contributors have a generally high affinity for security. However, security practices are rarely discussed in the community or enforced by projects. Furthermore, we see a strong influence of social mechanisms, such as trust, respect, or politeness, further impeding the sharing of security knowledge and best practices.We conclude our work with a discussion of the impact of our findings on open-source software and supply chain security, and make recommendations for the open-source software community. Sabrina Klivan, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky, Sascha Fahl |
SP | 1 |
| 2024 | "You have to read 50 different RFCs that contradict each other": An Interview Study on the Experiences of Implementing Cryptographic Standards
Nicolas Huaman Groschopf, Jacques Suray, Jan H. Klemmer, Marcel Fourné, Sabrina Klivan, Ivana Trummová, Yasemin Acar, Sascha Fahl |
USENIX Security Symposium | 5 |
| 2023 | "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsabstractMulti-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps. Sabrina Klivan, Sandra Höltervennhoff, Nicolas Huaman Groschopf, Alexander Krause 0002, Lucy Simko, Yasemin Acar, Sascha Fahl |
CCS | 1 |
| 2023 | "Would You Give the Same Priority to the Bank and a Game? I Do Not!" Exploring Credential Management Strategies and Obstacles during Password Manager Setup
Sabrina Klivan, Sandra Höltervennhoff, Nicolas Huaman Groschopf, Yasemin Acar, Sascha Fahl |
SOUPS | 1 |
| 2023 | Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by WebsitesabstractModern websites frequently use and embed third-party services to facilitate web development, connect to social media, or for monetization. This often introduces privacy issues as the inclusion of third-party services on a website can allow the third party to collect personal data about the website's visitors. While the prevalence and mechanisms of third-party web tracking have been widely studied, little is known about the decision processes that lead to websites using third-party functionality and whether efforts are being made to protect their visitors' privacy. We report results from an online survey with 395 participants involved in the creation and maintenance of websites. For ten common website functionalities we investigated if privacy has played a role in decisions about how the functionality is integrated, if specific efforts for privacy protection have been made during integration, and to what degree people are aware of data collection through third parties. We find that ease of integration drives third-party adoption but visitor privacy is considered if there are legal requirements or respective guidelines. Awareness of data collection and privacy risks is higher if the collection is directly associated with the purpose for which the third-party service is used. Christine Utz, Sabrina Klivan, Martin Degeling, Thorsten Holz, Sascha Fahl, Florian Schaub |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Where to Recruit for Security Development Studies: Comparing Six Software Developer Samples
Harjot Kaur, Sabrina Klivan, Daniel Votipka, Yasemin Acar, Sascha Fahl |
USENIX Security Symposium | 2 |
| 2021 | They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesabstractPassword managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2,947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research. Nicolas Huaman Groschopf, Sabrina Klivan, Marten Oltrogge, Yasemin Acar, Sascha Fahl |
SP | 2 |
| 2021 | Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android Applications
Marten Oltrogge, Nicolas Huaman Groschopf, Sabrina Klivan, Yasemin Acar, Michael Backes 0001, Sascha Fahl |
USENIX Security Symposium | 3 |