Maximilian Häring

dblp:252/3848 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0002-5516-0293ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 5 since 2021Security and privacy · 4 · 3 since 2021
YearPublicationVenuePosition
2025 "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in Germany
abstract
Two-factor authentication is often recommended for increasing online security, and users often follow this by using their phones. If physical items become unavailable, there is a risk of losing access to the account due to missing authentication requirements. In such cases, users need a backup or help from the service. Previous work found no standardized approach to how services address this issue, assist users, or offer backup options. Until now, it is unclear how users handle backups and account recovery and what their expectations towards service providers are. To shed light on this, we conducted 16 interviews and a survey with 95 participants. We found that most had never considered how to access their accounts if the second factor was lost, and only a few had a backup plan. Instead, users often rely on website support, assuming that personal data will help them regain access. We give recommendations for services.
Eva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau
CHI3
2025 I Have Not Understood but Agree: Studying Informed Consent in the Context of the German COVID-19 Contact Tracing App
abstract
Many EU data collectors rely on informed consent for data processing, requiring users to consent after being informed. To do so, it is necessary for users to have at least partially correct assumptions about what the software does. The introduction of the official German contact tracing app, the Corona-Warn-App (CWA), provides an interesting use case to explore whether potential users are capable of being informed with a reasonable amount of effort by the publishers of software. We captured CWA users’ and non-users’ mental models of data collection and processing in the app in interviews (N = 20) and a survey study (N = 352). We investigated whether users have enough correct assumptions to be considered informed. Our findings show that the participants had misconceptions. Therefore, we argue that user consent might often lack the required level of informedness and may be replaced by a more rigorous privacy-by-design principle.
Maximilian Häring, Eva Tiefenau, Christian Tiefenau, Felix Kretschmer-Pietralla, Alina Stöver, Nina Gerber
ACM Trans. Comput. Hum. Interact.1
2023 Less About Privacy: Revisiting a Survey about the German COVID-19 Contact Tracing App
abstract
The release of COVID-19 contact tracing apps was accompanied by a heated public debate with much focus on privacy concerns, e.g., possible government surveillance. Many papers studied people’s intended behavior to research potential features and uptake of the apps. Studies in Germany conducted before the app’s release, such as that by Häring et al., showed that privacy was an important factor in the intention to install the app. We conducted a follow-up study two months post-release to investigate the intention-behavior-gap, see how attitudes changed after the release, and capture reported behavior. Analyzing a quota sample (n=837) for Germany, we found that fewer participants mentioned privacy concerns post-release, whereas utility now plays a greater role. We provide further evidence that the results of intention-based studies should be handled with care when used for prediction purposes.
Maximilian Häring, Eva Tiefenau, Matthew Smith 0001, Christian Tiefenau
CHI1
2023 Evolution of Password Expiry in Companies: Measuring the Adoption of Recommendations by the German Federal Office for Information Security
Eva Tiefenau, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau
SOUPS2
2023 Adventures in Recovery Land: Testing the Account Recovery of Popular Websites When the Second Factor is Lost
Eva Tiefenau, Maximilian Häring, Charlotte Theresa Mädler, Matthew Smith 0001, Christian Tiefenau
SOUPS2
2023 Attitudes towards Client-Side Scanning for CSAM, Terrorism, Drug Trafficking, Drug Use and Tax Evasion in Germany
abstract
In recent years, there have been a rising number of legislative efforts and proposed technical measures to weaken privacy-preserving technology, with the stated goal of countering serious crimes like child abuse. One of these proposed measures is Client-Side Scanning (CSS). CSS has been hotly debated both in the context of Apple stating their intention to deploy it in 2021 as well as EU legislation being proposed in 2022. Both sides of the argument state that they are working in the best interests of the people. To shed some light on this, we conducted a survey with a representative sample of German citizens. We investigated the general acceptance of CSS vs cloud-based scanning for different types of crimes and analyzed how trust in the German government and companies such as Google and Apple influenced our participants’ views. We found that, by and large, the majority of participants were willing to accept CSS measures to combat serious crimes such as child abuse or terrorism, but support dropped significantly for other illegal activities. However, the majority of participants who supported CSS were also worried about potential abuse, with only 20% stating that they were not concerned. These results suggest that many of our participants would be willing to have their devices scanned and accept some risks in the hope of aiding law enforcement. In our analysis, we argue that there are good reasons to not see this as a carte blanche for the introduction of CSS but as a call to action for the S&P community. More research is needed into how a population’s desire to prevent serious crime online can be achieved while mitigating the risks to privacy and society.
Lisa Geierhaas, Fabian Otto, Maximilian Häring, Matthew Smith 0001
SP3
2019 A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done Right
abstract
The correct configuration of HTTPS is a complex set of tasks, which many administrators have struggled with in the past. Let's Encrypt and Electronic Frontier Foundation's Certbot aim to improve the TLS ecosystem by offering free trusted certificates (Let's Encrypt) and by providing user-friendly support to configure and harden TLS (Certbot). Although adoption rates have increased, to date, there has been only a little scientific evidence of the actual usability and security benefits of this semi-automated approach. Therefore, we conducted a randomized control trial to evaluate the usability of Let's Encrypt and Certbot in comparison to the traditional certificate authority approach. We performed a within-subjects lab study with 31 participants. The study sheds light on the security and usability enhancements that Let's Encrypt and Certbot provide. We highlight how usability improvements aimed at administrators can have a large impact on security and discuss takeaways for Certbot and other security-related tasks that experts struggle with.
Christian Tiefenau, Emanuel von Zezschwitz, Maximilian Häring, Katharina Krombholz, Matthew Smith 0001
CCS3