Matthias Fassl

dblp:292/5433 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-2894-3751ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 7 · 3 first-author · 7 since 2021Security and privacy · 4 · 4 since 2021
YearPublicationVenuePosition
2026 SoK: Mapping Threats to Defenses in Online Survey Fraud
Shiza Ali, Wellington Esposito Barbosa, Matthias Fassl, Aditi Ganapathi, Jaron Mink, Adam J. Aviv
SOUPS3
2026 "Because I didn't touch these and even don't know why I should to change these": Why App Developers Do (Not) Update Apple's Privacy Labels
abstract
Apple introduced app-based privacy labels in 2020 to improve apps' communication of their data practices. However, most developers appear to treat privacy labels as a ``set-once'' mechanism. To better understand the dynamics of this system, we first analyzed a four-year longitudinal dataset of Apple's Privacy Label. Next, we conducted an email survey of developers who have changed (or not changed) their privacy labels during this period, and finally, performed follow-up interviews with developers from each group. We find that only 51,364 apps (less than 6%) over this period have made any changes to their privacy labels, many of them changing their initial 'Do Not Collect' label to more refined classification. From the emails and interviews, the ``black box'' of third-party data practice may lead developers to underreport their app's data practices. Many developers reported that privacy labels are a valuable marketing tool for promoting their apps as privacy-friendly. Privacy labels may appear stable not necessarily because practices are stable, but because ambiguity encourages minimal or optimistic disclosure. To improve privacy label maintenance, we recommend enhanced transparency mechanisms for third-party libraries, stronger workflow integration, and platform support that guides developers and strengthens users' control.
Arwa Alsahdi, Monica Kodwani, Matthias Fassl, Chris Kanich, Adam J. Aviv
Proc. Priv. Enhancing Technol.4
2025 Towards Anti-Imperialist Security, Privacy, and Safety Research in HCI
abstract
Usable security and privacy is an interdisciplinary research field at the intersection of computer security, privacy, and HCI founded over 20 years ago. Since then, the field has expanded its domain to claim a wider range of human-centered security and privacy issues. Our field’s increasing breadth warrants both celebration of scientific exploration as well as careful consideration of the process itself. The expansionary process of a scientific domain to study a different societies, particularly those that have less global privilege, shares some characteristics with imperialism: the development and maintenance of power of one country over another through various forms of domination. In this work, we take a first step towards anti-imperialist research by identifying how imperialist tendencies manifest in security, privacy, and safety research in HCI and characterizing systemic trends. To aid the development of a critical eye for imperialism in our field, we offer reflection questions for individual researchers.
Miranda Wei, Matthias Fassl
NSPW2
2025 AirTag-Facilitated Stalking Protection: Evaluating Unwanted Tracking Notifications and Tracker Locating Features
Dañiel Gerhardt, Matthias Fassl, Carolyn Guthoff, Adrian Dabrowski, Katharina Krombholz
USENIX Security Symposium2
2023 Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with Autoethnography
abstract
Authentication ceremonies detect and mitigate Man-in-the-Middle (MitM) attacks on end-to-end encrypted messengers, such as Signal, WhatsApp, or Threema. However, prior work found that adoption remains low as non-expert users have difficulties using them correctly. Anecdotal evidence suggests that security researchers also have trouble authenticating others. Since their issues are probably unrelated to user comprehension or usability, the root causes may lie deeper.
Matthias Fassl, Katharina Krombholz
CHI1
2023 Different Researchers, Different Results? Analyzing the Influence of Researcher Experience and Data Type During Qualitative Analysis of an Interview and Survey Study on Security Advice
abstract
When conducting qualitative research it is necessary to decide how many researchers should be involved in coding the data: Is one enough or are more coders beneficial? To offer empirical evidence for this question, we designed a series of studies investigating qualitative coding. We replicated and extended a usable security and privacy study by Ion et al. to gather both simple survey data and complex interview data. We had a total of 65 students and seven researchers analyze different parts of this data. We analyzed the codebook creation process, similarity of outcomes, inter-rater reliability, and compared the student to the researcher outcomes. We also surveyed five years of SOUPS-PC members about their views on coding. The reviewers view on coding practices for complex and simple data are almost identical. However, our results suggest that the coding process can be different for the two types of data, with complex data benefiting more from interaction between coders.
Anna-Marie Ortloff, Matthias Fassl, Alexander Ponticello, Florin Martius, Anne Mertens, Katharina Krombholz, Matthew Smith 0001
CHI2
2023 Investigating Security Folklore: A Case Study on the Tor over VPN Phenomenon
abstract
Users face security folklore in their daily lives in the form of security advice, myths, and word-of-mouth stories. Using a VPN to access the Tor network, i.e., Tor over VPN, is an interesting example of security folklore because of its inconclusive security benefits and its occurrence in pop-culture media. Following the Theory of Reasoned Action, we investigated the phenomenon with three studies: (1) we quantified the behavior on real-world Tor traffic and measured a prevalence of 6.23%; (2) we surveyed users' intentions and beliefs, discovering that they try to protect themselves from the Tor network or increase their general security; and (3) we analyzed online information sources, suggesting that perceived norms and ease-of-use play a significant role while behavioral beliefs about the purpose and effect are less crucial in spreading security folklore. We discuss how to communicate security advice effectively and combat security misinformation and misconceptions.
Matthias Fassl, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz
Proc. ACM Hum. Comput. Interact.1
2021 Exploring User-Centered Security Design for Usable Authentication Ceremonies
abstract
Security technology often follows a systems design approach that focuses on components instead of users. As a result, the users’ needs and values are not sufficiently addressed, which has implications on security usability. In this paper, we report our lessons learned from applying a user-centered security design process to a well-understood security usability challenge, namely key authentication in secure instant messaging. Users rarely perform these key authentication ceremonies, which makes their end-to-end encrypted communication vulnerable. Our approach includes collaborative design workshops, an expert evaluation, iterative storyboard prototyping, and an online evaluation.
Matthias Fassl, Lea Gröber, Katharina Krombholz
CHI1
2021 Investigating Car Drivers' Information Demand after Safety and Security Critical Incidents
abstract
Modern cars include a vast array of computer systems designed to remove the burden on drivers and enhance safety. As cars are evolving towards autonomy and taking over control, e.g. in the form of autopilots, it becomes harder for drivers to pinpoint the root causes of a car’s malfunctioning. Drivers may need additional information to assess these ambiguous situations correctly. However, it is yet unclear which information is relevant and helpful to drivers in such situations. Hence, we conducted a mixed-methods online survey (N = 60) on Amazon MTurk where we exposed participants to two security- and safety-critical situations with one of three different explanations. We applied Thematic and Correspondence Analysis to understand which factors in these situations moderate drivers’ information demand. We identified a fundamental information demand across scenarios that is expanded by error-specific information types. Moreover, we found that it is necessary to communicate error sources, since drivers might not be able to identify them correctly otherwise. Thereby, malicious intrusions are typically perceived as more critical than technical malfunctions.
Lea Gröber, Matthias Fassl, Abhilash Gupta, Katharina Krombholz
CHI2
2021 A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security Research
abstract
Usable privacy and security researchers have developed a variety of approaches to represent risk to research participants. To understand how these approaches are used and when each might be most appropriate, we conducted a systematic literature review of methods used in security and privacy studies with human participants. From a sample of 633 papers published at five top conferences between 2014 and 2018 that included keywords related to both security/privacy and usability, we systematically selected and analyzed 284 full-length papers that included human subjects studies. Our analysis focused on study methods; risk representation; the use of prototypes, scenarios, and educational intervention; the use of deception to simulate risk; and types of participants. We discuss benefits and shortcomings of the methods, and identify key methodological, ethical, and research challenges when representing and assessing security and privacy risk. We also provide guidelines for the reporting of user studies in security and privacy.
Verena Distler, Matthias Fassl, Hana Habib, Katharina Krombholz, Gabriele Lenzini, Carine Lallemand, Lorrie Faith Cranor, Vincent Koenig
ACM Trans. Comput. Hum. Interact.2