VLDB 2026 Research / reviewers in the wild / expert
Alexander Ponticello
dblp:301/5910
· DBLP profile ↗
10ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0001-6119-9701ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based RestorationabstractThe growing popularity of wearable camera glasses raises pressing concerns about bystanders being recorded without their consent. Most existing privacy-enhancing technologies (PETs) rely on opt-out models that place the burden of privacy protection on bystanders. We conducted a qualitative study on wearers’ and bystanders’ perceptions of opt-in, privacy-by-default approaches for camera glasses. To enable this study, we designed and evaluated an opt-in privacy-by-default protocol. We then conducted semi-structured interviews with camera glass wearers and bystanders (N = 18) to examine their perceptions of the protocol. Our findings show that bystanders viewed the opt-in protocol as essential and advocated for even stronger anonymization. Wearers appreciated the protocol’s safeguards but found it visually limiting, expressing desire for a context-dependent version that can be enabled in relevant scenarios. Our findings highlight the need for context-aware PETs that provide effective mechanisms for consent negotiation. Yahya Khawaja, Shirin Rehman, Alexander Ponticello, Divyanshu Bhardwaj 0001, Katharina Krombholz, Muhammad Hamad Alizai, Naveed Anwar Bhatti |
CHI | 3 |
| 2025 | How Blind and Low-Vision Users Manage Their PasswordsabstractManaging passwords securely and conveniently is still an open problem for many users. Existing research has examined users' password management strategies and identified pain points, such as security concerns, leading to insecure practices. We investigate how Blind and Low-Vision (BLV) users tackle this problem and how password managers can assist them. This paper presents the results of a qualitative interview study with N = 33 BLV participants. We found that all participants utilize password managers to some extent, which they perceive as fairly accessible. However, the adoption is mainly driven by the convenience of storing and retrieving passwords. The security advantages -- generating strong, random passwords -- were avoided mainly due to the absence of practical accessibility. Password managers do not adhere to BLV users' underlying needs for agency, which stem from experiences with inaccessible software and vendors who deprioritize accessibility issues. Underutilization of password managers leads BLV users to adopt insecure practices, such as reusing predictable passwords or resorting to 'security through obscurity' by writing important credentials in braille. We conclude our analysis by discussing the need to implement practical accessibility and usability improvements for password managers as a way of establishing trust and secure practices while maintaining BLV users' agency. Alexander Ponticello, Filipo Sharevski, Simon Anell, Katharina Krombholz |
CCS | 1 |
| 2025 | "You Creep! It Really Worked!": An Empirical Study of Telephone Scams with Cloned Familiar Voices and Trusted Caller IDsabstractTelephone scams often attempt to defraud or steal the identity of individuals by eliciting a response to a pressing request for payments or submission of information such as social security numbers. These calls usually come from numbers that individuals have not encountered before, and the request is passed through as a pre-recorded message with a generic voice. But AI-enabled voice cloning and the ability to spoof Caller IDs have given scammers the opportunity to run schemes targeted individuals with a cloned familiar voice coming from trusted numbers. This paper reports the findings from an empirical study that replicates this scenario with 14 participants (7 pairs of family relatives of friends) to capture the experiences of receiving such a scam call and responses to it. The results of our thematic analysis show that the familiar voice, coming from a trusted number of a family relative or a friend, is highly persuasive towards deceiving the call receiver (i.e., callee) to indeed follow through with the scammer’s request. The callee, together with the caller or the participants who volunteered their voices for cloning, saw this scam working particularly in the context of family emergencies, as real-world reports have surfaced about children held for ransom, grandchildren under arrest, or relatives in car accidents. The callers and callees saw no immediate way to fend off these “family emergency scams” than for families and friends to work on “family/friend codewords” that are hard to be inferred by the scammers (and thus cloned). We discuss our findings towards the development of user-centered interventions that would facilitate the detection of a wide range of AI-enabled voice cloning scams, in addition to the suggested personal ways of scam detection. Filipo Sharevski, Jennifer Vander Loop, Bill Evans, Alexander Ponticello |
NSPW | 4 |
| 2025 | Analyzing the iOS Local Network Permission from a Technical and User PerspectiveabstractIn the past, malicious apps attacked routers or identified locations through local network communication. To mitigate security and privacy risks from local network access, Apple introduced a new permission with iOS 14. To be effective, the permission needs to protect against technical threats, and users must be able to make an informed permission decision. The latter is presumably hindered by the intrinsic technicality of the concept of the local network. In this paper, we perform the first comprehensive analysis of the local network permission by studying four key aspects. We investigate the security of its implementation by systematically accessing the local network. We explore local network accesses via a large-scale dynamic analysis of 10,862 iOS and Android apps. We analyze the concepts that constitute the permission prompts, as this is all the information users get before making a decision. Based on the identified concepts, we conduct an online survey$(N=150)$to comprehend users' understanding of the permission, their threat awareness, and common misconceptions. Our work reveals two methods to bypass the permission from webviews, and that the protected local network addresses are insufficient. We show how and when apps access the local network, and how the situation differs between iOS and Android. Finally, we present the light and shadow of users' understanding of the permission. While nearly every participant is aware of at least one threat (83.11%), misconceptions are even more common (84.46%). Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz, Martina Lindorfer |
SP | 2 |
| 2025 | (Blind) Users Really Do Heed Aural Telephone Scam WarningsabstractThis paper reports on a study exploring how two groups of individuals, legally blind$(n=36)$and sighted ones$(n=36)$, react to aural telephone scam warnings in naturalistic settings. As spoofing a CallerID is trivial, communicating the context of an incoming call instead offers a better possibility to warn a receiver about a potential scam. Usually, such warnings are visual in nature and fail to cater to users with visual disabilities. To address this exclusion, we developed an aural variant of telephone scam warnings and tested them in three conditions: baseline (no warning), short warning, and contextual warning that preceded the scam's content. We tested the two most common scam scenarios: fraud (interest rate reduction) and identity theft (social security number) by coldcalling participants and recording their actions, and debriefing and obtaining consent afterward. Only two participants “pressed one” as the scam demanded, both from the legally blind group that heard the contextual warning for the social security scenario. Upon close inspection, we learned that one of them did so because of accessibility issues with their screen reader and the other did so intentionally because the warning convinced them to waste the scammer's time, so they don't scam vulnerable people. Both the legally blind and sighted participants found the contextual warnings as powerful usable security cues that, together with STIR/SHAKEN indicators like Scam Likely, would provide robust protection against any type of scam. We also discussed the potential privacy implications of the contextual warnings and collected recommendations for usably accessible implementation. Filipo Sharevski, Jennifer Vander Loop, Bill Evans, Alexander Ponticello |
SP | 4 |
| 2024 | In Focus, Out of Privacy: The Wearer's Perspective on the Privacy Dilemma of Camera GlassesabstractThe rising popularity of camera glasses challenges societal norms of recording bystanders and thus requires efforts to mediate privacy preferences. We present the first study on the wearers’ perspectives and explore privacy challenges associated with wearing camera glasses when bystanders are present. We conducted a micro-longitudinal diary study (N = 15) followed by exit interviews with existing users and people without prior experience. Our results show that wearers consider the currently available privacy indicators ineffective. They believe the looks and interaction design of the glasses conceal the technology from unaware people. Due to the lack of effective privacy-mediating measures, wearers feel emotionally burdened with preserving bystanders’ privacy. We furthermore elicit how this sentiment impacts their usage of camera glasses and highlight the need for technical and non-technical solutions. Finally, we compare the wearers’ and bystanders’ perspectives and discuss the design space of a future privacy-preserving ecosystem for wearable cameras. Divyanshu Bhardwaj 0001, Alexander Ponticello, Shreya Tomar, Adrian Dabrowski, Katharina Krombholz |
CHI | 2 |
| 2024 | Let me quickly share it - Time Pressure when Sharing on Social Media
Rebecca Panskus, Tangila Islam Tanni, Alexander Ponticello, Echo Meißner, Yan Solihin, Katharina Krombholz, Karola Marky |
MUM | 3 |
| 2023 | Different Researchers, Different Results? Analyzing the Influence of Researcher Experience and Data Type During Qualitative Analysis of an Interview and Survey Study on Security AdviceabstractWhen conducting qualitative research it is necessary to decide how many researchers should be involved in coding the data: Is one enough or are more coders beneficial? To offer empirical evidence for this question, we designed a series of studies investigating qualitative coding. We replicated and extended a usable security and privacy study by Ion et al. to gather both simple survey data and complex interview data. We had a total of 65 students and seven researchers analyze different parts of this data. We analyzed the codebook creation process, similarity of outcomes, inter-rater reliability, and compared the student to the researcher outcomes. We also surveyed five years of SOUPS-PC members about their views on coding. The reviewers view on coding practices for complex and simple data are almost identical. However, our results suggest that the coding process can be different for the two types of data, with complex data benefiting more from interaction between coders. Anna-Marie Ortloff, Matthias Fassl, Alexander Ponticello, Florin Martius, Anne Mertens, Katharina Krombholz, Matthew Smith 0001 |
CHI | 3 |
| 2023 | Investigating Verification Behavior and Perceptions of Visual Digital Certificates
Dañiel Gerhardt, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 2 |
| 2023 | Investigating Security Folklore: A Case Study on the Tor over VPN PhenomenonabstractUsers face security folklore in their daily lives in the form of security advice, myths, and word-of-mouth stories. Using a VPN to access the Tor network, i.e., Tor over VPN, is an interesting example of security folklore because of its inconclusive security benefits and its occurrence in pop-culture media. Following the Theory of Reasoned Action, we investigated the phenomenon with three studies: (1) we quantified the behavior on real-world Tor traffic and measured a prevalence of 6.23%; (2) we surveyed users' intentions and beliefs, discovering that they try to protect themselves from the Tor network or increase their general security; and (3) we analyzed online information sources, suggesting that perceived norms and ease-of-use play a significant role while behavioral beliefs about the purpose and effect are less crucial in spreading security folklore. We discuss how to communicate security advice effectively and combat security misinformation and misconceptions. Matthias Fassl, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
Proc. ACM Hum. Comput. Interact. | 2 |