Sena Sahin

dblp:306/1347 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2025
0009-0009-1090-2044ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021
YearPublicationVenuePosition
2025 The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power Sector
abstract
In various industries, cybersecurity regulations have been enacted in an effort to drive improvements to organizational security postures. Despite the prominent influence of these regulations, there has been limited prior investigation of how organizations engage with these regulations and the challenges that they face. Assessing these factors is vital for understanding the impact of cybersecurity regulations in practice and how to enhance them moving forward.
Sena Sahin, Burak Sahin, Robin Berthier, Katherine R. Davis 0001, Saman A. Zonouz, Frank Li 0001
CCS1
2025 Was This You? Investigating the Design Considerations for Suspicious Login Notifications
Sena Sahin, Burak Sahin, Frank Li 0001
NDSS1
2024 Unmasking the Security and Usability of Password Masking
abstract
Password masking, a practice where passwords are obscured during entry, is widely adopted for online authentication. However, its merits have been debated for over a decade, with questions about its security benefits and concerns about its usability impact. Yet to date, masking has received limited prior exploration.
Suood Alroomi, Sena Sahin, Frank Li 0001
CCS3
2023 Investigating the Password Policy Practices of Website Administrators
abstract
Passwords are the de facto standard for online authentication today, and will likely remain so for the foreseeable future. As a consequence, the security community has extensively explored how users behave with passwords, producing recommendations for password policies that promote password security and usability for users. However, it is the website administrators who must adopt such recommendations to enact improvements to online authentication in practice. To date, there has been limited investigation of how web administrators manage password policies for their sites. To improve online authentication at scale, we must understand the factors behind this specific population’s behaviors and decisions, and how to help administrators deploy more secure password policies.In this paper, we explore how web administrators determine the password policies that they employ, what considerations impact a policy’s evolution, and what challenges administrators encounter when managing a site’s policy. To do so, we conduct an online survey and in-depth semi-structured interviews with 11 US-based web administrators with direct experience managing website password policies. Through our qualitative study, we identify a small set of key factors driving the majority of password policy decisions, and barriers that inhibit administrators from enacting policies that are more aligned with modern guidelines. Moving forward, we propose directions for future research and community action that may help administrators manage password policies more effectively.
Sena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank Li 0001
SP1
2021 Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password Authentication
abstract
To enhance the usability of password authentication, typo-tolerant password authentication schemes permit certain deviations in the user-supplied password, to account for common typographical errors yet still allow the user to successfully log in. In prior work, analysis by Chatterjee et al. demonstrated that typo-tolerance indeed notably improves password usability, yet (surprisingly) does not appear to significantly degrade authentication security. In practice, major web services such as Facebook have employed typo-tolerant password authentication systems. In this paper, we revisit the security impact of typo-tolerant password authentication. We observe that the existing security analysis of such systems considers only password spraying attacks. However, this threat model is incomplete, as password authentication systems must also contend with credential stuffing and tweaking attacks. Factoring in these missing attack vectors, we empirically re-evaluate the security impact of password typo-tolerance using password leak datasets, discovering a significantly larger degradation in security. To mitigate this issue, we explore machine learning classifiers that predict when a password's security is likely affected by typo-tolerance. Our resulting models offer various suitable operating points on the functionality-security tradeoff spectrum, ultimately allowing for partial deployment of typo-tolerant password authentication, preserving its functionality for many users while reducing the security risks.
Sena Sahin, Frank Li 0001
CCS1