Annalina Buckmann

dblp:313/4504 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0002-7959-9743ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Noise and Stress Don't Help With Learning: A Qualitative Study to Inform Design of Effective Cybersecurity Awareness in Manufacturing Environments
abstract
With Industry 4.0, cybersecurity risks in manufacturing contexts are increasing rapidly. Since mandatory cybersecurity awareness programs (CAP) are considered best practice, companies looking at adapting training for this group, and allowed us to conduct a study. We conducted semi-structured interviews with n=33 manufacturing workers in 6 locations, to determine what they knew about cybersecurity risks, to what extent they consider them relevant, and what their experiences with, and perceptions of cybersecurity measures and training were. The interviews were analyzed using qualitative content analysis. Most of our participants reported only occasional interaction with what they consider ''office'' information and communication technology (ICT) in the context of their daily work. For most, the only touchpoints were HR-related transactions (pay and vacation), conducted via shared digital shopfloor kiosk PCs, through which they also received corporate communications. Most participants did not consider cybersecurity their responsibility, associating it with ''office'' and ''management'' roles. Most ICT and cybersecurity as potential threats to ''smooth running'' of work processes and their productivity. At the same time, there was positive perception of safety measures and training, with a clear preference for face-to-face team-based training in situ, so they could ask questions and point out possible issues - very different from the company's idea of individual computer-based trained, which most would receive via shared kiosk PCs on a noisy shop floor. Our results suggest that successful CAP needs to tailor content not only according to relevant risks, but relating those to key values and work practices, and consider different ways of delivering it.
Lina Brunken, Markus Schöps, Annalina Buckmann, Florian Meißner, M. Angela Sasse
CCS3
2025 Bridging the Gap Between Usable Security Research and Open-Source Practice - Lessons From a Long-Term Engagement With VeraCrypt
Felix Reichmann, Annalina Buckmann, Konstantin Fischer, M. Angela Sasse, Alena Naiakshina
CHI2
2025 More than Usability: Differential Access to Digital Security and Privacy
Annalina Buckmann, Jan Magnus Nold, Yasemin Acar, Yixin Zou
SOUPS1
2025 "If You Want to Encrypt It Really, Really Hardcore...": User Perceptions of Key Transparency in WhatsApp
abstract
WhatsApp is the first popular chat app to roll out a real-world, large-scale implementation of key transparency. If implemented correctly, key transparency allows users to check whether they are currently victim of a Machine-in-the-Middle attack mounted by WhatsApp server operators. Through 16 in-depth semi-structured interviews with WhatsApp users in Germany, we investigate how people judge and perceive the security and privacy of chat apps, whether end-users perceive benefits from key transparency, and how this affects trust and usage. We find that our interview participants mostly know what end-to-end encryption is, but that they struggle to show an understanding of the nuanced threat models needed to grasp the point of key transparency. Seeing key transparency in action led to a slight increase in perceived security in some, while others dismissed it as an unconvincing UI sham that would not change their presumptions about WhatsApp and its companies' motives. Some participants even felt less secure after performing a key transparency check, which we attribute to certain misconceptions we uncovered during the interviews. We conclude that exposing end-users to key transparency, without an accompanying explanation, is unlikely to directly meaningfully enhance trust or perceived security, and can even lead to users feeling less secure in some cases. We underline that the real strength of KT lies in 1) what we call the "deterrence effect" and 2) the future possibility to better automate key transparency checks. Based on our results we offer recommendations for industry practitioners as well as for promising future work in academia.
Konstantin Fischer, Markus Keil, Annalina Buckmann, M. Angela Sasse
Proc. Priv. Enhancing Technol.3
2024 Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User Groups
abstract
This paper investigates the digital security experiences of four at-risk user groups in Germany, including older adults (70+), teenagers (14-17), people with migration backgrounds, and people with low formal education. Using computer-assisted telephone interviews, we sampled 250 participants per group, representative of region, gender, and partly age distributions. We examine their device usage, concerns, prior negative incidents, perceptions of potential attackers, and information sources. Our study provides the first quantitative and nationally representative insights into the digital security experiences of these four at-risk groups in Germany. Our findings show that participants with migration backgrounds used the most devices, sought more security information, and reported more experiences with cybercrime incidents than other groups. Older adults used the fewest devices and were least affected by cybercrimes. All groups relied on friends and family and online news as their primary sources of security information, with little concern about their social circles being potential attackers. We highlight the nuanced differences between the four at-risk groups and compare them to the broader German population when possible. We conclude by presenting recommendations for education, policy, and future research aimed at addressing the digital security needs of these at-risk user groups.
Franziska Herbert, Steffen Becker 0003, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Dürmuth, Yixin Zou, M. Angela Sasse
SP3
2023 "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing Campaigns
Lina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela Sasse
USENIX Security Symposium2