VLDB 2026 Research / reviewers in the wild / expert
Philip Klostermeyer
dblp:322/5233
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0002-8829-6074ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsabstractCryptographic libraries are a vital security component of software systems, yet their misuse has caused several incidents. Prior work has established that misuse of cryptographic libraries is common, and developers struggle to use their APIs correctly. However, it is currently unknown how the design and implementation decisions that shape cryptographic library APIs are made. To investigate these decisions and associated challenges in the design and implementation process of cryptographic library APIs, we conducted 21 semi-structured interviews with experienced developers of cryptographic libraries and used thematic analysis to identify overarching topics and challenges they encountered. We find that design decisions span a spectrum of abstraction levels and are heavily influenced by cryptographic standards, other libraries, legacy code, and developers' intuitions. Developers are challenged by the optimal level of abstraction for cryptographic APIs to balance security, usability, and flexibility. They lack systematic knowledge on defining usability and achieving such balance. Consequently, developers rely on usability self-tests, personal experiences, and opinions. Based on our findings, we make detailed recommendations to tailor future research toward better empirically validated support of cryptographic library API design and implementation decisions. Further, we advocate for integrating research-based usability guidance into cryptographic standardization to foster community discussion early on and better support secure, usable, and flexible cryptographic library APIs. Juliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha Fahl |
SP | 2 |
| 2025 | Towards Secure and Usable XR Authentication Schemes for Head-Mounted Displays: A Co-Creation Study with ExpertsabstractHead-mounted displays (HMDs) are increasingly integrated into users’ daily lives to provide immersive extended reality (XR) interactions. However, authentication on HMDs can disrupt this immersion because unsuitable 2D methods (e.g., passwords or PINs) are used, or HMDs are not secured at all. This paper presents in-depth results of seven co-creation workshops with 24 security and HCI experts to develop novel authentication concepts specifically tailored for HMDs. First, we collected 123 authentication concept ideas. Second, we extracted critical properties to propose overall design requirements for secure and usable interactions (e.g., user awareness, discreetness, and re-purposing of body parts), and security (e.g., resilience to virtual observation) in HMD authentication. We conclude the paper by discussing how schemes can be tailored to the users’ circumstances and options to ease the tension between security, usability, and privacy in HMD authentication. Reyhan Duezguen, Philip Klostermeyer, Lena Swienty, Sascha Fahl, Karola Marky |
VRST | 2 |
| 2024 | Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game DevelopmentabstractThe video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Philip Klostermeyer, Sabrina Klivan, Sandra Höltervennhoff, Alexander Krause 0002, Niklas Busch, Sascha Fahl |
CCS | 1 |
| 2023 | "I wouldn't want my unsafe code to run my pacemaker": An Interview Study on the Use, Comprehension, and Perceived Risks of Unsafe Rust
Sandra Höltervennhoff, Philip Klostermeyer, Noah Wöhler, Yasemin Acar, Sascha Fahl |
USENIX Security Symposium | 2 |