VLDB 2026 Research / reviewers in the wild / expert
Michael Schilling 0001
dblp:40/1587
· DBLP profile ↗
8ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0003-2338-5866ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The (Un)usual Suspects - Studying Reasons for Lacking Updates in WordPress
Maria Hellenthal, Lena Gotsche, Rafael Mrowczynski, Sarah Kugel, Michael Schilling 0001, Ben Stock |
NDSS | 5 |
| 2024 | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityabstractThis paper assesses the effects of Stack Overflow code snippet evolution on the security of open-source projects. Users on Stack Overflow actively revise posted code snippets, sometimes addressing bugs and vulnerabilities. Accordingly, developers that reuse code from Stack Overflow should treat it like any other evolving code dependency and be vigilant about updates. It is unclear whether developers are doing so, to what extent outdated code snippets from Stack Overflow are present in GitHub projects, and whether developers miss security-relevant updates to reused snippets.To shed light on those questions, we devised a method to 1) detect outdated code snippets versions from 1.5M Stack Overflow snippets in 11,479 popular GitHub projects and 2) detect security-relevant updates to those Stack Overflow code snippets not reflected in those GitHub projects. Our results show that developers did not update dependent code snippets when those evolved on Stack Overflow. We found that 2,405 code snippet versions reused in 2,109 GitHub projects were outdated, with 43 projects missing fixes to bugs and vulnerabilities on Stack Overflow. Those 43 projects containing outdated, insecure snippets were forked on average 1,085 times (max. 16,121), indicating that our results are likely a lower bound for affected code bases. An important insight from our work is that treating Stack Overflow code as purely static code impedes holistic solutions to the problem of copying insecure code from Stack Overflow. Instead, our results suggest that developers need tools that continuously monitor Stack Overflow for security warnings and code fixes for reused code snippets and not only warn during copy-pasting. Alfusainey Jallow, Michael Schilling 0001, Michael Backes 0001, Sven Bugiel |
SP | 2 |
| 2024 | Towards Privacy and Security in Private Clouds: A Representative Survey on the Prevalence of Private Hosting and Administrator Characteristics
Lea Gröber, Simon Lenau, Rebecca Weil, Elena Groben, Michael Schilling 0001, Katharina Krombholz |
USENIX Security Symposium | 5 |
| 2023 | Poster: From Hashes to Ashes - A Comparison of Transcription ServicesabstractIn recent years, semi-structured interviews gained more and more importance in cyber security research. Transcribing audio recordings of such interviews is a crucial step in qualitative data analysis, but it is also a work-intensive and time-consuming task. While outsourcing presents a common option, maintaining research quality requires precise transcriptions -- a task further compounded by technical jargon and established expressions in the research field. In this study, we compare different transcription services and evaluate their outcome quality within the context of cyber security. Our findings provide insights for researchers navigating the complex landscape of transcription services, offering informed choices to enhance the accuracy and validity of qualitative data analysis. Rudolf Siegel, Rafael Mrowczynski, Maria Hellenthal, Michael Schilling 0001 |
CCS | 4 |
| 2021 | Measuring User Perception for Detecting Unexpected Access to Sensitive Resource in Mobile AppsabstractUnderstanding users' perception of app behaviors is an important step to detect data access that violates user expectations. While existing works have used various proxies to infer user expectations (e.g., by analyzing app descriptions), how real-world users perceive an app's data access when they interact with graphical user interfaces (UI) has not been fully explored. Trung Tin Nguyen, Duc Cuong Nguyen 0001, Michael Schilling 0001, Gang Wang 0011, Michael Backes 0001 |
AsiaCCS | 3 |
| 2021 | Explanation Beats Context: The Effect of Timing & Rationales on Users' Runtime Permission Decisions
Yusra Elbitar, Michael Schilling 0001, Trung Tin Nguyen, Michael Backes 0001, Sven Bugiel |
USENIX Security Symposium | 2 |
| 2020 | Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationabstractThe newest contender for succeeding passwords as the incumbent web authentication scheme is the FIDO2 standard. Jointly developed and backed by the FIDO Alliance and the W3C, FIDO2 has found support in virtually every browser, finds increasing support by service providers, and has adoptions beyond browser-software on its way. While it supports MFA and 2FA, its single-factor, passwordless authentication with security tokens has received the bulk of attention and was hailed by its supporters and the media as the solution that will replace text-passwords on the web. Despite its obvious security and deployability benefits—a setting that no prior solution had in this strong combination—the paradigm shift from a familiar knowledge factor to purely a possession factor raises questions about the acceptance of passwordless authentication by end-users.This paper presents the first large-scale lab study of FIDO2 single-factor authentication to collect insights about end-users’ perception, acceptance, and concerns about passwordless authentication. Through hands-on tasks our participants gather first-hand experience with passwordless authentication using a security key, which they afterwards reflect on in a survey. Our results show that users are willing to accept a direct replacement of text-based passwords with a security key for single-factor authentication. That is an encouraging result in the quest to replace passwords. But, our results also identify new concerns that can potentially hinder the widespread adoption of FIDO2 passwordless authentication. In order to mitigate these factors, we derive concrete recommendations to try to help in the ongoing proliferation of passwordless authentication on the web. Sanam Ghorbani Lyastani, Michael Schilling 0001, Michaela Neumayr, Michael Backes 0001, Sven Bugiel |
SP | 2 |
| 2018 | Better managed than memorized? Studying the Impact of Managers on Password Strength and Reuse
Sanam Ghorbani Lyastani, Michael Schilling 0001, Sascha Fahl, Michael Backes 0001, Sven Bugiel |
USENIX Security Symposium | 2 |