Ivan Flechais

dblp:57/3469 · DBLP profile ↗
← Back
29ranked-venue papers
4as first author
10since 2021 · last 2025
0000-0002-3620-0843ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 12 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 4
YearPublicationVenuePosition
2025 Smart Spaces, Private Lives: A Culturally Grounded Examination of Privacy Tensions in Smart Homes
Yara Alsiyat, Yuanhaur Chang, Ning Zhang 0017, Ivan Flechais
SOUPS4
2024 Co-Designing a Mobile App for Bystander Privacy Protection in Jordanian Smart Homes: A Step Towards Addressing a Complex Privacy Landscape
Wael S. Albayaydh, Ivan Flechais
USENIX Security Symposium2
2024 Useful shortcuts: Using design heuristics for consent and permission in smart home devices
abstract
Prior research in smart home privacy highlights significant issues with how users understand, permit, and consent to data use. Some of the underlying issues point to unclear data protection regulations, lack of design principles, and dark patterns. In this paper, we explore heuristics (also called “mental shortcuts” or “rules of thumb”) as a means to address security and privacy design challenges in smart homes. First, we systematically analyze an existing body of data on smart homes to derive a set of heuristics for the design of consent and permission. Second, we apply these heuristics in four participatory co-design workshops (n = 14) and report on their use. Third, we analyze the use of the heuristics through thematic analysis highlighting heuristic application, purpose, and effectiveness in successful and unsuccessful design outcomes. We conclude with a discussion of the wider challenges, opportunities, and future work for improving design practices for consent in smart homes.
George Chalhoub, Martin J. Kraemer, Ivan Flechais
Int. J. Hum. Comput. Stud.3
2024 "Innovative Technologies or Invasive Technologies?": Exploring Design Challenges of Privacy Protection With Smart Home in Jordan
abstract
The growing adoption of smart devices has fuelled privacy concerns, and prior research has highlighted the privacy of bystanders: individuals who are subjected to the smart device use of others. Most of this research has focused on households in Western contexts (i.e., Europe and North America), but few studies have explored the design challenges of protecting bystanders, and even fewer have explored these in Muslim Arab Middle Eastern settings, such as Jordan. We conduct 44 interviews with users (i.e., families, domestic workers), local and international business leaders, and smart device designers to explore design challenges for privacy protection in the Jordanian context. Our analysis highlights the importance of considering contextual influences and power dynamics, localization and design guidelines, innovative technologies, awareness to design, and regulation. This paper concludes with recommendations for technical, social, business, and legal interventions to improve data protection design of smart devices in Jordan.
Wael S. Albayaydh, Ivan Flechais
Proc. ACM Hum. Comput. Interact.2
2023 Practical Cybersecurity Ethics: Mapping CyBOK to Ethical Concerns
abstract
Research into the ethics of cybersecurity is an established and growing topic of investigation, however the translation of this research into practice is lacking: there exists a small number of professional codes of ethics or codes of practice in cybersecurity, e.g. the ISSA or the UK Cyber Security Council’s code of ethics, however these are very broad and do not offer much insight into the ethical dilemmas that can be faced while performing specific cybersecurity activities. In order to address this gap, we leverage ongoing work on the Cyber Security Body of Knowledge (CyBOK) to help elicit and document the responsibilities and ethics of the profession.
Ivan Flechais, George Chalhoub
NSPW1
2023 Examining Power Dynamics and User Privacy in Smart Technology Use Among Jordanian Households
Wael S. Albayaydh, Ivan Flechais
USENIX Security Symposium2
2023 "It becomes more of an abstract idea, this privacy" - Informing the design for communal privacy experiences in smart homes
abstract
In spite of research recognizing the home as a shared space and privacy as inherently social, privacy in smart homes has mainly been researched from an individual angle. Sometimes contrasting and comparing perspectives of multiple individuals, research has rarely focused on how household members might use devices communally to achieve common privacy goals. An investigation of communal use of smart home devices and its relationship with privacy in the home is lacking. The paper presents a grounded analysis based on a synergistic relationship between an ethnomethodologically-informed (EM-informed) study and a grounded theory (GT) approach. The study focuses on household members’ interactions to show that household members’ ability to coordinate the everyday use of their devices depends on appropriate conceptualizations of roles, rules, and privacy that are fundamentally different from those embodied by off-the-shelf products. Privacy is rarely an explicit, actionable, and practical consideration among household members, but rather a consideration wrapped up in everyday concerns. Roles and rules are not used to create social order, but to account for it. To sensitize to this everyday perspective and to reconcile privacy as wrapped up in everyday concerns with the design of smart home systems, the paper presents the social organization of communal use as a descriptive framework. The framework is descriptive in capturing how households navigate the ‘murky waters’ of communal use in practice, where prior research highlighted seemingly irreconcilable differences in interest, attitude, and aptitude between multiple individuals and with other stakeholders. Discussing how households’ use of roles, rules, and privacy in-practice differed from what off-the-shelf products afforded, the framework highlights critical challenges and opportunities for the design of communal privacy experiences.
Martin J. Kraemer, George Chalhoub, Helena Webb, Ivan Flechais
Int. J. Hum. Comput. Stud.4
2022 Exploring Bystanders' Privacy Concerns with Smart Homes in Jordan
abstract
Smart homes continue to raise concerns about privacy and encroachment of businesses into intimate spaces. Prior research has focused on families and device owners in western contexts (Europe and North America), and has identified the importance of bystanders: individuals who are subjected to smart device use of others. Given the cultural and contextual aspects of accommodating bystanders, we identify a gap where bystanders in non-western societies have been insufficiently researched. To address this we conduct 20 interviews with domestic workers and household employers in Jordan, exploring privacy attitudes and practices. Our analysis uncovers a complex interplay between religious and social norms; legal and regulatory perspectives on privacy; and tensions between households and their domestic workers. We explore issues arising from smart homes coexisting as a residence and workplace, and highlight how workplace protections are ill-suited. We structure our findings to help inform public awareness, policy makers, manufacturers, and future research.
Wael S. Albayaydh, Ivan Flechais
CHI2
2022 Data Protection at a Discount: Investigating the UX of Data Protection from User, Designer, and Business Leader Perspectives
abstract
Smart homes are dangerous - a sentiment arising from prior research exploring the user experience (UX) of data protection for smart home devices. While this research has explored data protection shortcomings for users, UX is a designed encounter reconciling development, economic, compliance and strategic business priorities. And so, in addition to studying user perspectives, there is a gap in understanding how designers and business leaders influence the UX of data protection. To address this gap, we study smart home users, designers and business leaders, exploring how they experience data protection interactions, regulation, and processes. Our findings confirm that users have poor data protection interactions (e.g., consent and data access requests). We also find that business leaders and designers experience difficulties in identifying, applying, and tailoring suitable processes and practices for data protection for which some have developed "discount data protection": shortcuts, heuristics, and common sense practices to overcome these challenges.
George Chalhoub, Ivan Flechais
Proc. ACM Hum. Comput. Interact.2
2021 "It did not give me an option to decline": A Longitudinal Analysis of the User Experience of Security and Privacy in Smart Home Products
abstract
Smart home products aren’t living up to their promise. They claim to transform the way we live, providing convenience, energy efficiency, and safety. However, the reality is significantly less profound and often frustrating. This is particularly apparent in security and privacy experiences: powerlessness, confusion, and annoyance have all been reported.
George Chalhoub, Martin J. Kraemer, Norbert Nthala, Ivan Flechais
CHI4
2016 Finding and resolving security misusability with misusability cases
abstract
Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems.
Shamal Faily, Ivan Flechais
Requir. Eng.2
2015 Experiences in Developing and Delivering a Programme of Part-Time Education in Software and Systems Security
abstract
We report upon our experiences in developing and delivering a programme of part-time education in Software and Systems Security at the University of Oxford. The MSc in Software and Systems Security is delivered as part of the Software Engineering Programme at Oxford - a collection of one-week intensive courses aimed at individuals who are responsible for the procurement, development, deployment and maintenance of large-scale software-based systems. We expect that our experiences will be useful to those considering a similar journey.
Andrew C. Simpson, Andrew P. Martin, Cas Cremers, Ivan Flechais, Ivan Martinovic, Kasper Bonne Rasmussen
ICSE (2)4
2015 Security Practices for Households Bank Customers in the Kingdom of Saudi Arabia
Deena Alghamdi, Ivan Flechais, Marina Jirotka
SOUPS2
2012 On the Design and Development of webinos: A Distributed Mobile Application Middleware
John Lyle, Shamal Faily, Ivan Flechais, André Paul, Ayse Göker, Hans I. Myrhaug, Heiko Desruelle, Andrew P. Martin
DAIS3
2011 Here's Johnny: A Methodology for Developing Attacker Personas
abstract
The adversarial element is an intrinsic part of the design of secure systems, but our assumptions about attackers and threat is often limited or stereotypical. Although there has been previous work on applying User-Centered Design on Persona development to build personas for possible attackers, such work is only speculative and fails to build upon recent research. This paper presents an approach for developing Attacker Personas which is both grounded and validated by structured data about attackers. We describe a case study example where the personas were developed and used to support the development of a Context of Use description for the EU FP7 webinos project.
Andrea S. Atzeni, Cesare Cameroni, Shamal Faily, John Lyle, Ivan Flechais
ARES5
2011 User-Centered Information Security Policy Development in a Post-Stuxnet World
abstract
A balanced approach is needed for developing information security policies in Critical National Infrastructure (CNI) contexts. Requirements Engineering methods can facilitate such an approach, but these tend to focus on either security at the expense of usability, or vice-versa, it is also uncertain whether existing techniques are useful when the time available for applying them is limited. In this paper, we describe a case study where Usability and Requirements Engineering techniques were used to derive missing requirements for an information security policy for a UK water company following reports of the Stuxnet worm. We motivate and describe the approach taken while carrying out this case study, and conclude with three lessons informing future efforts to integrate Security, Usability, and Requirements Engineering techniques for secure system design.
Shamal Faily, Ivan Flechais
ARES2
2011 Persona cases: a technique for grounding personas
abstract
Personas are a popular technique in User-Centered Design, however their validity can be called into question. While the techniques used to developed personas and their integration with other design activities provide some measure of validity, a persona's legitimacy can be threatened by challenging its characteristics. This note presents Persona Cases: personas whose characteristics are both grounded in, and traceable to their originating source of empirical data. This approach builds on the premise that sense-making in qualitative data analysis is an argumentative activity, and aligns concepts associated with a Grounded Theory analysis with recent work on arguing the characteristics of personas. We illustrate this approach using a case study in the Critical Infrastructure Protection domain.
Shamal Faily, Ivan Flechais
CHI2
2011 Eliciting usable security requirements with misusability cases
abstract
Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. We present Mis-usability Cases: scenarios which describe how design decisions may lead to usability problems subsequently leading to system misuse. We describe the steps carried out to develop and apply misusability cases to elicit requirements and report preliminary results applying this technique in a recent case study.
Shamal Faily, Ivan Flechais
RE2
2010 Analysing and Visualising Security and Usability in IRIS
abstract
Despite a long standing need to incorporate human factors into security risk analysis, taking a balanced approach to analysing security and usability concerns remains a challenge. Balancing security and usability is difficult due to human biases in security perception, and managing the sheer volume of data arising from risk and task analysis. This paper presents an approach for qualitatively and quantitively analysing and visualising the results of risk and task analysis. We demonstrate this approach using a realistic example, and we discuss how these techniques fit within the larger context of secure systems design.
Shamal Faily, Ivan Flechais
ARES2
2010 Security and Usability: Analysis and Evaluation
abstract
The differences between the fields of Human-Computer Interaction and Security (HCISec) and Human-Computer Interaction (HCI) have not been investigated very closely. Many HCI methods and procedures have been adopted by HCISec researchers, however the extent to which these apply to the field of HCISec is arguable given the fine balance between improving the ease of use of a secure system and potentially weakening its security. That is to say that the techniques prevalent in HCI are aimed at improving users' effectiveness, efficiency or satisfaction, but they do not take into account the potential threats and vulnerabilities that they can introduce. To address this problem, we propose a security and usability threat model detailing the different factors that are pertinent to the security and usability of secure systems, together with a process for assessing these.
Ronald Kainda, Ivan Flechais, A. W. Roscoe 0001
ARES2
2010 To boldly go where invention isn't secure: applying security entrepreneurship to secure systems design
abstract
When designing secure systems, we are inundated with an eclectic mix of security and non-security requirements; this makes predicting a successful outcome from the universe of possible security design decisions a difficult problem. We propose augmenting the process of security design with the paradigm of Security Entrepreneurship: the application of innovation models and principles to organise, create, and manage security design elements to bring about improved system security. We propose three initial Security Entrepreneurship techniques as examples of this paradigm, describe how their underlying models align with secure systems design, and help predict the social and technical impact of possible design decisions. We also pose a number of thought experiments, and suggest possible research agendas for Security Entrepreneurship.
Shamal Faily, Ivan Flechais
NSPW2
2010 Two heads are better than one: security and usability of device associations in group scenarios
abstract
We analyse and evaluate the usability and security of the process of bootstrapping security among devices in group scenarios. While a lot of work has been done in single user scenarios, we are not aware of any that focusses on group situations. Unlike in single user scenarios, bootstrapping security in a group requires coordination, attention, and cooperation of all group members. In this paper, we provide an analysis of the security and usability of bootstrapping security in group scenarios and present the results of a usability study on these scenarios. We also highlight crucial factors necessary for designing for secure group interactions.
Ronald Kainda, Ivan Flechais, A. W. Roscoe 0001
SOUPS2
2010 Secure and Usable Out-Of-Band Channels for Ad Hoc Mobile Device Interactions
Ronald Kainda, Ivan Flechais, A. W. Roscoe 0001
WISTP2
2010 Designing and Aligning e-Science Security Culture with Design
abstract
Purpose The purpose of this paper is to identify the key cultural concepts effecting security in multi‐organisational systems and align these with design techniques and tools. Design/methodology/approach A grounded theory model of security culture was derived from the related security culture literature and empirical data from an e‐Science project. Influencing concepts were derived from these and aligned with recent work on techniques and tools for usable secure systems design. Findings Roles and responsibility, sub‐cultural norms and contexts, and different perceptions of requirements were found to be influencing concepts towards a culture of security. These concepts align with recent work on personas, environment models, and related tool support. Originality/value This paper contributes a theoretically and empirically grounded model of security culture. This is also the first paper explicitly aligning key concepts of security culture to design techniques and tools.
Shamal Faily, Ivan Flechais
Inf. Manag. Comput. Secur.2
2009 Context-Sensitive Requirements and Risk Management with IRIS
abstract
Many systems are not designed for their contexts of operation. Subtle changes to context may lead to an increase in severity and likelihood of vulnerabilities and threats. The IRIS framework integrates the notion of context into requirements and risk management, by means of an integrated meta-model, design method, and software prototype. By applying this framework, requirements and risk analysis can be better situated for system contexts of operation.
Shamal Faily, Ivan Flechais
RE2
2009 Usability and security of out-of-band channels in secure device pairing protocols
abstract
Initiating and bootstrapping secure, yet low-cost, ad-hoc transactions is an important challenge that needs to be overcome if the promise of mobile and pervasive computing is to be fulfilled. For example, mobile payment applications would benefit from the ability to pair devices securely without resorting to conventional mechanisms such as shared secrets, a Public Key Infrastructure (PKI), or trusted third parties. A number of methods have been proposed for doing this based on the use of a secondary out-of-band (OOB) channel that either authenticates information passed over the normal communication channel or otherwise establishes an authenticated shared secret which can be used for subsequent secure communication. A key element of the success of these methods is dependent on the performance and effectiveness of the OOB channel, which usually depends on people performing certain critical tasks correctly.
Ronald Kainda, Ivan Flechais, A. W. Roscoe 0001
SOUPS2
2009 Stakeholder involvement, motivation, responsibility, communication: How to design usable security in e-Science
Ivan Flechais, M. Angela Sasse
Int. J. Hum. Comput. Stud.1
2005 Divide and conquer: the role of trust and assurance in the design of secure socio-technical systems
abstract
In order to be effective, secure systems need to be both correct (i.e. effective used as intended) and dependable (i.e. actually being used as intended). Given that most secure systems involve people, a strategy for achieving dependable security must address both people and technology. Current research in Human-Computer Interactions in Security (HCISec) aims to increase dependability of the human element by reducing mistakes (e.g. through better user interfaces to security tools). We argue that a successful strategy also needs to consider the impact of social interaction on security, and in this respect is a central concept. We compare the understanding of in secure systems with the more differentiated models of in social science research. The security definition of turns out to map onto strategies that would be correctly described as in the more differentiated model. We argue that distinguishing between and assurance yields a wider range of strategies for ensuring dependability of the human element in a secure socio-technical system. Furthermore, correctly placed can also benefit an organisation's culture and performance. We conclude by presenting design principles to help security designers decide when to trust and when to assure, and give examples of how both strategies would be implemented in practice.
Ivan Flechais, Jens Riegelsberger, M. Angela Sasse
NSPW1
2003 Bringing security home: a process for developing secure and usable systems
abstract
The aim of this paper is to provide better support for the development of secure systems. We argue that current development practice suffers from two key problems:1. Security requirements tend to be kept separate from other system requirements, and not integrated into any overall strategy.2. The impact of security measures on users and the operational cost of these measures on a day-to-day basis are usually not considered.Our new paradigm is the full integration of security and usability concerns into the software development process, thus enabling developers to build secure systems that work in the real world. We present AEGIS, a secure software engineering method which integrates asset identification, risk and threat analysis and context of use, bound together through the use of UML, and report its application to case studies on Grid projects. An additional benefit of the method is that the involvement of stakeholders in the high-level security analysis improves their understanding of security, and increases their motivation to comply with policies.
Ivan Flechais, M. Angela Sasse, Stephen Hailes
NSPW1