VLDB 2026 Research / reviewers in the wild / expert
M. Angela Sasse
dblp:s/MASasse · also Martina Angela Sasse
· DBLP profile ↗
79ranked-venue papers
3as first author
19since 2021 · last 2026
0000-0003-1823-5505ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 1 first-author · 14 since 2021Human-computer interaction and ubiquitous computing · 28 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 11Computer networks · 4Software engineering, systems software and programming languages · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Certified AI System = Trustworthy? Exploring Expert and Lay User Perceptions and Needs Regarding AI Certification
Sarah Abdelwahab Gaballah, Nur Efsan Cetinkaya, Magdalena Wischnewski, M. Angela Sasse |
CHI | 4 |
| 2025 | Noise and Stress Don't Help With Learning: A Qualitative Study to Inform Design of Effective Cybersecurity Awareness in Manufacturing EnvironmentsabstractWith Industry 4.0, cybersecurity risks in manufacturing contexts are increasing rapidly. Since mandatory cybersecurity awareness programs (CAP) are considered best practice, companies looking at adapting training for this group, and allowed us to conduct a study. We conducted semi-structured interviews with n=33 manufacturing workers in 6 locations, to determine what they knew about cybersecurity risks, to what extent they consider them relevant, and what their experiences with, and perceptions of cybersecurity measures and training were. The interviews were analyzed using qualitative content analysis. Most of our participants reported only occasional interaction with what they consider ''office'' information and communication technology (ICT) in the context of their daily work. For most, the only touchpoints were HR-related transactions (pay and vacation), conducted via shared digital shopfloor kiosk PCs, through which they also received corporate communications. Most participants did not consider cybersecurity their responsibility, associating it with ''office'' and ''management'' roles. Most ICT and cybersecurity as potential threats to ''smooth running'' of work processes and their productivity. At the same time, there was positive perception of safety measures and training, with a clear preference for face-to-face team-based training in situ, so they could ask questions and point out possible issues - very different from the company's idea of individual computer-based trained, which most would receive via shared kiosk PCs on a noisy shop floor. Our results suggest that successful CAP needs to tailor content not only according to relevant risks, but relating those to key values and work practices, and consider different ways of delivering it. Lina Brunken, Markus Schöps, Annalina Buckmann, Florian Meißner, M. Angela Sasse |
CCS | 5 |
| 2025 | Bridging the Gap Between Usable Security Research and Open-Source Practice - Lessons From a Long-Term Engagement With VeraCrypt
Felix Reichmann, Annalina Buckmann, Konstantin Fischer, M. Angela Sasse, Alena Naiakshina |
CHI | 4 |
| 2025 | "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision Making
Jens Christian Opdenbusch, Jonas Hielscher, M. Angela Sasse |
NDSS | 3 |
| 2025 | A Platform for Physiological and Behavioral SecurityabstractHuman-centered security research traditionally leverages self-reports and high-level behavioral data. However, the increasing ubiquity of sensors integrated into personal, wearable devices (e.g., smartphones, smartwatches) and in users’ environments (e.g., cameras) enables researchers to unobtrusively collect rich physiological and behavioral signals. These real-time data streams can reveal user states—such as attention or workload—that can be employed to design adaptive security mechanisms. In this paper, we present a platform that supports designing, building, and evaluating next-generation user interfaces that leverage physiological and behavioral data for enhanced security. First, we introduce the physio-behavioral security paradigm, highlighting how sensor-based insights into user states can inform individualized security interventions and accurately identify moments of vulnerability. We then outline the requirements, system architecture, and implementation details of the platform, illustrating how multiple data streams (e.g., gaze, heart rate, keystrokes, mouse movements) are integrated and securely processed. Finally, we report on an exploratory deployment in a mid-sized organization, showcasing how the tool captures real-time security behaviors and enables context-aware interventions. The deployment yields insights into factors influencing acceptance across different stakeholders (management, IT department, employees). Our results suggest that adaptive approaches, informed by physiological and behavioral signals, can improve security outcomes and user acceptance. Felix Dietz, Peter Heubl, Luke Haliburton, David Bothe, Jan Hörnemann, M. Angela Sasse, Florian Alt |
NSPW | 6 |
| 2025 | "It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security Requirements
Houda Naji, Felix Reichmann, Tobias Bruns, M. Angela Sasse, Alena Naiakshina |
USENIX Security Symposium | 4 |
| 2025 | A taxonomy of functional security features and how they can be locatedabstractAbstract Security must be considered in almost every software system. Unfortunately, selecting and implementing security features remains a challenge due to the wide variety of security threats and possible countermeasures. While security standards are intended to help developers, they are usually too abstract and vague to help implementing security features, or they merely help configuring such. A resource that describes security features at an abstraction level that lies between high-level (i.e., rather too general) and low-level (i.e., rather too specific) security standards could facilitate secure systems development. This resource should support the selection of appropriate security features to achieve high-level security goals, allow easy retrieval of relevant low-level details, and provide pointers to suitable ways to realize the security features. To realize security features, developers typically use external security libraries or frameworks, to minimize implementation mistakes. Even when using libraries, developers still make mistakes when writing code to integrate them, often resulting in security vulnerabilities. When security incidents occur or the system needs to be audited or maintained, it is essential to know what security features have been implemented and, more importantly, where they are located. This task, commonly referred to as feature location, is often tedious and error-prone. While dedicated feature location techniques exist, they require significant manual effort or adherence to strict development processes, preventing their use. Therefore, we have to support long-term tracking of implemented security features. We present a study of security features presented in the literature and their coverage in popular security frameworks. We contribute (1) a taxonomy of 68 functional implementation-level security features including a mapping to widely used security standards, (2) an examination of 21 popular security frameworks concerning which of these security features they provide, and (3) a discussion on the representation of security features in source code. Our taxonomy aims to aid developers in selecting appropriate security features and security frameworks, as well as relating them to security standards when they need to choose and implement security features for a software system. Kevin Hermann, Simon Schneider, Catherine Tony, Asli Yardim, Sven Peldszus, Thorsten Berger, Riccardo Scandariato, M. Angela Sasse, Alena Naiakshina |
Empir. Softw. Eng. | 8 |
| 2025 | "If You Want to Encrypt It Really, Really Hardcore...": User Perceptions of Key Transparency in WhatsAppabstractWhatsApp is the first popular chat app to roll out a real-world, large-scale implementation of key transparency. If implemented correctly, key transparency allows users to check whether they are currently victim of a Machine-in-the-Middle attack mounted by WhatsApp server operators. Through 16 in-depth semi-structured interviews with WhatsApp users in Germany, we investigate how people judge and perceive the security and privacy of chat apps, whether end-users perceive benefits from key transparency, and how this affects trust and usage. We find that our interview participants mostly know what end-to-end encryption is, but that they struggle to show an understanding of the nuanced threat models needed to grasp the point of key transparency. Seeing key transparency in action led to a slight increase in perceived security in some, while others dismissed it as an unconvincing UI sham that would not change their presumptions about WhatsApp and its companies' motives. Some participants even felt less secure after performing a key transparency check, which we attribute to certain misconceptions we uncovered during the interviews. We conclude that exposing end-users to key transparency, without an accompanying explanation, is unlikely to directly meaningfully enhance trust or perceived security, and can even lead to users feeling less secure in some cases. We underline that the real strength of KT lies in 1) what we call the "deterrence effect" and 2) the future possibility to better automate key transparency checks. Based on our results we offer recommendations for industry practitioners as well as for promising future work in academia. Konstantin Fischer, Markus Keil, Annalina Buckmann, M. Angela Sasse |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Self-Efficacy and Security Behavior: Results from a Systematic Review of Research MethodsabstractAmidst growing IT security challenges, psychological underpinnings of security behaviors have received considerable interest, e.g. cybersecurity Self-Efficacy (SE), the belief in one’s own ability to enact cybersecurity-related skills. Due to diverging definitions and proposed mechanisms, research methods in this field vary considerably, potentially impeding replicable evidence and meaningful research synthesis. We report a preregistered systematic literature review investigating (a) cybersecurity SE measures, (b) SE’s proposed roles, and (c) intervention approaches. We minimized selection bias by detailed exclusion criteria, interdisciplinary search strategy, and double coding. Among 174 cybersecurity SE studies (2010-2021) from 18 databases with 55,758 subjects, we identified 173 different SE measures with considerable differences in psychometric quality and validity evidence. We found 276 variables as assumed causes/outcomes of cybersecurity SE and identified 13 intervention designs. This review demonstrates the extent of methodological and conceptual fragmentation in cybersecurity SE research. We offer recommendations to inspire our research community toward standardization. Nele Borgert, Luisa Jansen, Imke Böse, Jennifer Friedauer, M. Angela Sasse, Malte Elson |
CHI | 5 |
| 2024 | Digital Security - A Question of Perspective A Large-Scale Telephone Survey with Four At-Risk User GroupsabstractThis paper investigates the digital security experiences of four at-risk user groups in Germany, including older adults (70+), teenagers (14-17), people with migration backgrounds, and people with low formal education. Using computer-assisted telephone interviews, we sampled 250 participants per group, representative of region, gender, and partly age distributions. We examine their device usage, concerns, prior negative incidents, perceptions of potential attackers, and information sources. Our study provides the first quantitative and nationally representative insights into the digital security experiences of these four at-risk groups in Germany. Our findings show that participants with migration backgrounds used the most devices, sought more security information, and reported more experiences with cybercrime incidents than other groups. Older adults used the fewest devices and were least affected by cybercrimes. All groups relied on friends and family and online news as their primary sources of security information, with little concern about their social circles being potential attackers. We highlight the nuanced differences between the four at-risk groups and compare them to the broader German population when possible. We conclude by presenting recommendations for education, policy, and future research aimed at addressing the digital security needs of these at-risk user groups. Franziska Herbert, Steffen Becker 0003, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Dürmuth, Yixin Zou, M. Angela Sasse |
SP | 9 |
| 2024 | The Challenges of Bringing Cryptography from Research Papers to Products: Results from an Interview Study with Experts
Konstantin Fischer, Ivana Trummová, Phillip Gajland, Yasemin Acar, Sascha Fahl, M. Angela Sasse |
USENIX Security Symposium | 6 |
| 2024 | Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-Efficacy
Markus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela Sasse |
USENIX Security Symposium | 4 |
| 2023 | "Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure AuthenticationabstractUsable and secure authentication on the web and beyond is mission-critical. While password-based authentication is still widespread, users have trouble dealing with potentially hundreds of online accounts and their passwords. Alternatives or extensions such as multi-factor authentication have their own challenges and find only limited adoption. Finding the right balance between security and usability is challenging for developers. Previous work found that developers use online resources to inform security decisions when writing code. Similar to other areas, lots of authentication advice for developers is available online, including blog posts, discussions on Stack Overflow, research papers, or guidelines by institutions like OWASP or NIST. Jan H. Klemmer, Marco Gutfleisch, Christian Stransky, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
CCS | 5 |
| 2023 | A World Full of Privacy and Security (Mis)conceptions? Findings of a Representative Survey in 12 CountriesabstractMisconceptions about digital security and privacy topics in the general public frequently lead to insecure behavior. However, little is known about the prevalence and extent of such misconceptions in a global context. In this work, we present the results of the first large-scale survey of a global population on misconceptions: We conducted an online survey with n = 12, 351 participants in 12 countries on four continents. By investigating influencing factors of misconceptions around eight common security and privacy topics (including E2EE, Wi-Fi, VPN, and malware), we find the country of residence to be the strongest estimate for holding misconceptions. We also identify differences between non-Western and Western countries, demonstrating the need for region-specific research on user security knowledge, perceptions, and behavior. While we did not observe many outright misconceptions, we did identify a lack of understanding and uncertainty about several fundamental privacy and security topics. Franziska Herbert, Steffen Becker 0003, Leonie Schaewitz, Jonas Hielscher, Marvin Kowalewski, M. Angela Sasse, Yasemin Acar, Markus Dürmuth |
CHI | 6 |
| 2023 | Lacking the Tools and Support to Fix Friction: Results from an Interview Study with Security Managers
Jonas Hielscher, Markus Schöps, Uta Menges, Marco Gutfleisch, Mirko Helbling, M. Angela Sasse |
SOUPS | 6 |
| 2023 | "To Do This Properly, You Need More Resources": The Hidden Costs of Introducing Simulated Phishing Campaigns
Lina Brunken, Annalina Buckmann, Jonas Hielscher, M. Angela Sasse |
USENIX Security Symposium | 4 |
| 2023 | "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred Security
Jonas Hielscher, Uta Menges, Simon Edward Parkin, Annette Kluge, M. Angela Sasse |
USENIX Security Symposium | 5 |
| 2022 | How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyabstractFor software to be secure in practice, users need to be willing and able to appropriately use security features. These features are usually implemented by software professionals during the software development process (SDP), who may be unable to consider the usability of these mechanisms. While research has made progress in supporting developers in creating secure software products, very little attention has been paid to whether and how these security features are made usable. In a semi-structured interview study with 25 software professionals (software developers, designers, architects), we explored how they and other decision-makers encounter and deal with security and usability during the software development process in their companies. Based on 37 hours of interview recordings, we qualitatively analyzed and investigated 23 distinct development contexts in detail. In addition to individual awareness and factors that directly influence the implementation phase, we identify a high impact of contextual factors, such as stakeholder pressure, presence of expertise, and collaboration culture, and the specific implementation of the SDP on usable security in software products. We conclude our work by highlighting important gaps, such as studying and improving contextual factors that contribute to usable security and discussing potential improvements of the status quo. Marco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar, M. Angela Sasse, Sascha Fahl |
SP | 5 |
| 2021 | "Taking out the Trash": Why Security Behavior Change requires Intentional ForgettingabstractSecurity awareness is big business – virtually every organization in the Western world provides some form of awareness or training, mostly bought from external vendors. However, studies and industry reports show that these programs have little to no effect in terms of changing the security behavior of employees. We explain the conditions that enable behavior change, and identify one significant blocker in the implementation phase: not disabling existing (insecure) routines – failure to take out the trash – prevents embedding of new (secure) routines. Organizational Psychology offers the paradigm Intentional Forgetting (IF) and associated tools for replacing old (insecure) behaviors with new (secure) ones by identifying and eliminating different cues (sensoric, routine-based, time and space based as well as situational strength cues) that trigger old behavior. We introduce the underlying theory, examples of successful application in safety contexts, and show how its application leads to effective behavior change by reducing the information that needs to be transmitted to employees, and suppressing obsolete routines. Jonas Hielscher, Annette Kluge, Uta Menges, M. Angela Sasse |
NSPW | 4 |
| 2020 | Attributes Affecting User Decision to Adopt a Virtual Private Network (VPN) App
Nissy Sombatruang, Tan Omiya, Daisuke Miyamoto, M. Angela Sasse, Youki Kadobayashi, Michelle Baddeley |
ICICS | 4 |
| 2020 | Interventions for long-term software security: Creating a lightweight program of assurance techniques for developersabstractSummary Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and awareness of assurance techniques, changing its security culture even when no security experts are involved. The interventions were developed after an Appreciative Inquiry and Grounded Theory survey of security professionals to find out what approaches work best. We tested the interventions in a participatory action research field study where we delivered the workshops to three software development organizations and evaluated their effectiveness through interviews beforehand, immediately afterwards, and after twelve months. We found that the interventions can be effective with teams with limited or no security experience and that improvement is long‐lasting. This approach and the learning points arising from the work here have the potential to be applied in many development teams, improving the security of software worldwide. Charles Weir, Ingolf Becker, James Noble 0001, Lynne Blair, M. Angela Sasse, Awais Rashid |
Softw. Pract. Exp. | 5 |
| 2019 | Why Jenny can't figure out which of these messages is a covert information operationabstractWe view foreign interference in US and UK elections via social manipulation through the lens of usable security. Our goal is to provide advice on what interventions on the socio-technical election system are likely to work, and which are likely to fail. Strategies that the usable security literature indicates are likely to work are those that (1) avoid overloading the user's primary task; (2) help people understand negative consequences of their actions; and (3) support the long-term education of users with analytic reasoning skills and adequate background knowledge. Several of the responses to election interference proposed by governments and technology companies so far do not abide by these recommendations and are likely to be ineffective. Tristan Caulfield, Jonathan M. Spring, M. Angela Sasse |
NSPW | 3 |
| 2019 | Factors influencing users to use unsecured wi-fi networks: evidence in the wildabstractSecurity experts often question why some users take actions that could expose them to security and privacy risks. Using unsecured Wi-Fi networks is one common example. Even though mobile data is now a more secure means to connect to the Internet, and is becoming faster and more affordable, many users continue to use unsecured Wi-Fi. To identify risk mitigating strategies, the research community first needs to understand the underlying factors driving users' decisions. Previous studies examined stated preferences --- what people said they have done or think they would do --- but that may not truly reflect real-life behavior. This study is the first to examine revealed preferences --- what people actually do in naturalistic settings. Specifically, we investigated how users' desire to save mobile data and battery power influenced their decisions at the time when they connected to open unsecured Wi-Fi in the wild. We also examined whether the decision to use unsecured Wi-Fi networks could be driven by demographic factors and the user's perception of the risk associated with using these networks. We recruited 71 participants in the UK to install My Wi-Fi Choices, our own Android app, on their mobile device, and run it for three months in the background. The app captured details of mobile data allowance and battery power on participants' devices whenever they used open unsecured Wi-Fi networks. We found that depleting mobile data significantly drove participants to use these networks, especially when their remaining allowance reached approximately 30%. Battery level, however, did not play a significant role. The perceived risks of unsecured Wi-Fi did not affect the decision-making either. Age, education, and income level were also correlated with increased use of unsecured Wi-Fi. Nissy Sombatruang, Lucky Onwuzurike, M. Angela Sasse, Michelle Baddeley |
WiSec | 3 |
| 2018 | The continued risks of unsecured public Wi-Fi and why users keep using it: Evidence from JapanabstractMany people today use public Wi-Fi networks but they harbor security and privacy risks. We investigated the extent of these risk today, and what factors influenced users to use the networks, adapting the design of a previous UK study, this time in Japan. We first set up an experimental open public Wi-Fi network at ll locations in downtown Nara and captured Internet traffic. From approximately 7.7 million packets captured from 196 unique mobile devices during a 150-hour experiment, we found private photos, emails, documents, and login credentials being transmitted without encryption - showing that many people use unsecured public Wi-Fi networks, and many applications do not encrypt data they send. We then examined why people use public Wi-Fi in a range of scenarios through a survey with 103 participants. We found that the desire to conserve mobile data allowance was linked to a risk-taking attitude, and use of unsecured public Wi-Fi, especially among participants with a low monthly data allowance. Gender and education also played a role; female participants and those with high school education were more likely to use public Wi-Fi. Nissy Sombatruang, Youki Kadobayashi, M. Angela Sasse, Michelle Baddeley, Daisuke Miyamoto |
PST | 3 |
| 2018 | The Rewards and Costs of Stronger Passwords in a University: Linking Password Lifetime to Strength
Ingolf Becker, Simon Edward Parkin, M. Angela Sasse |
USENIX Security Symposium | 3 |
| 2018 | Studying users' adaptation to Android's run-time fine-grained access control system
Panagiotis Andriotis, Gianluca Stringhini, M. Angela Sasse |
J. Inf. Secur. Appl. | 3 |
| 2018 | Privacy Unraveling Around Explicit HIV Status Disclosure Fields in the Online Geosocial Hookup App GrindrabstractmHealth applications ("apps") must be searched for and downloaded prior to use, creating a potential barrier to uptake. Integrating health interventions into existing online social environments removes this barrier. However, little is known about the effects of linking sensitive health information to existing online identities. Our qualitative analysis of online comments (n=192) explores the user views of an HIV intervention integrated into the geosocial hookup app Grindr. We find some HIV positive users report keeping their status private to reduce their stigma exposure, whilst others report publicly disclosing their status to avoid being stigmatised by others. Where users keep their status private, we find concerns that social assumptions may develop around these non-disclosures, creating a privacy unraveling effect which restricts disclosure choice. Using Peppet's four proposed limits to privacy unraveling, we develop a set of descriptive conceptual designs to explore the privacy respecting potential of these limits within this context and propose further research to address this privacy challenge. Mark Warner, Andreas Gutmann, M. Angela Sasse, Ann Blandford |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2017 | Obstacles to the Adoption of Secure Communication ToolsabstractThe computer security community has advocated widespread adoption of secure communication tools to counter mass surveillance. Several popular personal communication tools (e.g., WhatsApp, iMessage) have adopted end-to-end encryption, and many new tools (e.g., Signal, Telegram) have been launched with security as a key selling point. However it remains unclear if users understand what protection these tools offer, and if they value that protection. In this study, we interviewed 60 participants about their experience with different communication tools and their perceptions of the tools' security properties. We found that the adoption of secure communication tools is hindered by fragmented user bases and incompatible tools. Furthermore, the vast majority of participants did not understand the essential concept of end-to-end encryption, limiting their motivation to adopt secure tools. We identified a number of incorrect mental models that underpinned participants' beliefs. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova, Alena Naiakshina, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | Look Before You Leap: Improving the Users' Ability to Detect Fraud in Electronic MarketplacesabstractReputation systems in current electronic marketplaces can easily be manipulated by malicious sellers in order to appear more reputable than appropriate. We conducted a controlled experiment with 40 UK and 41 German participants on their ability to detect malicious behavior by means of an eBay-like feedback profile versus a novel interface involving an interactive visualization of reputation data. The results show that participants using the new interface could better detect and understand malicious behavior in three out of four attacks (the overall detection accuracy 77% in the new vs. 56% in the old interface). Moreover, with the new interface, only 7% of the users decided to buy from the malicious seller (the options being to buy from one of the available sellers or to abstain from buying), as opposed to 30% in the old interface condition. Johannes Sänger, Norman Hänsch, Brian Glass, Zinaida Benenson, Robert Landwirth, M. Angela Sasse |
CHI | 6 |
| 2016 | Productive Security: A Scalable Methodology for Analysing Employee Security Behaviours
Adam Beautement, Ingolf Becker, Simon Edward Parkin, Kat Krol, M. Angela Sasse |
SOUPS | 5 |
| 2015 | POSTER: Secure Chat for the Masses? User-centered Security to the RescueabstractIn light of recent revelations of mass state surveillance of phone and Internet communications, many solutions now claim to provide secure messaging. This includes both a broad range of new projects and several widely adopted applications that have added security features. However, despite the demand for better solutions, there is no clear winner in the race for widespread development and deployment of messaging products. Recently, the Electronic Frontier Foundation evaluated dozens of messaging tools based on security best practices, and publicized the results via the Secure Messaging Scorecard. Our goal is to expand the scorecard by evaluating messaging tools on a range of usefulness (utility and usability) attributes. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Matthew Smith 0001 |
CCS | 2 |
| 2015 | Employee Rule Breakers, Excuse Makers and Security Champions: : Mapping the risk perceptions and emotions that drive security behaviorsabstractWe introduce a new methodology for identifying the factors that drive employee security behaviors in organizations, based on a well-known paradigm from psychology, the Johari Window. An analysis of 93 interviews with staff from 2 multinational organizations revealed that security behavior is driven by a combination of risk understanding and emotional stance towards security policy. Furthermore, we found that a quantitative analysis of these dimensions is capable of differentiating between the staff populations of the two organizations. Organization B showed a healthier set of security behaviors, as a result of its employees having better risk understanding and a more positive emotional stance. The framework distinguishes between 16 theoretical behavioral types, (3 of which are rule breakers, excuse makers and security champions). It can be used to identify groups of employees that potentially pose a risk to the organization, as well as those with beneficial skills and expertise. This allows highly specific messages to be targeted to change the risk perception and emotional stance of such groups. Assuming the organization has ensured security hygiene (i.e. its policies can be complied with in the context of productive activity), this can shift behavior towards compliance. Our framework thus offers diagnostic and intervention-shaping tools for the next step in improving security culture. Odette Beris, Adam Beautement, M. Angela Sasse |
NSPW | 3 |
| 2014 | Desperately seeking assurances: Segmenting users by their information-seeking preferencesabstractUsers of technology services try to evaluate the risks of disclosing personal information in light of the benefits they believe they will receive. However, because of cognitive, time or other constraints, users concentrate on minimizing the uncertainties of disclosure - reducing their level of privacy concern - by using a limited set of information cues. We suggest an individual's information-seeking behavior is focused on those cues which are important to them. Q methodology was used to determine if users of technology services can be segmented, based on the type of information cues they consider important - many of which are related to technology services' privacy behavior. The study consisted of 58 participants split into two cohorts, who rank-ordered 40 statements describing the attributes of a technology service. In our study, 69% of participants loaded significantly into only one of five groups: 1) Information Controllers; 2) Security Concerned; 3) Benefits Seekers; 4) Crowd Followers; and 5) Organizational Assurance Seekers. Only 12% of participants did not load significantly into any of the five groups. Our findings assist practitioners in understanding how their privacy behavior (e.g. repurposing information) and privacy-sensitive technology design (e.g. providing feedback and control mechanisms) could encourage or discourage the adoption of technology services by different types of users. We argue the user segmentation identified by this study can inform the construction of more holistic privacy personas. Anthony Morton, M. Angela Sasse |
PST | 2 |
| 2014 | Building a National E-Service using Sentire experience report on the use of Sentire: A volere-based requirements framework driven by calibrated personas and simulated user feedbackabstractUser experience (UX) is difficult to quantify and thus more challenging to require and guarantee. It is also difficult to gauge the potential impact on users' lived experience, especially at the earlier stages of the development life cycle, particularly before hi fidelity prototypes are developed. We believe that the enrolment process is a major hurdle for e-government service adoption and badly designed processes might result in negative repercussions for both the policy maker and the different user groups involved; non-adoption and resentment are two risks that may result in low return on investment (ROI), lost political goodwill and ultimately a negative lived experience for citizens. Identity assurance requirements need to balance out the real value of the assets being secured (risk) with the user groups' acceptance thresholds (based on a continuous cost-benefit exercise factoring in cognitive and physical workload). Sentire is a persona-centric requirements framework built on and extending the Volere requirements process with UX-analytics, reusable user behavioural models and simulated user feedback through calibrated personas. In this paper we present a story on how Sentire was adopted in the development of a national public-facing e-service. Daily journaling was used throughout the project and a custom built cloud-based CASE tool was used to manage the whole process. This paper outlines our experiences and lessons learnt. Chris Porter, Emmanuel Letier, M. Angela Sasse |
RE | 3 |
| 2013 | CISOs and organisational culture: Their own worst enemy?
Debi Ashenden, M. Angela Sasse |
Comput. Secur. | 2 |
| 2012 | Too close for comfort: a study of the effectiveness and acceptability of rich-media personalized advertisingabstractOnline display advertising is predicted to make $29.53 billion this year. Advertisers believe targeted and personalized ads to be more effective, but many users are concerned about their privacy. We conducted a study where 30 participants completed a simulated holiday booking task; each page showing ads with different degrees of personalization. Participants fixated twice as long when ads contained their photo. Participants reported being more likely to notice ads with their photo, holiday destination, and name, but also increasing levels of discomfort with increasing personalization. We conclude that greater personalization in ad content may achieve higher levels of attention, but that the most personalized ads are also the least acceptable. The noticeability benefit in using someone's photo to make them look at an ad may be offset by the privacy cost. As more personal data becomes available to advertisers, it becomes important that these trade-offs are considered. Miguel Malheiros, Charlene Jennett, Snehalee Patel, Sacha Brostoff, M. Angela Sasse |
CHI | 5 |
| 2012 | Don't work. Can't work? Why it's time to rethink security warningsabstractAs the number of Internet users has grown, so have the security threats that they face online. Security warnings are one key strategy for trying to warn users about those threats; but recently, it has been questioned whether they are effective. We conducted a study in which 120 participants brought their own laptops to a usability test of a new academic article summary tool. They encountered a PDF download warning for one of the papers. All participants noticed the warning, but 98 (81.7%) downloaded the PDF file that triggered it. There was no significant difference between responses to a brief generic warning, and a longer specific one. The participants who heeded the warning were overwhelmingly female, and either had previous experience with viruses or lower levels of computing skills. Our analysis of the reasons for ignoring warnings shows that participants have become desensitised by frequent exposure and false alarms, and think they can recognise security risks. At the same time, their answers revealed some misunderstandings about security threats: for instance, they rely on anti-virus software to protect them from a wide range of threats, and do not believe that PDF files can infect their machine with viruses. We conclude that security warnings in their current forms are largely ineffective, and will remain so, unless the number of false positives can be reduced. Kat Krol, Matthew Moroz, M. Angela Sasse |
CRiSIS | 3 |
| 2012 | Privacy is a process, not a PET: a theory for effective privacy practiceabstractPrivacy research has not helped practitioners -- who struggle to reconcile users' demands for information privacy with information security, legislation, information management and use -- to improve privacy practice. Beginning with the principle that information security is necessary but not sufficient for privacy, we present an innovative layered framework - the Privacy Security Trust (PST) Framework - which integrates, in one model, the different activities practitioners must undertake for effective privacy practice. The PST Framework considers information security, information management and data protection legislation as privacy hygiene factors, representing the minimum processes for effective privacy practice. The framework also includes privacy influencers - developed from previous research in information security culture, information ethics and information culture - and privacy by design principles. The framework helps to deliver good privacy practice by providing: 1) a clear hierarchy of the activities needed for effective privacy practice; 2) delineation of information security and privacy; and 3) justification for placing data protection at the heart of those activities involved in maintaining information privacy. We present a proof-of-concept application of the PST Framework to an example technology -- electricity smart meters. Anthony Morton, M. Angela Sasse |
NSPW | 2 |
| 2011 | Do you know dis?: a user study of a knowledge discovery tool for organizationsabstractOrganisations today have no reliable way of ensuring that all employees are aware of information that may be relevant to their work. In this paper we report on a 2-year project in which we have iteratively designed, developed and tested a knowledge discovery system (KnowDis) for organizations. Early stages of our study revealed that, employees do not know what is available on the corporate intranet, or files and messages they have stored. KnowDis proactively fetches relevant information and displays it in an unobtrusive form; this increases employee awareness without disrupting their tasks. We discuss and characterize knowledge workers' email usage behavior. Our main study with 28 users of KnowDis-enhanced email showed it can improve the user experience and performance on information retrieval tasks for knowledge workers. Sven Laqua, M. Angela Sasse, Steven Greenspan, Carrie Gates |
CHI | 2 |
| 2011 | Make mine a quadruple: Strengthening the security of graphical one-time PIN authenticationabstractSecure and reliable authentication is an essential prerequisite for many online systems, yet achieving this in a way which is acceptable to customers remains a challenge. GrIDsure, a one-time PIN scheme using random grids and personal patterns, has been proposed as a way to overcome some of these challenges. We present an analytical study which demonstrates that GrIDsure in its current form is vulnerable to interception. To strengthen the scheme, we propose a way to fortify GrIDsure against Man-in-the-Middle attacks through (i) an additional secret transmitted out-of-band and (ii) multiple patterns. Since the need to recall multiple patterns increases user workload, we evaluated user performance with multiple captures with 26 participants making 15 authentication attempts each over a 3-week period. In contrast with other research into the use of multiple graphical passwords, we find no significant difference in the usability of GrIDsure with single and with multiple patterns. Ravi Jhawar, Philip Inglesant, Nicolas T. Courtois, M. Angela Sasse |
NSS | 4 |
| 2010 | The true cost of unusable password policies: password use in the wildabstractHCI research published 10 years ago pointed out that many users cannot cope with the number and complexity of passwords, and resort to insecure workarounds as a consequence. We present a study which re-examined password policies and password practice in the workplace today. Philip Inglesant, M. Angela Sasse |
CHI | 2 |
| 2010 | A stealth approach to usable security: helping IT security managers to identify workable security solutionsabstractRecent advances in the research of usable security have produced many new security mechanisms that improve usability. However, these mechanisms have not been widely adopted in practice. In most organisations, IT security managers decide on security policies and mechanisms, seemingly without considering usability. IT security managers consider risk reduction and the business impact of information security controls, but not the impact that controls have on users. Rather than trying to remind security managers of usability, we present a new paradigm -- a stealth approach which incorporates the impact of security controls on users' productivity and willingness to comply into business impact and risk reduction. During two 2-hour sessions, 3 IT security managers discussed with us mock-up tool prototypes that embody these principles, alongside a range of potential usage scenarios (e.g. cloud-based password-cracking attacks and "hot-desking" initiatives). Our tool design process elicits findings to help develop mechanisms to visualise these tradeoffs. Simon Edward Parkin, Aad P. A. van Moorsel, Philip Inglesant, M. Angela Sasse |
NSPW | 4 |
| 2009 | Designing and evaluating usable security and privacy technologyabstractNo abstract available. M. Angela Sasse, Clare-Marie Karat, Roy A. Maxion |
SOUPS | 1 |
| 2009 | Stakeholder involvement, motivation, responsibility, communication: How to design usable security in e-Science
Ivan Flechais, M. Angela Sasse |
Int. J. Hum. Comput. Stud. | 2 |
| 2009 | The big picture on small screens delivering acceptable video quality in mobile TVabstractMobile TV viewers can change the viewing distance and (on some devices) scale the picture to their preferred viewing ratio, trading off size for angular resolution. We investigated optimal trade-offs between size and resolution through a series of studies. Participants selected their preferred size and rated the acceptability of the visual experience on a 200ppi device at a 4:3 aspect ratio. They preferred viewing ratios similar to living room TV setups regardless of the much lower resolution: at a minimum 14 pixels per degree. While traveling on trains people required videos with a height larger than 35mm. Hendrik Knoche, M. Angela Sasse |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2008 | To catch a thief - you need at least 8 frames per second: the impact of frame rates on user performance in a CCTV detection taskabstractThe new generation of digital CCTV systems can be tailored to serve a wide range of security requirements. However, many digital CCTV systems produce video which is insufficient in video quality to support specific security tasks, such as crime detection. We report a study investigating the impact of lowering frame rates on an observer's ability to distinguish between crime and no crime events from post-event recorded video. 80 participants viewed 32 video scenes at 1, 5, 8, and 12 frames per second (fps). The task required observers to determine if one of three possible events had occurred. Results showed that the number of correct detections, task confidence decreased significantly at 8 fps and lower. Our results provide CCTV practitioners with a minimum frame rate level (8 fps) for event detection, a task performed by CCTV users of varying skill and experience. Hina Uttam Keval, M. Angela Sasse |
ACM Multimedia | 2 |
| 2008 | The sweet spot: how people trade off size and definition on mobile devicesabstractMobile TV can deliver up-to-date content to users on the move. But it is currently unclear how to best adapt higher resolution TV content. In this paper, we describe a laboratory study with 35 participants who watched short clips of different content and shot types on a 200ppi PDA display at a resolution of either 120x90 or 168x128. Participants selected their preferred size and rated the acceptability of the visual experience. The preferred viewing ratio depended on the resolution and had to be at least 9.8H. The minimal angular resolution people required and which limited the up-scaling factor was 14 pixels per degree. Extreme long shots were best when depicted actors were at least 0.7° high. A second study researched the ecological validity of previous lab results by comparing them to results from the field. Image size yielded more value for users in the field than was apparent from lab results. In conclusion, current prediction models based on preferred viewing distances for TV and large displays do not predict viewing preferences on mobile devices. Our results will help to further the understanding of multimedia perception and service designers to deliver both economically viable and enjoyable experiences. Hendrik Knoche, M. Angela Sasse |
ACM Multimedia | 2 |
| 2008 | The compliance budget: managing security behaviour in organisationsabstractA significant number of security breaches result from employees' failure to comply with security policies. Many organizations have tried to change or influence security behaviour, but found it a major challenge. Drawing on previous research on usable security and economics of security, we propose a new approach to managing employee security behaviour. We conducted interviews with 17 employees from two major commercial organizations, asking why they do or don't comply with security policies. Our results show that key factors in the compliance decision are the actual and anticipated cost and benefits of compliance to the individual employee, and perceived cost and benefits to the organization. We present a new paradigm -- the Compliance Budget - as a means of understanding how individuals perceive the costs and benefits of compliance with organisational security goals, and identify a range of approaches that security managers can use to influence employee's perceptions (which, in turn, influence security behaviour). The Compliance Budget should be understood and managed in the same way as any financial budget, as compliance directly affects, and can place a cap on, effectiveness of organisational security measures. Adam Beautement, M. Angela Sasse, Mike Wonham |
NSPW | 2 |
| 2008 | Expressions of expertness: the virtuous circle of natural language for access control policy specificationabstractThe implementation of usable security is particularly challenging in the growing field of Grid computing, where control is decentralised, systems are heterogeneous, and authorization applies across administrative domains. PERMIS, based on the Role-Based Access Control (RBAC) model, provides a unified infrastructure to address these challenges. Previous research has found that resource owners who do not understand the PERMIS RBAC model have difficulty expressing access control policies. We have addressed this issue by investigating the use of a controlled natural language parser for expressing these policies. In this paper, we describe our experiences in the design, implementation, and evaluation of this parser for the PERMIS Editor. We began by understanding Grid access control needs as expressed by resource owners, through interviews and focus groups with 45 Grid practitioners. We found that the many areas of Grid computing use present varied security requirements; this suggests a minimal, open design. We designed and implemented a controlled natural language system to support these needs, which we evaluated with a cross-section of 17 target users. We found that participants were not daunted by the text editor, and understood the syntax easily. However, some strict requirements of the controlled language were problematic. Using controlled natural language helps overcome some conceptual mis-matches between PERMIS RBAC and older paradigms; however, there are still subtleties which are not always understood. In conclusion, the parser is not sufficient on its own, and should be seen in the interplay with other parts of the PERMIS Editor, so that, iteratively, users are helped to understand the underlying PERMIS model and to express their security policies more accurately and more completely. Philip Inglesant, M. Angela Sasse, David W. Chadwick, Lei Lei Shi |
SOUPS | 2 |
| 2008 | How low can you go? The effect of low resolutions on shot types in mobile TV
Hendrik Knoche, John D. McCarthy, M. Angela Sasse |
Multim. Tools Appl. | 3 |
| 2007 | The kindest cut: enhancing the user experience of mobile tv through adequate zoomingabstractThe growing market of Mobile TV requires automated adaptation of standard TV footage to small size displays. Especially extreme long shots (XLS) depicting distant objects can spoil the user experience, e.g. in soccer content. Automated zooming schemes can improve the visual experience if the resulting footage meets user expectations in terms of the visual detail and quality but does not omit valuable context information. Current zooming schemes are ignorant of beneficial zoom ranges for a given target size when applied to standard definition TV footage. In two experiments 84 participants were able to switch between original and zoom enhanced soccer footage at three sizes - from 320x240 (QVGA) down to 176x144 (QCIF). Eye tracking and subjective ratings showed that zoom factors between 1.14 and 1.33 were preferred for all sizes. Interviews revealed that a zoom factor of 1.6 was too high for QVGA content due to low perceived video quality, but beneficial for QCIF size. The optimal zoom depended on the target display size. We include a function to compute the optimal zoom for XLS depending on the target device size. It can be applied in automatic content adaptation schemes and should stimulate further research on the requirements of different shot types in video coding. Hendrik Knoche, Marco Papaleo, M. Angela Sasse, Alessandro Vanelli-Coralli |
ACM Multimedia | 3 |
| 2006 | Accounting for taste: using profile similarity to improve recommender systemsabstractRecommender systems have been developed to address the abundance of choice we face in taste domains (films, music, restaurants) when shopping or going out. However, consumers currently struggle to evaluate the appropriateness of recommendations offered. With collaborative filtering, recommendations are based on people's ratings of items. In this paper, we propose that the usefulness of recommender systems can be improved by including more information about recommenders. We conducted a laboratory online experiment with 100 participants simulating a movie recommender system to determine how familiarity of the recommender, profile similarity between decision-maker and recommender, and rating overlap with a particular recommender influence the choices of decision-makers in such a context. While familiarity in this experiment did not affect the participants' choices, profile similarity and rating overlap had a significant influence. These results help us understand the decision-making processes in an online context and form the basis for user-centered social recommender system design. Philip Bonhard, Clare Harries, John D. McCarthy, M. Angela Sasse |
CHI | 4 |
| 2006 | Reading the fine print: the effect of text legibility on perceived video quality in mobile tvabstractMobile TV services are available in an increasing number of countries. For cost reasons, most of these services offer material directly recoded for mobile consumption (i.e. without additional editing). This paper reports the findings of a study on the influence of text legibility and quality on the perceived video quality of mobile TV content. The study, with 64 participants, examined responses to news footage presented at four image resolutions and seven video encoding bitrates. The results showed that a simulated separate delivery of a news ticker and other textual information significantly increased the perceived video quality of the entire screen for native speakers. In addition, some automatable changes to the layout of news content resulted in substantial increases in perceived video quality. The results can be used to quantify the perceived quality gains when considering text delivery separately from the video stream and in the development of more accurate multimedia quality models. Hendrik Knoche, John D. McCarthy, M. Angela Sasse |
ACM Multimedia | 3 |
| 2005 | Can small be beautiful?: assessing image resolution requirements for mobile TVabstractMobile TV services are now being offered in several countries, but for cost reasons, most of these services offer material directly recoded for mobile consumption (i.e. without additional editing). The experiment reported in this paper, aims to assess the image resolution and bitrate requirements for displaying this type of material on mobile devices. The study, with 128 participants, examined responses to four different image resolutions, seven video encoding bitrates, two audio bitrates and four content types. The results show that acceptability is significantly lower for images smaller than 168x126, regardless of content type. The effect is more pronounced when bandwidth is abundant, and is due to important detail being lost in the smaller screens. In contrast to previous studies, participants are more likely to rate image quality as unacceptable when the audio quality is high. Hendrik Knoche, John D. McCarthy, M. Angela Sasse |
ACM Multimedia | 3 |
| 2005 | Designing a large-scale video chat applicationabstractStudies of video conferencing systems generally focus on scenarios where users communicate using an audio channel. However, text chat serves users in a wide variety of contexts, and is commonly included in multimedia conferencing systems as a complement to the audio channel. This paper introduces a prototype application which integrates video and text communication, and describes a formative evaluation of the prototype with 53 users in a social setting. We focus the evaluation on bandwidth and view navigation requirements in order to determine how to better serve users with video chat, and discuss how the findings from this evaluation can inform the design of future video chat applications. Bandwidth requirements are evaluated through user perceptions of video delivered using three different bandwidth schemes. For view navigation, we examine a system that automatically switches the video focus to the current "chatter", instead of requiring users to navigate manually to find the video steam they are interested in viewing. Jeremiah Scholl, Peter Parnes, John D. McCarthy, M. Angela Sasse |
ACM Multimedia | 4 |
| 2005 | Divide and conquer: the role of trust and assurance in the design of secure socio-technical systemsabstractIn order to be effective, secure systems need to be both correct (i.e. effective used as intended) and dependable (i.e. actually being used as intended). Given that most secure systems involve people, a strategy for achieving dependable security must address both people and technology. Current research in Human-Computer Interactions in Security (HCISec) aims to increase dependability of the human element by reducing mistakes (e.g. through better user interfaces to security tools). We argue that a successful strategy also needs to consider the impact of social interaction on security, and in this respect is a central concept. We compare the understanding of in secure systems with the more differentiated models of in social science research. The security definition of turns out to map onto strategies that would be correctly described as in the more differentiated model. We argue that distinguishing between and assurance yields a wider range of strategies for ensuring dependability of the human element in a secure socio-technical system. Furthermore, correctly placed can also benefit an organisation's culture and performance. We conclude by presenting design principles to help security designers decide when to trust and when to assure, and give examples of how both strategies would be implemented in practice. Ivan Flechais, Jens Riegelsberger, M. Angela Sasse |
NSPW | 3 |
| 2005 | The mechanics of trust: A framework for research and design
Jens Riegelsberger, M. Angela Sasse, John D. McCarthy |
Int. J. Hum. Comput. Stud. | 2 |
| 2005 | 'R-What?' Development of a role-based access control policy-writing tool for e-ScientistsabstractAbstract A lightweight role‐based access control policy authoring tool was developed for e‐Scientists, a community for which access policies have to be implemented for an increasingly heterogeneous group of local and remote users. Two fundamental problems were identified: (1) lack of understanding of what the policy components are (i.e. how authorization policies are structured), and (2) lack of understanding of the underlying policy paradigm (i.e. what should go into the policy, and what should be left out). Conceptual design (CD) techniques were used to revise the user interface (UI) labels so that e‐Scientists and developers were better able to describe access policy components from labels, and match labels with components (t = 6.28, df = 7, p = 0.000 two‐tailed). CD, instructional text, bubble help, UI behaviour and alert boxes were used to shape users' models of the policy paradigm. The final prototype improved users' efficiency and effectiveness by more than doubling the speed with which expert users could write authorization policies, and facilitating users without specialist security knowledge to overcome the policy paradigm and components problems, enabling them to complete 80% of basic and 75% of advanced authorization policy‐writing tasks in a usability trial. Copyright © 2005 John Wiley & Sons, Ltd. Sacha Brostoff, M. Angela Sasse, David W. Chadwick, Jim Cunningham, Uche M. Mbanaso, Sassa Otenko |
Softw. Pract. Exp. | 2 |
| 2004 | "Stuff goes into the computer and doesn't come out": a cross-tool study of personal information managementabstractThis paper reports a study of Personal Information Management (PIM), which advances research in two ways: (1) rather than focusing on one tool, we collected cross-tool data relating to file, email and web bookmark usage for each participant, and (2) we collected longitudinal data for a subset of the participants. We found that individuals employ a rich variety of strategies both within and across PIM tools, and we present new strategy classifications that reflect this behaviour. We discuss synergies and differences between tools that may be useful in guiding the design of tool integration. Our longitudinal data provides insight into how PIM behaviour evolves over time, and suggests how the supporting nature of PIM discourages reflection by users on their strategies. We discuss how the promotion of some reflection by tools and organizations may benefit users. Richard Boardman, M. Angela Sasse |
CHI | 2 |
| 2004 | Sharp or smooth?: comparing the effects of quantization vs. frame rate for streamed videoabstractWe introduce a new methodology to evaluate the perceived quality of video with variable physical quality. The methodology is used to evaluate existing guidelines - that frame is more important than quantization when watching motion video, such as sports coverage. We test this claim in two studies that examine the relationship between these physical quality metrics and perceived quality. In Study 1, 41 soccer fans viewed CIF-sized images on a desktop computer. Study 2 repeated the experiment with 37 soccer fans, viewing the same content, in QCIF size, on a palmtop device. Contrary to existing guidelines, we found that users prefer high-resolution images to frame rate. We conclude that the rule high motion = frame rate does not apply to small screens. With small screen devices, reducing quantization removes important information about the players and the ball. These findings have important implications for service providers and designers of streamed video applications. John D. McCarthy, M. Angela Sasse, Dimitrios Miras |
CHI | 2 |
| 2004 | From doing to being: getting closer to the user experienceabstractThe research by Scheirer et al. (2002) is pivotal in promoting the use of psychophysiological measures in HCI. We argue that rather than inferring users' emotional states from the data, which is difficult to do reliably, the signals can be used as an indicator of user cost by monitoring changes in users' physiological responses. We applied this approach by monitoring Skin Conductance, Heart Rate and Blood Volume Pulse (as well as task performance and user satisfaction) to investigate the impact of media quality degradations on users. Five studies were conducted utilising this approach. Results show that psychophysiological data show responses to audio and video degradations: users respond to specific degradations with increased levels of arousal. In addition, psychophysiological responses do not always correlate with each other and subjective and physiological measures do not always concur, which means that psychophysiological data may detect responses that users are either not aware of or cannot recall at post-session subjective assessment. We thus conclude that psychophysiological measures have a valuable role to play in media quality evaluation. Gillian May Wilson, M. Angela Sasse |
Interact. Comput. | 2 |
| 2003 | The impact of avatar realism and eye gaze control on perceived quality of communication in a shared immersive virtual environmentabstractThis paper presents an experiment designed to investigate the impact of visual and behavioral realism in avatars on perceived quality of communication in an immersive virtual environment. Participants were paired by gender and were randomly assigned to a CAVE‘-like system or a head-mounted display. Both were represented by a humanoid avatar in the shared 3D environment. The visual appearance of the avatars was either basic and genderless (like a "match-stick" figure), or more photorealistic and gender-specific. Similarly, eye gaze behavior was either random or inferred from voice, to reflect different levels of behavioral realism. Our comparative analysis of 48 post-experiment questionnaires confirms earlier findings from non-immersive studies using semi-photorealistic avatars, where inferred gaze significantly outperformed random gaze. However responses to the lower-realism avatar are adversely affected by inferred gaze, revealing a significant interaction effect between appearance and behavior. We discuss the importance of aligning visual and behavioral realism for increased avatar effectiveness. Maia Garau, Mel Slater, Vinoba Vinayagamoorthy, Andrea Brogni, Anthony Steed, M. Angela Sasse |
CHI | 6 |
| 2003 | Shiny happy people building trust?: photos on e-commerce websites and consumer trustabstractDesigning for trust in technology-mediated interaction is an increasing concern in CHI. In advertising, images of people have long been used to create positive attitudes to products or trust in brands. However, the evidence as to whether placing photographs of people on e-commerce web sites has the intended effect has been mixed. This paper reports a study that examined the effect of adding such photographs to 12 existing e-commerce sites, whose reputation had been established through customer ratings. In an experiment with 115 participants, trust was measured using methods that induced financial risk, adapted from experimental economics. Averaging across sites, neither the presence of a photo, nor trustworthiness of the person depicted, had a significant effect. However, the presence of photos reduced participants' ability to identify vendors with good and bad reputations -- the perceived trustworthiness of poorly performing vendors was increased, whereas that of vendors with good reputation was decreased. This result advocates caution when using photos on e-commerce sites to boost trustworthiness, and demonstrates the need for further research into interpersonal cues and on-line trust. Jens Riegelsberger, M. Angela Sasse, John D. McCarthy |
CHI | 2 |
| 2003 | Bringing security home: a process for developing secure and usable systemsabstractThe aim of this paper is to provide better support for the development of secure systems. We argue that current development practice suffers from two key problems:1. Security requirements tend to be kept separate from other system requirements, and not integrated into any overall strategy.2. The impact of security measures on users and the operational cost of these measures on a day-to-day basis are usually not considered.Our new paradigm is the full integration of security and usability concerns into the software development process, thus enabling developers to build secure systems that work in the real world. We present AEGIS, a secure software engineering method which integrates asset identification, risk and threat analysis and context of use, bound together through the use of UML, and report its application to case studies on Grid projects. An additional benefit of the method is that the involvement of stakeholders in the high-level security analysis improves their understanding of security, and increases their motivation to comply with policies. Ivan Flechais, M. Angela Sasse, Stephen Hailes |
NSPW | 2 |
| 2003 | The researcher's dilemma: evaluating trust in computer-mediated communication
Jens Riegelsberger, M. Angela Sasse, John D. McCarthy |
Int. J. Hum. Comput. Stud. | 2 |
| 2001 | The impact of eye gaze on communication using humanoid avatarsabstractIn this paper we describe an experiment designed to investigate the importance of eye gaze in humanoid avatar's representing people engaged in conversation. We compare responses to dyadic conversations in four mediated conditions: video, audio-only, and two avatar conditions. The avatar conditions differed only in their treatment of eye gaze. In the random-gaze condition the avatars head and eye animations were unrelated to conversational flow. In the informed-gaze condition, they were related to turn-taking during the conversation. The head animations were tracked and the eye animations were inferred from the audio stream. Our comparative analysis of 100 post-experiment questionnaires showed that the random-gaze avatar did not improve on audio-only communication. The informed-gaze avatar significantly outperformed the random-gaze model and also outperformed audio-only on several response measures. We conclude that an avatar whose gaze behaviour is related to the conversation provides a marked improvement on an avatar that merely exhibits liveliness. Maia Garau, Mel Slater, Simon Bee, M. Angela Sasse |
CHI | 4 |
| 2001 | Why Value Is Everything: A User-Centered Approach to Internet Quality of Service and Pricing
Anna Bouch, M. Angela Sasse |
IWQoS | 2 |
| 2001 | Safe and sound: a safety-critical approach to securityabstractThis paper firstly argues that the design of security applications needs to consider more than technical elements. Since almost all security systems involve human users as well as technology, security should be considered, and designed as, a socio-technical work system. Secondly, we argue that safety-critical systems design has similar goals and issues to security design, and should thus provide a good starting point. Thirdly, we identify Reason's (1990) Generic Error Modeling System/Basic Elements of Production as the most suitable starting point for a socio-technical approach, and demonstrate how its basic elements can be applied to the domain of information security. We demonstrate how the application of the model's concepts, especially the distinction between active and latent failures, offers an effective way of identifying and addressing security issues that involve human behavior. Finally, we identify strengths and weaknesses of this approach, and the requirement for further work to produce a security-specific socio-technical design framework. Sacha Brostoff, M. Angela Sasse |
NSPW | 2 |
| 2001 | Pretty good persuasion: a first step towards effective password security in the real worldabstractIn the past, research on password mechanisms has focussed almost entirely on technical issues. Only in recent years has the security research community acknowledged that user behavior plays a part in many security failures, and that policies alone may not be sufficient to ensure correct behavior. We argue that password mechanisms and their users form a socio-technical system, whose effectiveness relies strongly on users' willingness to make the extra effort that security-conscious behavior requires. In most organizations, users cannot be forced to comply; rather, they have to be persuaded to do so. Ultimately, the mechanisms themselves, policies, tutorials, training and the general discourse have to be designed with their persuasive power in mind. We present the results of a first study that can guide such persuasive efforts, and describe methods that can be used to persuade users to employ proper password practice. Dirk Weirich 0001, M. Angela Sasse |
NSPW | 2 |
| 2000 | The good, the bad, and the muffled: the impact of different degradations on Internet speechabstractThis paper presents an experiment comparing the relative impact of different types of degradation on subjective quality ratings of interactive speech transmitted over packet-switched networks. The experiment was inspired by observations made during a large-scale, long-term field trial of multicast conferencing. We observed that user reports of unsatisfactory speech quality were rarely due to network effects such as packet loss and jitter. A subsequent analysis of conference recordings found that in most cases, the impairment was caused by end-system hardware, equipment setup or user behavior. The results from the experiment confirm that the effects of volume differences, echo and bad microphones are rated worse than the level of packet loss most users are likely to experience on the Internet today, provided that a simple repair mechanism is used. Consequently, anyone designing or deploying network speech applications and services ought to consider the addition of diagnostics and tutorials to ensure acceptable speech quality. Anna Watson, M. Angela Sasse |
ACM Multimedia | 2 |
| 1999 | It Ain't What You Charge, It's The Way That You Do It: A User Perspective of Network QoS and PricingabstractShared networks, such as the Internet, are fast becoming able to support heterogeneous applications and a diverse user community. In this climate, it becomes increasingly likely that some form of pricing mechanism will be necessary in order to manage the quality of service (QoS) requirements of different applications. So far, research in this area has focused on technical mechanisms for implementing QoS and charging. This paper reports a series of studies in which users' perceptions of QoS, and their attitudes to a range of pricing mechanisms, were investigated. We found that users' knowledge and experience of networks, and the real-world task they perform with applications, determine their evaluation of QoS and attitude to payment. Users' payment behavior is governed by their level of confidence in the performance of salient QoS parameters. User confidence, in turn, depends on a number of other factors. In conclusion, we argue that charging models that undermine user confidence are not only undesirable from the users' point of view, but may also lead to user behavior that may have a negative impact on QoS. Anna Bouch, M. Angela Sasse |
Integrated Network Management | 2 |
| 1999 | Privacy Issues in Ubiquitous Multimedia Environments: Wake Sleeping Dogs, or Let Them Lie?
Anne Adams, M. Angela Sasse |
INTERACT | 2 |
| 1999 | Examining Users' Repertoire of Internet Applications
Jon Rimmer, Ian Wakeman, Louise Sheeran, M. Angela Sasse |
INTERACT | 4 |
| 1999 | Taming the wolf in sheep's clothing: privacy in multimedia communicationsabstractWhen ubiquitous multimedia technology is introduced in an organization, the privacy implications of that technology are rarely addressed. Users usually extend the trust they have in an organization to the technology it employs. This paper reports results from interviews with 24 Internet Engineering Task Force (IETF) attendees whose presentations or contributions to IETF sessions were transmitted on the multicast backbone (Mbone). Due to a high level of trust in the organization, these users had few initial concerns about the privacy implications of this technology. However, interviewees' trust relied on inaccurate assumptions, since the interviews revealed a number of potential and actual invasions of privacy in transmission, recording and editing of multicast data. Previous research found that users who experience an unexpected invasion of their privacy are not only likely to reject the technology that afforded the invasion, but lose trust in the organization that introduced it [2,3]. We discuss a number of mechanisms and policies for protecting users' privacy in this particular application, and propose a strategy for introducing networked multimedia technology in general. Anne Adams, M. Angela Sasse |
ACM Multimedia (1) | 2 |
| 1998 | Measuring Perceived Quality of Speech and Video in Multimedia Conferencing ApplicationsabstractI&m is currenffymuch discussion of Quality of service (Qos) measurements at the network IeveIof real-time mdimedia serviq but it is theszd.jectie@typerwivedbytie-r that will determine whether these applications are adopteil This paperangues that ITU-recommended metiodsfor subjective quality msessment of _ and video arenotsuitalie for asssing the qua?ityof many newer services and applications.We present an outline of what we beiieve to be a more suitabIe testingmethodoIogy, vddchacknowkdges tie muklimensional mture of perceived audio and video qwdity.1.1 Anna Watson, M. Angela Sasse |
ACM Multimedia | 2 |
| 1996 | Evaluating Audio and Video Quality in Low-Cost Multimedia Conferencing SystemsabstractReal-time audio and video transmission over shared packet networks, such as the Internet, has become possible thanks to efficient data compression schemes and the provision of high-speed networks. Low-cost multimedia conferencing technology could benefit many users in different areas, such as remote collaboration, distance education and health-care. It is likely that diverse tasks performed by users in different application domains will require different levels of audio and video quality. Established methods of rating audio and video quality in the broadcast and telephony world cannot be applied to digital, lower quality images and sound. The providers of networks and services are looking to HCI to provide a means of assessing audio and video quality. The paper describes two different approaches to assessing audio and video of desktop conferencing systems — a controlled experimental study and an informal field trial. The advantages and disadvantages of both approaches for providing task-specific quality assessment are discussed, and future work to integrate lab-based and field trials into a valid and reliable assessment approach is outlined. Anna Watson, M. Angela Sasse |
Interact. Comput. | 2 |
| 1993 | Support for Collaborative Authoring via Electronic Mail: The MESSIE Environment
M. Angela Sasse, Mark Handley, Shaw-Cheng Chuang |
ECSCW | 1 |
| 1993 | Multimedia Integrated Conferencing for European Researchers (MICE): Piloting Activities and the Conference Management and Multiplexing Centre
Mark Handley, Peter T. Kirstein, M. Angela Sasse |
Comput. Networks ISDN Syst. | 3 |
| 1991 | Book Review: "Cognitive Ergonomics and Human-Computer Interaction, " edited by J. Long and A. Whitefield
M. Angela Sasse |
Int. J. Man Mach. Stud. | 1 |