VLDB 2026 Research / reviewers in the wild / expert
Stuart E. Schechter
dblp:s/SESchechter
· DBLP profile ↗
27ranked-venue papers
13as first author
0since 2021 · last 2019
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 10 first-authorHuman-computer interaction and ubiquitous computing · 10 · 5 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
13 papers |
Authentication and access control · 45% Usable security · 14% Network security · 10% | |
| Human-computer interaction and pervasive computing
3 papers |
Ubiquitous computing and smart environments · 56% Collaborative and social computing · 28% Usability and user experience research · 17% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Memory systems · 77% Hardware reliability and fault tolerance · 23% |
Topics — the 24 heaviest of 30, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › intrusion detection and prevention
intrusion detection |
0.4 | 1 | 2019 | Distinguishing Attacks from Legitimate Authentication Traffic at Scale · NDSS 2019 |
Authentication and access control
knowledge-based authentication |
0.3 | 2 | 2014 | Towards Reliable Storage of 56-bit Secrets in Human Memory · USENIX Security Symposium 2014 It's No Secret. Measuring the Security and Reliability of Authentication via "Secret" Questions · SP 2009 |
Systems and software security
operating system security |
0.3 | 2 | 2012 | Operating system framed in case of mistaken identity: measuring the success of web-based spoofing attacks on OS password-entry dialogs · CCS 2012 These aren't the droids you're looking for: retrofitting android to protect data from imperious applications · CCS 2011 |
Cryptographic primitives and cryptanalysis › hash functions
memory-hard functions |
0.2 | 1 | 2016 | Balloon Hashing: A Memory-Hard Function Providing Provable Protection Against Sequential Attacks · ASIACRYPT (1) 2016 |
Usable security
authentication usability |
0.2 | 2 | 2012 | Operating system framed in case of mistaken identity: measuring the success of web-based spoofing attacks on OS password-entry dialogs · CCS 2012 It's No Secret. Measuring the Security and Reliability of Authentication via "Secret" Questions · SP 2009 |
Ubiquitous computing and smart environments
smart home |
0.2 | 1 | 2014 | Intruders versus intrusiveness: teens' and parents' perspectives on home-entryway surveillance · UbiComp 2014 |
Privacy and data protection › privacy of vulnerable populations
adolescent online privacy |
0.2 | 1 | 2014 | Intruders versus intrusiveness: teens' and parents' perspectives on home-entryway surveillance · UbiComp 2014 |
Authentication and access control
password security |
0.2 | 1 | 2014 | Telepathwords: Preventing Weak Passwords by Reading Users' Minds · USENIX Security Symposium 2014 |
Authentication and access control › password security
password strength |
0.2 | 1 | 2014 | Telepathwords: Preventing Weak Passwords by Reading Users' Minds · USENIX Security Symposium 2014 |
Authentication and access control › authentication › authentication attack
credential theft |
0.1 | 1 | 2012 | Operating system framed in case of mistaken identity: measuring the success of web-based spoofing attacks on OS password-entry dialogs · CCS 2012 |
Authentication and access control
access control |
0.1 | 1 | 2011 | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications · CCS 2011 |
Web and mobile security › mobile security
android security |
0.1 | 1 | 2011 | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications · CCS 2011 |
Authentication and access control › access control
least privilege |
0.1 | 1 | 2011 | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications · CCS 2011 |
Network measurement and analytics
traffic classification |
0.1 | 1 | 2019 | Distinguishing Attacks from Legitimate Authentication Traffic at Scale · NDSS 2019 |
Memory systems
non-volatile memory |
0.1 | 1 | 2010 | Use ECP, not ECC, for hard failures in resistive memories · ISCA 2010 |
Authentication and access control › user authentication
backup authentication |
0.1 | 1 | 2009 | It's not what you know, but who you know: a social approach to last-resort authentication · CHI 2009 |
Authentication and access control › user authentication
social authentication |
0.1 | 1 | 2009 | It's not what you know, but who you know: a social approach to last-resort authentication · CHI 2009 |
Web and mobile security
phishing resistance |
0.1 | 1 | 2007 | The Emperor's New Security Indicators · S&P 2007 |
Usable security › risk communication
security indicators |
0.1 | 1 | 2007 | The Emperor's New Security Indicators · S&P 2007 |
Cryptographic protocols and secure computation › secure message transmission
SSH |
0.1 | 1 | 2006 | Inoculating SSH Against Address Harvesting · NDSS 2006 |
Usability and user experience research
security usability |
0.1 | 1 | 2014 | Telepathwords: Preventing Weak Passwords by Reading Users' Minds · USENIX Security Symposium 2014 |
Privacy and data protection
privacy perceptions |
0.1 | 1 | 2014 | Intruders versus intrusiveness: teens' and parents' perspectives on home-entryway surveillance · UbiComp 2014 |
Web and mobile security
mobile security |
0.0 | 1 | 2011 | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications · CCS 2011 |
Software maintenance and evolution › software evolution
software aging |
0.0 | 1 | 2006 | Milk or Wine: Does Software Security Improve with Age? · USENIX Security Symposium 2006 |
Methods — techniques the papers use, named apart from their topics
statistical modeling · 0.8machine learning · 0.8interviews · 0.6user study · 0.4online study · 0.4provable security · 0.2retrofitting · 0.1data protection · 0.1guessing attack · 0.1experiment · 0.1empirical measurement · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | StopGuessing: Using Guessed Passwords to Thwart Online GuessingabstractPractitioners who seek to defend password-protected resources from online guessing attacks will find a shortage of tooling and techniques to help them. Little research suggests anything beyond blocking or throttling traffic from IP addresses sending suspicious traffic; counting failed authentication requests, or some variant, is often the sole feature used to determine suspicion. In this paper we show that several other features can greatly help distinguishing benign and attack traffic. First, we increase the penalties for clients responsible for fail events involving passwords frequently-guessed by attackers. Second, we reduce the threshold (and thus protect better) for accounts with weak passwords. Third, we detect, and are more forgiving of, login failures caused by users mistyping their passwords. Most importantly, we achieve all of these goals without needing any marker that indicates weak accounts, changing the format in which passwords are stored (i.e. we do not store passwords plaintext or in any recoverable form), or storing any information that might be harmful if leaked. We present an open-source implementation of this system and demonstrate its improvement over simpler blocking strategies in various simulated scenarios. Stuart E. Schechter, Yuan Tian 0001, Cormac Herley |
EuroS&P | 1 |
| 2019 | Distinguishing Attacks from Legitimate Authentication Traffic at Scale
Cormac Herley, Stuart E. Schechter |
NDSS | 2 |
| 2016 | Balloon Hashing: A Memory-Hard Function Providing Provable Protection Against Sequential Attacks
Dan Boneh, Henry Corrigan-Gibbs, Stuart E. Schechter |
ASIACRYPT (1) | 3 |
| 2015 | Learning Assigned Secrets for Unlocking Mobile Devices
Stuart E. Schechter, Joseph Bonneau |
SOUPS | 1 |
| 2014 | Intruders versus intrusiveness: teens' and parents' perspectives on home-entryway surveillanceabstractWe investigated how household deployment of Internet-connected locks and security cameras could impact teenagers' privacy. In interviews with 13 teenagers and 11 parents, we investigated reactions to audit logs of family members' comings and goings. All parents wanted audit logs with photographs, whereas most teenagers preferred text-only logs or no logs at all. We unpack these attitudes by examining participants' parenting philosophies, concerns, and current monitoring practices. In a follow-up online study, 19 parents configured an Internet-connected lock and camera system they thought might be deployed in their home. All 19 participants chose to monitor their children either through unrestricted access to logs or through real-time notifications of access. We discuss directions for auditing interfaces that could improve home security without impacting privacy. Blase Ur, Jaeyeon Jung, Stuart E. Schechter |
UbiComp | 3 |
| 2014 | Harder to Ignore? Revisiting Pop-Up Fatigue and Approaches to Prevent It
Cristian Bravo-Lillo, Lorrie Faith Cranor, Saranga Komanduri, Stuart E. Schechter, Manya Sleeper |
SOUPS | 4 |
| 2014 | Towards Reliable Storage of 56-bit Secrets in Human Memory
Joseph Bonneau, Stuart E. Schechter |
USENIX Security Symposium | 2 |
| 2014 | Telepathwords: Preventing Weak Passwords by Reading Users' Minds
Saranga Komanduri, Richard Shay, Lorrie Faith Cranor, Cormac Herley, Stuart E. Schechter |
USENIX Security Symposium | 5 |
| 2013 | Your attention please: designing security-decision UIs to make genuine risks harder to ignoreabstractWe designed and tested attractors for computer security dialogs: user-interface modifications used to draw users' attention to the most important information for making decisions. Some of these modifications were purely visual, while others temporarily inhibited potentially-dangerous behaviors to redirect users' attention to salient information. We conducted three between-subjects experiments to test the effectiveness of the attractors. Cristian Bravo-Lillo, Saranga Komanduri, Lorrie Faith Cranor, Robert W. Reeder, Manya Sleeper, Julie S. Downs, Stuart E. Schechter |
SOUPS | 7 |
| 2012 | Operating system framed in case of mistaken identity: measuring the success of web-based spoofing attacks on OS password-entry dialogsabstractWhen asking users to enter credentials, today's desktop operating systems often use windows that provide scant evidence that a trusted path has been established; evidence that would allow a user to know that a request is genuine and that the password will not be read by untrusted principals. We measure the efficacy of web-based attacks that spoof these operating system credential-entry windows to steal users' device-login passwords. We recruited 504 users of Amazon's Mechanical Turk to evaluate a series of games on third-party websites. The third such website indicated that it needed to install software from the publisher that provided the participants' operating system: Microsoft's Silverlight for Windows Vista/7 users and Apple's QuickTime for Mac OS users. The website then displayed a spoofed replica of a window the participant's client operating system would use to request a user's device credentials. In our most effective attacks, over 20% of participants entered passwords that they later admitted were the genuine credentials used to login to their devices. Even among those who declined to enter their credentials, many participants were oblivious to the spoofing attack. Participants were more likely to confirm that they were worried about the consequences of installing software from a legitimate source than to report that they thought the credential-entry window might have appeared as a result of an attempt to steal their password. Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie S. Downs, Saranga Komanduri, Stuart E. Schechter, Manya Sleeper |
CCS | 5 |
| 2012 | Goldilocks and the two mobile devices: going beyond all-or-nothing access to a device's applicationsabstractMost mobile phones and tablets support only two access control device states: locked and unlocked. We investigated how well all or-nothing device access control meets the need of users by interviewing 20 participants who had both a smartphone and tablet. We find all-or-nothing device access control to be a remarkably poor fit with users' preferences. On both phones and tablets, participants wanted roughly half their applications to be available even when their device was locked and half protected by authentication. We also solicited participants' interest in new access control mechanisms designed specifically to facilitate device sharing. Fourteen participants out of 20 preferred these controls to existing security locks alone. Finally, we gauged participants' interest in using face and voice biometrics to authenticate to their mobile phone and tablets; participants were surprisingly receptive to biometrics, given that they were also aware of security and reliability limitations. Eiji Hayashi, Oriana Riva, Karin Strauss, A. J. Bernheim Brush, Stuart E. Schechter |
SOUPS | 5 |
| 2011 | These aren't the droids you're looking for: retrofitting android to protect data from imperious applications
Peter Hornyack, Seungyeop Han, Jaeyeon Jung, Stuart E. Schechter, David Wetherall |
CCS | 4 |
| 2011 | Privacy Revelations for Web and Mobile Apps
David Wetherall, David R. Choffnes, Ben Greenstein, Seungyeop Han, Peter Hornyack, Jaeyeon Jung, Stuart E. Schechter, Xiao Sophia Wang |
HotOS | 7 |
| 2010 | Use ECP, not ECC, for hard failures in resistive memoriesabstractAs leakage and other charge storage limitations begin to impair the scalability of DRAM, non-volatile resistive memories are being developed as a potential replacement. Unfortunately, current error correction techniques are poorly suited to this emerging class of memory technologies. Unlike DRAM, PCM and other resistive memories have wear lifetimes, measured in writes, that are sufficiently short to make cell failures common during a system's lifetime. However, resistive memories are much less susceptible to transient faults than DRAM. The Hamming-based ECC codes used in DRAM are designed to handle transient faults with no effective lifetime limits, but ECC codes applied to resistive memories would wear out faster than the cells they are designed to repair. This paper evaluates Error-Correcting Pointers (ECP), a new approach to error correction optimized for memories in which errors are the result of permanent cell failures that occur, and are immediately detectable, at write time. ECP corrects errors by permanently encoding the locations of failed cells into a table and assigning cells to replace them. ECP provides longer lifetimes than previously proposed solutions with equivalent overhead. What's more, as the level of variance in cell lifetimes increases -- a likely consequence of further scalaing -- ECP's margin of improvement over existing schemes increases. Stuart E. Schechter, Gabriel H. Loh, Karin Strauss, Doug Burger |
ISCA | 1 |
| 2010 | Popularity Is Everything: A New Approach to Protecting Passwords from Statistical-Guessing Attacks
Stuart E. Schechter, Cormac Herley, Michael Mitzenmacher |
HotSec | 1 |
| 2009 | Can I borrow your phone?: understanding concerns when sharing mobile phonesabstractMobile phones are becoming increasingly personalized in terms of the data they store and the types of services they provide. At the same time, field studies have reported that there are a variety of situations in which it is natural for people to share their phones with others. However, most mobile phones support a binary security model that offers all-or-nothing access to the phone. We interviewed 12 smartphone users to explore how security and data privacy concerns affected their willingness to share their mobile phones. The diversity of guest user categorizations and associated security constraints expressed by the participants suggests the need for a security model richer than today's binary model. Amy K. Karlson, A. J. Bernheim Brush, Stuart E. Schechter |
CHI | 3 |
| 2009 | It's not what you know, but who you know: a social approach to last-resort authenticationabstractBackup authentication mechanisms help users who have forgotten their passwords regain access to their accounts-or at least try. Today's systems fall short in meeting both security and reliability requirements. We designed, built, and tested a new backup authentication system that employs a social-authentication mechanism. The system employs trustees previously appointed by the account holder to verify the account holder's identity. We ran three experiments to determine whether the system could (1) reliably authenticate account holders, (2) resist email attacks that target trustees by impersonating account holders, and (3) resist phone-based attacks from individuals close to account holders. Results were encouraging: seventeen of the nineteen participants who made the effort to call trustees authenticated successfully. However, we also found that users must be reminded of who their trustees are. While email-based attacks were largely unsuccessful, stronger countermeasures will be required to counter highly-personalized phone-based attacks. Stuart E. Schechter, Serge Egelman, Robert W. Reeder |
CHI | 1 |
| 2009 | Laissez-faire file sharing: access control designed for individuals at the endpointsabstractWhen organizations deploy file systems with access control mechanisms that prevent users from reliably sharing files with others, these users will inevitably find alternative means to share. Alas, these alternatives rarely provide the same level of confidentiality, integrity, or auditability provided by the prescribed file systems. Thus, the imposition of restrictive mechanisms and policies by system designers and administrators may actually reduce the system's security. Maritza L. Johnson, Steven M. Bellovin, Robert W. Reeder, Stuart E. Schechter |
NSPW | 4 |
| 2009 | It's no secret: measuring the security and reliability of authentication via 'secret' questionsabstractAll four of the most popular webmail providers ‐ AOL, Google, Microsoft, and Yahoo! ‐ rely on personal questions as the secondary authentication secrets used to reset account passwords. The security of these questions has received limited formal scrutiny, almost all of which predates webmail. We ran a user study to measure the reliability and security of the questions used by all four webmail providers. We asked participants to answer these questions and then asked their acquaintances to guess their answers. Acquaintances with whom participants reported being unwilling to share their webmail passwords were able to guess 17% of their answers. Participants forgot 20% of their own answers within six months. What’s more, 13% of answers could be guessed within five attempts by guessing the most popular answers of other participants, though this weakness is partially attributable to the geographic homogeneity of our participant pool. Stuart E. Schechter, A. J. Bernheim Brush, Serge Egelman |
SOUPS | 1 |
| 2009 | It's not what you know, but who you know: a social approach to last-resort authenticationabstractBackup authentication mechanisms help users who have forgotten their passwords regain access to their accounts-or at least try. Today's systems fall short in meeting both security and reliability requirements. We designed, built, and tested a new backup authentication system that employs a social-authentication mechanism. The system employs trustees previously appointed by the account holder to verify the account holder's identity. We ran three experiments to determine whether the system could (1) reliably authenticate account holders, (2) resist email attacks that target trustees by impersonating account holders, and (3) resist phone-based attacks from individuals close to account holders. Results were encouraging: seventeen of the nineteen participants who made the effort to call trustees authenticated successfully. However, we also found that users must be reminded of who their trustees are. While email-based attacks were largely unsuccessful, stronger countermeasures will be required to counter highly-personalized phone-based attacks. Stuart E. Schechter, Serge Egelman, Robert W. Reeder |
SOUPS | 1 |
| 2009 | 1 + 1 = you: measuring the comprehensibility of metaphors for configuring backup authenticationabstractBackup authentication systems verify the identity of users who are unable to perform primary authentication usually as a result of forgetting passwords. The two most common authentication mechanisms used for backup authentication by webmail services, personal authentication questions and email-based authentication, are insufficient. Many webmail users cannot benefit from email-based authentication because their webmail account is their primary email account. Personal authentication questions are frequently forgotten and prone to security failures, as illustrated by the increased scrutiny they received following their implication in the compromise of Republican vice presidential candidate Sarah Palin's Yahoo! account. Stuart E. Schechter, Robert W. Reeder |
SOUPS | 1 |
| 2009 | It's No Secret. Measuring the Security and Reliability of Authentication via "Secret" QuestionsabstractAll four of the most popular webmail providers - AOL, Google, Microsoft, and Yahoo! - rely on personal questions as the secondary authentication secrets used to reset account passwords. The security of these questions has received limited formal scrutiny, almost all of which predates webmail. We ran a user study to measure the reliability and security of the questions used by all four webmail providers. We asked participants to answer these questions and then asked their acquaintances to guess their answers. Acquaintances with whom participants reported being unwilling to share their webmail passwords were able to guess 17% of their answers. Participants forgot 20% of their own answers within six months. What's more, 13% of answers could be guessed within five attempts by guessing the most popular answers of other participants, though this weakness is partially attributable to the geographic homogeneity of our participant pool. Stuart E. Schechter, A. J. Bernheim Brush, Serge Egelman |
SP | 1 |
| 2007 | The Emperor's New Security IndicatorsabstractWe evaluate Website authentication measures that are designed to protect users from man-in-the-middle, 'phishing', and other site forgery attacks. We asked 67 bank customers to conduct common online banking tasks. Each time they logged in, we presented increasingly alarming clues that their connection was insecure. First, we removed HTTPS indicators. Next, we removed the participant's site-authentication image--the customer-selected image that many Websites now expect their users to verify before entering their passwords. Finally, we replaced the bank's password-entry page with a warning page. After each clue, we determined whether participants entered their passwords or withheld them. We also investigate how a study's design affects participant behavior: we asked some participants to play a role and others to use their own accounts and passwords. We also presented some participants with security-focused instructions. We confirm prior findings that users ignore HTTPS indicators: no participants withheld their passwords when these indicators were removed. We present the first empirical investigation of site-authentication images, and we find them to be ineffective: even when we removed them, 23 of the 25 (92%) participants who used their own accounts entered their passwords. We also contribute the first empirical evidence that role playing affects participants' security behavior: role-playing participants behaved significantly less securely than those using their own passwords. Stuart E. Schechter, Rachna Dhamija, Andy Ozment, Ian Fischer |
S&P | 1 |
| 2006 | Inoculating SSH Against Address Harvesting
Stuart E. Schechter, Jaeyeon Jung, Will Stockwell, Cynthia D. McLain |
NDSS | 1 |
| 2006 | Milk or Wine: Does Software Security Improve with Age?
Andy Ozment, Stuart E. Schechter |
USENIX Security Symposium | 2 |
| 2004 | Fast Detection of Scanning Worm Infections
Stuart E. Schechter, Jaeyeon Jung, Arthur W. Berger |
RAID | 1 |
| 1998 | Using Path Profiles to Predict HTTP Requests
Stuart E. Schechter, Murali Krishnan, Michael D. Smith 0001 |
Comput. Networks | 1 |