Robert W. Reeder

dblp:08/873 · also Rob Reeder · DBLP profile ↗
← Back
30ranked-venue papers
8as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 24 · 5 first-authorSecurity and privacy · 15 · 4 first-authorSystems, architecture and hardware · 2 · 2 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
11 papers
Usable security · 46% Authentication and access control · 33% Web and mobile security · 17%
Human-computer interaction and pervasive computing
5 papers
Ubiquitous computing and smart environments · 51% Usability and user experience research · 31% User interface design and tools · 18%

Topics — the 15 heaviest of 24, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Usable security
security warnings
0.422015
Improving SSL Warnings: Comprehension and Adherence · CHI 2015
Experimenting at scale with google chrome's SSL warning · CHI 2014
Ubiquitous computing and smart environments › domestic technology
domestic technology use
0.212016
"She'll just grab any device that's closer": A Study of Everyday Device & Account Sharing in Households · CHI 2016
Web and mobile security › web security
account hijacking
0.212014
"My religious aunt asked why i was trying to sell her viagra": experiences with account hijacking · CHI 2014
Authentication and access control
account security
0.212014
"My religious aunt asked why i was trying to sell her viagra": experiences with account hijacking · CHI 2014
Web and mobile security
browser security
0.122015
Improving SSL Warnings: Comprehension and Adherence · CHI 2015
Experimenting at scale with google chrome's SSL warning · CHI 2014
Usability and user experience research › evaluation methodology › interface evaluation
interface comparison
0.112010
Visual vs. compact: a comparison of privacy policy interfaces · CHI 2010
Authentication and access control › access control
access control management
0.112009
Real life challenges in access-control management · CHI 2009
Authentication and access control › user authentication
backup authentication
0.112009
It's not what you know, but who you know: a social approach to last-resort authentication · CHI 2009
Authentication and access control › access control policy engineering
policy management
0.112009
Real life challenges in access-control management · CHI 2009
Authentication and access control › user authentication
social authentication
0.112009
It's not what you know, but who you know: a social approach to last-resort authentication · CHI 2009
Authentication and access control
access control policy
0.112008
A user study of policy creation in a flexible access-control system · CHI 2008
Information retrieval › information seeking
information scent
0.012001
Information scent as a driver of Web behavior graphs: results of a protocol analysis method for Web usability · CHI 2001
Information retrieval › user behavior
search behavior
0.012001
Information scent as a driver of Web behavior graphs: results of a protocol analysis method for Web usability · CHI 2001
Usability and user experience research › usability engineering
web usability
0.012001
Information scent as a driver of Web behavior graphs: results of a protocol analysis method for Web usability · CHI 2001
Usable security
security user studies
0.012008
A user study of policy creation in a flexible access-control system · CHI 2008

Methods — techniques the papers use, named apart from their topics

user study · 0.7survey · 0.5taxonomy development · 0.5multiple-methods study · 0.5field experiment · 0.4experience sampling · 0.3microsurvey · 0.2thematic analysis · 0.2error mitigation techniques · 0.1interview study · 0.1experiment · 0.1talk-aloud protocols · 0.1protocol analysis · 0.1
YearPublicationVenuePosition
2018 An Experience Sampling Study of User Reactions to Browser Warnings in the Field
abstract
Web browser warnings should help protect people from malware, phishing, and network attacks. Adhering to warnings keeps people safer online. Recent improvements in warning design have raised adherence rates, but they could still be higher. And prior work suggests many people still do not understand them. Thus, two challenges remain: increasing both comprehension and adherence rates. To dig deeper into user decision making and comprehension of warnings, we performed an experience sampling study of web browser security warnings, which involved surveying over 6,000 Chrome and Firefox users in situ to gather reasons for adhering or not to real warnings. We find these reasons are many and vary with context. Contrary to older prior work, we do not find a single dominant failure in modern warning design---like habituation---that prevents effective decisions. We conclude that further improvements to warnings will require solving a range of smaller contextual misunderstandings.
Robert W. Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson 0002, Serge Egelman
CHI1
2016 "She'll just grab any device that's closer": A Study of Everyday Device & Account Sharing in Households
abstract
Many technologies assume a single user will use an account or device. But account and device sharing situations (when 2+ people use a single device or account) may arise during everyday life. We present results from a multiple-methods study of device and account sharing practices among household members and their relations. Among our findings are that device and account sharing was common, and mobile phones were often shared despite being considered "personal" devices. Based on our study results, we organize sharing practices into a taxonomy of six sharing types--distinct patterns of what, why, and how people shared. We also present two themes that cut across sharing types: that (1) trust in sharees and (2) convenience highly influenced sharing practices. Based on these findings, we discuss implications for study and technology design.
Tara Matthews, Kerwell Liao, Anna Turner, Marianne Berkovich, Robert W. Reeder, Sunny Consolvo
CHI5
2016 Rethinking Connection Security Indicators
Adrienne Porter Felt, Robert W. Reeder, Alex Ainslie, Helen Harris, Max Walker, Christopher Thompson 0002, Mustafa Emre Acer, Elisabeth Morant, Sunny Consolvo
SOUPS2
2015 Improving SSL Warnings: Comprehension and Adherence
abstract
Browsers warn users when the privacy of an SSL/TLS connection might be at risk. An ideal SSL warning would empower users to make informed decisions and, failing that, guide confused users to safety. Unfortunately, users struggle to understand and often disregard real SSL warnings. We report on the task of designing a new SSL warning, with the goal of improving comprehension and adherence. We designed a new SSL warning based on recommendations from warning literature and tested our proposal with microsurveys and a field experiment. We ultimately failed at our goal of a well-understood warning. However, nearly 30% more total users chose to remain safe after seeing our warning. We attribute this success to opinionated design, which promotes safety with visual cues. Subsequently, our proposal was released as the new Google Chrome SSL warning. We raise questions about warning comprehension advice and recommend that other warning designers use opinionated design.
Adrienne Porter Felt, Alex Ainslie, Robert W. Reeder, Sunny Consolvo, Somas Thyagaraja, Alan Bettes, Helen Harris, Jeff Grimes
CHI3
2015 "...No one Can Hack My Mind": Comparing Expert and Non-Expert Security Practices
Iulia Ion, Robert W. Reeder, Sunny Consolvo
SOUPS2
2014 Experimenting at scale with google chrome's SSL warning
abstract
Web browsers show HTTPS authentication warnings (i.e., SSL warnings) when the integrity and confidentiality of users' interactions with websites are at risk. Our goal in this work is to decrease the number of users who click through the Google Chrome SSL warning. Prior research showed that the Mozilla Firefox SSL warning has a much lower click-through rate (CTR) than Chrome. We investigate several factors that could be responsible: the use of imagery, extra steps before the user can proceed, and style choices. To test these factors, we ran six experimental SSL warnings in Google Chrome 29 and measured 130,754 impressions.
Adrienne Porter Felt, Robert W. Reeder, Hazim Almuhimedi, Sunny Consolvo
CHI2
2014 "My religious aunt asked why i was trying to sell her viagra": experiences with account hijacking
abstract
With so much of our lives digital, online, and not entirely under our control, we risk losing access to our communications, reputation, and data. Recent years have brought a rash of high-profile account compromises, but account hijacking is not limited to high-profile accounts. In this paper, we report results of a survey about people's experiences with and attitudes toward account hijacking. The problem is widespread; 30% of our 294 participants had an email or social networking account accessed by an unauthorized party. Five themes emerged from our results: (1) compromised accounts are often valuable to victims, (2) attackers are mostly unknown, but sometimes known, to victims, (3) users acknowledge some responsibility for keeping their accounts secure, (4) users' understanding of important security measures is incomplete, and (5) harm from account hijacking is concrete and emotional. We discuss implications for designing security mechanisms to improve chances for user adoption.
Richard Shay, Iulia Ion, Robert W. Reeder, Sunny Consolvo
CHI3
2014 Your Reputation Precedes You: History, Reputation, and the Chrome Malware Warning
Hazim Almuhimedi, Adrienne Porter Felt, Robert W. Reeder, Sunny Consolvo
SOUPS3
2013 Your attention please: designing security-decision UIs to make genuine risks harder to ignore
abstract
We designed and tested attractors for computer security dialogs: user-interface modifications used to draw users' attention to the most important information for making decisions. Some of these modifications were purely visual, while others temporarily inhibited potentially-dangerous behaviors to redirect users' attention to salient information. We conducted three between-subjects experiments to test the effectiveness of the attractors.
Cristian Bravo-Lillo, Saranga Komanduri, Lorrie Faith Cranor, Robert W. Reeder, Manya Sleeper, Julie S. Downs, Stuart E. Schechter
SOUPS4
2011 More than skin deep: measuring effects of the underlying model on access-control system usability
abstract
In access-control systems, policy rules conflict when they prescribe different decisions (allow or deny) for the same access. We present the results of a user study that demonstrates the significant impact of conflict-resolution method on policy-authoring usability. In our study of 54 participants, varying the conflict-resolution method yielded statistically significant differences in accuracy in five of the six tasks we tested, including differences in accuracy rates of up to 78%. Our results suggest that a conflict-resolution method favoring rules of smaller scope over rules of larger scope is more usable than the Microsoft Windows operating system's method of favoring deny rules over allow rules. Perhaps more importantly, our results demonstrate that even seemingly small changes to a system's semantics can fundamentally affect the system's usability in ways that are beyond the power of user interfaces to correct.
Robert W. Reeder, Lujo Bauer, Lorrie Faith Cranor, Michael K. Reiter, Kami Vaniea
CHI1
2011 Usable access control for all
abstract
No abstract available.
Robert W. Reeder
SACMAT1
2010 Visual vs. compact: a comparison of privacy policy interfaces
abstract
In this paper, we compare the impact of two different privacy policy representations -- AudienceView and Expandable Grids -- on users modifying privacy policies for a social network site. Despite the very different interfaces, there were very few differences in user performance. However, users had clear, and different, preferences and acknowledged the tradeoffs between the two representations. Our results imply that while either interface would be a usable option for policy settings, a combination may appeal to a wider audience and offer the best of both worlds.
Heather Lipford, Jason Watson, Michael Whitney, Katherine Froiland, Robert W. Reeder
CHI5
2009 Real life challenges in access-control management
abstract
In this work we ask the question: what are the challenges of managing a physical or file system access-control policy for a large organization? To answer the question, we conducted a series of interviews with thirteen administrators who manage access-control policy for either a file system or a physical space. Based on these interviews we identified three sets of real-world requirements that are either ignored or inadequately addressed by technology: 1) policies are made/implemented by multiple people; 2) policy makers are distinct from policy implementers; and 3) access-control systems don't always have the capability to implement the desired policy. We present our interview results and propose several possible solutions to address the observed issues.
Lujo Bauer, Lorrie Faith Cranor, Robert W. Reeder, Michael K. Reiter, Kami Vaniea
CHI3
2009 It's not what you know, but who you know: a social approach to last-resort authentication
abstract
Backup authentication mechanisms help users who have forgotten their passwords regain access to their accounts-or at least try. Today's systems fall short in meeting both security and reliability requirements. We designed, built, and tested a new backup authentication system that employs a social-authentication mechanism. The system employs trustees previously appointed by the account holder to verify the account holder's identity. We ran three experiments to determine whether the system could (1) reliably authenticate account holders, (2) resist email attacks that target trustees by impersonating account holders, and (3) resist phone-based attacks from individuals close to account holders. Results were encouraging: seventeen of the nineteen participants who made the effort to call trustees authenticated successfully. However, we also found that users must be reminded of who their trustees are. While email-based attacks were largely unsuccessful, stronger countermeasures will be required to counter highly-personalized phone-based attacks.
Stuart E. Schechter, Serge Egelman, Robert W. Reeder
CHI3
2009 Laissez-faire file sharing: access control designed for individuals at the endpoints
abstract
When organizations deploy file systems with access control mechanisms that prevent users from reliably sharing files with others, these users will inevitably find alternative means to share. Alas, these alternatives rarely provide the same level of confidentiality, integrity, or auditability provided by the prescribed file systems. Thus, the imposition of restrictive mechanisms and policies by system designers and administrators may actually reduce the system's security.
Maritza L. Johnson, Steven M. Bellovin, Robert W. Reeder, Stuart E. Schechter
NSPW3
2009 A Comparative Study of Online Privacy Policies and Formats
Aleecia M. McDonald, Robert W. Reeder, Patrick Gage Kelley, Lorrie Faith Cranor
Privacy Enhancing Technologies2
2009 Usability meets access control: challenges and research opportunities
abstract
This panel discusses specific challenges in the usability of access control technologies and new opportunities for research. The questions vary from "Why nobody, even experts, uses access control lists (ACLs)?" to "Shall access controls (and corresponding languages) be totally embedded and invisible and never, ever seen by the users?" to "What should be the user-study methodology for access control systems?".
Konstantin Beznosov, Philip Inglesant, Jorge Lobo 0001, Robert W. Reeder, Mary Ellen Zurko
SACMAT4
2009 A "nutrition label" for privacy
abstract
We used an iterative design process to develop a privacy label that presents to consumers the ways organizations collect, use, and share personal information. Many surveys have shown that consumers are concerned about online privacy, yet current mechanisms to present website privacy policies have not been successful. This research addresses the present gap in the communication and understanding of privacy policies, by creating an information design that improves the visual presentation and comprehensibility of privacy policies. Drawing from nutrition, warning, and energy labeling, as well as from the effort towards creating a standardized banking privacy notification, we present our process for constructing and refining a label tuned to privacy. This paper describes our design methodology; findings from two focus groups; and accuracy, timing, and likeability results from a laboratory study with 24 participants. Our study results demonstrate that compared to existing natural language privacy policies, the proposed privacy label allows participants to find information more quickly and accurately, and provides a more enjoyable information seeking experience.
Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, Robert W. Reeder
SOUPS4
2009 A comparative study of online privacy policies and formats
abstract
No abstract available.
Aleecia M. McDonald, Robert W. Reeder, Patrick Gage Kelley, Lorrie Faith Cranor
SOUPS2
2009 A user study of the expandable grid applied to P3P privacy policy visualization
abstract
No abstract available.
Robert W. Reeder, Patrick Gage Kelley, Aleecia M. McDonald, Lorrie Faith Cranor
SOUPS1
2009 It's not what you know, but who you know: a social approach to last-resort authentication
abstract
Backup authentication mechanisms help users who have forgotten their passwords regain access to their accounts-or at least try. Today's systems fall short in meeting both security and reliability requirements. We designed, built, and tested a new backup authentication system that employs a social-authentication mechanism. The system employs trustees previously appointed by the account holder to verify the account holder's identity. We ran three experiments to determine whether the system could (1) reliably authenticate account holders, (2) resist email attacks that target trustees by impersonating account holders, and (3) resist phone-based attacks from individuals close to account holders. Results were encouraging: seventeen of the nineteen participants who made the effort to call trustees authenticated successfully. However, we also found that users must be reminded of who their trustees are. While email-based attacks were largely unsuccessful, stronger countermeasures will be required to counter highly-personalized phone-based attacks.
Stuart E. Schechter, Serge Egelman, Robert W. Reeder
SOUPS3
2009 1 + 1 = you: measuring the comprehensibility of metaphors for configuring backup authentication
abstract
Backup authentication systems verify the identity of users who are unable to perform primary authentication usually as a result of forgetting passwords. The two most common authentication mechanisms used for backup authentication by webmail services, personal authentication questions and email-based authentication, are insufficient. Many webmail users cannot benefit from email-based authentication because their webmail account is their primary email account. Personal authentication questions are frequently forgotten and prone to security failures, as illustrated by the increased scrutiny they received following their implication in the compromise of Republican vice presidential candidate Sarah Palin's Yahoo! account.
Stuart E. Schechter, Robert W. Reeder
SOUPS2
2008 A user study of policy creation in a flexible access-control system
abstract
Significant effort has been invested in developing expressive and flexible access-control languages and systems. However, little has been done to evaluate these systems in practical situations with real users, and few attempts have been made to discover and analyze the access-control policies that users actually want to implement. We report on a user study in which we derive the ideal access policies desired by a group of users for physical security in an office environment. We compare these ideal policies to the policies the users actually implemented with keys and with a smartphone-based distributed access-control system. We develop a methodology that allows us to show quantitatively that the smartphone system allowed our users to implement their ideal policies more accurately and securely than they could with keys, and we describe where each system fell short.
Lujo Bauer, Lorrie Faith Cranor, Robert W. Reeder, Michael K. Reiter, Kami Vaniea
CHI3
2008 Expandable grids for visualizing and authoring computer security policies
abstract
We introduce the Expandable Grid, a novel interaction technique for creating, editing, and viewing many types of security policies. Security policies, such as file permissions policies, have traditionally been displayed and edited in user interfaces based on a list of rules, each of which can only be viewed or edited in isolation. These list-of-rules interfaces cause problems for users when multiple rules interact, because the interfaces have no means of conveying the interactions amongst rules to users. Instead, users are left to figure out these rule interactions themselves. An Expandable Grid is an interactive matrix visualization designed to address the problems that list-of-rules interfaces have in conveying policies to users. This paper describes the Expandable Grid concept, shows a system using an Expandable Grid for setting file permissions in the Microsoft Windows XP operating system, and gives results of a user study involving 36 participants in which the Expandable Grid approach vastly outperformed the native Windows XP file-permissions interface on a broad range of policy-authoring tasks.
Robert W. Reeder, Lujo Bauer, Lorrie Faith Cranor, Michael K. Reiter, Kelli Bacon, Keisha How, Heather Strong
CHI1
2007 Usability Challenges in Security and Privacy Policy-Authoring Interfaces
Robert W. Reeder, Clare-Marie Karat, John Karat, Carolyn Brodie
INTERACT (2)1
2006 User Interface Defect Detection by Hesitation Analysis
abstract
Delays and errors are the frequent consequences of people having difficulty with a user interface. Such delays and errors can result in severe problems, particularly for mission-critical applications in which speed and accuracy are of the essence. User difficulty is often caused by interface-design defects that confuse or mislead users. Current techniques for isolating such defects are time-consuming and expensive, because they require human analysts to identify the points at which users experience difficulty; only then can diagnosis and repair of the defects take place. This paper presents an automated method for detecting instances of user difficulty based on identifying hesitations during system use. The method's accuracy was evaluated by comparing its judgments of user difficulty with ground truth generated by human analysts. The method's accuracy at a range of threshold parameter values is given; representative points include 92% of periods of user difficulty identified (with a 35% false-alarm rate); 86% (24% false-alarm rate); and 20% (3% false-alarm rate). Applications of the method to addressing interface defects are discussed
Robert W. Reeder, Roy A. Maxion
DSN1
2005 User Interface Dependability through Goal-Error Prevention
abstract
User interfaces form a critical coupling between humans and computers. When the interface fails, the user fails, and the mission is lost. For example, in computer security applications, human-made configuration errors can expose entire systems to various forms of attack. To avoid interaction failures, a dependable user interface must facilitate the speedy and accurate completion of user tasks. Defects in the interface cause user errors (e.g., goal, plan, action and perception errors), which impinge on speed and accuracy goals, and can lead to mission failure. One source of user error is poor information representation in the interface. This can cause users to commit a specific class of errors - goal errors. A design principle (anchor-based subgoaling) for mitigating this cause was formulated. The principle was evaluated in the domain of setting Windows file permissions. The native Windows XP file permissions interface, which did not support anchor-based subgoaling, was compared to an alternative, called Salmon, which did. In an experiment with 24 users, Salmon achieved as much as a four-fold increase in accuracy for a representative task and a 94% reduction in the number of goal errors committed, compared to the XP interface.
Robert W. Reeder, Roy A. Maxion
DSN1
2005 Improving user-interface dependability through mitigation of human error
Roy A. Maxion, Robert W. Reeder
Int. J. Hum. Comput. Stud.2
2002 A user-tracing architecture for modeling interaction with the world wide web
abstract
We have developed a methodology for studying and analyzing the psychology of users performing ecologically valid WWW tasks. A user trace is a record of all significant states and events in the user-WWW interaction based on eye tracking data, application-level logs, and think-aloud protocols. A user-tracing architecture has been implemented for developing simulation models of user-WWW interaction and for comparing a simulation model (SNIF-ACT) against user-trace data. The user tracing architecture compares each action of the SNIF-ACT simulation directly against observed user actions. The model and architecture have been used to successfully match detailed user trace data from four users working on two tasks each.
Peter Pirolli, Wai-Tat Fu, Robert W. Reeder, Stuart K. Card
AVI3
2001 Information scent as a driver of Web behavior graphs: results of a protocol analysis method for Web usability
abstract
The purpose of this paper is to introduce a replicable WWW protocol analysis methodology illustrated by application to data collected in the laboratory. The methodology uses instrumentation to obtain detailed recordings of user actions with a browser, caches Web pages encoutered, and videotapes talk-aloud protocols. We apply the current form of the method to the analysis of eight Web protocols, visualizing the structure of the interaction and showing the strong effect of information scent in determining the path followed.
Stuart K. Card, Peter Pirolli, Mija M. Van Der Wege, Julie Bauer Morrison, Robert W. Reeder, Pamela K. Schraedley, Jenea Boshart
CHI5