EDBT 2026 Demo / reviewers in the wild / expert
Katharina Krombholz
dblp:128/4803
· DBLP profile ↗
47ranked-venue papers
6as first author
32since 2021 · last 2026
0000-0003-2425-3013ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 6 first-author · 17 since 2021Human-computer interaction and ubiquitous computing · 16 · 1 first-author · 15 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy & Safety Challenges of On-Body Interaction TechniquesabstractOn-body computing systems offer new forms of interaction, but while they are increasingly integrated into everyday contexts, their unique privacy and safety challenges remain understudied. This paper examines these challenges through a two-round interview study with N = 15 experts in human-computer interaction, and privacy and safety, using speculative scenarios and adversarial roleplaying to elicit insights. Our findings reveal risks specific to on-body interactions, including over-collection of sensitive data, unwanted inferences, harm to bystanders, and threats to bodily autonomy and psychological well-being. Importantly, in the on-body context, privacy and safety concerns are deeply interconnected and cannot be addressed in isolation. We contribute an empirically grounded characterization of these entangled challenges and derive eight actionable design guidelines to support safer, more privacy-aware, on-body systems. This work informs future research and design in ubiquitous computing by highlighting the need for proactive and integrated approaches to privacy and safety in trustworthy on-body computing. Dañiel Gerhardt, Divyanshu Bhardwaj 0001, Ashwin Ram 0004, André Zenner, Jürgen Steimle, Katharina Krombholz |
CHI | 6 |
| 2026 | See Me If You Can: A Multi-Layer Protocol for Bystander Privacy with Consent-Based RestorationabstractThe growing popularity of wearable camera glasses raises pressing concerns about bystanders being recorded without their consent. Most existing privacy-enhancing technologies (PETs) rely on opt-out models that place the burden of privacy protection on bystanders. We conducted a qualitative study on wearers’ and bystanders’ perceptions of opt-in, privacy-by-default approaches for camera glasses. To enable this study, we designed and evaluated an opt-in privacy-by-default protocol. We then conducted semi-structured interviews with camera glass wearers and bystanders (N = 18) to examine their perceptions of the protocol. Our findings show that bystanders viewed the opt-in protocol as essential and advocated for even stronger anonymization. Wearers appreciated the protocol’s safeguards but found it visually limiting, expressing desire for a context-dependent version that can be enabled in relevant scenarios. Our findings highlight the need for context-aware PETs that provide effective mechanisms for consent negotiation. Yahya Khawaja, Shirin Rehman, Alexander Ponticello, Divyanshu Bhardwaj 0001, Katharina Krombholz, Muhammad Hamad Alizai, Naveed Anwar Bhatti |
CHI | 5 |
| 2026 | From Discovery to Decisions: Archetypal Journeys of Mobile App Users and Their Implications on PrivacyabstractMobile permission decisions are often studied at the moment a permission request appears. However, our study shows that users’ choices are shaped much earlier, across a multi-stage journey that begins with app-need recognition and unfolds through app discovery, exploration, selection, installation, and first use. Drawing on interviews with 19 U.S. Android users, we map this process and identify four archetypal journeys that explain how early cues, such as discovery sources, app type, and social trust, shape later permission behavior. These insights align with theoretical models like Privacy Calculus, showing how users weigh perceived benefits and risks at each step, and complement Contextual Integrity theory, explaining how social norms and information flows shape expectations and constrain privacy agency across steps. We contribute an empirically grounded framework that clarifies why permission outcomes vary across contexts. Our results reframe mobile privacy as a sequential, path-dependent process, offering implications for future design and research. H. T. M. A. Riyadh, Divyanshu Bhardwaj 0001, Maria Victoria Hellenthal, Alexander Hart, Katharina Krombholz, Sven Bugiel |
CHI | 5 |
| 2026 | Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration Challenges
Sumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz, Mobin Javed |
NDSS | 4 |
| 2026 | Now You See Me, Now You Don't: Consent-Driven Privacy for Smart Glasses
Yahya Khawaja, Eman Nabeel, Sana Humayun, Eruj Javed, Katharina Krombholz, Muhammad Hamad Alizai, Naveed Anwar Bhatti |
PerCom | 5 |
| 2025 | How Blind and Low-Vision Users Manage Their PasswordsabstractManaging passwords securely and conveniently is still an open problem for many users. Existing research has examined users' password management strategies and identified pain points, such as security concerns, leading to insecure practices. We investigate how Blind and Low-Vision (BLV) users tackle this problem and how password managers can assist them. This paper presents the results of a qualitative interview study with N = 33 BLV participants. We found that all participants utilize password managers to some extent, which they perceive as fairly accessible. However, the adoption is mainly driven by the convenience of storing and retrieving passwords. The security advantages -- generating strong, random passwords -- were avoided mainly due to the absence of practical accessibility. Password managers do not adhere to BLV users' underlying needs for agency, which stem from experiences with inaccessible software and vendors who deprioritize accessibility issues. Underutilization of password managers leads BLV users to adopt insecure practices, such as reusing predictable passwords or resorting to 'security through obscurity' by writing important credentials in braille. We conclude our analysis by discussing the need to implement practical accessibility and usability improvements for password managers as a way of establishing trust and secure practices while maintaining BLV users' agency. Alexander Ponticello, Filipo Sharevski, Simon Anell, Katharina Krombholz |
CCS | 4 |
| 2025 | Understanding the Security Advice Mechanisms of Low Socioeconomic PakistanisabstractFigure 1: The helper (on the right) sets up a password for the user's new Android phone. Sumair Ijaz Hashmi, Rimsha Sarfaraz, Lea Gröber, Mobin Javed, Katharina Krombholz |
CHI | 5 |
| 2025 | Analyzing the iOS Local Network Permission from a Technical and User PerspectiveabstractIn the past, malicious apps attacked routers or identified locations through local network communication. To mitigate security and privacy risks from local network access, Apple introduced a new permission with iOS 14. To be effective, the permission needs to protect against technical threats, and users must be able to make an informed permission decision. The latter is presumably hindered by the intrinsic technicality of the concept of the local network. In this paper, we perform the first comprehensive analysis of the local network permission by studying four key aspects. We investigate the security of its implementation by systematically accessing the local network. We explore local network accesses via a large-scale dynamic analysis of 10,862 iOS and Android apps. We analyze the concepts that constitute the permission prompts, as this is all the information users get before making a decision. Based on the identified concepts, we conduct an online survey$(N=150)$to comprehend users' understanding of the permission, their threat awareness, and common misconceptions. Our work reveals two methods to bypass the permission from webviews, and that the protected local network addresses are insufficient. We show how and when apps access the local network, and how the situation differs between iOS and Android. Finally, we present the light and shadow of users' understanding of the permission. While nearly every participant is aware of at least one threat (83.11%), misconceptions are even more common (84.46%). Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz, Martina Lindorfer |
SP | 4 |
| 2025 | Understanding How Users Prepare for and React to Smartphone Theft
Divyanshu Bhardwaj 0001, Sumair Ijaz Hashmi, Katharina Krombholz, Maximilian Golla |
USENIX Security Symposium | 3 |
| 2025 | AirTag-Facilitated Stalking Protection: Evaluating Unwanted Tracking Notifications and Tracker Locating Features
Dañiel Gerhardt, Matthias Fassl, Carolyn Guthoff, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 5 |
| 2024 | Usable Authentication in Virtual Reality: Exploring the Usability of PINs and Gestures
H. T. M. A. Riyadh, Divyanshu Bhardwaj 0001, Adrian Dabrowski, Katharina Krombholz |
ACNS (3) | 4 |
| 2024 | Mental Models, Expectations and Implications of Client-Side Scanning: An Interview Study with ExpertsabstractClient-Side Scanning (CSS) is discussed as a potential solution to contain the dissemination of child sexual abuse material (CSAM). A significant challenge associated with this debate is that stakeholders have different interpretations of the capabilities and frontiers of the concept and its varying implementations. In this paper, we explore stakeholders’ understandings of the technology and the expectations and potential implications in the context of CSAM by conducting and analyzing 28 semi-structured interviews with a diverse sample of experts. We identified mental models of CSS and the expected challenges. Our results show that CSS is often a preferred solution in the child sexual abuse debate due to the lack of an alternative. Our findings illustrate the importance of further interdisciplinary discussions to define and comprehend the impact of CSS usage on society, particularly vulnerable groups such as children. Divyanshu Bhardwaj 0001, Carolyn Guthoff, Adrian Dabrowski, Sascha Fahl, Katharina Krombholz |
CHI | 5 |
| 2024 | In Focus, Out of Privacy: The Wearer's Perspective on the Privacy Dilemma of Camera GlassesabstractThe rising popularity of camera glasses challenges societal norms of recording bystanders and thus requires efforts to mediate privacy preferences. We present the first study on the wearers’ perspectives and explore privacy challenges associated with wearing camera glasses when bystanders are present. We conducted a micro-longitudinal diary study (N = 15) followed by exit interviews with existing users and people without prior experience. Our results show that wearers consider the currently available privacy indicators ineffective. They believe the looks and interaction design of the glasses conceal the technology from unaware people. Due to the lack of effective privacy-mediating measures, wearers feel emotionally burdened with preserving bystanders’ privacy. We furthermore elicit how this sentiment impacts their usage of camera glasses and highlight the need for technical and non-technical solutions. Finally, we compare the wearers’ and bystanders’ perspectives and discuss the design space of a future privacy-preserving ecosystem for wearable cameras. Divyanshu Bhardwaj 0001, Alexander Ponticello, Shreya Tomar, Adrian Dabrowski, Katharina Krombholz |
CHI | 5 |
| 2024 | Let me quickly share it - Time Pressure when Sharing on Social Media
Rebecca Panskus, Tangila Islam Tanni, Alexander Ponticello, Echo Meißner, Yan Solihin, Katharina Krombholz, Karola Marky |
MUM | 6 |
| 2024 | "I chose to fight, be brave, and to deal with it": Threat Experiences and Security Practices of Pakistani Content Creators
Lea Gröber, Waleed Arshad, Shanza, Angelica Goetzen, Elissa M. Redmiles, Maryam Mustafa, Katharina Krombholz |
USENIX Security Symposium | 7 |
| 2024 | Towards Privacy and Security in Private Clouds: A Representative Survey on the Prevalence of Private Hosting and Administrator Characteristics
Lea Gröber, Simon Lenau, Rebecca Weil, Elena Groben, Michael Schilling 0001, Katharina Krombholz |
USENIX Security Symposium | 6 |
| 2024 | Trust Me If You Can - How Usable Is Trusted Types In Practice?
Sebastian Roth, Lea Gröber, Philipp Baus, Katharina Krombholz, Ben Stock |
USENIX Security Symposium | 4 |
| 2023 | Pakistani Teens and Privacy - How Gender Disparities, Religion and Family Values Impact the Privacy Design SpaceabstractThe understanding of how teenagers perceive, manage and perform privacy is less well-understood in spaces outside of Western, educated, industrialised, rich and democratic countries. Maryam Mustafa, Abdul Moeed Asad, Shehrbano Hassan, Urooj Haider, Zainab Durrani, Katharina Krombholz |
CCS | 6 |
| 2023 | Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with AutoethnographyabstractAuthentication ceremonies detect and mitigate Man-in-the-Middle (MitM) attacks on end-to-end encrypted messengers, such as Signal, WhatsApp, or Threema. However, prior work found that adoption remains low as non-expert users have difficulties using them correctly. Anecdotal evidence suggests that security researchers also have trouble authenticating others. Since their issues are probably unrelated to user comprehension or usability, the root causes may lie deeper. Matthias Fassl, Katharina Krombholz |
CHI | 2 |
| 2023 | A Psychometric Scale to Measure Individuals' Value of Other People's Privacy (VOPP)abstractResearchers invested enormous efforts to understand and mitigate the concerns of users as technologies collect their private data. However, users often undermine other people’s privacy when, e.g., posting other people’s photos online, granting mobile applications to access contacts, or using technologies that continuously sense the surrounding. Research to understand technology adoption and behaviors related to collecting and sharing data about non-users has been severely lacking. An essential step to progress in this direction is to identify and quantify factors that affect technology’s use. Toward this goal, we propose and validate a psychometric scale to measure how much an individual values other people’s privacy. We theoretically grounded the appropriateness and relevance of the construct and empirically demonstrated the scale’s internal consistency and validity. This scale will advance the field by enabling researchers to predict behaviors, design adaptive privacy-enhancing technologies, and develop interventions to raise awareness and mitigate privacy risks. Rakibul Hasan 0001, Rebecca Weil, Rudolf Siegel, Katharina Krombholz |
CHI | 4 |
| 2023 | Different Researchers, Different Results? Analyzing the Influence of Researcher Experience and Data Type During Qualitative Analysis of an Interview and Survey Study on Security AdviceabstractWhen conducting qualitative research it is necessary to decide how many researchers should be involved in coding the data: Is one enough or are more coders beneficial? To offer empirical evidence for this question, we designed a series of studies investigating qualitative coding. We replicated and extended a usable security and privacy study by Ion et al. to gather both simple survey data and complex interview data. We had a total of 65 students and seven researchers analyze different parts of this data. We analyzed the codebook creation process, similarity of outcomes, inter-rater reliability, and compared the student to the researcher outcomes. We also surveyed five years of SOUPS-PC members about their views on coding. The reviewers view on coding practices for complex and simple data are almost identical. However, our results suggest that the coding process can be different for the two types of data, with complex data benefiting more from interaction between coders. Anna-Marie Ortloff, Matthias Fassl, Alexander Ponticello, Florin Martius, Anne Mertens, Katharina Krombholz, Matthew Smith 0001 |
CHI | 6 |
| 2023 | Perceptions of Distributed Ledger Technology Key Management - An Interview Study with Finance ProfessionalsabstractKey management is an integral part of using distributed ledger technology (DLT). Previous work has primarily focused on key management for single-user scenarios on Bitcoin. Over the last decade, DLT has evolved to commercial and financial sectors; for example, a new German law allows the trading of a variety of financial securities via DLT. Instead of a single-user paradigm, financial institutions follow a multi-user paradigm. Combining multi-user key management with single-user key management solutions leads to unique challenges with usability and security. We extend current research through a two-stage qualitative interview study with 13 finance professionals. We investigate how the technical reality contrasts with perceptions of key management practices in corporate financial organizations. Our interdisciplinary study shows, among other things, that DLT does not meet real-world requirements in this particular domain. Moreover, it introduces additional challenges in terms of authentication and auditing. Our findings suggest that corporate financial institutions strongly support the adoption of blockchain solutions. However, to comply with regulatory and operational requirements, they face additional usability and security challenges, e.g., authentication and access control. Better mechanisms or novel design approaches are required to cover professional environments. This includes how multiple users can access the same assets and approve joint transactions. Carolyn Guthoff, Simon Anell, Johann Hainzinger, Adrian Dabrowski, Katharina Krombholz |
SP | 5 |
| 2023 | Investigating Verification Behavior and Perceptions of Visual Digital Certificates
Dañiel Gerhardt, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 4 |
| 2023 | To Cloud or not to Cloud: A Qualitative Study on Self-Hosters' Motivation, Operation, and Security Mindset
Lea Gröber, Rafael Mrowczynski, Nimisha Vijay, Daphne A. Muller, Adrian Dabrowski, Katharina Krombholz |
USENIX Security Symposium | 6 |
| 2023 | Investigating Security Folklore: A Case Study on the Tor over VPN PhenomenonabstractUsers face security folklore in their daily lives in the form of security advice, myths, and word-of-mouth stories. Using a VPN to access the Tor network, i.e., Tor over VPN, is an interesting example of security folklore because of its inconclusive security benefits and its occurrence in pop-culture media. Following the Theory of Reasoned Action, we investigated the phenomenon with three studies: (1) we quantified the behavior on real-world Tor traffic and measured a prevalence of 6.23%; (2) we surveyed users' intentions and beliefs, discovering that they try to protect themselves from the Tor network or increase their general security; and (3) we analyzed online information sources, suggesting that perceived norms and ease-of-use play a significant role while behavioral beliefs about the purpose and effect are less crucial in spreading security folklore. We discuss how to communicate security advice effectively and combat security misinformation and misconceptions. Matthias Fassl, Alexander Ponticello, Adrian Dabrowski, Katharina Krombholz |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2023 | Machine Learning Security in Industry: A Quantitative SurveyabstractDespite the large body of academic work on machine learning security, little is known about the occurrence of attacks on machine learning systems in the wild. In this paper, we report on a quantitative study with 139 industrial practitioners. We analyze attack occurrence and concern and evaluate statistical hypotheses on factors influencing threat perception and exposure. Our results shed light on real-world attacks on deployed machine learning. On the organizational level, while we find no predictors for threat exposure in our sample, the amount of implement defenses depends on exposure to threats or expected likelihood to become a target. We also provide a detailed analysis of practitioners’ replies on the relevance of individual machine learning attacks, unveiling complex concerns like unreliable decision making, business information leakage, and bias introduction into models. Finally, we find that on the individual level, prior knowledge about machine learning security influences threat perception. Our work paves the way for more research about adversarial machine learning in practice, but yields also insights for regulation and auditing. Kathrin Grosse, Lukas Bieringer, Tarek R. Besold, Battista Biggio, Katharina Krombholz |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate Context
Veroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters, Katsiaryna Labunets |
USENIX Security Symposium | 3 |
| 2021 | 12 Angry Developers - A Qualitative Study on Developers' Struggles with CSPabstractThe Web has improved our ways of communicating, collaborating, teaching, and entertaining us and our fellow human beings. However, this cornerstone of our modern society is also one of the main targets of attacks, most prominently Cross-Site Scripting (XSS). A correctly crafted Content Security Policy (CSP) is capable of effectively mitigating the effect of those Cross-Site Scripting attacks. However, research has shown that the vast majority of all policies in the wild are trivially bypassable. Sebastian Roth, Lea Gröber, Michael Backes 0001, Katharina Krombholz, Ben Stock |
CCS | 4 |
| 2021 | Exploring User-Centered Security Design for Usable Authentication CeremoniesabstractSecurity technology often follows a systems design approach that focuses on components instead of users. As a result, the users’ needs and values are not sufficiently addressed, which has implications on security usability. In this paper, we report our lessons learned from applying a user-centered security design process to a well-understood security usability challenge, namely key authentication in secure instant messaging. Users rarely perform these key authentication ceremonies, which makes their end-to-end encrypted communication vulnerable. Our approach includes collaborative design workshops, an expert evaluation, iterative storyboard prototyping, and an online evaluation. Matthias Fassl, Lea Gröber, Katharina Krombholz |
CHI | 3 |
| 2021 | Investigating Car Drivers' Information Demand after Safety and Security Critical IncidentsabstractModern cars include a vast array of computer systems designed to remove the burden on drivers and enhance safety. As cars are evolving towards autonomy and taking over control, e.g. in the form of autopilots, it becomes harder for drivers to pinpoint the root causes of a car’s malfunctioning. Drivers may need additional information to assess these ambiguous situations correctly. However, it is yet unclear which information is relevant and helpful to drivers in such situations. Hence, we conducted a mixed-methods online survey (N = 60) on Amazon MTurk where we exposed participants to two security- and safety-critical situations with one of three different explanations. We applied Thematic and Correspondence Analysis to understand which factors in these situations moderate drivers’ information demand. We identified a fundamental information demand across scenarios that is expanded by error-specific information types. Moreover, we found that it is necessary to communicate error sources, since drivers might not be able to identify them correctly otherwise. Thereby, malicious intrusions are typically perceived as more critical than technical malfunctions. Lea Gröber, Matthias Fassl, Abhilash Gupta, Katharina Krombholz |
CHI | 4 |
| 2021 | On the Usability of Authenticity Checks for Hardware Security Tokens
Katharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer, Philipp Schindler, Edgar R. Weippl, Michael Franz, Katharina Krombholz |
USENIX Security Symposium | 8 |
| 2021 | A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security ResearchabstractUsable privacy and security researchers have developed a variety of approaches to represent risk to research participants. To understand how these approaches are used and when each might be most appropriate, we conducted a systematic literature review of methods used in security and privacy studies with human participants. From a sample of 633 papers published at five top conferences between 2014 and 2018 that included keywords related to both security/privacy and usability, we systematically selected and analyzed 284 full-length papers that included human subjects studies. Our analysis focused on study methods; risk representation; the use of prototypes, scenarios, and educational intervention; the use of deception to simulate risk; and types of participants. We discuss benefits and shortcomings of the methods, and identify key methodological, ethical, and research challenges when representing and assessing security and privacy risk. We also provide guidelines for the reporting of user studies in security and privacy. Verena Distler, Matthias Fassl, Hana Habib, Katharina Krombholz, Gabriele Lenzini, Carine Lallemand, Lorrie Faith Cranor, Vincent Koenig |
ACM Trans. Comput. Hum. Interact. | 4 |
| 2020 | VisualPhishNet: Zero-Day Phishing Website Detection by Visual SimilarityabstractPhishing websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, similarity-based detection methods do not offer sufficient protection for the trusted websites, in particular against unseen phishing pages. This paper contributes VisualPhishNet, a new similarity-based phishing detection framework, based on a triplet Convolutional Neural Network (CNN). VisualPhishNet learns profiles for websites in order to detect phishing websites by a similarity metric that can generalize to pages with new visual appearances. We furthermore present VisualPhish, the largest dataset to date that facilitates visual phishing detection in an ecologically valid manner. We show that our method outperforms previous visual similarity phishing detection approaches by a large margin while being robust against a range of evasion attacks. Sahar Abdelnabi, Katharina Krombholz, Mario Fritz |
CCS | 2 |
| 2019 | Poster: Let History not Repeat Itself (this Time) - Tackling WebAuthn Developer Issues Early OnabstractThe FIDO2 open authentication standard, developed jointly by the FIDO Alliance and the W3C, provides end-users with the means to use public-key cryptography in addition to or even instead of text-based passwords for authentication on the web. Its WebAuthn protocol has been adopted by all major browser vendors and recently also by major service providers (e.g., Google, GitHub, Dropbox, Microsoft, and others). Thus, FIDO2 is a very strong contender for finally tackling the problem of insecure user authentication on the web. However, there remain a number of open questions to be answered for FIDO2 to succeed as expected. In this poster, we focus specifically on the critical question of how well web-service developers can securely roll out WebAuthn in their own services and which issues have to be tackled to help developers in this task. The past has unfortunately shown that software developers struggle with correctly implementing or using security-critical APIs, such as TLS/SSL, password storage, or cryptographic APIs. We report here on ongoing work that investigates potential problem areas and concrete pitfalls for adopters of WebAuthn and tries to lay out a plan of how our community can help developers. We believe that raising awareness for foreseeable developer problems and calling for action to support developers early on is critical on the path for establishing FIDO2 as a de-facto authentication solution. Katharina Krombholz, Sven Bugiel |
CCS | 2 |
| 2019 | A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done RightabstractThe correct configuration of HTTPS is a complex set of tasks, which many administrators have struggled with in the past. Let's Encrypt and Electronic Frontier Foundation's Certbot aim to improve the TLS ecosystem by offering free trusted certificates (Let's Encrypt) and by providing user-friendly support to configure and harden TLS (Certbot). Although adoption rates have increased, to date, there has been only a little scientific evidence of the actual usability and security benefits of this semi-automated approach. Therefore, we conducted a randomized control trial to evaluate the usability of Let's Encrypt and Certbot in comparison to the traditional certificate authority approach. We performed a within-subjects lab study with 31 participants. The study sheds light on the security and usability enhancements that Let's Encrypt and Certbot provide. We highlight how usability improvements aimed at administrators can have a large impact on security and discuss takeaways for Certbot and other security-related tasks that experts struggle with. Christian Tiefenau, Emanuel von Zezschwitz, Maximilian Häring, Katharina Krombholz, Matthew Smith 0001 |
CCS | 4 |
| 2019 | "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSabstractHTTPS is one of the most important protocols used to secure communication and is, fortunately, becoming more pervasive. However, especially the long tail of websites is still not sufficiently secured. HTTPS involves different types of users, e.g., end users who are forced to make critical security decisions when faced with warnings or administrators who are required to deal with cryptographic fundamentals and complex decisions concerning compatibility. In this work, we present the first qualitative study of both end user and administrator mental models of HTTPS. We interviewed 18 end users and 12 administrators; our findings reveal misconceptions about security benefits and threat models from both groups. We identify protocol components that interfere with secure configurations and usage behavior and reveal differences between administrator and end user mental models. Our results suggest that end user mental models are more conceptual while administrator models are more protocol-based. We also found that end users often confuse encryption with authentication, significantly underestimate the security benefits of HTTPS, and ignore and distrust security indicators while administrators often do not understand the interplay of functional protocol components. Based on the different mental models, we discuss implications and provide actionable recommendations for future designs of user interfaces and protocols. Katharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 0001, Emanuel von Zezschwitz |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | Investigating System Operators' Perspective on Security MisconfigurationsabstractNowadays, security incidents have become a familiar "nuisance," and they regularly lead to the exposure of private and sensitive data. The root causes for such incidents are rarely complex attacks. Instead, they are enabled by simple misconfigurations, such as authentication not being required, or security updates not being installed. For example, the leak of over 140 million Americans' private data from Equifax's systems is among most severe misconfigurations in recent history: The underlying vulnerability was long known, and a security patch had been available for months, but was never applied. Ultimately, Equifax blamed an employee for forgetting to update the affected system, highlighting his personal responsibility. In this paper, we investigate the operators' perspective on security misconfigurations to approach the human component of this class of security issues. We focus our analysis on system operators, who have not received significant attention by prior research. Hence, we investigate their perspective with an inductive approach and apply a multi-step empirical methodology: (i), a qualitative study to understand how to approach the target group and measure the misconfiguration phenomenon (ii) a quantitative survey rooted in the qualitative data. We then provide the first analysis of system operators' perspective on security misconfigurations, and we determine the factors that operators perceive as the root causes. Based on our findings, we provide practical recommendations on how to reduce security misconfigurations' frequency and impact. Constanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias Fiebig |
CCS | 2 |
| 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS
Katharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. Weippl |
USENIX Security Symposium | 1 |
| 2016 | Hand Dynamics for Behavioral User AuthenticationabstractWe propose and evaluate a method to authenticate individuals by their unique hand dynamics, based on measurements from wearable sensors. Our approach utilises individual characteristics of hand movement when opening a door. We implement a sensor-fusion machine learning algorithm to classify individuals based on their hand movement and conduct a lab study with 20 participants to test the feasibility of the concept in the context of accessing physical doors as found in office buildings. Our results show that our approach yields an accuracy of 92% in classifying an individual and thus highlights the potential for behavioral hand dynamics for authentication. Fuensanta Torres Garcia, Katharina Krombholz, Rudolf Mayer, Edgar R. Weippl |
ARES | 2 |
| 2016 | Use the Force: Evaluating Force-Sensitive Authentication for Mobile Devices
Katharina Krombholz, Thomas Hupperich, Thorsten Holz |
SOUPS | 1 |
| 2015 | QR Code Security - How Secure and Usable Apps Can Protect Users Against Malicious QR CodesabstractQR codes have emerged as a popular medium to make content instantly accessible. With their high information density and robust error correction, they have found their way to the mobile ecosystem. However, QR codes have also proven to be an efficient attack vector, e.g. To perform phishing attacks. Attackers distribute malicious codes under false pretenses in busy places or paste malicious QR codes over already existing ones on billboards. Ultimately, people depend on reader software to ascertain if a given QR code is benign or malicious. In this paper, we present a comprehensive analysis of QR code security. We determine why users are still susceptible to QR code based attacks and why currently deployed smartphone apps are unable to mitigate these attacks. Based on our findings, we present a set of design recommendations to build usable and secure mobile applications. To evaluate our guidelines, we implemented a prototype and found that secure and usable apps can effectively protect users from malicious QR codes. Katharina Krombholz, Peter Frühwirt, Thomas Rieder, Ioannis Kapsalis, Johanna Ullrich, Edgar R. Weippl |
ARES | 1 |
| 2015 | On Reconnaissance with IPv6: A Pattern-Based Scanning ApproachabstractToday's capability of fast Internet-wide scanning allows insights into the Internet ecosystem, but the on-going transition to the new Internet Protocol version 6 (IPv6) makes the approach of probing all possible addresses infeasible, even at current speeds of more than a million probes per second. As a consequence, the exploitation of frequent patterns has been proposed to reduce the search space. Current patterns are manually crafted and based on educated guesses of administrators. At the time of writing, their adequacy has not yet been evaluated. In this paper, we assess the idea of pattern-based scanning for the first time, and use an experimental set-up in combination with three real-world data sets. In addition, we developed a pattern-based algorithm that automatically discovers patterns in a sample and generates addresses for scanning based on its findings. Our experimental results confirm that pattern-based scanning is a promising approach for IPv6 reconnaissance, but also that currently known patterns are of limited benefit and are outperformed by our new algorithm. Our algorithm not only discovers more addresses, but also finds implicit patterns. Furthermore, it is more adaptable to future changes in IPv6 addressing and harder to mitigate than approaches with manually crafted patterns. Johanna Ullrich, Peter Kieseberg, Katharina Krombholz, Edgar R. Weippl |
ARES | 3 |
| 2015 | Advanced social engineering attacks
Katharina Krombholz, Heidelinde Hobel, Markus Huber 0001, Edgar R. Weippl |
J. Inf. Secur. Appl. | 1 |
| 2014 | Towards a Hardware Trojan Detection CycleabstractIntentionally inserted malfunctions in integrated circuits, referred to as Hardware Trojans, have become an emerging threat. Recently, the scientific community started to propose technical approaches to mitigate the threat of unspecified and potentially malicious functionality. However, these detection and prevention mechanisms are still hardly integrated in the industry's Hardware development life cycles. We therefore propose in this work a secure hardware development life cycle that assembles methods from trustworthy software engineering. In addition to full traceability from specification to implementation, and down to each gate, we introduce a feedback detection cycle that systematically escorts every single step of the development process. To do so, we integrate different detection methods for each development phase that are derived from a common knowledge base. Adrian Dabrowski, Heidelinde Hobel, Johanna Ullrich, Katharina Krombholz, Edgar R. Weippl |
ARES | 4 |
| 2014 | Automated Analysis of Underground Marketplaces
Aleksandar Hudic, Katharina Krombholz, Thomas Otterbein, Christian Platzer, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 2 |
| 2014 | A Decision Framework Model for Migration into Cloud: Business, Application, Security and Privacy PerspectivesabstractCloud computing offers a different, affordable approach for supporting the IT needs of organisations. However, despite the unprecedented benefits cloud migration may bring, there are numerous difficulties involved in moving business critical applications, legacy systems or corporate data into the cloud. It is necessary to consider a broad view over all business areas, and taking into account the technical and business minutiae of a full scale cloud migration, as well as the wider concerns of security, privacy and other business and technical risks. A detailed understanding of all these areas is required in order to make the correct decisions concerning cloud migration. This paper aims to take a broad view of the issues relating to migration. We propose a process model to identify risks and requirements, as well as to provide control assurance during the migration decision. We also define an outline migration strategy by focusing on the context of the organisation. Shareeful Islam, Edgar R. Weippl, Katharina Krombholz |
iiWAS | 3 |
| 2013 | Social engineering attacks on the knowledge workerabstractSocial engineering has become an emerging threat in virtual communities and is an effective means to attack information systems. Today's knowledge workers make use of a number of services that leverage sophisticated social engineering attacks. Moreover, there is a trend towards BYOD (bring your own device) policies and the usage of online communication and collaboration tools in private and business environments. In globally acting companies, teams are no longer geographically co-located but staffed just-in-time. The decrease in personal interaction combined with the plethora of tools used (E-Mail, IM, Skype, Dropbox, LinkedIn, Lync, etc.) create new attack vectors for social engineering attacks. Recent attacks on companies such as the New York Times, RSA, or Apple have shown that targeted spear-phishing attacks are an effective evolution of social engineering attacks. When combined with zero-day-exploits they become a dangerous weapon, often used by advanced persistent threats. This paper provides a taxonomy of well-known social engineering attacks as well as a comprehensive overview of advanced social engineering attacks on the knowledge worker. Katharina Krombholz, Heidelinde Hobel, Markus Huber 0001, Edgar R. Weippl |
SIN | 1 |