EDBT 2026 Demo / reviewers in the wild / expert
Patrick Gage Kelley
dblp:15/3631
· DBLP profile ↗
55ranked-venue papers
9as first author
23since 2021 · last 2026
0000-0003-4405-0010ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 40 · 8 first-author · 16 since 2021Security and privacy · 26 · 3 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "It didn't feel right but I needed a job so desperately": Understanding People's Emotions and Help Needs During ScamsabstractOnline financial scams represent a long-standing and serious threat for which people seek help. We present a study to understand people’s in situ motivations for engaging with scams and the help needs they express before, during, and after encountering a scam. We identify the main emotions scammers exploited (e.g., fear, hope) and characterize how they did so. We examine factors—such as financial insecurity and legal precarity—which elevate people’s risk of engaging with specific scams and experiencing harm. We indicate when people sought help and describe their help-seeking needs and emotions at different stages of the scam. We discuss how these needs could be met through the design of contextually-specific prevention, diagnostic, mitigation, and recovery interventions. Jake Chanenson, Tara Matthews, Sunny Consolvo, Patrick Gage Kelley, Jessica McClearn, Sarah Meiklejohn, Renee Shelby, Kurt Thomas, Amelia Hassoun |
CHI | 4 |
| 2026 | Who Is At Risk? Examining the Prevalence of Digital-Safety Attacks and Contextual Risk Factors in the United StatesabstractA growing body of qualitative research has identified contextual risk factors that elevate people’s chances of experiencing digital-safety attacks. However, the lack of quantitative data on the population-level distribution of these risk factors prevents policymakers and tech companies from developing targeted, evidence-based interventions to improve digital safety. To address this gap, we surveyed 5,001 adults in the United States to analyze: (1) the frequency of and relationship between digital-safety attacks (e.g., scams, harassment, account hacking), and (2) how these attacks align with 10 contextual risk factors. Nearly half of our respondents identify as resource constrained, which significantly correlates with higher likelihood of experiencing four common attacks. We also present qualitative insights to expand our understanding of the factors beyond the existing literature (e.g., “prominence” included high-visibility roles in local communities). This study provides the first large-scale quantitative analysis correlating digital-safety attacks with contextual risk factors and demographics. Sharon Heung, Claire Weizenegger, Mo Houtti, Sunny Consolvo, Patrick Gage Kelley, Tara Matthews, Renee Shelby, Kurt Thomas, Ashley Marie Walker |
CHI | 5 |
| 2026 | How Generative AI Empowers Attackers and Defenders Across the Trust & Safety LandscapeabstractGenerative AI (GenAI) is a powerful technology poised to reshape Trust & Safety. While misuse by attackers is a growing concern, its defensive capacity remains underexplored. This paper examines these effects through a qualitative study with 43 Trust & Safety experts across five domains: child safety, election integrity, hate and harassment, scams, and violent extremism. Our findings characterize a landscape in which GenAI empowers both attackers and defenders. GenAI dramatically increases the scale and speed of attacks, lowering the barrier to entry for creating harmful content, including sophisticated propaganda and deepfakes. Conversely, defenders envision leveraging GenAI to detect and mitigate harmful content at scale, conduct investigations, deploy persuasive counternarratives, improve moderator wellbeing, and offer user support. This work provides a strategic framework for understanding GenAI’s impact on Trust & Safety and charts a path for its responsible use in creating safer online environments. Patrick Gage Kelley, Steven Rousso-Schindler, Renee Shelby, Kurt Thomas, Allison Woodruff |
CHI | 1 |
| 2025 | "Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business Enabler
Kimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass, Patrick Gage Kelley, Kurt Thomas, Zakir Durumeric |
CHI | 5 |
| 2025 | "We are not Future-ready": Understanding AI Privacy Risks and Existing Mitigation Strategies from the Perspective of AI Developers in Europe
Alexandra Klymenko, Stephen Meisenbacher, Patrick Gage Kelley, Sai Teja Peddinti, Kurt Thomas, Florian Matthes |
SOUPS | 3 |
| 2025 | Integrating Large Language Models into Security Incident Response
Diana Kramer, Lambert Rosique, Ajay Narotam, Elie Bursztein, Patrick Gage Kelley, Kurt Thomas, Allison Woodruff |
SOUPS | 5 |
| 2025 | Supporting Human Raters with the Detection of Harmful Content Using Large Language ModelsabstractIn this paper, we explore the feasibility of leveraging large language models (LLMs) to automate or otherwise assist human raters with identifying harmful content including hate speech, harassment, violent extremism, and election misinformation. Using a dataset of 50,000 user comments, we demonstrate that LLMs can achieve 90 % accuracy when compared to human verdicts. We explore how to best leverage these capabilities, proposing five design patterns that integrate LLMs with human rating, such as pre-filtering non-violative content, detecting potential errors in human rating, or surfacing critical context to support human rating. We outline how to support all of these design patterns using a single, optimized prompt. Beyond these synthetic experiments, we share how piloting our proposed techniques in a real-world review queue yielded a 41.5% improvement in optimizing available human rater capacity, and a 9–11 % increase (absolute) in precision and recall for detecting violative content. Kurt Thomas, Patrick Gage Kelley, David Tao, Sarah Meiklejohn, Owen Vallis, Shunwen Tan, Blaz Bratanic, Felipe Tiengo Ferreira, Vijay Eranti, Elie Bursztein |
SP | 2 |
| 2025 | Help-seeking and Coping Strategies for Technology-facilitated Abuse Experienced by YouthabstractTechnology provides youth (ages 10--17) with near-constant opportunities for learning, communication, and self-expression. It can also expose them to technology-facilitated abuse: harassment, coercion, fraud, and more. The ability of youth to navigate such abuse is crucial for their well-being and development. A recent advisory by the U.S. Surgeon General called for better support of youth, including that youth should ''reach out for help.'' However, little is known about how youth seek help or otherwise cope with technology-facilitated abuse. Through a qualitative study in the U.S., we examine how youth engage in self-reliance, seek help from others, and how others seek help on a youth's behalf. We discuss these strategies and outline opportunities for how the HCI community can better support youth who experience technology-facilitated abuse. Diana Freed, Sunny Consolvo, Dan Cosley, Patrick Gage Kelley, Ender Ricart, Kurt Thomas, Natalya N. Bazarova |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2025 | Supporting the Digital Safety of At-Risk Users: Lessons Learned from 9+ Years of Research and TrainingabstractCreating information technologies intended for broad use that allow everyone to participate safely online—which we refer to as inclusive digital safety —requires understanding and addressing the digital-safety needs of a diverse range of users who face elevated risk of technology-facilitated attacks or disproportionate harm from such attacks—i.e., at-risk users . This article draws from more than 9 years of our work at Google to understand and support the digital safety of at-risk users—including survivors of intimate partner abuse, people involved with political campaigns, content creators, youth, and more—in technology intended for broad use. Among our learnings is that designing for inclusive digital safety across widely varied user needs and dynamic contexts is a wicked problem with no “correct” solution. Given this, we describe frameworks and design principles we have developed to help make at-risk research findings practically applicable to technologies intended for broad use and lessons we have learned about communicating them to practitioners. Tara Matthews, Elie Bursztein, Patrick Gage Kelley, Lea Kissner, Andreas Kramm, Andrew Oplinger, Andreas Schou, Manya Sleeper, Stephan Somogyi, Dalila Szostak, Kurt Thomas, Anna Turner, Jill Palzkill Woelfer, Lawrence You, Izzie Zahorian, Sunny Consolvo |
ACM Trans. Comput. Hum. Interact. | 3 |
| 2024 | How Knowledge Workers Think Generative AI Will (Not) Transform Their IndustriesabstractGenerative AI is expected to have transformative effects in multiple knowledge industries. To better understand how knowledge workers expect generative AI may affect their industries in the future, we conducted participatory research workshops for seven different industries, with a total of 54 participants across three US cities. We describe participants’ expectations of generative AI’s impact, including a dominant narrative that cut across the groups’ discourse: participants largely envision generative AI as a tool to perform menial work, under human review. Participants do not generally anticipate the disruptive changes to knowledge industries currently projected in common media and academic narratives. Participants do however envision generative AI may amplify four social forces currently shaping their industries: deskilling, dehumanization, disconnection, and disinformation. We describe these forces, and then we provide additional detail regarding attitudes in specific knowledge industries. We conclude with a discussion of implications and research challenges for the HCI community. Allison Woodruff, Renee Shelby, Patrick Gage Kelley, Steven Rousso-Schindler, Jamila Smith-Loud, Lauren Wilcox |
CHI | 3 |
| 2024 | SoK: Safer Digital-Safety Research Involving At-Risk UsersabstractResearch involving at-risk users—that is, users who are more likely to experience a digital attack or to be disproportionately affected when harm from such an attack occurs—can pose significant safety challenges to both users and researchers. Nevertheless, pursuing research in computer security & privacy (S&P) is crucial to understanding how to meet the digital-safety needs of at-risk users and to design safer technology for all. To standardize and bolster safer research involving such users, we offer an analysis of 196 academic works to elicit 14 research risks and 36 safety practices used by a growing community of researchers. We pair this inconsistent set of reported safety practices with oral histories from 12 domain experts to contribute scaffolded and consolidated pragmatic guidance that researchers can use to plan, execute, and share safer digital-safety research involving at-risk users. We conclude by suggesting areas for future research regarding the reporting, study, and funding of at-risk user research. Rosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla, Tara Matthews, Sunny Consolvo, Jill Palzkill Woelfer, Patrick Gage Kelley, Michelle L. Mazurek, Dana Cuomo, Nicola Dell, Thomas Ristenpart |
SP | 8 |
| 2024 | Understanding Help-Seeking and Help-Giving on Social Media for Image-Based Sexual Abuse
Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Tara Matthews, Sarah Meiklejohn, Franziska Roesner, Renee Shelby, Kurt Thomas, Rebecca Umbach |
USENIX Security Symposium | 3 |
| 2023 | Understanding Digital-Safety Experiences of Youth in the U.SabstractThe seamless integration of technology into the lives of youth has raised concerns about their digital safety. While prior work has explored youth experiences with physical, sexual, and emotional threats—such as bullying and trafficking—a comprehensive and in-depth understanding of the myriad threats that youth experience is needed. By synthesizing the perspectives of 36 youth and 65 adult participants from the U.S., we provide an overview of today’s complex digital-safety landscape. We describe attacks youth experienced, how these moved across platforms and into the physical world, and the resulting harms. We also describe protective practices the youth and the adults who support them took to prevent, mitigate, and recover from attacks, and key barriers to doing this effectively. Our findings provide a broad perspective to help improve digital safety for youth and set directions for future work. Diana Freed, Natalya N. Bazarova, Sunny Consolvo, Eunice J. Han, Patrick Gage Kelley, Kurt Thomas, Dan Cosley |
CHI | 5 |
| 2023 | Practicing Information Sensibility: How Gen Z Engages with Online InformationabstractAssessing the trustworthiness of information online is complicated. Literacy-based paradigms are both widely used to help and widely critiqued. We conducted a study with 35 Gen Zers from across the U.S. to understand how they assess information online. We found that they tended to encounter—rather than search for—information, and that those encounters were shaped more by social motivations than by truth-seeking queries. For them, information processing is fundamentally a social practice. Gen Zers interpreted online information together, as aspirational members of social groups. Our participants sought information sensibility: a socially-informed awareness of the value of information encountered online. We outline key challenges they faced and practices they used to make sense of information. Our findings suggest that like their information sensibility practices, solutions and strategies to address misinformation should be embedded in social contexts online. Amelia Hassoun, Ian Beacock, Sunny Consolvo, Beth Goldberg, Patrick Gage Kelley, Daniel M. Russell |
CHI | 5 |
| 2023 | "There's so much responsibility on users right now: " Expert Advice for Staying Safer From Hate and HarassmentabstractOnline hate and harassment poses a threat to the digital safety of people globally. In light of this risk, there is a need to equip as many people as possible with advice to stay safer online. We interviewed 24 experts to understand what threats and advice internet users should prioritize to prevent or mitigate harm. As part of this, we asked experts to evaluate 45 pieces of existing hate-and-harassment-specific digital-safety advice to understand why they felt advice was viable or not. We find that experts frequently had competing perspectives for which threats and advice they would prioritize. We synthesize sources of disagreement, while also highlighting the primary threats and advice where experts concurred. Our results inform immediate efforts to protect users from online hate and harassment, as well as more expansive socio-technical efforts to establish enduring safety. Miranda Wei, Sunny Consolvo, Patrick Gage Kelley, Tadayoshi Kohno, Franziska Roesner, Kurt Thomas |
CHI | 3 |
| 2023 | "Discover AI in Daily Life": An AI Literacy Lesson for Middle School StudentsabstractWe describe "Discover AI in Daily Life", a lesson in Google's Applied Digital Skills curriculum. The lesson introduces elements of AI literacy and is freely available online at g.co/DiscoverAI. It is designed for middle school students while also supporting high school and adult learners. Allison Woodruff, Annica Schjott Voneche, Kelly Thunstrom, Reena Jana, Rebecca L. Hardy, Derek R. Aoki, Patrick Gage Kelley |
SIGCSE (2) | 7 |
| 2023 | "There will be less privacy, of course": How and why people in 10 countries expect AI will affect privacy in the future
Patrick Gage Kelley, Celestina Cornejo, Lisa Hayes, Ellie Shuo Jin, Aaron Sedley, Kurt Thomas, Allison Woodruff |
SOUPS | 1 |
| 2023 | "Millions of people are watching you": Understanding the Digital-Safety Needs and Practices of Creators
Patrawat Samermit, Anna Turner, Patrick Gage Kelley, Tara Matthews, Vanessia Wu, Sunny Consolvo, Kurt Thomas |
USENIX Security Symposium | 3 |
| 2022 | "It's common and a part of being a content creator": Understanding How Creators Experience and Cope with Hate and Harassment OnlineabstractContent creators—social media personalities with large audiences on platforms like Instagram, TikTok, and YouTube—face a heightened risk of online hate and harassment. We surveyed 135 creators to understand their personal experiences with attacks (including toxic comments, impersonation, stalking, and more), the coping practices they employ, and gaps they experience with existing solutions (such as moderation or reporting). We find that while a majority of creators view audience interactions favorably, nearly every creator could recall at least one incident of hate and harassment, and attacks are a regular occurrence for one in three creators. As a result of hate and harassment, creators report self-censoring their content and leaving platforms. Through their personal stories, their attitudes towards platform-provided tools, and their strategies for coping with attacks and harms, we inform the broader design space for how to better protect people online from hate and harassment. Kurt Thomas, Patrick Gage Kelley, Sunny Consolvo, Patrawat Samermit, Elie Bursztein |
CHI | 2 |
| 2022 | SoK: A Framework for Unifying At-Risk User ResearchabstractAt-risk users are people who experience risk factors that augment or amplify their chances of being digitally attacked and/or suffering disproportionate harms. In this systematization work, we present a framework for reasoning about at-risk users based on a wide-ranging meta-analysis of 95 papers. Across the varied populations that we examined (e.g., children, activists, people with disabilities), we identified 10 unifying contextual risk factors —such as marginalization and access to a sensitive resource —that augment or amplify digital-safety risks and their resulting harms. We also identified technical and non-technical practices that at-risk users adopt to attempt to protect themselves from digital-safety risks. We use this framework to discuss barriers that limit at-risk users’ ability or willingness to take protective actions. We believe that researchers and technology creators can use our framework to identify and shape research investments to benefit at-risk users, and to guide technology design to better support at-risk users. Noel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul, Sunny Consolvo, Patrick Gage Kelley, Nathan Malkin, Michelle L. Mazurek, Manya Sleeper, Kurt Thomas |
SP | 6 |
| 2021 | Exciting, Useful, Worrying, Futuristic: Public Perception of Artificial Intelligence in 8 CountriesabstractAs the influence and use of artificial intelligence (AI) have grown and its transformative potential has become more apparent, many questions have been raised regarding the economic, political, social, and ethical implications of its use. Public opinion plays an important role in these discussions, influencing product adoption, commercial development, research funding, and regulation. In this paper we present results of an in-depth survey of public opinion of artificial intelligence conducted with 10,005 respondents spanning eight countries and six continents. We report widespread perception that AI will have significant impact on society, accompanied by strong support for the responsible development and use of AI, and also characterize the public's sentiment towards AI with four key themes (exciting, useful, worrying, and futuristic) whose prevalence distinguishes response to AI in different countries. Patrick Gage Kelley, Courtney Heldreth, Christopher Moessner, Aaron Sedley, Andreas Kramm, David T. Newman, Allison Woodruff |
AIES | 1 |
| 2021 | SoK: Hate, Harassment, and the Changing Landscape of Online AbuseabstractWe argue that existing security, privacy, and antiabuse protections fail to address the growing threat of online hate and harassment. In order for our community to understand and address this gap, we propose a taxonomy for reasoning about online hate and harassment. Our taxonomy draws on over 150 interdisciplinary research papers that cover disparate threats ranging from intimate partner violence to coordinated mobs. In the process, we identify seven classes of attacks—such as toxic content and surveillance—that each stem from different attacker capabilities and intents. We also provide longitudinal evidence from a three-year survey that hate and harassment is a pervasive, growing experience for online users, particularly for at-risk communities like young adults and people who identify as LGBTQ+. Responding to each class of hate and harassment requires a unique strategy and we highlight five such potential research directions that ultimately empower individuals, communities, and platforms to do so. Kurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh, Elie Bursztein, Sunny Consolvo, Nicola Dell, Zakir Durumeric, Patrick Gage Kelley, Deepak Kumar 0006, Damon McCoy, Sarah Meiklejohn, Thomas Ristenpart, Gianluca Stringhini |
SP | 9 |
| 2021 | "Why wouldn't someone think of democracy as a target?": Security practices & challenges of people involved with U.S. political campaigns
Sunny Consolvo, Patrick Gage Kelley, Tara Matthews, Kurt Thomas, Lee Dunn, Elie Bursztein |
USENIX Security Symposium | 2 |
| 2019 | Protecting accounts from credential stuffing with password breach alerting
Kurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan, Patrick Gage Kelley, Luca Invernizzi, Borbala Benko, Tadek Pietraszek, Sarvar Patel, Dan Boneh, Elie Bursztein |
USENIX Security Symposium | 5 |
| 2016 | An Inconvenient Trust: User Attitudes toward Security and Usability Tradeoffs for Key-Directory Encryption Systems
Wei Bai 0004, Moses Namara, Yichen Qian, Patrick Gage Kelley, Michelle L. Mazurek, Doowon Kim |
SOUPS | 4 |
| 2015 | I Would Like To..., I Shouldn't..., I Wish I...: Exploring Behavior-Change Goals for Social Networking SitesabstractDespite benefits and uses of social networking sites (SNSs) users are not always satisfied with their behaviors on the sites. These desires for behavior change both provide insight into users' perceptions of how SNSs impact their lives (positively or negatively) and can inform tools for helping users achieve desired behavior changes. We use a 604-participant online survey to explore SNS users' behavior-change goals for Facebook, Instagram, and Twitter. While some participants want to reduce site use, others want to improve their use or increase a range of behaviors. These desired changes differ by SNS, and, for Twitter, by participants' levels of site use. Participants also expect a range of benefits from these goals, including increased time, contact with others, intrinsic benefits, better security/privacy, and improved self presentation. Based on these results we provide insights both into how participants perceive different SNSs, as well as potential designs for behavior-change mechanisms to target SNS behaviors. Manya Sleeper, Alessandro Acquisti, Lorrie Faith Cranor, Patrick Gage Kelley, Sean A. Munson, Norman M. Sadeh |
CSCW | 4 |
| 2015 | Fast image segmentation on mobile phone using multi-level graph cut
Steven Garcia, Patrick Gage Kelley, Yin Yang 0002 |
Graphics Interface | 2 |
| 2015 | Interactive design and simulation of tubular supporting structure
Ran Luo 0001, Lifeng Zhu, Weiwei Xu 0003, Patrick Gage Kelley, Vanessa Svihla, Yin Yang 0002 |
Graph. Model. | 4 |
| 2014 | Curated city: capturing individual city guides through social curationabstractWe report on our design of Curated City, a website that lets people build their own personal guide to the city's neighborhoods by chronicling their favorite experiences. Although users make their own personal guides, they are immersed in a social curatorial experience where they are influenced directly and indirectly by the guides of others. We use a 2-week field trial involving 20 residents of Pittsburgh as a technological probe to explore the initial design decisions, and we further refine the design landscape through subject interviews. Based on this study, we identify a set of design recommendations for building scalable social platforms for curating the experiences of the city. Justin Cranshaw, Kurt Luther, Patrick Gage Kelley, Norman M. Sadeh |
CHI | 3 |
| 2014 | Molecular tetris: crowdsourcing molecular docking using path-planning and haptic devicesabstractMany biological processes, including immune recognition, enzyme catalysis, and molecular signaling, which is still an open problem in biological sciences. We present Molecular Tetris, a game in which a player can explore the binding between a protein receptor and ligand. This exploration is similar to the game Tetris with atomic forces guiding best fits between shapes. This game will be utilized for crowdsourced haptic-guided motion planning. Haptic touch devices enable users to feel the interactions of two molecules as they move the ligand into an appropriate binding site on the receptor. We demonstrate the method on a critical piece of human immune response, ligand binding to a Major Histocompatibility Complex (MHC) molecule. Through multiple runs by our users, we construct a global roadmap that finds low energy paths to molecular docking sites. These paths are comparable to a highly-biased roadmap generated by Gaussian sampling around the known bound state. Our users are able to find low energy paths with both a specialized force-feedback device and a commodity game console controller. Torin Adamson, John E. G. Baxter, Kasra Manavi, April Suknot, Bruna Jacobson, Patrick Gage Kelley, Lydia Tapia |
MIG | 6 |
| 2013 | Measuring password guessability for an entire universityabstractDespite considerable research on passwords, empirical studies of password strength have been limited by lack of access to plaintext passwords, small data sets, and password sets specifically collected for a research study or from low-value accounts. Properties of passwords used for high-value accounts thus remain poorly understood. Michelle L. Mazurek, Saranga Komanduri, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Patrick Gage Kelley, Richard Shay, Blase Ur |
CCS | 7 |
| 2013 | Privacy as part of the app decision-making processabstractSmartphones have unprecedented access to sensitive personal information. While users report having privacy concerns, they may not actively consider privacy while downloading apps from smartphone application marketplaces. Currently, Android users have only the Android permissions display, which appears after they have selected an app to download, to help them understand how applications access their information. We investigate how permissions and privacy could play a more active role in app-selection decisions. We designed a short "Privacy Facts' display, which we tested in a 20-participant lab study and a 366-participant online experiment. We found that by bringing privacy information to the user when they were making the decision and by presenting it in a clearer fashion, we could assist users in choosing applications that request fewer permissions. Patrick Gage Kelley, Lorrie Faith Cranor, Norman M. Sadeh |
CHI | 1 |
| 2013 | "i read my Twitter the next morning and was astonished": a conversational perspective on Twitter regretsabstractWe present the results of an online survey of 1,221 Twitter users, comparing messages individuals regretted either saying during in-person conversations or posting on Twitter. Participants generally reported similar types of regrets in person and on Twitter. In particular, they often regretted messages that were critical of others. However, regretted messages that were cathartic/expressive or revealed too much information were reported at a higher rate for Twitter. Regretted messages on Twitter also reached broader audiences. In addition, we found that participants who posted on Twitter became aware of, and tried to repair, regret more slowly than those reporting in-person regrets. From this comparison of Twitter and in-person regrets, we provide preliminary ideas for tools to help Twitter users avoid and cope with regret. Manya Sleeper, Justin Cranshaw, Patrick Gage Kelley, Blase Ur, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh |
CHI | 3 |
| 2012 | Correct horse battery staple: exploring the usability of system-assigned passphrasesabstractUsers tend to create passwords that are easy to guess, while system-assigned passwords tend to be hard to remember. Passphrases, space-delimited sets of natural language words, have been suggested as both secure and usable for decades. In a 1,476-participant online study, we explored the usability of 3- and 4-word system-assigned passphrases in comparison to system-assigned passwords composed of 5 to 6 random characters, and 8-character system-assigned pronounceable passwords. Contrary to expectations, system-assigned passphrases performed similarly to system-assigned passwords of similar entropy across the usability metrics we examined. Passphrases and passwords were forgotten at similar rates, led to similar levels of user difficulty and annoyance, and were both written down by a majority of participants. However, passphrases took significantly longer for participants to enter, and appear to require error-correction to counteract entry mistakes. Passphrase usability did not seem to increase when we shrunk the dictionary from which words were chosen, reduced the number of words in a passphrase, or allowed users to change the order of words. Richard Shay, Patrick Gage Kelley, Saranga Komanduri, Michelle L. Mazurek, Blase Ur, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor |
SOUPS | 2 |
| 2012 | Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking AlgorithmsabstractText-based passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform password cracking. In response to this threat, password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize password strength and using them to evaluate password-composition policies. In this paper, we analyze 12,000 passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic password-guessing algorithms guess passwords. Leveraging this method, we investigate (a) the resistance of passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training sets, (c) the relationship between passwords explicitly created under a given composition policy and other passwords that happen to meet the same requirements, and (d) the relationship between guess ability, as measured with password-cracking algorithms, and entropy estimates. Our findings advance understanding of both password-composition policies and metrics for quantifying password security. Patrick Gage Kelley, Saranga Komanduri, Michelle L. Mazurek, Richard Shay, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Julio C. López 0001 |
IEEE Symposium on Security and Privacy | 1 |
| 2012 | How Does Your Password Measure Up? The Effect of Strength Meters on Password Creation
Blase Ur, Patrick Gage Kelley, Saranga Komanduri, Joel Lee, Michael Maass, Michelle L. Mazurek, Timothy Passaro, Richard Shay, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor |
USENIX Security Symposium | 2 |
| 2011 | When are users comfortable sharing locations with advertisers?abstractAs smartphones and other mobile computing devices have increased in ubiquity, advertisers have begun to realize a more effective way of targeting users and a promising area for revenue growth: location-based advertising. This trend brings to bear new questions about whether or not users will adopt products involving this potentially invasive form of advertising and what sorts of protections they should be given. Our real-world user study of 27 participants echoes earlier findings that users have significant privacy concerns regarding sharing their locations with advertisers. However, we examine these concerns in more detail and find that they are complex (e.g., relating not only to the quantity of ads, but the locations and times at which they are received). With advanced privacy settings, users stated they would feel more comfortable and share more information than with a simple opt-in/opt-out mechanism. Patrick Gage Kelley, Michael Benisch, Lorrie Faith Cranor, Norman M. Sadeh |
CHI | 1 |
| 2011 | Of passwords and people: measuring the effect of password-composition policiesabstractText-based passwords are the most common mechanism for authenticating humans to computer systems. To prevent users from picking passwords that are too easy for an adversary to guess, system administrators adopt password-composition policies (e.g., requiring passwords to contain symbols and numbers). Unfortunately, little is known about the relationship between password-composition policies and the strength of the resulting passwords, or about the behavior of users (e.g., writing down passwords) in response to different policies. We present a large-scale study that investigates password strength, user behavior, and user sentiment across four password-composition policies. We characterize the predictability of passwords by calculating their entropy, and find that a number of commonly held beliefs about password composition and strength are inaccurate. We correlate our results with user behavior and sentiment to produce several recommendations for password-composition policies that result in strong passwords without unduly burdening users. Saranga Komanduri, Richard Shay, Patrick Gage Kelley, Michelle L. Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Serge Egelman |
CHI | 3 |
| 2011 | Are you close with me? are you nearby?: investigating social groups, closeness, and willingness to shareabstractAs ubiquitous computing becomes increasingly mobile and social, personal information sharing will likely increase in frequency, the variety of friends to share with, and range of information that can be shared. Past work has identified that whom you share with is important for choosing whether or not to share, but little work has explored which features of interpersonal relationships influence sharing. We present the results of a study of 42 participants, who self-report aspects of their relationships with 70 of their friends, including frequency of collocation and communication, closeness, and social group. Participants rated their willingness to share in 21 different scenarios based on information a UbiComp system could provide. Our findings show that (a) self-reported closeness is the strongest indicator of willingness to share, (b) individuals are more likely to share in scenarios with common information (e.g. we are within one mile of each other) than other kinds of scenarios (e.g. my location wherever I am), and (c) frequency of communication predicts both closeness and willingness to share better than frequency of collocation. Jason Wiese, Patrick Gage Kelley, Lorrie Faith Cranor, Laura A. Dabbish, Jason I. Hong, John Zimmerman |
UbiComp | 2 |
| 2011 | An Investigation into Facebook Friend Grouping
Patrick Gage Kelley, Robin Brewer, Yael Mayer, Lorrie Faith Cranor, Norman M. Sadeh |
INTERACT (3) | 1 |
| 2011 | Capturing location-privacy preferences: quantifying accuracy and user-burden tradeoffs
Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh, Lorrie Faith Cranor |
Pers. Ubiquitous Comput. | 2 |
| 2010 | Standardizing privacy notices: an online study of the nutrition label approachabstractEarlier work has shown that consumers cannot effectively find information in privacy policies and that they do not enjoy using them. In our previous research we developed a standardized table format for privacy policies. We compared this standardized format, and two short variants (one tabular, one text) with the current status quo: full text natural-language policies and layered policies. We conducted an online user study of 764 participants to test if these three more-intentionally designed, standardized privacy policy formats, assisted by consumer education, can benefit consumers. Our results show that standardized privacy policy presentations can have significant positive effects on accuracy and speed of information finding and on reader enjoyment of privacy policies. Patrick Gage Kelley, Lucian Cesca, Joanna Bresee, Lorrie Faith Cranor |
CHI | 1 |
| 2010 | Empirical models of privacy in location sharingabstractThe rapid adoption of location tracking and mobile social networking technologies raises significant privacy challenges. Today our understanding of people's location sharing privacy preferences remains very limited, including how these preferences are impacted by the type of location tracking device or the nature of the locations visited. To address this gap, we deployed Locaccino, a mobile location sharing system, in a four week long field study, where we examined the behavior of study participants (n=28) who shared their location with their acquaintances (n=373.) Our results show that users appear more comfortable sharing their presence at locations visited by a large and diverse set of people. Our study also indicates that people who visit a wider number of places tend to also be the subject of a greater number of requests for their locations. Over time these same people tend to also evolve more sophisticated privacy preferences, reflected by an increase in time- and location-based restrictions. We conclude by discussing the implications our findings. Eran Toch, Justin Cranshaw, Paul Hankes Drielsma, Janice Y. Tsai, Patrick Gage Kelley, James Springfield, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh |
UbiComp | 5 |
| 2010 | Encountering stronger password requirements: user attitudes and behaviorsabstractText-based passwords are still the most commonly used authentication mechanism in information systems. We took advantage of a unique opportunity presented by a significant change in the Carnegie Mellon University (CMU) computing services password policy that required users to change their passwords. Through our survey of 470 CMU computer users, we collected data about behaviors and practices related to the use and creation of passwords. We also captured users' opinions about the new, stronger policy requirements. Our analysis shows that, although most of the users were annoyed by the need to create a complex password, they believe that they are now more secure. Furthermore, we perform an entropy analysis and discuss how our findings relate to NIST recommendations for creating a password policy. We also examine how users answer specific questions related to their passwords. Our results can be helpful in designing better password policies that consider not only technical aspects of specific policy rules, but also users' behavior in response to those rules. Richard Shay, Saranga Komanduri, Patrick Gage Kelley, Pedro Giovanni Leon, Michelle L. Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor |
SOUPS | 3 |
| 2009 | Who's viewed you?: the impact of feedback in a mobile location-sharing applicationabstractFeedback is viewed as an essential element of ubiquitous computing systems in the HCI literature for helping people manage their privacy. However, the success of online social networks and existing commercial systems for mobile location sharing which do not incorporate feedback would seem to call the importance of feedback into question. We investigated this issue in the context of a mobile location sharing system. Specifically, we report on the findings of a field de-ployment of Locyoution, a mobile location sharing system. In our study of 56 users, one group was given feedback in the form of a history of location requests, and a second group was given no feedback at all. Our major contribution has been to show that feedback is an important contributing factor towards improving user comfort levels and allaying privacy concerns. Participants' privacy concerns were reduced after using the mobile location sharing system. Additionally,our study suggests that peer opinion and technical savviness contribute most to whether or not participants thought they would continue to use a mobile location technology. Janice Y. Tsai, Patrick Gage Kelley, Paul Hankes Drielsma, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh |
CHI | 2 |
| 2009 | A Comparative Study of Online Privacy Policies and Formats
Aleecia M. McDonald, Robert W. Reeder, Patrick Gage Kelley, Lorrie Faith Cranor |
Privacy Enhancing Technologies | 3 |
| 2009 | Capturing Social Networking Privacy Preferences: Can Default Policies Help Alleviate Tradeoffs between Expressiveness and User Burden?
Ramprasad Ravichandran, Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh |
Privacy Enhancing Technologies | 3 |
| 2009 | The impact of expressiveness on the effectiveness of privacy mechanisms for location-sharingabstractNo abstract available. Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh, Tuomas Sandholm, Janice Y. Tsai, Lorrie Faith Cranor, Paul Hankes Drielsma |
SOUPS | 2 |
| 2009 | A "nutrition label" for privacyabstractWe used an iterative design process to develop a privacy label that presents to consumers the ways organizations collect, use, and share personal information. Many surveys have shown that consumers are concerned about online privacy, yet current mechanisms to present website privacy policies have not been successful. This research addresses the present gap in the communication and understanding of privacy policies, by creating an information design that improves the visual presentation and comprehensibility of privacy policies. Drawing from nutrition, warning, and energy labeling, as well as from the effort towards creating a standardized banking privacy notification, we present our process for constructing and refining a label tuned to privacy. This paper describes our design methodology; findings from two focus groups; and accuracy, timing, and likeability results from a laboratory study with 24 participants. Our study results demonstrate that compared to existing natural language privacy policies, the proposed privacy label allows participants to find information more quickly and accurately, and provides a more enjoyable information seeking experience. Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, Robert W. Reeder |
SOUPS | 1 |
| 2009 | A comparative study of online privacy policies and formatsabstractNo abstract available. Aleecia M. McDonald, Robert W. Reeder, Patrick Gage Kelley, Lorrie Faith Cranor |
SOUPS | 3 |
| 2009 | Capturing social networking privacy preferences: can default policies help alleviate tradeoffs between expressiveness and user burden?abstractNo abstract available. Ramprasad Ravichandran, Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh |
SOUPS | 3 |
| 2009 | A user study of the expandable grid applied to P3P privacy policy visualizationabstractNo abstract available. Robert W. Reeder, Patrick Gage Kelley, Aleecia M. McDonald, Lorrie Faith Cranor |
SOUPS | 2 |
| 2009 | Analyzing use of privacy policy attributes in a location sharing applicationabstractNo abstract available. Eran Toch, Ramprasad Ravichandran, Lorrie Faith Cranor, Paul Hankes Drielsma, Jason I. Hong, Patrick Gage Kelley, Norman M. Sadeh, Janice Y. Tsai |
SOUPS | 6 |
| 2009 | Who's viewed you?: the impact of feedback in a mobile location-sharing applicationabstractFeedback is viewed as an essential element of ubiquitous computing systems in the HCI literature for helping people manage their privacy. However, the success of online social networks and existing commercial systems for mobile location sharing which do not incorporate feedback would seem to call the importance of feedback into question. We investigated this issue in the context of a mobile location sharing system. Specifically, we report on the findings of a field de-ployment of Locyoution, a mobile location sharing system. In our study of 56 users, one group was given feedback in the form of a history of location requests, and a second group was given no feedback at all. Our major contribution has been to show that feedback is an important contributing factor towards improving user comfort levels and allaying privacy concerns. Participants' privacy concerns were reduced after using the mobile location sharing system. Additionally,our study suggests that peer opinion and technical savviness contribute most to whether or not participants thought they would continue to use a mobile location technology. Janice Y. Tsai, Patrick Gage Kelley, Paul Hankes Drielsma, Lorrie Faith Cranor, Jason I. Hong, Norman M. Sadeh |
SOUPS | 2 |
| 2009 | Understanding and capturing people's privacy policies in a mobile social networking application
Norman M. Sadeh, Jason I. Hong, Lorrie Faith Cranor, Ian Fette, Patrick Gage Kelley, Madhu K. Prabaker, Jinghai Rao |
Pers. Ubiquitous Comput. | 5 |