Nathan Malkin

dblp:179/4686 · DBLP profile ↗
← Back
19ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0001-8195-4671ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 5 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 8 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AI
abstract
For mobile developers to comply with privacy regulations, they must create privacy policies that accurately describe their apps’ data practices. This requires a complete understanding of their apps’ behaviors, including those of embedded third-party SDKs. Despite the complexity of this process, little is known about how privacy policies are created and validated. To investigate, we interviewed 20 developers from around the world about their processes, also observing them use a large language model (LLM) to prepare privacy policies for their apps. We found that developers struggle with collecting information about third-party SDKs, even when they use LLMs, and feel uncertain about the legal validity of LLM outputs. Many developers do not seek legal assistance and believe that, as long as app stores accept their privacy policies, they are protected. Our findings suggest that reliance on LLMs and developers’ desire to externalize validation may result in increasingly unreliable privacy policies.
Shiva Mayahi, Noura Alomar, Nathan Malkin
CHI3
2026 A Penny for Your Prompts: Experiments Detecting and Mitigating LLM Usage by Survey Respondents
Zane Xu, Nathan Malkin
SOUPS2
2026 How Experts Personalize Privacy & Security Advice for At-Risk Users
abstract
Prioritizing privacy and security advice is a particular challenge for at-risk users, requiring difficult judgment calls with the risk of harmful consequences. We interviewed 18 experts who tailor privacy and security advice for at-risk users in personalized consultations and trainings, to understand their strategies and challenges. We identify five main objectives that experts balance as they differentiate the content and delivery of advice, and we explore how different types of context about clients are used to achieve those objectives. We also describe four methods used to ascertain this context, which have different trade-offs regarding priorities such as using time efficiently and managing the reliability of information. Through this, we especially focus on the challenges and rationales that motivate providers to follow particular practices. By surfacing choices that experts make about advice differentiation and by identifying areas for researchers and technologists to assist experts, our work can inform next steps in research, tool design, and ultimately better advice for at-risk users.
Wentao Guo 0005, Alexander Yang, Nathan Malkin, Michelle L. Mazurek
Proc. Priv. Enhancing Technol.3
2025 "That's something that as a senior person you have to consider now": Unpacking Older Adults' Preferences for End-of-Life Data Planning
abstract
What happens to a person's data after they pass away?Designing for digital legacy requires input from individuals across all life stages, as motivations to plan vary with age.Yet, the specific perspectives that older adults have on end-of-life data management have not been investigated in depth.Through interviews with 16 older adults, we examine their preferences and motivations for managing everyday digital data (e.g., text messages, social media, photos) after death.Our findings surface several implications for end-of-life data planning, including creating awareness about digital legacy and associated risks.We also unpack and discuss how older adults' life stage and familiarity with end-of-life planning uniquely positions them to identify barriers and opportunities in managing digital legacy, such as how post-mortem data can encode societal norms of a period or be donated for the greater good. CCS Concepts• Human-centered computing → Human computer interaction (HCI); • Social and professional topics → Seniors.
Ramprabu Thangaraj, Jed R. Brubaker, Nathan Malkin, Alisha Pradhan
Conference on Designing Interactive Systems3
2025 Do You See If I See? Investigating Reciprocity in Interpersonal Access-Control Settings (in the U.S.)
Nathan Malkin, Alan F. Luo, Evan J. Zhao, Michelle L. Mazurek
SOUPS1
2025 Privacy Solution or Menace? Investigating Perceptions of Radio-Frequency Sensing
Maximiliane Windl, Omer Akgul, Nathan Malkin, Lorrie Faith Cranor
USENIX Security Symposium3
2023 Optimistic Access Control for the Smart Home
abstract
One of the biggest privacy concerns of smart home users is enforcing limits on household members’ access to devices and each other’s data. While people commonly express preferences for intricate access control policies, in practice they often settle for less secure defaults. As an alternative, this paper investigates "optimistic access control" policies that allow users to obtain access and data without pre-approval, subject to oversight from other household members. This solution allows users to leverage the interpersonal trust they already rely on in order to establish privacy boundaries commensurate with more complex access control methods, while retaining the convenience of less secure strategies. To evaluate this concept, we conducted a series of surveys with 604 people total, studying the acceptability and perceptions of this approach. We found that a number of respondents preferred optimistic modes to existing access control methods and that interest in optimistic access varied with device type and household characteristics.
Nathan Malkin, Alan F. Luo, Julio Poveda, Michelle L. Mazurek
SP1
2023 Characterizing Everyday Misuse of Smart Home Devices
abstract
Exploration of Internet of Things (IoT) security often focuses on threats posed by external and technically-skilled attackers. While it is important to understand these most extreme cases, it is equally important to understand the most likely risks of harm posed by smart device ownership. In this paper, we explore how smart devices are misused — used without permission in a manner that causes harm — by device owners’ everyday associates such as friends, family, and romantic partners. In a preliminary characterization survey (n = 100), we broadly capture the kinds of unauthorized use and misuse incidents participants have experienced or engaged in. Then, in a prevalence survey (n = 483), we assess the prevalence of these incidents in a demographically-representative population. Our findings show that unauthorized use of smart devices is widespread (experienced by 43% of participants), and that misuse is also common (experienced by at least 19% of participants). However, highly individual factors determine whether these unauthorized use events constitute misuse. Through a focus on everyday abuses, this work sheds light on the most prevalent security and privacy threats faced by smart-home owners today.
Phoebe Moh, Pubali Datta, Noel Warford, Adam Bates 0001, Nathan Malkin, Michelle L. Mazurek
SP5
2023 Is Cryptographic Deniability Sufficientƒ Non-Expert Perceptions of Deniability in Secure Messaging
abstract
Cryptographers have long been concerned with secure messaging protocols threatening deniability. Many messaging protocols—including, surprisingly, modern email— contain digital signatures which definitively tie the author to their message. If stolen or leaked, these signatures make it impossible to deny authorship. As illustrated by events surrounding leaks from Hilary Clinton’s 2016 U.S. presidential campaign, this concern has proven well founded. Deniable protocols are meant to avoid this very outcome, letting politicians and dissidents alike safely disavow authorship. Despite being deployed on billions of devices in Signal and WhatsApp, the effectiveness of such protocols in convincing people remains unstudied. While the absence of cryptographic evidence is clearly necessary for an effective denial, is it sufficientƒWe conduct a survey study (n = 1, 200) to understand how people perceive evidence of deniability related to encrypted messaging protocols. Surprisingly, in a world of "fake news" and Photoshop, we find that simple denials of message authorship, when presented in a courtroom setting without supporting evidence, are not effective. In contrast, participants who were given access to a screenshot forgery tool or even told one exists were much more likely to believe a denial. Similarly, but to a lesser degree, we find an expert cryptographer’s assertion that there is no evidence is also effective.
Nathan Reitinger, Nathan Malkin, Omer Akgul, Michelle L. Mazurek, Ian Miers
SP2
2022 Incidental Incremental In-Band Fingerprint Verification: a Novel Authentication Ceremony for End-to-End Encrypted Messaging
abstract
End-to-end encryption in popular messaging applications relies on centralized key servers. To keep these honest, users are supposed to meet in person and compare “fingerprints” of their public keys. Very few people do this, despite attempts to make this process more usable, making trust in the systems tenuous. To encourage broader adoption of verification behaviors, this paper proposes a new type of authentication ceremony, incidental incremental in-band fingerprint verification (I3FV), in which users periodically share with their friends photos or videos of themselves responding to simple visual or behavioral prompts (“challenges”). This strategy allows verification to be performed incidentally to normal user activities, incrementally over time, and in-band within the messaging application. By replacing a dedicated security task with a fun, already-widespread activity, I3FV has the potential to vastly increase the number of people verifying keys and therefore strengthen trust in encrypted messaging.
Nathan Malkin
NSPW1
2022 SoK: A Framework for Unifying At-Risk User Research
abstract
At-risk users are people who experience risk factors that augment or amplify their chances of being digitally attacked and/or suffering disproportionate harms. In this systematization work, we present a framework for reasoning about at-risk users based on a wide-ranging meta-analysis of 95 papers. Across the varied populations that we examined (e.g., children, activists, people with disabilities), we identified 10 unifying contextual risk factors —such as marginalization and access to a sensitive resource —that augment or amplify digital-safety risks and their resulting harms. We also identified technical and non-technical practices that at-risk users adopt to attempt to protect themselves from digital-safety risks. We use this framework to discuss barriers that limit at-risk users’ ability or willingness to take protective actions. We believe that researchers and technology creators can use our framework to identify and shape research investments to benefit at-risk users, and to guide technology design to better support at-risk users.
Noel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul, Sunny Consolvo, Patrick Gage Kelley, Nathan Malkin, Michelle L. Mazurek, Manya Sleeper, Kurt Thomas
SP7
2022 Can Humans Detect Malicious Always-Listening Assistants? A Framework for Crowdsourcing Test Drives
abstract
As intelligent voice assistants become more widespread and the scope of their listening increases, they become attractive targets for attackers. In the future, a malicious actor could train voice assistants to listen to audio outside their purview, creating a threat to users' privacy and security. How can this misbehavior be detected? Due to the ambiguities of natural language, people may need to work in conjunction with algorithms to determine whether a given conversation should be heard. To investigate how accurately humans can perform this task, we developed a framework for people to conduct "Test Drives" of always-listening services: after submitting sample conversations, users receive instant feedback about whether these would have been captured. Leveraging a Wizard of Oz interface, we conducted a study with 200 participants to determine whether they could detect one of four types of attacks on three different services. We studied the behavior of individuals, as well as groups working collaboratively, and investigated the effects of task framing on performance. We found that individuals were able to successfully detect malicious apps at varying rates (7.5% to 75%), depending on the type of malicious attack, and that groups were highly successful when considered collectively. Our results suggest that the Test Drive framework can be an effective tool for studying user behaviors and concerns, as well as a potentially welcome addition to voice assistant app stores, where it could decrease privacy concerns surrounding always-listening services.
Nathan Malkin, David A. Wagner 0001, Serge Egelman
Proc. ACM Hum. Comput. Interact.1
2022 Effects of Privacy Permissions on User Choices in Voice Assistant App Stores
abstract
Intelligent voice assistants, and the thirdparty apps (aka “skills” or “actions”) that power them, are increasing in popularity and beginning to experiment with the ability to continuously listen to users. This paper studies how privacy concerns related to such always-listening voice assistants might affect consumer behavior and whether certain privacy mitigations would render them more acceptable. To explore these questions with more realistic user choices, we built an interactive app store that allowed users to install apps for a hypothetical always-listening voice assistant. In a study with 214 participants, we asked users to browse the app store and install apps for different voice assistants that offered varying levels of privacy protections. We found that users were generally more willing to install continuously-listening apps when there were greater privacy protections, but this effect was not universally present. The majority did not review any permissions in detail, but still expressed a preference for stronger privacy protections. Our results suggest that privacy factors into user choice, but many people choose to skip this information.
Gary Liu, Nathan Malkin
Proc. Priv. Enhancing Technol.2
2019 A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
abstract
Commitment devices are a technique from behavioral economics that have been shown to mitigate the effects of present bias---the tendency to discount future risks and gains in favor of immediate gratifications. In this paper, we explore the feasibility of using commitment devices to nudge users towards complying with varying online security mitigations. Using two online experiments, with over 1,000 participants total, we offered participants the option to be reminded or to schedule security tasks in the future. We find that both reminders and commitment nudges can increase users' intentions to install security updates and enable two-factor authentication, but not to configure automatic backups. Using qualitative data, we gain insights into the reasons for postponement and how to improve future nudges. We posit that current nudges may not live up to their full potential, as the timing options offered to users may be too rigid.
Alisa Frik, Nathan Malkin, Marian Harbach, Eyal Péer, Serge Egelman
CHI2
2019 Privacy controls for always-listening devices
abstract
Intelligent voice assistants (IVAs) and other voice-enabled devices already form an integral component of the Internet of Things and will continue to grow in popularity. As their capabilities evolve, they will move beyond relying on the wake-words today's IVAs use, engaging instead in continuous listening. Though potentially useful, the continuous recording and analysis of speech can pose a serious threat to individuals' privacy. Ideally, users would be able to limit or control the types of information such devices have access to. But existing technical approaches are insufficient for enforcing any such restrictions. To begin formulating a solution, we develop a systematic methodology for studying continuous-listening applications and survey architectural approaches to designing a system that enhances privacy while preserving the benefits of always-listening assistants.
Nathan Malkin, Serge Egelman, David A. Wagner 0001
NSPW1
2019 Privacy Attitudes of Smart Speaker Users
abstract
Abstract As devices with always-on microphones located in people’s homes, smart speakers have significant privacy implications. We surveyed smart speaker owners about their beliefs, attitudes, and concerns about the recordings that are made and shared by their devices. To ground participants’ responses in concrete interactions, rather than collecting their opinions abstractly, we framed our survey around randomly selected recordings of saved interactions with their devices. We surveyed 116 owners of Amazon and Google smart speakers and found that almost half did not know that their recordings were being permanently stored and that they could review them; only a quarter reported reviewing interactions, and very few had ever deleted any. While participants did not consider their own recordings especially sensitive, they were more protective of others’ recordings (such as children and guests) and were strongly opposed to use of their data by third parties or for advertising. They also considered permanent retention, the status quo, unsatisfactory. Based on our findings, we make recommendations for more agreeable data retention policies and future privacy controls.
Nathan Malkin, Joe Deatrick, Allen Tong, Primal Wijesekera, Serge Egelman, David A. Wagner 0001
Proc. Priv. Enhancing Technol.1
2018 An Experience Sampling Study of User Reactions to Browser Warnings in the Field
abstract
Web browser warnings should help protect people from malware, phishing, and network attacks. Adhering to warnings keeps people safer online. Recent improvements in warning design have raised adherence rates, but they could still be higher. And prior work suggests many people still do not understand them. Thus, two challenges remain: increasing both comprehension and adherence rates. To dig deeper into user decision making and comprehension of warnings, we performed an experience sampling study of web browser security warnings, which involved surveying over 6,000 Chrome and Firefox users in situ to gather reasons for adhering or not to real warnings. We find these reasons are many and vary with context. Contrary to older prior work, we do not find a single dominant failure in modern warning design---like habituation---that prevents effective decisions. We conclude that further improvements to warnings will require solving a range of smaller contextual misunderstandings.
Robert W. Reeder, Adrienne Porter Felt, Sunny Consolvo, Nathan Malkin, Christopher Thompson 0002, Serge Egelman
CHI4
2017 A Usability Evaluation of Tor Launcher
abstract
Abstract Although Tor has state-of-the art anticensorship measures, users in heavily censored environments will not be able to connect to Tor if they cannot configure their connections. We perform the first usability evaluation of Tor Launcher, the graphical user interface (GUI) that Tor Browser uses to configure connections to Tor. Our study shows that 79% (363 of 458) of user attempts to connect to Tor in simulated censored environments failed. We found that users were often frustrated during the process and tried options at random. In this paper, we measure potential usability issues, discuss design constraints unique to Tor, and provide recommendations based on what we learned to help more users connect to Tor while reducing the time they take to do so. Tor Browser incorporated the changes proposed by this study.
Linda Naeun Lee, David Fifield, Nathan Malkin, Ganesh Iyer, Serge Egelman, David A. Wagner 0001
Proc. Priv. Enhancing Technol.3
2016 Keep on Lockin' in the Free World: A Multi-National Comparison of Smartphone Locking
abstract
We present the results of an online survey of smartphone unlocking (N=8,286) that we conducted in eight different countries. The goal was to investigate differences in attitudes towards smartphone unlocking between different national cultures. Our results show that there are indeed significant differences across a range of categories. For instance, participants in Japan considered the data on their smartphones to be much more sensitive than those in other countries, and respondents in Germany were 4.5 times more likely than others to say that protecting data on their smartphones was important. The results of this study shed light on how motivations to use various security mechanisms are likely to differ from country to country.
Marian Harbach, Alexander De Luca, Nathan Malkin, Serge Egelman
CHI3