EDBT 2026 Demo / reviewers in the wild / expert
Oliver Wiese
dblp:186/0348
· DBLP profile ↗
9ranked-venue papers
2as first author
7since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites
Alexander Krause 0002, Jacques Suray, Lea Schmüser, Marten Oltrogge, Oliver Wiese, Maximillian Golla, Sascha Fahl |
SOUPS | 5 |
| 2025 | Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain Security
Jan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer 0009, Nicolas Huaman Groschopf, Niklas Busch, Jan H. Klemmer, Marcel Fourné, Oliver Wiese, Dominik Wermke, Sascha Fahl |
NDSS | 8 |
| 2025 | "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic Code
Alexander Krause 0002, Harjot Kaur, Jan H. Klemmer, Oliver Wiese, Sascha Fahl |
USENIX Security Symposium | 4 |
| 2025 | SoK: The past decade of user deception in emails and today's email clients' susceptibility to phishing techniquesabstractUser deception in emails is still one of the biggest security risks companies and end-users face alike. Attackers try to mislead their victims when assessing whether emails are dangerous to interact with, e.g., by using techniques based on dangerous links, dangerous attachments, or both. In this work, we present a systematic literature research of deception techniques discussed in the scientific literature of the last decade. We systematize the deception techniques, focusing on techniques that use misleading sender, link, and/or attachment information. We identify 23 deception techniques which we classify as either those that email clients should protect users against (13) and those that email clients cannot protect against and thus should be addressed in security awareness measures (10). We propose a security rating for the susceptibility of email clients to these 13 deception techniques and perform an empirical evaluation to analyze the susceptibility of seven representative email clients (web, mobile apps, desktop apps) to these deception techniques. The results of our evaluation indicate that most email clients are in need of improvement to defend against the deception techniques. Hardening email clients against these deception techniques is necessary to increase the resistance against them — without unnecessarily burdening users. Maxime Veit, Oliver Wiese, Fabian Ballreich, Melanie Volkamer, Douglas Engels, Peter Mayer 0001 |
Comput. Secur. | 2 |
| 2024 | A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted Service
Sandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge, Yasemin Acar, Oliver Wiese, Sascha Fahl |
USENIX Security Symposium | 6 |
| 2022 | 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire UniversityabstractEmail is one of the main communication tools and has seen significant adoption in the past decades. However, emails are sent in plain text by default and allow attackers easy access. Users can protect their emails by end-to-end encrypting them using tools such as S/MIME or PGP.Although PGP had already been introduced in 1991, it is a commonly held belief that email encryption is a niche tool that has not seen widespread adoption to date. Previous user studies identified ample usability issues with email encryption such as key management and user interface challenges, which likely contribute to the limited success of email encryption.However, so far ground truth based on longitudinal field data is missing in the literature. Towards filling this gap, we measure the use of email encryption based on 27 years of data for 37,089 users at a large university. While attending to ethical and data privacy concerns, we were able to analyze the use of S/MIME and PGP in 81,612,595 emails.We found that only 5.46% of all users ever used S/MIME or PGP. This led to 0.06% encrypted and 2.8% signed emails. Users were more likely to use S/MIME than PGP by a factor of six. We saw that using multiple email clients had a negative impact on signing as well as encrypting emails and that only 3.36% of all emails between S/MIME users who had previously exchanged certificates were encrypted on average.Our results imply that the adoption of email encryption is indeed very low and that key management challenges negatively impact even users who have set up S/MIME or PGP previously. Christian Stransky, Oliver Wiese, Volker Roth 0002, Yasemin Acar, Sascha Fahl |
SP | 2 |
| 2021 | The U in Crypto Stands for Usable: An Empirical Study of User Experience with Mobile Cryptocurrency WalletsabstractIn a corpus of 45,821 app reviews of the top five mobile cryptocurrency wallets, we identified and qualitatively analyzed 6,859 reviews pertaining to the user experience (UX) with those wallets. Our analysis suggests that both new and experienced users struggle with general and domain-specific UX issues that, aside from frustration and disengagement, might lead to dangerous errors and irreversible monetary losses. We reveal shortcomings of current wallet UX as well as users’ misconceptions, some of which can be traced back to a reliance on their understanding of conventional payment systems. For example, some users believed that transactions were free, reversible, and could be canceled anytime, which is not the case in reality. Correspondingly, these beliefs often resulted in unmet expectations. Based on our findings, we provide recommendations on how to design cryptocurrency wallets that both alleviate the identified issues and counteract some of the misconceptions in order to better support newcomers. Artemij Voskobojnikov, Oliver Wiese, Masoud Mehrabi Koushki, Volker Roth 0002, Konstantin Beznosov |
CHI | 2 |
| 2018 | I Need this Back, Later!: An Exploration of Practical Secret SharingabstractSharing encryption keys secretly can be useful to protect the availability and confidentiality of redundant encrypted backups. Key shares may be distributed and managed conveniently online, or offline with security benefits. We carried out a field study in order to learn how practical secret sharing is in the offline case using two form factors as carriers of share information: paper printouts and key tags. Our findings suggest that offline sharing is practical but slow. The form factor did not have a significant effect on retrieval success. Perhaps other parameters may be optimized instead such as convenience and costs of share production. We used k = 3, n = 5 as the secret sharing parameters in our study. This appears to suffice in many cases but we also found that increasing n and k is recommendable in practice because the safety and security margin was thin in our study. Oliver Wiese, Christoph Weinhold, Jan-Ole Malchow, Volker Roth 0002 |
ACSAC | 1 |
| 2016 | See you next time: a model for modern shoulder surfersabstractFriends, family and colleagues at work may repeatedly observe how their peers unlock their smartphones. These "insiders" may combine multiple partial observations to form a hypothesis of a target's secret. This changing landscape requires that we update the methods used to assess the security of unlocking mechanisms against human shoulder surfing attacks. In our paper, we introduce a methodology to study shoulder surfing risks in the insider threat model. Our methodology dissects the authentication process into minimal observations by humans. Further processing is based on simulations. The outcome is an estimate of the number of observations needed to break a mechanism. The flexibility of this approach benefits the design of new mechanisms. We demonstrate the application of our methodology by performing an analysis of the SwiPIN scheme published at CHI 2015. Our results indicate that SwiPIN can be defeated reliably by a majority of the population with as few as 6 to 11 observations. Oliver Wiese, Volker Roth 0002 |
MobileHCI | 1 |