Kopo M. Ramokapane

dblp:190/2066 · also Kopo Marvin Ramokapane · DBLP profile ↗
← Back
19ranked-venue papers
6as first author
17since 2021 · last 2026
0000-0001-8420-3929ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 4 first-author · 11 since 2021Human-computer interaction and ubiquitous computing · 8 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 "I feel as though my privacy is being violated": Privacy Risks and Barriers in Instant Messaging for Blind and Low-Vision Users
Sohana Akter, Wejdan Alsarih, Blessy Kalluri, Kopo M. Ramokapane, Taslima Akter
SOUPS4
2026 How Effective are Privacy Labels at Informing Users About App Data Handling Practices?
Sophia Walsh, Lukasz Piwek, Kopo M. Ramokapane
SOUPS3
2026 Between a Rock and a Hard Place: Examining Public Understanding and Perceptions of Data Practices in Smart Cities
abstract
Smart cities are often presented as modern, sustainable, and efficient environments that enhance safety and convenience through advanced technologies. However, their heavy reliance on data collection raises significant privacy concerns. As technology evolves faster than public awareness, questions emerge about whether these cities adequately protect individuals’ data. This study explores residents’ understanding of smart cities and their perceptions of data collection and sharing. In this study, we conduct semi-structured interviews with 19 residents across two countries to examine how people conceptualise smart cities and interpret the collection, processing, and sharing of their data. Our analysis shows that residents hold fragmented and often inaccurate mental models of smart-city infrastructures; view data practices as simultaneously beneficial and risky; and lack meaningful clarity about data flows, retention, and institutional responsibility. Participants considered consent important yet mostly infeasible given the pervasive and unavoidable nature of smart-city data collection. We also identify culturally grounded differences in trust, privacy sensitivities, and expectations of governance across the two contexts. Our findings challenge assumptions embedded in current smart-city governance and consent models and point to the need for transparent, accountable, and contextually attuned data practices.
Wejdan Alsarih, Inah Omoronyia, Kopo M. Ramokapane
Proc. Priv. Enhancing Technol.3
2025 Ownership and Gatekeeping vs. Safeguarding and Consent: How Migrant Parents Navigate Child Data Management Complexities
abstract
Parents pursuing opportunities abroad increasingly find themselves raising children in new cultural and legal environments. This responsibility extends to complying with unfamiliar regulations and safeguarding their children's data which is often complex and a challenging task. In this study, we examine how migrant parents perceive, manage, and safeguard data related to their children. Through interviews with 17 migrant parents and guardians in the UK, we uncover nuanced and evolving perspectives on data ownership and management. Migrant parents express significant concerns about losing control over data shared locally and with extended families abroad, with fears of misuse that could harm their children or jeopardize their immigration status. We discuss their data management strategies and approaches to navigating changing concepts of data ownership and consent. Our findings underscore the need for culturally sensitive support to help migrant families safeguard their children's data and highlight directions for future research into the complexities of cross-border data sharing and its implications.
Rui Huan, Kopo M. Ramokapane, Awais Rashid
SP2
2025 "Erasing the Echo": The Usability of Data Deletion in Smart Personal Assistants
abstract
Smart home personal assistants (SPAs) have gained widespread popularity in recent years. Despite their widespread adoption, existing research indicates that many users remain unaware of how to delete from these devices. While data deletion has been explored in other contexts, in the context of SPAs it is not well understood. This paper addresses this gap by investigating users' understanding of data deletion in the context of SPAs and evaluating the usability of existing deletion mechanisms. To address this, we conducted an interview study with 20 Amazon Alexa and Google Home users, during which we also observed their interactions with deletion processes. Our findings reveal that users hold diverse mental models regarding data deletion, recovery, and data storage, often leading to uncertainty and a lack of confidence in the deletion process. Moreover, we identified several usability challenges, particularly when users attempted to delete data using voice commands. Based on these insights, we discuss the implications for the design of more effective and transparent data deletion mechanisms in SPAs.
Cheng Cheng 0006, Kopo M. Ramokapane
Proc. Priv. Enhancing Technol.2
2024 Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber Defense
Priyanka Badva, Kopo M. Ramokapane, Eleonora Pantano, Awais Rashid
USENIX Security Symposium2
2024 Voice App Developer Experiences with Alexa and Google Assistant: Juggling Risks, Liability, and Security
William Seymour, Noura Abdi, Kopo M. Ramokapane, Jide S. Edu, Guillermo Suarez-Tangil, Jose M. Such
USENIX Security Symposium3
2023 Multiuser Privacy and Security Conflicts in the Cloud
abstract
Collaborative cloud platforms make it easier and more convenient for multiple users to work together on files (GoogleDocs, Office365) and store and share them (Dropbox, OneDrive). However, this can lead to privacy and security conflicts between the users involved, for instance when a user adds someone to a shared folder or changes its permissions. Such multiuser conflicts (MCs), though known to happen in the literature, have not yet been studied in-depth. In this paper, we report a study with 1,050 participants about MCs they experienced in the cloud. We show what are the MCs that arise when multiple users work together in the cloud and how and why they arise, what is the prevalence and severity of MCs, what are their consequences on users, and how do users work around MCs. We derive recommendations for designing mechanisms to help users avoid, mitigate, and resolve MCs in the cloud.
Eman Alhelali, Kopo M. Ramokapane, Jose M. Such
CHI2
2023 ExD: Explainable Deletion
abstract
This paper focuses on a critical yet often overlooked aspect of data in digital systems and services—deletion. Through a review of existing literature we highlight the challenges that user face when attempting to delete data from systems and services, the lack of transparency in how such requests are handled or processed and the lack of clear assurance that the data has been deleted. We highlight that this not only impacts users’ agency over their data but also poses issues with regards to compliance with fundamental legal rights such as the right to be forgotten. We propose a new paradigm – explainable deletion – to improve users’ agency and control over their data and enable systems to deliver effective assurance, transparency and compliance. We discuss the properties required of such explanations and their relevance and benefit for various individuals and groups involved or having an interest in data deletion processes and implications. We discuss various design implications pertaining to explainable deletion and present a research agenda for the community.
Kopo M. Ramokapane, Awais Rashid
NSPW1
2023 Co-creating a Transdisciplinary Map of Technology-mediated Harms, Risks and Vulnerabilities: Challenges, Ambivalences and Opportunities
abstract
The phrase "online harms'' has emerged in recent years out of a growing political willingness to address the ethical and social issues associated with the use of the Internet and digital technology at large. The broad landscape that surrounds online harms gathers a multitude of disciplinary, sectoral and organizational efforts while raising myriad challenges and opportunities for the crossing entrenched boundaries. In this paper we draw lessons from a journey of co-creating a transdisciplinary knowledge infrastructure within a large research initiative animated by the online harms agenda. We begin with a reflection of the implications of mapping, taxonomizing and constructing knowledge infrastructures and a brief review of how online harm and adjacent themes have been theorized and classified in the literature to date. Grounded on our own experience of co-creating a map of online harms, we then argue that the map---and the process of mapping---perform three mutually constitutive functions, acting simultaneously as method, medium and provocation. We draw lessons from how an open-ended approach to mapping, despite not guaranteeing consensus, can foster productive debate and collaboration in ethically and politically fraught areas of research. We end with a call for CSCW research to surface and engage with the multiple temporalities, social lives and political sensibilities of knowledge infrastructures.
Andrés Domínguez Hernández, Kopo M. Ramokapane, Partha Das Chowdhury, Ola Aleksandra Michalec, Emily Johnstone, Emily Godwin, Alicia G. Cork, Awais Rashid
Proc. ACM Hum. Comput. Interact.2
2023 What Users Want From Cloud Deletion and the Information They Need: A Participatory Action Study
abstract
Current cloud deletion mechanisms fall short in meeting users’ various deletion needs. They assume all data is deleted the same way—data is temporally removed (or hidden) from users’ cloud accounts before being completely deleted. This assumption neglects users’ desire to have data completely deleted instantly or their preference to have it recoverable for a more extended period. To date, these preferences have not been explored. To address this gap, we conducted a participatory study with four groups of active cloud users (five subjects per group). We examined their deletion preferences and the information they require to aid deletion. In particular, we explored how users want to delete cloud data and identify what information about cloud deletion they consider essential, the time it should be made available to them, and the communication channel that should be used. We show that cloud deletion preferences are complex and multi-dimensional, varying between subjects and groups. Information about deletion should be within reach when needed, for instance, be part of deletion controls. Based on these findings, we discuss the implications of our study in improving the current deletion mechanism to accommodate these preferences.
Kopo M. Ramokapane, Jose M. Such, Awais Rashid
ACM Trans. Priv. Secur.1
2022 Privacy Design Strategies for Home Energy Management Systems (HEMS)
abstract
Home energy management systems (HEMS) offer control and the ability to manage energy, generating and collecting energy consumption data at the most detailed level. However, data at this level poses various privacy concerns, including, for instance, profiling consumer behaviors and large-scale surveillance. The question of how utility providers can get value from such data without infringing consumers’ privacy has remained under-investigated. We address this gap by exploring the pro-sharing attitudes and privacy perceptions of 30 HEMS users and non-users through an interview study. While participants are concerned about data misuse and stigmatization, our analysis also reveals that incentives, altruism, trust, security and privacy, transparency and accountability encourage data sharing. From this analysis, we derive privacy design strategies for HEMS that can both improve privacy and engender adoption.
Kopo M. Ramokapane, Caroline Bird, Awais Rashid, Ruzanna Chitchyan
CHI1
2022 From Utility to Capability: A New Paradigm to Conceptualize and Develop Inclusive PETs
abstract
The wider adoption of Privacy Enhancing Technologies (PETs) has relied on usability studies – which focus mainly on an assessment of how a specified group of users interface, in particular contexts, with the technical properties of a system. While human-centred efforts in usability aim to achieve important technical improvements and drive technology adoption, a focus on the usability of PETs alone is not enough. PETs development and adoption requires a broadening of focus to adequately capture the specific needs of individuals, particularly of vulnerable individuals and/or individuals in marginalized populations. We argue for a departure, from the utilitarian evaluation of surface features aimed at maximizing adoption, towards a bottom-up evaluation of what real opportunities humans have to use a particular system. We delineate a new paradigm for the way PETs are conceived and developed. To that end, we propose that Amartya Sen’s capability approach offers a foundation for the comprehensive evaluation of the opportunities individuals have based on their personal and environmental circumstances which can, in turn, inform the evolution of PETs. This includes considerations of vulnerability, age, education, physical and mental ability, language barriers, gender, access to technology, freedom from oppression among many important contextual factors.
Partha Das Chowdhury, Andrés Domínguez Hernández, Kopo M. Ramokapane, Awais Rashid
NSPW3
2022 Charting App Developers' Journey Through Privacy Regulation Features in Ad Networks
abstract
Mobile apps enable ad networks to collect and track users. App developers are given “configurations” on these platforms to limit data collection and adhere to privacy regulations; however, the prevalence of apps that violate privacy regulations because of third parties, including ad networks, begs the question of how developers work through these configurations and how easy they are to utilize. We study privacy regulations-related interfaces on three widely used ad networks using two empirical studies, a systematic review and think-aloud sessions with eleven developers, to shed light on how ad networks present privacy regulations and how usable the provided configurations are for developers. We find that information about privacy regulations is scattered in several pages, buried under multiple layers, and uses terms and language developers do not understand. While ad networks put the burden of complying with the regulations on developers, our participants, on the other hand, see ad networks responsible for ensuring compliance with regulations. To assist developers in building privacy regulations-compliant apps, we suggest dedicating a section to privacy, offering easily accessible configurations (both in graphical and code level), building testing systems for privacy regulations, and creating multimedia materials such as videos to promote privacy values in the ad networks’ documentation.
Mohammad Tahaei, Kopo M. Ramokapane, Tianshi Li 0001, Jason I. Hong, Awais Rashid
Proc. Priv. Enhancing Technol.2
2022 The Best Laid Plans or Lack Thereof: Security Decision-Making of Different Stakeholder Groups
abstract
Cyber security requirements are influenced by the priorities and decisions of a range of stakeholders. Board members and Chief Information Security Officers (CISOs) determine strategic priorities. Managers have responsibility for resource allocation and project management. Legal professionals concern themselves with regulatory compliance. Little is understood about how the security decision-making approaches of these different stakeholders contrast, and if particular groups of stakeholders have a better appreciation of security requirements during decision-making. Are risk analysts better decision makers than CISOs? Do security experts exhibit more effective strategies than board members? This paper explores the effect that different experience and diversity of expertise has on the quality of a team's cyber security decision-making and whether teams with members from more varied backgrounds perform better than those with more focused, homogeneous skill sets. Using data from 208 sessions and 948 players of a tabletop game runin the wildby a major national organization over 16 months, we explore how choices are affected by player background (e.g., cyber security experts versus risk analysts, board-level decision makers versus technical experts) and different team make-ups (homogeneous teams of security experts versus various mixes). We find that no group of experts makes significantly better game decisions than anyone else, and that their biases lead them to not fully comprehend what they are defending or how the defenses work.
Ben Shreeve, Joseph Hallett, Matthew Edwards 0001, Kopo M. Ramokapane, Richard Atkins, Awais Rashid
IEEE Trans. Software Eng.4
2021 Privacy Norms for Smart Home Personal Assistants
abstract
Smart Home Personal Assistants (SPA) have a complex ecosystem that enables them to carry out various tasks on behalf of the user with just voice commands. SPA capabilities are continually growing, with over a hundred thousand third-party skills in Amazon Alexa, covering several categories, from tasks within the home (e.g. managing smart devices) to tasks beyond the boundaries of the home (e.g. purchasing online, booking a ride). In the SPA ecosystem, information flows through several entities including SPA providers, third-party skills providers, providers of Smart Devices, other users and external parties. Prior studies have not explored privacy norms in the SPA ecosystem, i.e., the acceptability of these information flows. In this paper, we study privacy norms in SPAs based on Contextual Integrity through a large-scale study with 1,738 participants. We also study the influence that the Contextual Integrity parameters and personal factors have on the privacy norms. Further, we identify the similarities in terms of the Contextual Integrity parameters of the privacy norms studied to distill more general privacy norms, which could be useful, for instance, to establish suitable privacy defaults in SPA. We finally provide recommendations for SPA and third-party skill providers based on the privacy norms studied.
Noura Abdi, Xiao Zhan, Kopo M. Ramokapane, Jose M. Such
CHI3
2021 Truth or Dare: Understanding and Predicting How Users Lie and Provide Untruthful Data Online
abstract
Individuals are known to lie and/or provide untruthful data when providing information online as a way to protect their privacy. Prior studies have attempted to explain when and why individuals lie online. However, no work has examined into how people lie or provide untruthful data online, i.e. the specific strategies they follow to provide untruthful data, or attempted to predict whether people would be truthful or not depending on the specific question/data. To close this gap, we present a large-scale study with over 800 participants. Based on it, we show that it is possible to predict whether users are truthful or not using machine learning with very high accuracy (89.7%). We also identify four main strategies people employ to provide untruthful data and show the factors that influence the choices of their strategies. We discuss the implications of findings and argue that understanding privacy lies at this level can help both users and data collectors.
Kopo M. Ramokapane, Gaurav Misra, Jose M. Such, Sören Preibusch
CHI1
2019 Skip, Skip, Skip, Accept!!!: A Study on the Usability of Smartphone Manufacturer Provided Default Features and User Privacy
abstract
Abstract Smartphone manufacturer provided default features (e.g., default location services, iCloud, Google Assistant, ad tracking) enhance the usability and extend the functionality of these devices. Prior studies have highlighted smartphone vulnerabilities and how users’ data can be harvested without their knowledge. However, little is known about manufacturer provided default features in this regard—their usability concerning configuring them during usage, and how users perceive them with regards to privacy. To bridge this gap, we conducted a task-based study with 27 Android and iOS smart-phone users in order to learn about their perceptions, concerns and practices, and to understand the usability of these features with regards to privacy. We explored the following: users’ awareness of these features, why and when do they change the settings of these features, the challenges they face while configuring these features, and finally the mitigation strategies they adopt. Our findings reveal that users of both platforms have limited awareness of these features and their privacy implications. Awareness of these features does not imply that a user can easily locate and adjust them when needed. Furthermore, users attribute their failure to configure default features to hidden controls and insufficient knowledge on how to configure them. To cope with difficulties of finding controls, users employ various coping strategies, some of which are platform specific but most often applicable to both platforms. However, some of these coping strategies leave users vulnerable.
Kopo M. Ramokapane, Anthony C. Mazeli, Awais Rashid
Proc. Priv. Enhancing Technol.1
2017 "I feel stupid I can't delete...": A Study of Users' Cloud Deletion Practices and Coping Strategies
Kopo M. Ramokapane, Awais Rashid, Jose M. Such
SOUPS1