EDBT 2026 Demo / reviewers in the wild / expert
Nicolas Huaman Groschopf
dblp:213/7298 · also Nicolas Huaman
· DBLP profile ↗
11ranked-venue papers
4as first author
10since 2021 · last 2025
0000-0003-2733-5073ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Competing for Attention: An Interview Study with Participants of Cryptography CompetitionsabstractCryptography competitions often contribute to the development and standardization of new cryptography. They help select primitives and algorithms that solve specific cryptographic problems securely and efficiently from a list of candidate submissions. Over the last decades, several competitions held by NIST and other research and regulatory organizations resulted in standards for, e.g., symmetric and asymmetric encryption, hashing, digital signatures, and, most recently, quantum secure cryptography. However, while these competitions fostered much technical research on the submitted schemes, little is currently known about the human aspects of cryptography competition processes, how they shape the competition results, and their perceived impact on cryptography security. Ivana Trummová, Juliane Schmüser, Nicolas Huaman Groschopf, Sascha Fahl |
CCS | 3 |
| 2025 | Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain Security
Jan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer 0009, Nicolas Huaman Groschopf, Niklas Busch, Jan H. Klemmer, Marcel Fourné, Oliver Wiese, Dominik Wermke, Sascha Fahl |
NDSS | 4 |
| 2024 | Passwords To-Go: Investigating Multifaceted Challenges for Password Managers in the Android EcosystemabstractAndroid provides two APIs to help mobile apps and browsers interact with password managers, the Android Autofill framework (AAF) and the Credentials API. Mobile password managers rely on these APIs to insert stored credentials into apps and browsers, limiting user interaction during authentication. However, implementing these APIs correctly can be challenging for app developers. For example, misusing the AAF can lead to insecure authentication, login credential phishing, and decreased usability.In this work, we conduct a mixed-methods study on the use of Android authentication APIs, focusing on their password manager support and impact on authentication security and usability. We first conduct a large-scale analysis of the two authentication APIs in 639,731 Android apps. Secondly, we perform an in-depth qualitative analysis of the AAF with 100 apps, ten browsers, and eleven password managers on Android. The Credentials API has not yet been adopted broadly, illustrating its recent introduction. Regarding Android’s Autofill framework, our qualitative analysis identified various unsupported edge cases like credit card management and password changing. Based on our findings, we make recommendations for improving the AAF and relate them to the Credentials API. We find that while a lot of the partially supported cases will work better in the new API, especially the lesser supported cases in our analysis currently fail for both APIs. Nicolas Huaman Groschopf, Marten Oltrogge, Sabrina Klivan, Yannick Evers, Sascha Fahl |
ACSAC | 1 |
| 2024 | "You have to read 50 different RFCs that contradict each other": An Interview Study on the Experiences of Implementing Cryptographic Standards
Nicolas Huaman Groschopf, Jacques Suray, Jan H. Klemmer, Marcel Fourné, Sabrina Klivan, Ivana Trummová, Yasemin Acar, Sascha Fahl |
USENIX Security Symposium | 1 |
| 2023 | "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsabstractMulti-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps. Sabrina Klivan, Sandra Höltervennhoff, Nicolas Huaman Groschopf, Alexander Krause 0002, Lucy Simko, Yasemin Acar, Sascha Fahl |
CCS | 3 |
| 2023 | "Would You Give the Same Priority to the Bank and a Game? I Do Not!" Exploring Credential Management Strategies and Obstacles during Password Manager Setup
Sabrina Klivan, Sandra Höltervennhoff, Nicolas Huaman Groschopf, Yasemin Acar, Sascha Fahl |
SOUPS | 3 |
| 2023 | Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code Repositories
Alexander Krause 0002, Jan H. Klemmer, Nicolas Huaman Groschopf, Dominik Wermke, Yasemin Acar, Sascha Fahl |
USENIX Security Symposium | 3 |
| 2021 | They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesabstractPassword managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2,947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research. Nicolas Huaman Groschopf, Sabrina Klivan, Marten Oltrogge, Yasemin Acar, Sascha Fahl |
SP | 1 |
| 2021 | A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized Enterprises
Nicolas Huaman Groschopf, Bennet von Skarczinski, Christian Stransky, Dominik Wermke, Yasemin Acar, Arne Dreißigacker, Sascha Fahl |
USENIX Security Symposium | 1 |
| 2021 | Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android Applications
Marten Oltrogge, Nicolas Huaman Groschopf, Sabrina Klivan, Yasemin Acar, Michael Backes 0001, Sascha Fahl |
USENIX Security Symposium | 2 |
| 2018 | A Large Scale Investigation of Obfuscation Use in Google PlayabstractAndroid applications are frequently plagiarized or repackaged, and software obfuscation is a recommended protection against these practices. However, there is very little data on the overall rates of app obfuscation, the techniques used, or factors that lead to developers to choose to obfuscate their apps. In this paper, we present the first comprehensive analysis of the use of and challenges to software obfuscation in Android applications. We analyzed 1.7 million free Android apps from Google Play to detect various obfuscation techniques, finding that only 24.92% of apps are obfuscated by the developer. To better understand this rate of obfuscation, we surveyed 308 Google Play developers about their experiences and attitudes about obfuscation. We found that while developers feel that apps in general are at risk of plagiarism, they do not fear theft of their own apps. Developers also report difficulties obfuscating their own apps. To better understand, we conducted a follow-up study where the vast majority of 70 participants failed to obfuscate a realistic sample app even while many mistakenly believed they had been successful. These findings have broad implications both for improving the security of Android apps and for all tools that aim to help developers write more secure software. Dominik Wermke, Nicolas Huaman Groschopf, Yasemin Acar, Bradley Reaves, Patrick Traynor, Sascha Fahl |
ACSAC | 2 |