EDBT 2026 Demo / reviewers in the wild / expert
Alexander De Luca
dblp:22/3157
· DBLP profile ↗
48ranked-venue papers
12as first author
0since 2021 · last 2019
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 48 · 12 first-authorSecurity and privacy · 6 · 3 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
19 papers |
Authentication and access control · 42% Usable security · 28% Biometric security · 20% | |
| Human-computer interaction and pervasive computing
7 papers |
User interface design and tools · 30% Usability and user experience research · 22% Haptics and multimodal interaction · 20% |
Topics — the 28 heaviest of 31, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Authentication and access control › mobile authentication
smartphone unlocking |
0.7 | 3 | 2016 | Keep on Lockin' in the Free World: A Multi-National Comparison of Smartphone Locking · CHI 2016 The Anatomy of Smartphone Unlocking: A Field Study of Android Lock Screens · CHI 2016 Glass Unlock: Enhancing Security of Smartphone Unlocking through Leveraging a Private Near-eye Display · CHI 2015 |
Biometric security
behavioral biometrics |
0.6 | 3 | 2016 | Evaluating the Influence of Targets and Hand Postures on Touch-based Behavioural Biometrics · CHI 2016 Improving Accuracy, Applicability and Usability of Keystroke Biometrics on Mobile Touchscreen Devices · CHI 2015 Touch me once and i know it's you!: implicit authentication based on touch screen patterns · CHI 2012 |
Authentication and access control › knowledge-based authentication
graphical password |
0.5 | 3 | 2015 | Easy to Draw, but Hard to Trace?: On the Observability of Grid-based (Un)lock Patterns · CHI 2015 Using fake cursors to secure on-screen password entry · CHI 2013 Back-of-device authentication on smartphones · CHI 2013 |
Authentication and access control
knowledge-based authentication |
0.5 | 3 | 2015 | SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015 Using fake cursors to secure on-screen password entry · CHI 2013 Back-of-device authentication on smartphones · CHI 2013 |
Biometric security › behavioral biometrics
touch biometrics |
0.5 | 2 | 2016 | Evaluating the Influence of Targets and Hand Postures on Touch-based Behavioural Biometrics · CHI 2016 Improving Accuracy, Applicability and Usability of Keystroke Biometrics on Mobile Touchscreen Devices · CHI 2015 |
Privacy and data protection › image privacy
observation resistance |
0.5 | 4 | 2015 | Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014 ColorPIN: securing PIN entry through indirect input · CHI 2010 Vibrapass: secure authentication based on shared lies · CHI 2009 |
Authentication and access control › mobile authentication
smartphone authentication |
0.4 | 2 | 2019 | Towards Understanding the Link Between Age and Smartphone Authentication · CHI 2019 I Know What You Did Last Week! Do You?: Dynamic Security Questions for Fallback Authentication on Smartphones · CHI 2015 |
Authentication and access control › password authentication
PIN entry |
0.4 | 3 | 2015 | SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015 ColorPIN: securing PIN entry through indirect input · CHI 2010 Vibrapass: secure authentication based on shared lies · CHI 2009 |
Usable security
shoulder surfing resistance |
0.4 | 4 | 2015 | Glass Unlock: Enhancing Security of Smartphone Unlocking through Leveraging a Private Near-eye Display · CHI 2015 SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015 Using fake cursors to secure on-screen password entry · CHI 2013 |
Usable security › authentication usability
user authentication behavior |
0.4 | 1 | 2019 | Towards Understanding the Link Between Age and Smartphone Authentication · CHI 2019 |
Usable security › authentication usability
smartphone locking |
0.4 | 2 | 2019 | The Anatomy of Smartphone Unlocking: A Field Study of Android Lock Screens · CHI 2016 Towards Understanding the Link Between Age and Smartphone Authentication · CHI 2019 |
Usable security
shoulder surfing |
0.3 | 2 | 2014 | Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014 ColorPIN: securing PIN entry through indirect input · CHI 2010 |
Biometric security
biometric authentication |
0.3 | 2 | 2016 | I Feel Like I'm Taking Selfies All Day!: Towards Understanding Biometric Authentication on Smartphones · CHI 2015 The Anatomy of Smartphone Unlocking: A Field Study of Android Lock Screens · CHI 2016 |
Privacy and data protection
image privacy |
0.2 | 1 | 2016 | You Can't Watch This!: Privacy-Respectful Photo Browsing on Smartphones · CHI 2016 |
Usable security
security-usability tradeoff |
0.2 | 1 | 2016 | The Anatomy of Smartphone Unlocking: A Field Study of Android Lock Screens · CHI 2016 |
Authentication and access control › user authentication
backup authentication |
0.2 | 1 | 2015 | I Know What You Did Last Week! Do You?: Dynamic Security Questions for Fallback Authentication on Smartphones · CHI 2015 |
Biometric security › biometric authentication
keystroke dynamics authentication |
0.2 | 1 | 2015 | Improving Accuracy, Applicability and Usability of Keystroke Biometrics on Mobile Touchscreen Devices · CHI 2015 |
Authentication and access control › continuous authentication
implicit authentication |
0.1 | 1 | 2012 | Touch me once and i know it's you!: implicit authentication based on touch screen patterns · CHI 2012 |
Biometric security › biometric authentication
touch-based authentication |
0.1 | 1 | 2012 | Touch me once and i know it's you!: implicit authentication based on touch screen patterns · CHI 2012 |
Web and mobile security › phishing
phishing prevention |
0.1 | 1 | 2011 | Does MoodyBoard make internet use more secure?: evaluating an ambient security visualization tool · CHI 2011 |
Usable security
security visualization |
0.1 | 1 | 2011 | Does MoodyBoard make internet use more secure?: evaluating an ambient security visualization tool · CHI 2011 |
Haptics and multimodal interaction › haptic feedback
tactile feedback |
0.1 | 1 | 2009 | Vibrapass: secure authentication based on shared lies · CHI 2009 |
Design research and methods
field study |
0.1 | 1 | 2016 | SnapApp: Reducing Authentication Overhead with a Time-Constrained Fast Unlock Option · CHI 2016 |
User interface design and tools › layout design
GUI layout |
0.1 | 1 | 2016 | Evaluating the Influence of Targets and Hand Postures on Touch-based Behavioural Biometrics · CHI 2016 |
Usability and user experience research
evaluation methodology |
0.1 | 1 | 2015 | Improving Accuracy, Applicability and Usability of Keystroke Biometrics on Mobile Touchscreen Devices · CHI 2015 |
User interface design and tools › display technology
near-eye display |
0.1 | 1 | 2015 | Glass Unlock: Enhancing Security of Smartphone Unlocking through Leveraging a Private Near-eye Display · CHI 2015 |
Interaction techniques and input › non-visual interaction
eyes-free interaction |
0.1 | 1 | 2014 | Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014 |
Usable security
deception |
0.0 | 1 | 2009 | Vibrapass: secure authentication based on shared lies · CHI 2009 |
Methods — techniques the papers use, named apart from their topics
user study · 2.2field study · 0.6metric for user-revealing information · 0.5experience sampling · 0.5data logging · 0.5probabilistic framework · 0.4equal error rate analysis · 0.4online survey · 0.2logging · 0.2image distortion filters · 0.23d printed prototype · 0.2user evaluation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Towards Understanding the Link Between Age and Smartphone AuthenticationabstractWhile previous work on smartphone (un)locking has revealed real world usage patterns, several aspects still need to be explored. In this paper, we fill one of these knowledge gaps: the interplay between age and smartphone authentication behavior. To do this, we performed a two-month long field study (N = 134). Our results indicate that there are indeed significant differences across age. For instance, younger participants were more likely to use biometric unlocking mechanisms and older participants relied more on auto locks. Lina Qiu, Alexander De Luca, Ildar Muslukhov, Konstantin Beznosov |
CHI | 2 |
| 2016 | SnapApp: Reducing Authentication Overhead with a Time-Constrained Fast Unlock OptionabstractWe present SnapApp, a novel unlock concept for mobile devices that reduces authentication overhead with a time-constrained quick-access option. SnapApp provides two unlock methods at once: While PIN entry enables full access to the device, users can also bypass authentication with a short sliding gesture ("Snap"). This grants access for a limited amount of time (e.g. 30 seconds). The device then automatically locks itself upon expiration. Our concept further explores limiting the possible number of Snaps in a row, and configuring blacklists for app use during short access (e.g. to exclude banking apps). We discuss opportunities and challenges of this concept based on a 30-day field study with 18 participants, including data logging and experience sampling methods. Snaps significantly reduced unlock times, and our app was perceived to offer a good tradeoff. Conceptual challenges include, for example, supporting users in configuring their blacklists. Daniel Buschek, Fabian Hartmann, Emanuel von Zezschwitz, Alexander De Luca, Florian Alt |
CHI | 4 |
| 2016 | Evaluating the Influence of Targets and Hand Postures on Touch-based Behavioural BiometricsabstractUsers' individual differences in their mobile touch behaviour can help to continuously verify identity and protect personal data. However, little is known about the influence of GUI elements and hand postures on such touch biometrics. Thus, we present a metric to measure the amount of user-revealing information that can be extracted from touch targeting interactions and apply it in eight targeting tasks with over 150,000 touches from 24 users in two sessions. We compare touch-to-target offset patterns for four target types and two hand postures. Our analyses reveal that small, compactly shaped targets near screen edges yield the most descriptive touch targeting patterns. Moreover, our results show that thumb touches are more individual than index finger ones. We conclude that touch-based user identification systems should analyse GUI layouts and infer hand postures. We also describe a framework to estimate the usefulness of GUIs for touch biometrics. Daniel Buschek, Alexander De Luca, Florian Alt |
CHI | 2 |
| 2016 | The Anatomy of Smartphone Unlocking: A Field Study of Android Lock ScreensabstractTo prevent unauthorized parties from accessing data stored on their smartphones, users have the option of enabling a "lock screen" that requires a secret code (e.g., PIN, drawing a pattern, or biometric) to gain access to their devices. We present a detailed analysis of the smartphone locking mechanisms currently available to billions of smartphone users worldwide. Through a month-long field study, we logged events from a panel of users with instrumented smartphones (N=134). We are able to show how existing lock screen mechanisms provide users with distinct tradeoffs between usability (unlocking speed vs. unlocking frequency) and security. We find that PIN users take longer to enter their codes, but commit fewer errors than pattern users, who unlock more frequently and are very prone to errors. Overall, PIN and pattern users spent the same amount of time unlocking their devices on average. Additionally, unlock performance seemed unaffected for users enabling the stealth mode for patterns. Based on our results, we identify areas where device locking mechanisms can be improved to result in fewer human errors -- increasing usability -- while also maintaining security. Marian Harbach, Alexander De Luca, Serge Egelman |
CHI | 2 |
| 2016 | Keep on Lockin' in the Free World: A Multi-National Comparison of Smartphone LockingabstractWe present the results of an online survey of smartphone unlocking (N=8,286) that we conducted in eight different countries. The goal was to investigate differences in attitudes towards smartphone unlocking between different national cultures. Our results show that there are indeed significant differences across a range of categories. For instance, participants in Japan considered the data on their smartphones to be much more sensitive than those in other countries, and respondents in Germany were 4.5 times more likely than others to say that protecting data on their smartphones was important. The results of this study shed light on how motivations to use various security mechanisms are likely to differ from country to country. Marian Harbach, Alexander De Luca, Nathan Malkin, Serge Egelman |
CHI | 2 |
| 2016 | You Can't Watch This!: Privacy-Respectful Photo Browsing on SmartphonesabstractWe present an approach to protect photos on smartphones from unwanted observations by distorting them in a way that makes it hard or impossible to recognize their content for an onlooker who does not know the photographs. On the other hand, due to the chosen way of distortion, the device owners who know the original images have no problems recognizing photos. We report the results of a user study (n=18) that showed very high usability properties for all tested graphical filters (only 11 out of 216 distorted photos were not correctly identified by their owners). At the same time, two of the filters significantly reduced the observability of the image contents. Emanuel von Zezschwitz, Sigrid Ebbinghaus, Heinrich Hußmann, Alexander De Luca |
CHI | 4 |
| 2016 | On quantifying the effective password space of grid-based unlock gesturesabstractWe present a similarity metric for Android unlock patterns to quantify the effective password space of user-defined gestures. Our metric is the first of its kind to reflect that users choose patterns based on human intuition and interest in geometric properties of the resulting shapes. Applying our metric to a dataset of 506 user-defined patterns reveals very similar shapes that only differ by simple geometric transformations such as rotation. This shrinks the effective password space by 66% and allows informed guessing attacks. Consequently, we present an approach to subtly nudge users to create more diverse patterns by showing background images and animations during pattern creation. Results from a user study (n = 496) show that applying such countermeasures can significantly increase pattern diversity. We conclude with implications for pattern choices and the design of enrollment processes. Emanuel von Zezschwitz, Malin Eiband, Daniel Buschek, Sascha Oberhuber, Alexander De Luca, Florian Alt, Heinrich Hußmann |
MUM | 5 |
| 2016 | Expert and Non-Expert Attitudes towards (Secure) Instant Messaging
Alexander De Luca, Sauvik Das, Martin Ortlieb, Iulia Ion, Ben Laurie |
SOUPS | 1 |
| 2015 | Improving Accuracy, Applicability and Usability of Keystroke Biometrics on Mobile Touchscreen DevicesabstractAuthentication methods can be improved by considering implicit, individual behavioural cues. In particular, verifying users based on typing behaviour has been widely studied with physical keyboards. On mobile touchscreens, the same concepts have been applied with little adaptations so far. This paper presents the first reported study on mobile keystroke biometrics which compares touch-specific features between three different hand postures and evaluation schemes. Based on 20.160 password entries from a study with 28 participants over two weeks, we show that including spatial touch features reduces implicit authentication equal error rates (EER) by 26.4 - 36.8% relative to the previously used temporal features. We also show that authentication works better for some hand postures than others. To improve applicability and usability, we further quantify the influence of common evaluation assumptions: known attacker data, training and testing on data from a single typing session, and fixed hand postures. We show that these practices can lead to overly optimistic evaluations. In consequence, we describe evaluation recommendations, a probabilistic framework to handle unknown hand postures, and ideas for further improvements. Daniel Buschek, Alexander De Luca, Florian Alt |
CHI | 2 |
| 2015 | I Know What You Did Last Week! Do You?: Dynamic Security Questions for Fallback Authentication on SmartphonesabstractIn this paper, we present the design and evaluation of dynamic security questions for fallback authentication. In case users lose access to their device, the system asks questions about their usage behavior (e.g. calls, text messages or app usage). We performed two consecutive user studies with real users and real adversaries to identify questions that work well in the sense that they are easy to answer for the genuine user, but hard to guess for an adversary. The results show that app installations and communication are the most promising categories of questions. Using three questions from the evaluated categories was sufficient to get an accuracy of 95.5% - 100%. Alina Hang, Alexander De Luca, Heinrich Hußmann |
CHI | 2 |
| 2015 | I Feel Like I'm Taking Selfies All Day!: Towards Understanding Biometric Authentication on SmartphonesabstractWe present the results of an MTurk survey (n=383) on the reasons for using and not using biometric authentication systems on smartphones. We focused on Apple's Touch ID as well as Android's Face Unlock as they are the most prevalent systems on the market. For both systems, we categorized the participants as a) current users, b) former users that deactivated it at some point and c) nonusers. The results show that usability is one of the main factors that influences the decision on whether or not to use biometric verification on the smartphone. To our surprise and as opposed to previous research on biometric authentication, privacy and trust issues were not among the most important decision factors. Alexander De Luca, Alina Hang, Emanuel von Zezschwitz, Heinrich Hußmann |
CHI | 1 |
| 2015 | Glass Unlock: Enhancing Security of Smartphone Unlocking through Leveraging a Private Near-eye DisplayabstractThis paper presents Glass Unlock, a novel concept using smart glasses for smartphone unlocking, which is theoretically secure against smudge attacks, shoulder-surfing, and camera attacks. By introducing an additional temporary secret like the layout of digits that is only shown on the private near-eye display, attackers cannot make sense of the observed input on the almost empty phone screen. We report a user study with three alternative input methods and compare them to current state-of-the-art systems. Our findings show that Glass Unlock only moderately increases authentication times and that users favor the input method yielding the slowest input times as it avoids focus switches between displays. Christian Winkler 0001, Jan Gugenheimer, Alexander De Luca, Gabriel Haas 0001, Philipp Speidel, David Dobbelstein, Enrico Rukzio |
CHI | 3 |
| 2015 | SwiPIN: Fast and Secure PIN-Entry on SmartphonesabstractIn this paper, we present SwiPIN, a novel authentication system that allows input of traditional PINs using simple touch gestures like up or down and makes it secure against human observers. We present two user studies which evaluated different designs of SwiPIN and compared it against traditional PIN. The results show that SwiPIN performs adequately fast (3.7 s) to serve as an alternative input method for risky situations. Furthermore, SwiPIN is easy to use, significantly more secure against shoulder surfing attacks and switching between PIN and SwiPIN feels natural. Emanuel von Zezschwitz, Alexander De Luca, Bruno Brunkow, Heinrich Hußmann |
CHI | 2 |
| 2015 | Easy to Draw, but Hard to Trace?: On the Observability of Grid-based (Un)lock PatternsabstractWe performed a systematic evaluation of the shoulder surfing susceptibility of the Android pattern (un)lock. The results of an online study (n=298) enabled us to quantify the influence of pattern length, line visibility, number of knight moves, number of overlaps and number of intersections on observation resistance. The results show that all parameters have a highly significant influence, with line visibility and pattern length being most important. We discuss implications for real-world patterns and present a linear regression model that can predict the observability of a given pattern. The model can be used to provide proactive security measurements for (un)lock patterns, in analogy to password meters. Emanuel von Zezschwitz, Alexander De Luca, Philipp Janssen, Heinrich Hußmann |
CHI | 2 |
| 2015 | Automatic Privacy Classification of Personal Photos
Daniel Buschek, Moritz Bader, Emanuel von Zezschwitz, Alexander De Luca |
INTERACT (2) | 4 |
| 2015 | There is more to Typing than Speed: Expressive Mobile Touch Keyboards via Dynamic Font PersonalisationabstractTyping is a common task on mobile devices and has been widely addressed in HCI research, mostly regarding quantitative factors such as error rates and speed. Qualitative aspects, like personal expressiveness, have received less attention. This paper makes individual typing behaviour visible to the users to render mobile typing more personal and expressive in varying contexts: We introduce a dynamic font personalisation framework, TapScript, which adapts a finger-drawn font according to user behaviour and context, such as finger placement, device orientation and movements - resulting in a handwritten-looking font. We implemented TapScript for evaluation with an online survey (N=91) and a field study with a chat app (N=11). Looking at resulting fonts, survey participants distinguished pairs of typists with 84.5% accuracy and walking/sitting with 94.8%. Study participants perceived fonts as individual and the chat experience as personal. They also made creative explicit use of font adaptations. Daniel Buschek, Alexander De Luca, Florian Alt |
MobileHCI | 2 |
| 2015 | ColorSnakes: Using Colored Decoys to Secure Authentication in Sensitive ContextsabstractIn this paper we present ColorSnakes, a PIN-based authentication mechanism for smartphones which uses fake paths on a grid of numbers to disguise user input. In a lab study (n=24),we evaluated variations of ColorSnakes in terms of usability and security. In comparison to direct input, indirect input significantly reduced the risk of shoulder surfing (10.5%) without increasing the input time. In a follow up real-world study (n=12), we compared ColorSnakes with PIN entry and Android's Pattern Unlock over the course of three weeks. Although authentication time for ColorSnakes was higher than for the other two mechanisms, participants valued the security benefit over its slightly higher error rate and increased authentication time. We argue that ColorSnakes could be used as an additional authentication mechanism alongside current mechanisms, thus providing the user with the choice of changing to ColorSnakes for certain applications or when there is an observer. Jan Gugenheimer, Alexander De Luca, Hayato Hess, Stefan Karg, Dennis Wolf 0002, Enrico Rukzio |
MobileHCI | 2 |
| 2015 | Locked Your Phone? Buy a New One? From Tales of Fallback Authentication on Smartphones to Actual ConceptsabstractWe describe three scenarios in which fallback authentication on smartphones can occur and evaluate their real-life occurrences in an online survey (n=244) and complementing interviews (n=12). The results provide first insights into frequencies, reasons, countermeasures taken and problems of lockout experiences. Overall, study participants were satisfied with current fallback schemes, but at the same time, fallback authentication was aggravated when special circumstances applied and thus, leave room for improvements. Based on this, we propose an alternative concept for fallback authentication that quizzes users about installed and not installed apps on their device. Authentication succeeds, when users identify a certain number of apps correctly. Our evaluation showed that the concept yields an overall accuracy of 95%. Alina Hang, Alexander De Luca, Emanuel von Zezschwitz, Manuel Demmler, Heinrich Hußmann |
MobileHCI | 2 |
| 2015 | Where Have You Been? Using Location-Based Security Questions for Fallback Authentication
Alina Hang, Alexander De Luca, Matthew Smith 0001, Heinrich Hußmann |
SOUPS | 2 |
| 2014 | Now you see me, now you don't: protecting smartphone authentication from shoulder surfersabstractIn this paper, we present XSide, an authentication mechanism that uses the front and the back of smartphones to enter stroke-based passwords. Users can switch sides during input to minimize the risk of shoulder surfing. We performed a user study (n = 32) to explore how switching sides during authentication affects usability and security of the system. The results indicate that switching the sides increases security while authentication speed stays relatively fast (≤ 4 seconds). The paper furthermore provides insights on accuracy of eyes-free input (as used in XSide) and shows how 3D printed prototype cases can improve the back-of-device interaction experience. Alexander De Luca, Marian Harbach, Emanuel von Zezschwitz, Max-Emanuel Maurer, Bernhard Ewald Slawik, Heinrich Hußmann, Matthew Smith 0001 |
CHI | 1 |
| 2014 | It's a Hard Lock Life: A Field Study of Smartphone (Un)Locking Behavior and Risk Perception
Marian Harbach, Emanuel von Zezschwitz, Andreas Fichtner, Alexander De Luca, Matthew Smith 0001 |
SOUPS | 4 |
| 2013 | Back-of-device authentication on smartphonesabstractThis paper presents BoD Shapes, a novel authentication method for smartphones that uses the back of the device for input. We argue that this increases the resistance to shoulder surfing while remaining reasonably fast and easy-to-use. We performed a user study (n=24) comparing BoD Shapes to PIN authentication, Android grid unlock, and a front version of our system. Testing a front version allowed us to directly compare performance and security measures between front and back authentication. Our results show that BoD Shapes is significantly more secure than the three other approaches. While performance declined, our results show that BoD Shapes can be very fast (up to 1.5 seconds in the user study) and that learning effects have an influence on its performance. This indicates that speed improvements can be expected in long-term use. Alexander De Luca, Emanuel von Zezschwitz, Ngo Dieu Huong Nguyen, Max-Emanuel Maurer, Elisa Rubegni, Marcello Paolo Scipioni, Marc Langheinrich |
CHI | 1 |
| 2013 | Using fake cursors to secure on-screen password entryabstractIn this paper, we present a concept using fake cursors to disguise on-screen password entry. We performed two user studies with different amounts of dummy cursors and differently colored cursors. The results show that dummy cursors significantly improve security. At the same time, decrease in performance is kept within an acceptable range. Depending on the required degree of security, the studies favor 8 or 16 differently colored cursors as the best trade-off between security and usability. Alexander De Luca, Emanuel von Zezschwitz, Laurent Pichler, Heinrich Hußmann |
CHI | 1 |
| 2013 | Travel Routes or Geography Facts? An Evaluation of Voice Authentication User Interfaces
Alina Hang, Alexander De Luca, Katharina Frison, Emanuel von Zezschwitz, Massimo Tedesco, Marcel Kockmann, Heinrich Hußmann |
INTERACT (3) | 2 |
| 2013 | Investigating Pointing Tasks across Angularly Coupled Display Areas
Fabian Hennecke, Alexander De Luca, Ngo Dieu Huong Nguyen, Sebastian Boring, Andreas Butz |
INTERACT (1) | 2 |
| 2013 | Long-Term Experiences with an Iterative Design of a QR-Code-Based Payment System for Beverages
Max-Emanuel Maurer, Alexander De Luca, Alina Hang, Doris Hausen, Fabian Hennecke, Sebastian Löhmann, Henri Palleis, Hendrik Richter 0002, Simon Stusak, Aurélien Tabard, Sarah Tausch, Emanuel von Zezschwitz, Franziska Schwamb, Heinrich Hußmann, Andreas Butz |
INTERACT (4) | 2 |
| 2013 | Survival of the Shortest: A Retrospective Analysis of Influencing Factors on Password Composition
Emanuel von Zezschwitz, Alexander De Luca, Heinrich Hußmann |
INTERACT (3) | 2 |
| 2013 | Making graphic-based authentication secure against smudge attacksabstractMost of today's smartphones and tablet computers feature touchscreens as the main way of interaction. By using these touchscreens, oily residues of the users' fingers, smudge, remain on the device's display. As this smudge can be used to deduce formerly entered data, authentication tokens are jeopardized. Most notably, grid-based authentication methods, like the Android pattern scheme are prone to such attacks. Emanuel von Zezschwitz, Anton Koslow, Alexander De Luca, Heinrich Hußmann |
IUI | 3 |
| 2013 | Oh app, where art thou?: on app launching habits of smartphone usersabstractIn this paper, we present the results of a four-week real world study on app launches on smartphones. The results show that smartphone users are confident in the way they navigate on their devices, but that there are many opportunities for refinements. Users in our study tended to sort apps based on frequency of use, putting the most frequently used apps in places that they considered fastest to reach. Interestingly, users start most apps from within other apps, followed by the use of the homescreen. Alina Hang, Alexander De Luca, Jonas Hartmann, Heinrich Hußmann |
Mobile HCI | 2 |
| 2013 | Patterns in the wild: a field study of the usability of pattern and pin-based authentication on mobile devicesabstractGraphical password systems based upon the recall and reproduction of visual patterns (e.g. as seen on the Google Android platform) are assumed to have desirable usability and memorability properties. However, there are no empirical studies that explore whether this is actually the case on an everyday basis. In this paper, we present the results of a real world user study across 21 days that was conducted to gather such insight; we compared the performance of Android-like patterns to personal identification numbers (PIN), both on smartphones, in a field study. The quantitative results indicate that PIN outperforms the pattern lock when comparing input speed and error rates. However, the qualitative results suggest that users tend to accept this and are still in favor of the pattern lock to a certain extent. For instance, it was rated better in terms of ease-of-use, feedback and likeability. Most interestingly, even though the pattern lock does not provide any undo or cancel functionality, it was rated significantly better than PIN in terms of error recovery; this provides insight into the relationship between error prevention and error recovery in user authentication. Emanuel von Zezschwitz, Paul Dunphy, Alexander De Luca |
Mobile HCI | 3 |
| 2012 | Touch me once and i know it's you!: implicit authentication based on touch screen patternsabstractPassword patterns, as used on current Android phones, and other shape-based authentication schemes are highly usable and memorable. In terms of security, they are rather weak since the shapes are easy to steal and reproduce. In this work, we introduce an implicit authentication approach that enhances password patterns with an additional security layer, transparent to the user. In short, users are not only authenticated by the shape they input but also by the way they perform the input. We conducted two consecutive studies, a lab and a long-term study, using Android applications to collect and log data from user input on a touch screen of standard commercial smartphones. Analyses using dynamic time warping (DTW) provided first proof that it is actually possible to distinguish different users and use this information to increase security of the input while keeping the convenience for the user high. Alexander De Luca, Alina Hang, Frederik Brudy, Christian Lindner, Heinrich Hußmann |
CHI | 1 |
| 2012 | Don't queue up!: user attitudes towards mobile interactions with public terminalsabstractPublic terminals for service provision provide high convenience to users due to their constant availability. Yet, the interaction with them lacks security and privacy as it takes place in a public setting. Additionally, users have to wait in line until they can interact with the terminal. In comparison to that, personal mobile devices allow for private service execution. Since many services, like with-drawing money from an ATM, require physical presence at the terminal, hybrid approaches have been developed. These move parts of the interaction to a mobile device. In this work we present the results of a four week long real world user study, in which we investigated whether hybrid approaches would actually be used. The results show that users accept the hybrid service as they understood that they could use down downtimes (like bus rides) to prepare the interaction with the public terminal. Our findings give novel insights about security relevant aspects such as where and when users interact with the mobile service before accessing the public terminal. So the preparation of the transaction on the mobile phone was often conducted much further away from the terminal than expected (81.0% with a distance greater than 400m) and earlier than expected (82.1% at least 5 minutes in advance). Julian Seifert, Alexander De Luca, Enrico Rukzio |
MUM | 2 |
| 2011 | Does MoodyBoard make internet use more secure?: evaluating an ambient security visualization toolabstractInternet users are targets for ever-advancing phishing- and other attacks. The risks are, for example, to disclose credit card information or passwords to unauthorized instances. One approach to help users with insecure situations is provided by MoodyBoard, which uses ambient information to highlight potential risks. In this paper, we present findings from an evaluation of this system. Two user studies were conducted in order to find out whether an ambient security tool can protect users during sensitive tasks. We designed a pilot study to find out whether users understand the warnings and a security study to see if it helps to protect users from phishing attacks. Results show that MoodyBoard users behaved significantly more secure. Alexander De Luca, Bernhard Frauendienst, Max-Emanuel Maurer, Julian Seifert, Doris Hausen, Niels Kammerer, Heinrich Hußmann |
CHI | 1 |
| 2011 | Shining Chrome: Using Web Browser Personas to Enhance SSL Certificate Visualization
Max-Emanuel Maurer, Alexander De Luca, Tobias Seitz |
INTERACT (4) | 2 |
| 2011 | Using data type based security alert dialogs to raise online security awarenessabstractWhen browsing the Internet, users are likely to be exposed to security and privacy threats -- like fraudulent websites. Automatic browser mechanisms can protect them only to some extent. In other situations it is still important to raise the users' security awareness at the right moment. Passive indicators are mostly overlooked and blocking warnings are quickly dismissed by habituated users. In this work, we present a new concept of warnings that appear in-context, right next to data the user has just entered. Those dialogs are displayed whenever critical data types -- e.g. credit card data -- are entered by the users into online forms. Since they do not immediately interrupt the users' interaction but appear right in the users' focus, it is possible to place important security information in a way that it can be easily seen. Max-Emanuel Maurer, Alexander De Luca, Sylvia Kempe |
SOUPS | 2 |
| 2010 | On the design of a "moody" keyboardabstractTo counter the increasing number of online threats for users' privacy and security, this paper explores the design of an ambient security indicator, in form of a standard keyboard illuminated in different colors, and equipped with additional buttons and vibration functionality. We present the results of a focus group study, which notably influenced the design, and discuss a prototypical implementation called Moody Board. Alexander De Luca, Bernhard Frauendienst, Max-Emanuel Maurer, Doris Hausen |
Conference on Designing Interactive Systems | 1 |
| 2010 | ColorPIN: securing PIN entry through indirect inputabstractAutomated teller machine (ATM) frauds are increasing drastically these days. When analyzing the most common attacks and the reasons for successful frauds, it becomes apparent that the main problem lies in the PIN based authentication which in itself does not provide any security features (besides the use of asterisks). That is, security is solely based on a user's behavior. Indirect input is one way to solve this problem. This mostly comes at the costs of adding overhead to the input process. We present ColorPIN, an authentication mechanism that uses indirect input to provide security enhanced PIN entry. At the same time, ColorPIN remains a one-to-one relationship between the length of the PIN and the required number of clicks. A user study showed that ColorPIN is significantly more secure than standard PIN entry while enabling good authentication speed in comparison with related systems. Alexander De Luca, Katja Hertzschuch, Heinrich Hußmann |
CHI | 1 |
| 2010 | Towards understanding ATM security: a field study of real world ATM useabstractWith the increase of automated teller machine (ATM) frauds, new authentication mechanisms are developed to overcome security problems of personal identification numbers (PIN). Those mechanisms are usually judged on speed, security, and memorability in comparison with traditional PIN entry systems. It remains unclear, however, what appropriate values for PIN-based ATM authentication actually are. We conducted a field study and two smaller follow-up studies on real-world ATM use, in order to provide both a better understanding of PIN-based ATM authentication, and on how alternative authentication methods can be compared and evaluated. Our results show that there is a big influence of contextual factors on security and performance in PIN-based ATM use. Such factors include distractions, physical hindrance, trust relationships, and memorability. From these findings, we draw several implications for the design of alternative ATM authentication systems, such as resilience to distraction and social compatibility. Alexander De Luca, Marc Langheinrich, Heinrich Hußmann |
SOUPS | 1 |
| 2009 | Vibrapass: secure authentication based on shared liesabstractAuthentication in public spaces is a risky task. Frauds on cash machines (ATMs) are not uncommon nowadays. The biggest group of attacks is observation attacks, which focus on recording the input done by the users. In this work, we present VibraPass, a system created to be resilient against observation attacks using tactile feedback provided by the users' own mobile devices. In this way, secret information is shared between the terminal and the users to add an over-head of 'lies' to the input which makes it hard for attackers to steal the real PIN or password. We present an evaluation, which shows that VibraPass has the potential to replace current authentication systems due to increased security combined with reasonable input speed and error rates. Alexander De Luca, Emanuel von Zezschwitz, Heinrich Hußmann |
CHI | 1 |
| 2009 | Please touch the exhibits!: using NFC-based interaction for exploring a museumabstractMuseums often use mobile devices and applications to let visitors explore their exhibits and interact with them in order to make the user experience more immersive and enjoyable. This paper presents a mobile museum guide based on the physical interaction with a dynamic NFC-display, consisting of a grid of NFC-tags and a projected GUI. Visitors can browse tours on the public display, download them onto their mobile devices and use them for the exploration of the museum. The paper presents the design of the museum guide, a first prototype and a preliminary evaluation of its usability and the interaction with a dynamic NFC-display. Anna Magdalena Blöckner, Svetlana Danti, Jennifer Forrai, Gregor Broll, Alexander De Luca |
Mobile HCI | 5 |
| 2009 | pieTouch: a direct touch gesture interface for interacting with in-vehicle information systemsabstractTouch-sensitive displays seem like a natural and promising option for dealing with the increasing complexity of current in-vehicle information systems (IVIS), but since they can hardly be used without visual attention conventional point touch systems are rarely considered in cars. To ensure road safety, the drivers' visual attention needs to be focused almost entirely to the road. In order to integrate touch screens successfully into cars, new concepts are needed to reduce visual demand. The adaptation of pie menus serving as a visualisation of gestures reduces the user's cognitive load, and we were able to achieve an almost blind interaction with the IVIS. We compared our design to a generic touch system using a dual task evaluation method (Lane Change Task [18][20]), and the results regarding total task completion time, lane deviation and subjective preferences confirm a higher usability and efficiency, as well as an added hedonic quality of pieTouch. Ronald Ecker, Verena Broy, Andreas Butz, Alexander De Luca |
Mobile HCI | 4 |
| 2009 | SeCuUI: autocomplete your terminal inputabstractWith SeCuUI we present a solution that aims to increase security of data entry on public terminals. The user can enter all data requested by the terminal using her mobile device. Sensitive data can be hidden from prying eyes by exclusively showing it on the user's mobile. To speed up the whole process, the SeCuUI-client stores previously entered data on the mobile device to provide auto form filling capabilities. Max-Emanuel Maurer, Alexander De Luca |
Mobile HCI | 2 |
| 2009 | A context-sensitive security model for privacy protection on mobile phonesabstractIn this paper we present a context-sensitive security model for privacy protection on mobile phones. We describe the system TreasurePhone which implements this security model. The Privacy Protection is realized by spheres, which represent the user's context specific need for privacy. That is, users can create any number of spheres and define which services and data are accessible in each sphere. TreasurePhone integrates context information for supporting authentication and activation of spheres by locations and actions. A basic hierarchy is used for determining which location should be activated based on the associated sensor value. Julian Seifert, Alexander De Luca, Bettina Conradi |
Mobile HCI | 2 |
| 2009 | Look into my eyes!: can you guess my password?abstractAuthentication systems for public terminals and thus public spaces have to be fast, easy and secure. Security is of utmost importance since the public setting allows manifold attacks from simple shoulder surfing to advanced manipulations of the terminals. In this work, we present EyePassShapes, an eye tracking authentication method that has been designed to meet these requirements. Instead of using standard eye tracking input methods that require precise and expensive eye trackers, EyePassShapes uses eye gestures. This input method works well with data about the relative eye movement, which is much easier to detect than the precise position of the user's gaze and works with cheaper hardware. Different evaluations on technical aspects, usability, security and memorability show that EyePassShapes can significantly increase security while being easy to use and fast at the same time. Alexander De Luca, Martin Denzel, Heinrich Hußmann |
SOUPS | 1 |
| 2008 | CityFlocks: designing social navigation for urban mobile information systemsabstractCityFlocks is a mobile system enabling visitors and new residents in a city to tap into the knowledge and experiences of local residents, so as to gather information about their new environment.Its design specifically aims to lower existing barriers of access and facilitate social navigation in urban places.This paper presents a design case study of a mobile system prototype that offers an easy way for information seeking new residents or visitors to access tacit knowledge from local people about their new community.In various user tests we evaluate two general user interaction alternatives -direct and indirect social navigation -and analyse under what conditions which interaction method works better for people using a mobile device to socially navigate urban environments.The outcomes are relevant for the user interaction design of future mobile information systems that leverage off of a social navigation approach. Mark Bilandzic, Marcus Foth, Alexander De Luca |
Conference on Designing Interactive Systems | 3 |
| 2008 | Spybuster - a community-based privacy tagging platformabstractThe goal of Spybuster is to provide a powerful and easy accessible community platform, which helps the members to cope with the increasing number of threats for everyone's privacy in everyday life. Spybuster uses a geotagging system to associate privacy threats with their locations. Users can add supplemental information such as a description of the threat and the exact address. The resultant tags can either be accessed over a mobile application with an interactive radar or a website using a Google Maps-mashup for displaying tags in a certain area. Due to a shared database users can organize their tags on both platforms. Johannes Kiemer, Till Ballendat, Tim Langer, Alexander De Luca |
Mobile HCI | 5 |
| 2008 | Automatic form filling on mobile devices
Enrico Rukzio, Chie Noda, Alexander De Luca, John Hamard, Fatih Coskun |
Pervasive Mob. Comput. | 3 |
| 2006 | Visualization of uncertainty in context aware mobile applicationsabstractContext-aware mobile applications and systems have been extensively explored in the last decade and in the last few years we already saw promising products on the market. Most of these applications assume that context data is highly accurate. But in practice this information is often unreliable, especially when gathered from sensors or external sources. Previous research has argued that the system usability can be improved by displaying the uncertainty to the user. The research presented in this paper shows that it is not always an advantage to show the confidence of the context-aware application to the user. We developed a system for automatic form filling on mobile devices which fills in any web form with user data stored on the mobile device. The used algorithm generates rules which indicate with which probability which input field of a form should be filled in with which value. Based on this we developed two versions of our system. One shows the uncertainty of the system and one not. We then conducted a user study which shows that the user needs slightly more time and produces slightly more errors when the confidence of the system is visualized. Enrico Rukzio, John Hamard, Chie Noda, Alexander De Luca |
Mobile HCI | 4 |