Nikita Samarin

dblp:224/4443 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0001-7595-1079ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Defining Privacy Engineering as a Profession
abstract
Rapid technological advancements, evolving legal frameworks, and increasingly heightened public concern over personal data have catalyzed the emergence of privacy engineering as a critical discipline. However, the "privacy engineer" role remains loosely defined, with significant variability in responsibilities, required competencies, and organizational positioning. This paper presents a qualitative investigation into the practices, challenges, and professional profiles of privacy engineers through 27 semi-structured interviews with US-based practitioners from diverse organizational contexts. Our thematic analysis reveals four primary themes: (1) the conceptual ambiguity surrounding privacy engineering roles, (2) a blend of ethical motivation, intellectual curiosity, and the desire for career growth driving professionals into the field, (3) organizational and regulatory challenges, such as misaligned incentives and the difficulty of translating abstract legal requirements into actionable technical solutions, and (4) the critical competencies required, including robust technical skills, effective cross-functional communication, and risk management expertise. Our findings contribute to a deeper scholarly understanding of privacy engineering as a multidisciplinary practice and offer practical guidance for organizations aiming to integrate privacy more effectively into their product development cycles.
Nikita Samarin, Nandita Rao Narla, Liam Webster, Daniel Smullen
Proc. Priv. Enhancing Technol.1
2024 The Medium is the Message: How Secure Messaging Apps Leak Sensitive Data to Push Notification Services
abstract
Like most modern software, secure messaging apps rely on thirdparty components to implement important app functionality. Although this practice reduces engineering costs, it also introduces the risk of inadvertent privacy breaches due to misconfiguration errors or incomplete documentation. Our research investigated secure messaging apps' usage of Google's Firebase Cloud Messaging (FCM) service to send push notifications to Android devices. We analyzed 21 popular secure messaging apps from the Google Play Store to determine what personal information these apps leak in the payload of push notifications sent via FCM. Of these apps, 11 leaked metadata, including user identifiers (10 apps), sender or recipient names (7 apps), and phone numbers (2 apps), while 4 apps leaked the actual message content. Furthermore, none of the data we observed being leaked to FCM was specifically disclosed in those apps' privacy disclosures. We also found several apps employing strategies to mitigate this privacy leakage to FCM, with varying levels of success. Of the strategies we identified, none appeared to be common, shared, or well-supported. We argue that this is fundamentally an economics problem: incentives need to be correctly aligned to motivate platforms and SDK providers to make their systems secure and private by default.
Nikita Samarin, Alex Sanchez, Trinity Chung, Akshay Dan Bhavish Juleemun, Conor Gilsenan, Nick Merrill, Joel Reardon, Serge Egelman
Proc. Priv. Enhancing Technol.1
2023 Lessons in VCR Repair: Compliance of Android App Developers with the California Consumer Privacy Act (CCPA)
abstract
The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights. Our research investigated the extent to which Android app developers comply with the provisions of the CCPA that require them to provide consumers with accurate privacy notices and respond to "verifiable consumer requests" (VCRs) by disclosing personal information that they have collected, used, or shared about consumers for a business or commercial purpose. We compared the actual network traffic of 109 apps that we believe must comply with the CCPA to the data that apps state they collect in their privacy policies and the data contained in responses to "right to know" requests that we submitted to the app's developers. Of the 69 app developers who substantively replied to our requests, all but one provided specific pieces of personal data (as opposed to only categorical information). However, a significant percentage of apps collected information that was not disclosed, including identifiers (55 apps, 80%), geolocation data (21 apps, 30%), and sensory data (18 apps, 26%) among other categories. We discuss improvements to the CCPA that could help app developers comply with "right to know" requests and other related regulations.
Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Jay Hoofnagle, Serge Egelman
Proc. Priv. Enhancing Technol.1
2020 Empirical Measurement of Systemic 2FA Usability
Joshua Reynolds, Nikita Samarin, Joseph D. Barnes, Taylor Judd, Joshua Mason, Michael D. Bailey, Serge Egelman
USENIX Security Symposium2
2019 PILOT: Password and PIN information leakage from obfuscated typing videos
abstract
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters (∗ or ∙) that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos ( PILOT ). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work (In European Symposium on Research in Computer Security ( 2018 ) 263–280 Springer). In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.
Kiran S. Balagani, Matteo Cardaioli, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
J. Comput. Secur.10
2018 SILK-TV: Secret Information Leakage from Keystroke Timing Videos
Kiran S. Balagani, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
ESORICS (1)9