Theodor Schnitzler

dblp:243/0418 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
10since 2021 · last 2025
0000-0001-7575-1229ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021
YearPublicationVenuePosition
2025 Adding Context to Automated Vulnerability Detection for Teaching Software Security
abstract
Considering the recent developments in the fiel of generative AI, large language models (LLMs) can be leveraged to enhance static application security testing (SAST) tools and teaching about this topic. These models provide contextual information about identified vulnerabilities which can help students to differentiate genuine issues from false alarms while learning about software security. The approach includes analyzing vulnerabilities in android applications using SAST tools, clustering related code functionalities, and generating multi-level summaries for detected vulnerabilities. The process employs advanced clustering techniques and consensus-building methods to ensure accuracy.
Antoine Dorard, Bastian Küppers, Ashish Rajendra Sai, Theodor Schnitzler
ITiCSE (2)4
2025 Scanned and Scammed: Insecurity by ObsQRity? Measuring User Susceptibility and Awareness of QR Code-Based Attacks
Marvin Kowalewski, Leona Lassak, Markus Dürmuth, Theodor Schnitzler
USENIX Security Symposium4
2023 Hope of Delivery: Extracting User Locations From Mobile Instant Messengers
Theodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina Pöpper
NDSS1
2023 Freaky Leaky SMS: Extracting User Locations by Analyzing SMS Timings
Evangelos Bitsikas, Theodor Schnitzler, Christina Pöpper, Aanjhan Ranganathan
USENIX Security Symposium2
2023 52 Weeks Later: Attitudes Towards COVID-19 Apps for Different Purposes Over Time
abstract
The COVID-19 pandemic has prompted countries around the world to introduce smartphone apps to support disease control efforts. Their purposes range from digital contact tracing to quarantine enforcement to vaccination passports, and their effectiveness often depends on widespread adoption. While previous work has identified factors that promote or hinder adoption, it has typically examined data collected at a single point in time or focused exclusively on digital contact tracing apps. In this work, we conduct the first representative study that examines changes in people's attitudes towards COVID-19-related smartphone apps for five different purposes over the first 1.5 years of the pandemic. In three survey rounds conducted between Summer 2020 and Summer 2021 in the United States and Germany, with approximately 1,000 participants per round and country, we investigate people's willingness to use such apps, their perceived utility, and people's attitudes towards them in different stages of the pandemic. Our results indicate that privacy is a consistent concern for participants, even in a public health crisis, and the collection of identity-related data significantly decreases acceptance of COVID-19 apps. Trust in authorities is essential to increase confidence in government-backed apps and foster citizens' willingness to contribute to crisis management. There is a need for continuous communication with app users to emphasize the benefits of health crisis apps both for individuals and society, thus counteracting decreasing willingness to use them and perceived usefulness as the pandemic evolves.
Marvin Kowalewski, Christine Utz, Martin Degeling, Theodor Schnitzler, Franziska Herbert, Leonie Schaewitz, Florian Farke, Steffen Becker 0003, Markus Dürmuth
Proc. ACM Hum. Comput. Interact.4
2022 Proof-of-Vax: Studying User Preferences and Perception of Covid Vaccination Certificates
abstract
Abstract Digital tools play an important role in fighting the current global COVID-19 pandemic. We conducted a representative online study in Germany on a sample of 599 participants to evaluate the user perception of vaccination certificates. We investigated five different variants of vaccination certificates based on deployed and planned designs in a between-group design, including paper-based and app-based variants. Our main results show that the willingness to use and adopt vaccination certificates is generally high. Overall, paper-based vaccination certificates were favored over app-based solutions. The willingness to use digital apps decreased significantly by a higher disposition to privacy and increased by higher worries about the pandemic and acceptance of the coronavirus vaccination. Vaccination certificates resemble an interesting use case for studying privacy perceptions for health-related data. We hope that our work will educate the currently ongoing design of vaccination certificates, give us deeper insights into the privacy of health-related data and apps, and prepare us for future potential applications of vaccination certificates and health apps in general.
Marvin Kowalewski, Franziska Herbert, Theodor Schnitzler, Markus Dürmuth
Proc. Priv. Enhancing Technol.3
2022 Trace Oddity: Methodologies for Data-Driven Traffic Analysis on Tor
abstract
Traffic analysis attacks against encrypted web traffic are a persisting problem. However, there is a large gap between the scientific estimate of attack threats and the real-world situation. As traffic analysis attacks depend on very specific metadata information, they are sensitive to artificial changes in the transmission characteristics. While the advent of deep learning greatly improves the performance rates of traffic analysis attacks on Tor in research settings, deep neural networks are known for being implicitly vulnerable to artifacts in data. Removing artifacts from our experimental setups is essential to minimizing the risk of evaluation bias. In this work, we study a state-of-the-art end-to-end traffic correlation attack on Tor and propose a novel data collection setup. Our design addresses the key constraint of prior work: instead of using a single proxy node for collecting exit traffic, we deploy multiple proxies. Our extensive analysis shows that in the multi-proxy design (i) end-to-end round-trip times are more realistic than in the original design, and that (ii) traffic correlation attack performance degrades significantly on realistic timings. For a reliable and informative evaluation, we develop a general scientific methodology for replication and comparison of machine and deep-learning attacks on Tor. Our evaluation indicates high relevance of the multi-proxy data collection setup and the novel dataset.
Vera Rimmer, Theodor Schnitzler, Tom van Goethem, Abel Rodríguez Romero, Wouter Joosen, Katharina Kohls
Proc. Priv. Enhancing Technol.2
2021 Apps Against the Spread: Privacy Implications and User Acceptance of COVID-19-Related Smartphone Apps on Three Continents
abstract
The COVID-19 pandemic has fueled the development of smartphone applications to assist disease management. Many “corona apps” require widespread adoption to be effective, which has sparked public debates about the privacy, security, and societal implications of government-backed health applications. We conducted a representative online study in Germany (n = 1003), the US (n = 1003), and China (n = 1019) to investigate user acceptance of corona apps, using a vignette design based on the contextual integrity framework. We explored apps for contact tracing, symptom checks, quarantine enforcement, health certificates, and mere information. Our results provide insights into data processing practices that foster adoption and reveal significant differences between countries, with user acceptance being highest in China and lowest in the US. Chinese participants prefer the collection of personalized data, while German and US participants favor anonymity. Across countries, contact tracing is viewed more positively than quarantine enforcement, and technical malfunctions negatively impact user acceptance.
Christine Utz, Steffen Becker 0003, Theodor Schnitzler, Florian Farke, Franziska Herbert, Leonie Schaewitz, Martin Degeling, Markus Dürmuth
CHI3
2021 We Built This Circuit: Exploring Threat Vectors in Circuit Establishment in Tor
abstract
Traffic analysis attacks against the Tor network are a persisting threat to the anonymity of its users. The technical capabilities of attacks against encrypted Internet traffic have come a long way. Although the current state-of-the-art predicts high precision and accuracy for website fingerprinting and end-to-end confirmation, the concepts of these attacks often solely focus on their technical capabilities and ignore the operational requirements that are mandatory to get access to transmissions. In this work, we introduce three novel stepping-stone attacks that enable an adversary to (i) gain additional information about monitored connections, (ii) manipulate the Tor connection build-up, and (iii) conduct a targeted Denial-of-Service attack within the Tor infrastructure. All attacks exploit core defensive features of Tor and, consequently, are hard to patch. At the same time, our attacks are in line with standard attacker models for traffic analysis attacks. We demonstrate the feasibility of all three attacks in simulations and empirical case studies and emphasize their pivotal role in preparing a realistic setting for end-to-end confirmation attacks.
Theodor Schnitzler, Christina Pöpper, Markus Dürmuth, Katharina Kohls
EuroS&P1
2021 SoK: Managing Longitudinal Privacy of Publicly Shared Personal Online Data
abstract
Abstract Over the past decade, research has explored managing the availability of shared personal online data, with particular focus on longitudinal aspects of privacy. Yet, there is no taxonomy that takes user perspective and technical approaches into account. In this work, we systematize research on longitudinal privacy management of publicly shared personal online data from these two perspectives: user studies capturing users’ interactions related to the availability of their online data and technical proposals limiting the availability of data. Following a systematic approach, we derive conflicts between these two sides that have not yet been addressed appropriately, resulting in a list of challenging open problems to be tackled by future research. While limitations of data availability in proposed approaches and real systems are mostly time-based, users’ desired models are rather complex, taking into account content, audience, and the context in which data has been shared. Our systematic evaluation reveals interesting challenges broadly categorized by expiration conditions, data co-ownership, user awareness, and security and trust.
Theodor Schnitzler, Muhammad Shujaat Mirza, Markus Dürmuth, Christina Pöpper
Proc. Priv. Enhancing Technol.1
2019 Towards Contractual Agreements for Revocation of Online Data
Theodor Schnitzler, Markus Dürmuth, Christina Pöpper
SEC1