Lucy Simko

dblp:31/9612 · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0003-2191-1332ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 3 first-author · 11 since 2021Human-computer interaction and ubiquitous computing · 8 · 2 first-author · 7 since 2021Software engineering, systems software and programming languages · 2
YearPublicationVenuePosition
2026 From A to Zines: Narrative Threat Modeling in U.S. Reproductive Health Media
abstract
Post-Roe, people capable of pregnancy face fragmented reproductive privacy landscapes in the United States (U.S.), with risks spanning legal, digital, and interpersonal domains. These conditions demand new forms of privacy guidance. We analyzed 212 reproductive health zines— a DIY, subversive, and collectively produced media genre—to understand how they communicate reproductive health information. Zines foreground embodied, first-person narratives interwoven with historical context, medical guidance, and activist messaging. We argue their use of subversive or alternative medical knowledge enhanced credibility in contexts of low institutional trust. While some zines offer digital privacy strategies, many focus on avoiding institutional exposure altogether. These emotionally resonant, context-sensitive accounts illustrate threat models attuned to entangled risks of interpersonal betrayal, legal precarity, and surveillance. We conclude with design implications for how zines might better support people navigating reproductive risk through what we call narrative threat modeling—a situated practice that communicates privacy strategies through story, tone, and form rather than technical instructions or prescriptive checklists.
Cora Sula, Elizabeth Gorman, Kaitlyn Wei, Phoebe Moh, Nora McDonald, Lucy Simko
CHI6
2026 Quantifying Risk Perception and Scam Response Among International and Domestic US University Students
Alexandra Xinran Li, Elijah Robert Bouma-Sims, Lily Klucinec, Ray Liu, Ayesha Binte Mostofa, Arjun Arunasalam, Lorrie Faith Cranor, Pubali Datta, Lucy Simko, Karen Sowon
SOUPS9
2026 Reproductive Security & Privacy Advice on TikTok after the Overturn of Roe
Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Yasemin Acar, Lucy Simko
SOUPS4
2026 From Thrift Stores to Digital Storefronts: Users' Perspectives on Privacy and Security of Online Second-Hand Shopping in Germany
Darya Zarkalam, Anna Lena Rotthaler, Lucy Simko, Yasemin Acar
SOUPS3
2025 "It's Time. Time for Digital Security.": An End User Study on Actionable Security and Privacy Advice
abstract
Digital security advice is the focus of much research, with unsatisfying results: End users do not follow experts' security advice, and users and experts struggle to prioritize existing advice. Several studies point out that users are over-whelmed by the amount of available security advice, and make recommendations on how to improve existing advice. Nevertheless, we still do not know how to effectively give security advice. Inspired by daily habit apps, we developed a set of 30 pieces of short and actionable advice, and the Security App, an Android smartphone app to provide this advice to end users, to reduce mental effort, and to build secure habits. We conducted a 30-day online end-user (N=74) study to evaluate whether the set of advice is actionable and meaningful to users, whether users adopt the advice, and whether the app has an impact on security awareness and behavior. Our results show that the app is an appropriate tool to provide security advice to end users. Participants perceive the majority of tasks as comprehensible, actionable, and useful, and we show that the app in fact introduces secure behaviors. Our results can serve as a basis for future research on security advice and creating secure habits, and the possibility to effectively teach secure behavior.
Anna Lena Rotthaler, Harshini Sri Ramulu, Lucy Simko, Sascha Fahl, Yasemin Acar
SP3
2025 "It's been Lovely Watching you": Institutional Decision-Making on Online Proctoring Software
abstract
Universities have adopted remote proctoring software to maintain academic integrity during invigilated online exams. The use of this software, however, has raised privacy, security, and ethical concerns, including surveillance of students' bedrooms, processing of student data, and racially biased monitoring. Additionally, this software can require substantial local computer permissions. Prior work has explored student and educator perceptions and use of this software, but there remains a gap in understanding how senior administrators decide to adopt (or not adopt) these tools at an institutional level. This paper presents the results of interviews with 20 university administrators from the U.S. and Australia towards understanding how and why their universities decided to centrally adopt (or not adopt) remote proctoring software. We find that academic governance processes included senior administrators, legal, and IT teams, even during the rush at the start of the COVID-19 pandemic, but that students were sometimes structurally excluded from the process of adoption. We explore how administrators weighed the need for academic integrity against competing concerns about privacy, security, ethics, and long-term operational issues like cost. We find that universities adopted remote proctoring despite concerns about privacy and security, sometimes attempting to mitigate these concerns. As academia continues to explore hybrid learning, our research can guide institutions in the adoption of Educational Technologies and the assessment of student learning.
Elisa Shioji, Ani Meliksetyan, Lucy Simko, Ryan Watkins, Adam J. Aviv, Shaanan Cohney
SP3
2025 Beyond "Vulnerable Populations": A Unified Understanding of Vulnerability From A Socio-Ecological Perspective
abstract
HCI and CSCW research has witnessed increasing efforts to address diversity and inclusion in research and design practice, as evidenced by the growing body of research with populations deemed as vulnerable, marginalized, or underserved. However, this work has been largely limited to a population-specific approach, i.e., identifying certain populations as vulnerable and gathering their individual experiences. Drawing primarily from human-centered security and privacy research, we identify three key challenges faced by this population-specific approach: (1) It is limited in addressing user diversity within the target population; (2) It may fail to capture the complex social reality of vulnerability; and (3) It runs the risk of perpetuating othering and stereotypes. To address these limitations, we propose a socio-ecological perspective on vulnerability adapted from the Ecological System Theory (EST). We argue that a socio-ecological perspective of vulnerability can guide researchers to look beyond static and stigmatizing definitions of vulnerability --- instead, focus on the situations, relations, and structures that lead to vulnerability, eventually enabling transferable knowledge of vulnerability across populations. We demonstrate how the socio-ecological lens maps onto existing work and generates new insights in the case of older adults' security and privacy, as well as its potential for being applied to other contexts such as reproductive privacy and responsible artificial intelligence. We end by providing concrete recommendations on how HCI and CSCW research can better operationalize vulnerability in scholarship and design practice.
Xinru Tang, Gabriel Lima, Li Jiang 0013, Lucy Simko, Yixin Zou
Proc. ACM Hum. Comput. Interact.4
2024 "Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring Evasion
abstract
COVID-19 caused an abrupt shift towards remote learning, and along with it, an increased adoption of remote, online proctoring technology to both dissuade and identify academic dishonesty (i.e., cheating). This shift also came with significant discontent from students who took to online platforms to both express their displeasure with remote proctoring and the methods they used for evading monitoring methods, essentially discussing _hacks_ to subvert the software and cheat on exams. In this paper, we seek to understand both the methods this online community shares for evading online proctoring and why they do so. Through qualitative analysis of social media videos (n=137) and comments (n=4,297) on YouTube and TikTok, we find both non-technical (e.g., sticky-notes) and deeply technical (e.g., custom virtual machines) methods of evading proctoring. The online videos, as well as the active comment sections, provide an important window into both an (unethical) desire to cheat but also the development of a security mindset. Many see proctoring software as invasive surveillance technology, and the discussion and sharing of methods to subvert it have similar tones to that of the hacker/tinkerer communities who also seek to share their experiences of subverting technology, for fun and profit. We conclude with lessons for the security and privacy community about evading online exam proctoring, as well as a conversation about fairness and equity in proctoring design.
Lucy Simko, Adryana Hutchinson, Alvin Isaac, Evan Fries, Micah Sherr, Adam J. Aviv
CCS1
2024 Security, Privacy, and Data-sharing Trade-offs When Moving to the United States: Insights from a Qualitative Study
abstract
Moving to a new country often means that people leave their "known environment" and interact with new entities, often sharing sensitive and personal information. This exposes them to various risks. In this study, we investigate the challenges and concerns related to security, privacy, and data-sharing for people who have recently moved to the United States. Through semi-structured interviews (n=25), we find that most participants feel uncomfortable sharing documents containing their personal and sensitive information for the visa process e.g., their financial information and proof of relationship. Sharing this information makes participants concerned about their safety and privacy and sometimes violates their cultural information-sharing norms. Moving to a new environment, particularly to the US, also makes people vulnerable to fraud, specifically fraudulent online renting posts and scam calls. Those who move also navigate bureaucratic, administrative, and technical challenges that exacerbate their perceived security and privacy concerns. We further find a power imbalance that compels visa applicants to share all required information—to avoid getting their visa rejected—without feeling fully informed about the requirements and safeguards in place. Our study highlights the need for more guidance, transparency, and respect for individuals’ privacy from embassies and for technology designers to better support and protect those moving countries.
Mindy Tran, Collins W. Munyendo, Harshini Sri Ramulu, Rachel Gonzalez Rodriguez, Luisa Ball Schnell, Cora Sula, Lucy Simko, Yasemin Acar
SP7
2024 Exploring digital security and privacy in relative poverty in Germany through qualitative interviews
Anastassija Kostan, Sara Olschar, Lucy Simko, Yasemin Acar
USENIX Security Symposium3
2024 "But they have overlooked a few things in Afghanistan: " An Analysis of the Integration of Biometric Voter Verification in the 2019 Afghan Presidential Elections
Kabir Panahi, Shawn Robertson, Yasemin Acar, Alexandru G. Bardas, Tadayoshi Kohno, Lucy Simko
USENIX Security Symposium6
2023 "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments
abstract
Multi-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps.
Sabrina Klivan, Sandra Höltervennhoff, Nicolas Huaman Groschopf, Alexander Krause 0002, Lucy Simko, Yasemin Acar, Sascha Fahl
CCS5
2023 The Use and Non-Use of Technology During Hurricanes
abstract
Hurricanes can cause catastrophic damage; it is critical for those affected to access information about conditions, loved ones, and resources. Prior work in the HCI and CSCW communities has focused on how social media can be vital during natural disasters; non-social media technologies have been under-researched. To understand how technology other than social media can support or harm people during crises, we explore hurricane survivors' use and disuse of multiple kinds of technologies in online surveys with 138 US participants. We find substantial technology use supporting survivors' comfort and safety other than social media. We also observe that designing technologies for high-resource environments--as with many mainstream apps--causes users to decrease use of potentially critical technologies during utility outages, which are common during hurricanes. With themes of both (a) broad technology use and (b) conditions preventing technology use, we make recommendations for technical design, policy, and research to empower communities susceptible to hurricanes.
Lucy Simko, Harshini Sri Ramulu, Tadayoshi Kohno, Yasemin Acar
Proc. ACM Hum. Comput. Interact.1
2021 Would You Rather: A Focus Group Method for Eliciting and Discussing Formative Design Insights with Children
abstract
Would you rather go 1000 days without the Internet or five days where anyone can read your mind? We present “Would You Rather” (WYR), a technique for generating formative design insights (inspired by the conversational game of the same name) that combines design provocations with forced-choice scaffolding. Here, we describe the components of a WYR session, which include scenario generation, voting, and group discussion. As children disproportionately benefit from scaffolding during the co-design process, we also report on an evaluation of the technique with 16 children, conducted across seven sessions and spanning the course of one year. We find that WYR fulfills recommendations for focus groups (e.g. eliciting mental models and values, producing focused yet animated discussion) and leverages playfulness, humor, structure, and forced choice to overcome known common challenges of designing with children.
Lucy Simko, Britnie Chin, Sungmin Na, Harkiran Kaur Saluja, Tian Qi Zhu, Tadayoshi Kohno, Alexis Hiniker, Jason C. Yip 0001, Camille Cobb
IDC1
2021 Defensive Technology Use by Political Activists During the Sudanese Revolution
abstract
Political activism is a worldwide force in geopolitical change and has, historically, helped lead to greater justice, equality, and stopping human rights abuses. A modern revolution—an extreme form of political activism—pits activists, who rely on technology for critical operational tasks, against a resource-rich government that controls the very telecommunications network they must use to operationalize, putting the technology they use under extreme stress. Our work presents insights about activists’ technological defense strategies from interviews with 13 political activists who were active during the 2018-2019 Sudanese revolution. We find that politics and society are driving factors of security and privacy behavior and app adoption. Moreover, a social media blockade can trigger a series of anti-censorship approaches at scale, while a complete internet blackout can cripple activists’ use of technology. Even though the activists’ technological defenses against the threats of surveillance, arrest and physical device seizure were low tech, they were largely sufficient against their adversary. Through these results, we surface key design principles, but we observe that the generalization of design recommendations often runs into fundamental tensions between the security and usability needs of different user groups. Thus, we provide a set of structured questions in an attempt to turn these tensions into opportunities for technology designers and policy makers.
Alaa Daffalla, Lucy Simko, Tadayoshi Kohno, Alexandru G. Bardas
SP2
2020 User Experiences with Online Status Indicators
abstract
Online status indicators (OSIs) improve online communication by helping users convey and assess availability, but they also let users infer potentially sensitive information about one another. We surveyed 200 smartphone users to understand the extent to which users are aware of information shared via OSIs and the extent to which this shapes their behavior. Despite familiarity with OSIs, participants misunderstand many aspects of OSIs, and they describe carefully curating and seeking to control their self-presentation via OSIs. Some users further report leveraging OSI-conveyed information for problematic and malicious purposes. Drawing on existing constructs of app dependence (i.e., when users contort their behavior to meet an app's demands) and app enablement (i.e., when apps enable users to engage in behaviors they feel good about), we demonstrate that current OSI design patterns promote app dependence, and we call for a shift toward OSI designs that are more enabling for users.
Camille Cobb, Lucy Simko, Tadayoshi Kohno, Alexis Hiniker
CHI2
2020 A Privacy-Focused Systematic Analysis of Online Status Indicators
abstract
Abstract Online status indicators (or OSIs, i.e., interface elements that communicate whether a user is online) can leak potentially sensitive information about users. In this work, we analyze 184 mobile applications to systematically characterize the existing design space of OSIs. We identified 40 apps with OSIs across a variety of genres and conducted a design review of the OSIs in each, examining both Android and iOS versions of these apps. We found that OSI design decisions clustered into four major categories, namely: appearance, audience, settings, and fidelity to actual user behavior. Less than half of these apps allow users change the default settings for OSIs. Informed by our findings, we discuss: 1) how these design choices support adversarial behavior, 2) design guidelines for creating consistent, privacy-conscious OSIs, and 3) a set of novel design concepts for building future tools to augment users’ ability to control and understand the presence information they broadcast. By connecting the common design patterns we document to prior work on privacy in social technologies, we contribute an empirical understanding of the systematic ways in which OSIs can make users more or less vulnerable to unwanted information disclosure.
Camille Cobb, Lucy Simko, Tadayoshi Kohno, Alexis Hiniker
Proc. Priv. Enhancing Technol.2
2018 Computer Security and Privacy for Refugees in the United States
abstract
In this work, we consider the computer security and privacy practices and needs of recently resettled refugees in the United States. We ask: How do refugees use and rely on technology as they settle in the US? What computer security and privacy practices do they have, and what barriers do they face that may put them at risk? And how are their computer security mental models and practices shaped by the advice they receive? We study these questions through in-depth qualitative interviews with case managers and teachers who work with refugees at a local NGO, as well as through focus groups with refugees themselves. We find that refugees must rely heavily on technology (e.g., email) as they attempt to establish their lives and find jobs; that they also rely heavily on their case managers and teachers for help with those technologies; and that these pressures can push security practices into the background or make common security "best practices" infeasible. At the same time, we identify fundamental challenges to computer security and privacy for refugees, including barriers due to limited technical expertise, language skills, and cultural knowledge-for example, we find that scams as a threat are a new concept for many of the refugees we studied, and that many common security practices (e.g., password creation techniques and security questions) rely on US cultural knowledge. From these and other findings, we distill recommendations for the computer security community to better serve the computer security and privacy needs and constraints of refugees, a potentially vulnerable population that has not been previously studied in this context.
Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, Tadayoshi Kohno
IEEE Symposium on Security and Privacy1
2018 Recognizing and Imitating Programmer Style: Adversaries in Program Authorship Attribution
abstract
Abstract Source code attribution classifiers have recently become powerful. We consider the possibility that an adversary could craft code with the intention of causing a misclassification, i.e., creating a forgery of another author’s programming style in order to hide the forger’s own identity or blame the other author. We find that it is possible for a non-expert adversary to defeat such a system. In order to inform the design of adversarially resistant source code attribution classifiers, we conduct two studies with C/C++ programmers to explore the potential tactics and capabilities both of such adversaries and, conversely, of human analysts doing source code authorship attribution. Through the quantitative and qualitative analysis of these studies, we (1) evaluate a state-of-the-art machine classifier against forgeries, (2) evaluate programmers as human analysts/forgery detectors, and (3) compile a set of modifications made to create forgeries. Based on our analyses, we then suggest features that future source code attribution systems might incorporate in order to be adversarially resistant.
Lucy Simko, Luke Zettlemoyer, Tadayoshi Kohno
Proc. Priv. Enhancing Technol.1
2013 Configuring effective navigation models and abstract test cases for web applications by analysing user behaviour
abstract
SUMMARY As web applications become more complex and are used more pervasively, testing demands are increasing without corresponding automated support. One promising approach to automatic test generation is statistical model‐based testing, where logged user behaviour is used to build a usage‐based model of web application navigation, from which abstract test cases are generated. Executable test cases are then created by adding parameter values to the abstract test cases. Several researchers have proposed variations of this approach; however, no one has empirically examined the tradeoffs and implications of the different ways to represent user behaviour in a navigation model and the characteristics of the test cases automatically generated from different models. This paper reports on our exploratory study of automatically generated abstract test cases and the underlying usage‐based navigation models constructed from over 19,000 user sessions across five publicly deployed web applications. Our results suggest how web testers can easily configure statistical model‐based automatic test case generators for web applications toward generating tests closely related to user behaviour or toward new navigations without using large additional test resources. Copyright © 2013 John Wiley & Sons, Ltd.
Sara Sprenkle, Lori L. Pollock, Lucy Simko
Softw. Test. Verification Reliab.3
2011 A Study of Usage-Based Navigation Models and Generated Abstract Test Cases for Web Applications
abstract
While web applications expand in usage and complexity, testing demands are growing without corresponding automated support. One promising approach to automatic test generation is statistical model-based testing, where logged user behavior is used to build a usage-based model of web application navigation, from which abstract test cases are generated. Executable test cases are then created by adding parameter values to the abstract test cases. Several researchers have proposed variations of this approach, however, no one has empirically examined the tradeoffs and implications of the different ways to represent user behavior in a navigation model and the characteristics of the automatically generated test cases from different models. We report on our exploratory study of automatically generated abstract test cases and the underlying usage-based navigation models constructed from over 3500 user sessions across five publicly deployed web applications. Our results suggest how web testers can easily tune statistical model-based automatic test case generators for web applications toward generating tests closely related to user behavior or toward new navigations without using large additional test resources.
Sara Sprenkle, Lori L. Pollock, Lucy Simko
ICST3