Emanuel von Zezschwitz

dblp:44/3837 · DBLP profile ↗
← Back
23ranked-venue papers
7as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 21 · 7 first-authorSecurity and privacy · 3

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
13 papers
Authentication and access control · 40% Usable security · 34% Privacy and data protection · 14%
Human-computer interaction and pervasive computing
3 papers
Haptics and multimodal interaction · 42% Design research and methods · 33% Interaction techniques and input · 25%

Topics — the 18 heaviest of 21, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control › knowledge-based authentication
graphical password
0.532015
Easy to Draw, but Hard to Trace?: On the Observability of Grid-based (Un)lock Patterns · CHI 2015
Using fake cursors to secure on-screen password entry · CHI 2013
Back-of-device authentication on smartphones · CHI 2013
Authentication and access control
knowledge-based authentication
0.532015
SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015
Using fake cursors to secure on-screen password entry · CHI 2013
Back-of-device authentication on smartphones · CHI 2013
Usable security
shoulder surfing
0.522017
Understanding Shoulder Surfing in the Wild: Stories from Users and Observers · CHI 2017
Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014
Authentication and access control
certificate authority
0.412019
A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done Right · CCS 2019
Network security › secure communication › secure communication protocol
TLS
0.412019
A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done Right · CCS 2019
Privacy and data protection › image privacy
observation resistance
0.332015
Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014
Vibrapass: secure authentication based on shared lies · CHI 2009
Easy to Draw, but Hard to Trace?: On the Observability of Grid-based (Un)lock Patterns · CHI 2015
Authentication and access control › password authentication
PIN entry
0.322015
SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015
Vibrapass: secure authentication based on shared lies · CHI 2009
Privacy and data protection
privacy protection mechanisms
0.312017
Understanding Shoulder Surfing in the Wild: Stories from Users and Observers · CHI 2017
Privacy and data protection
image privacy
0.212016
You Can't Watch This!: Privacy-Respectful Photo Browsing on Smartphones · CHI 2016
Biometric security
biometric authentication
0.212015
I Feel Like I'm Taking Selfies All Day!: Towards Understanding Biometric Authentication on Smartphones · CHI 2015
Usable security
shoulder surfing resistance
0.232015
SwiPIN: Fast and Secure PIN-Entry on Smartphones · CHI 2015
Using fake cursors to secure on-screen password entry · CHI 2013
Back-of-device authentication on smartphones · CHI 2013
Network security › secure communication › secure communication protocol
HTTPS
0.112019
"If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPS · IEEE Symposium on Security and Privacy 2019
Authentication and access control › password security
secure password storage
0.112019
"If you want, I can store the encrypted password": A Password-Storage Field Study with Freelance Developers · CHI 2019
Authentication and access control › multi-factor authentication
two-factor authentication
0.112019
"If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPS · IEEE Symposium on Security and Privacy 2019
Haptics and multimodal interaction › haptic feedback
tactile feedback
0.112009
Vibrapass: secure authentication based on shared lies · CHI 2009
Design research and methods
field study
0.112016
SnapApp: Reducing Authentication Overhead with a Time-Constrained Fast Unlock Option · CHI 2016
Interaction techniques and input › non-visual interaction
eyes-free interaction
0.112014
Now you see me, now you don't: protecting smartphone authentication from shoulder surfers · CHI 2014
Usable security
deception
0.012009
Vibrapass: secure authentication based on shared lies · CHI 2009

Methods — techniques the papers use, named apart from their topics

user study · 1.2data logging · 0.5within-subjects lab study · 0.4randomized controlled trial · 0.4questionnaire · 0.4qualitative interview study · 0.4mixed-methods study · 0.4field study · 0.4user survey · 0.3qualitative analysis · 0.3experience sampling · 0.23d printed prototype · 0.2user evaluation · 0.1
YearPublicationVenuePosition
2019 A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done Right
abstract
The correct configuration of HTTPS is a complex set of tasks, which many administrators have struggled with in the past. Let's Encrypt and Electronic Frontier Foundation's Certbot aim to improve the TLS ecosystem by offering free trusted certificates (Let's Encrypt) and by providing user-friendly support to configure and harden TLS (Certbot). Although adoption rates have increased, to date, there has been only a little scientific evidence of the actual usability and security benefits of this semi-automated approach. Therefore, we conducted a randomized control trial to evaluate the usability of Let's Encrypt and Certbot in comparison to the traditional certificate authority approach. We performed a within-subjects lab study with 31 participants. The study sheds light on the security and usability enhancements that Let's Encrypt and Certbot provide. We highlight how usability improvements aimed at administrators can have a large impact on security and discuss takeaways for Certbot and other security-related tasks that experts struggle with.
Christian Tiefenau, Emanuel von Zezschwitz, Maximilian Häring, Katharina Krombholz, Matthew Smith 0001
CCS2
2019 "If you want, I can store the encrypted password": A Password-Storage Field Study with Freelance Developers
abstract
In 2017 and 2018, Naiakshina et al. (CCS'17, SOUPS'18) studied in a lab setting whether computer science students need to be told to write code that stores passwords securely. The authors' results showed that, without explicit prompting, none of the students implemented secure password storage. When asked about this oversight, a common answer was that they would have implemented secure storage - if they were creating code for a company. To shed light on this possible confusion, we conducted a mixed-methods field study with developers. We hired freelance developers online and gave them a similar password storage task followed by a questionnaire to gain additional insights into their work. From our research, we offer two contributions. First of all, we reveal that, similar to the students, freelancers do not store passwords securely unless prompted, they have misconceptions about secure password storage, and they use outdated methods. Secondly, we discuss the methodological implications of using freelancers and students in developer studies.
Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Emanuel von Zezschwitz, Matthew Smith 0001
CHI4
2019 "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPS
abstract
HTTPS is one of the most important protocols used to secure communication and is, fortunately, becoming more pervasive. However, especially the long tail of websites is still not sufficiently secured. HTTPS involves different types of users, e.g., end users who are forced to make critical security decisions when faced with warnings or administrators who are required to deal with cryptographic fundamentals and complex decisions concerning compatibility. In this work, we present the first qualitative study of both end user and administrator mental models of HTTPS. We interviewed 18 end users and 12 administrators; our findings reveal misconceptions about security benefits and threat models from both groups. We identify protocol components that interfere with secure configurations and usage behavior and reveal differences between administrator and end user mental models. Our results suggest that end user mental models are more conceptual while administrator models are more protocol-based. We also found that end users often confuse encryption with authentication, significantly underestimate the security benefits of HTTPS, and ignore and distrust security indicators while administrators often do not understand the interplay of functional protocol components. Based on the different mental models, we discuss implications and provide actionable recommendations for future designs of user interfaces and protocols.
Katharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 0001, Emanuel von Zezschwitz
IEEE Symposium on Security and Privacy5
2017 Understanding Shoulder Surfing in the Wild: Stories from Users and Observers
abstract
Research has brought forth a variety of authentication systems to mitigate observation attacks. However, there is little work about shoulder surfing situations in the real world. We present the results of a user survey (N=174) in which we investigate actual stories about shoulder surfing on mobile devices from both users and observers. Our analysis indicates that shoulder surfing mainly occurs in an opportunistic, non-malicious way. It usually does not have serious consequences, but evokes negative feelings for both parties, resulting in a variety of coping strategies. Observed data was personal in most cases and ranged from information about interests and hobbies to login data and intimate details about third persons and relationships. Thus, our work contributes evidence for shoulder surfing in the real world and informs implications for the design of privacy protection mechanisms.
Malin Eiband, Mohamed Khamis, Emanuel von Zezschwitz, Heinrich Hußmann, Florian Alt
CHI3
2017 GazeTouchPIN: protecting sensitive data on mobile devices using secure multimodal authentication
abstract
Although mobile devices provide access to a plethora of sensitive data, most users still only protect them with PINs or patterns, which are vulnerable to side-channel attacks (e.g., shoulder surfing). How-ever, prior research has shown that privacy-aware users are willing to take further steps to protect their private data. We propose GazeTouchPIN, a novel secure authentication scheme for mobile devices that combines gaze and touch input. Our multimodal approach complicates shoulder-surfing attacks by requiring attackers to ob-serve the screen as well as the user’s eyes to and the password. We evaluate the security and usability of GazeTouchPIN in two user studies (N=30). We found that while GazeTouchPIN requires longer entry times, privacy aware users would use it on-demand when feeling observed or when accessing sensitive data. The results show that successful shoulder surfing attack rate drops from 68% to 10.4%when using GazeTouchPIN.
Mohamed Khamis, Mariam Hassib, Emanuel von Zezschwitz, Andreas Bulling, Florian Alt
ICMI3
2016 SnapApp: Reducing Authentication Overhead with a Time-Constrained Fast Unlock Option
abstract
We present SnapApp, a novel unlock concept for mobile devices that reduces authentication overhead with a time-constrained quick-access option. SnapApp provides two unlock methods at once: While PIN entry enables full access to the device, users can also bypass authentication with a short sliding gesture ("Snap"). This grants access for a limited amount of time (e.g. 30 seconds). The device then automatically locks itself upon expiration. Our concept further explores limiting the possible number of Snaps in a row, and configuring blacklists for app use during short access (e.g. to exclude banking apps). We discuss opportunities and challenges of this concept based on a 30-day field study with 18 participants, including data logging and experience sampling methods. Snaps significantly reduced unlock times, and our app was perceived to offer a good tradeoff. Conceptual challenges include, for example, supporting users in configuring their blacklists.
Daniel Buschek, Fabian Hartmann, Emanuel von Zezschwitz, Alexander De Luca, Florian Alt
CHI3
2016 You Can't Watch This!: Privacy-Respectful Photo Browsing on Smartphones
abstract
We present an approach to protect photos on smartphones from unwanted observations by distorting them in a way that makes it hard or impossible to recognize their content for an onlooker who does not know the photographs. On the other hand, due to the chosen way of distortion, the device owners who know the original images have no problems recognizing photos. We report the results of a user study (n=18) that showed very high usability properties for all tested graphical filters (only 11 out of 216 distorted photos were not correctly identified by their owners). At the same time, two of the filters significantly reduced the observability of the image contents.
Emanuel von Zezschwitz, Sigrid Ebbinghaus, Heinrich Hußmann, Alexander De Luca
CHI1
2016 On quantifying the effective password space of grid-based unlock gestures
abstract
We present a similarity metric for Android unlock patterns to quantify the effective password space of user-defined gestures. Our metric is the first of its kind to reflect that users choose patterns based on human intuition and interest in geometric properties of the resulting shapes. Applying our metric to a dataset of 506 user-defined patterns reveals very similar shapes that only differ by simple geometric transformations such as rotation. This shrinks the effective password space by 66% and allows informed guessing attacks. Consequently, we present an approach to subtly nudge users to create more diverse patterns by showing background images and animations during pattern creation. Results from a user study (n = 496) show that applying such countermeasures can significantly increase pattern diversity. We conclude with implications for pattern choices and the design of enrollment processes.
Emanuel von Zezschwitz, Malin Eiband, Daniel Buschek, Sascha Oberhuber, Alexander De Luca, Florian Alt, Heinrich Hußmann
MUM1
2015 I Feel Like I'm Taking Selfies All Day!: Towards Understanding Biometric Authentication on Smartphones
abstract
We present the results of an MTurk survey (n=383) on the reasons for using and not using biometric authentication systems on smartphones. We focused on Apple's Touch ID as well as Android's Face Unlock as they are the most prevalent systems on the market. For both systems, we categorized the participants as a) current users, b) former users that deactivated it at some point and c) nonusers. The results show that usability is one of the main factors that influences the decision on whether or not to use biometric verification on the smartphone. To our surprise and as opposed to previous research on biometric authentication, privacy and trust issues were not among the most important decision factors.
Alexander De Luca, Alina Hang, Emanuel von Zezschwitz, Heinrich Hußmann
CHI3
2015 SwiPIN: Fast and Secure PIN-Entry on Smartphones
abstract
In this paper, we present SwiPIN, a novel authentication system that allows input of traditional PINs using simple touch gestures like up or down and makes it secure against human observers. We present two user studies which evaluated different designs of SwiPIN and compared it against traditional PIN. The results show that SwiPIN performs adequately fast (3.7 s) to serve as an alternative input method for risky situations. Furthermore, SwiPIN is easy to use, significantly more secure against shoulder surfing attacks and switching between PIN and SwiPIN feels natural.
Emanuel von Zezschwitz, Alexander De Luca, Bruno Brunkow, Heinrich Hußmann
CHI1
2015 Easy to Draw, but Hard to Trace?: On the Observability of Grid-based (Un)lock Patterns
abstract
We performed a systematic evaluation of the shoulder surfing susceptibility of the Android pattern (un)lock. The results of an online study (n=298) enabled us to quantify the influence of pattern length, line visibility, number of knight moves, number of overlaps and number of intersections on observation resistance. The results show that all parameters have a highly significant influence, with line visibility and pattern length being most important. We discuss implications for real-world patterns and present a linear regression model that can predict the observability of a given pattern. The model can be used to provide proactive security measurements for (un)lock patterns, in analogy to password meters.
Emanuel von Zezschwitz, Alexander De Luca, Philipp Janssen, Heinrich Hußmann
CHI1
2015 Automatic Privacy Classification of Personal Photos
Daniel Buschek, Moritz Bader, Emanuel von Zezschwitz, Alexander De Luca
INTERACT (2)3
2015 Locked Your Phone? Buy a New One? From Tales of Fallback Authentication on Smartphones to Actual Concepts
abstract
We describe three scenarios in which fallback authentication on smartphones can occur and evaluate their real-life occurrences in an online survey (n=244) and complementing interviews (n=12). The results provide first insights into frequencies, reasons, countermeasures taken and problems of lockout experiences. Overall, study participants were satisfied with current fallback schemes, but at the same time, fallback authentication was aggravated when special circumstances applied and thus, leave room for improvements. Based on this, we propose an alternative concept for fallback authentication that quizzes users about installed and not installed apps on their device. Authentication succeeds, when users identify a certain number of apps correctly. Our evaluation showed that the concept yields an overall accuracy of 95%.
Alina Hang, Alexander De Luca, Emanuel von Zezschwitz, Manuel Demmler, Heinrich Hußmann
MobileHCI3
2014 Now you see me, now you don't: protecting smartphone authentication from shoulder surfers
abstract
In this paper, we present XSide, an authentication mechanism that uses the front and the back of smartphones to enter stroke-based passwords. Users can switch sides during input to minimize the risk of shoulder surfing. We performed a user study (n = 32) to explore how switching sides during authentication affects usability and security of the system. The results indicate that switching the sides increases security while authentication speed stays relatively fast (≤ 4 seconds). The paper furthermore provides insights on accuracy of eyes-free input (as used in XSide) and shows how 3D printed prototype cases can improve the back-of-device interaction experience.
Alexander De Luca, Marian Harbach, Emanuel von Zezschwitz, Max-Emanuel Maurer, Bernhard Ewald Slawik, Heinrich Hußmann, Matthew Smith 0001
CHI3
2014 It's a Hard Lock Life: A Field Study of Smartphone (Un)Locking Behavior and Risk Perception
Marian Harbach, Emanuel von Zezschwitz, Andreas Fichtner, Alexander De Luca, Matthew Smith 0001
SOUPS2
2013 Back-of-device authentication on smartphones
abstract
This paper presents BoD Shapes, a novel authentication method for smartphones that uses the back of the device for input. We argue that this increases the resistance to shoulder surfing while remaining reasonably fast and easy-to-use. We performed a user study (n=24) comparing BoD Shapes to PIN authentication, Android grid unlock, and a front version of our system. Testing a front version allowed us to directly compare performance and security measures between front and back authentication. Our results show that BoD Shapes is significantly more secure than the three other approaches. While performance declined, our results show that BoD Shapes can be very fast (up to 1.5 seconds in the user study) and that learning effects have an influence on its performance. This indicates that speed improvements can be expected in long-term use.
Alexander De Luca, Emanuel von Zezschwitz, Ngo Dieu Huong Nguyen, Max-Emanuel Maurer, Elisa Rubegni, Marcello Paolo Scipioni, Marc Langheinrich
CHI2
2013 Using fake cursors to secure on-screen password entry
abstract
In this paper, we present a concept using fake cursors to disguise on-screen password entry. We performed two user studies with different amounts of dummy cursors and differently colored cursors. The results show that dummy cursors significantly improve security. At the same time, decrease in performance is kept within an acceptable range. Depending on the required degree of security, the studies favor 8 or 16 differently colored cursors as the best trade-off between security and usability.
Alexander De Luca, Emanuel von Zezschwitz, Laurent Pichler, Heinrich Hußmann
CHI2
2013 Travel Routes or Geography Facts? An Evaluation of Voice Authentication User Interfaces
Alina Hang, Alexander De Luca, Katharina Frison, Emanuel von Zezschwitz, Massimo Tedesco, Marcel Kockmann, Heinrich Hußmann
INTERACT (3)4
2013 Long-Term Experiences with an Iterative Design of a QR-Code-Based Payment System for Beverages
Max-Emanuel Maurer, Alexander De Luca, Alina Hang, Doris Hausen, Fabian Hennecke, Sebastian Löhmann, Henri Palleis, Hendrik Richter 0002, Simon Stusak, Aurélien Tabard, Sarah Tausch, Emanuel von Zezschwitz, Franziska Schwamb, Heinrich Hußmann, Andreas Butz
INTERACT (4)12
2013 Survival of the Shortest: A Retrospective Analysis of Influencing Factors on Password Composition
Emanuel von Zezschwitz, Alexander De Luca, Heinrich Hußmann
INTERACT (3)1
2013 Making graphic-based authentication secure against smudge attacks
abstract
Most of today's smartphones and tablet computers feature touchscreens as the main way of interaction. By using these touchscreens, oily residues of the users' fingers, smudge, remain on the device's display. As this smudge can be used to deduce formerly entered data, authentication tokens are jeopardized. Most notably, grid-based authentication methods, like the Android pattern scheme are prone to such attacks.
Emanuel von Zezschwitz, Anton Koslow, Alexander De Luca, Heinrich Hußmann
IUI1
2013 Patterns in the wild: a field study of the usability of pattern and pin-based authentication on mobile devices
abstract
Graphical password systems based upon the recall and reproduction of visual patterns (e.g. as seen on the Google Android platform) are assumed to have desirable usability and memorability properties. However, there are no empirical studies that explore whether this is actually the case on an everyday basis. In this paper, we present the results of a real world user study across 21 days that was conducted to gather such insight; we compared the performance of Android-like patterns to personal identification numbers (PIN), both on smartphones, in a field study. The quantitative results indicate that PIN outperforms the pattern lock when comparing input speed and error rates. However, the qualitative results suggest that users tend to accept this and are still in favor of the pattern lock to a certain extent. For instance, it was rated better in terms of ease-of-use, feedback and likeability. Most interestingly, even though the pattern lock does not provide any undo or cancel functionality, it was rated significantly better than PIN in terms of error recovery; this provides insight into the relationship between error prevention and error recovery in user authentication.
Emanuel von Zezschwitz, Paul Dunphy, Alexander De Luca
Mobile HCI1
2009 Vibrapass: secure authentication based on shared lies
abstract
Authentication in public spaces is a risky task. Frauds on cash machines (ATMs) are not uncommon nowadays. The biggest group of attacks is observation attacks, which focus on recording the input done by the users. In this work, we present VibraPass, a system created to be resilient against observation attacks using tactile feedback provided by the users' own mobile devices. In this way, secret information is shared between the terminal and the users to add an over-head of 'lies' to the input which makes it hard for attackers to steal the real PIN or password. We present an evaluation, which shows that VibraPass has the potential to replace current authentication systems due to increased security combined with reasonable input speed and error rates.
Alexander De Luca, Emanuel von Zezschwitz, Heinrich Hußmann
CHI2