EDBT 2026 Demo / reviewers in the wild / expert
Sameer Patil 0001
dblp:57/702
· DBLP profile ↗
49ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0002-8214-0765ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 39 · 10 first-author · 19 since 2021Security and privacy · 6 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | External-Facing Communication on Social Media During the Russia-Ukraine Conflict of 2014abstractAlthough communication with audiences abroad is important for movements based in regions with complicated geopolitical contexts, it has received limited research attention. To address this gap, we collected and analyzed English-language tweets posted during the Russia-Ukraine conflict of 2014, focusing on understanding the content and practices associated with external-facing communication on social media. Based on the political alignment of tweets and users, determined by hashtag projection, we divided the data into discourses associated with the opposing pro-Ukrainian and pro-separatist movements, along with a neutral discourse. Through topic modeling and qualitative coding, we identified 21 diverse themes across the three discourses, suggesting that users could benefit from more targeted ways of engaging with social media content that enable focused participation. We observed that the pro-Ukrainian movement struggled to sustain long-term participation and compete with inauthentic content. Our findings could be useful for investigating external-facing communication of other online social movements, which have become increasingly prevalent. Khawar Murad Ahmed, Sarah Choe, Christopher de Freitas, Sameer Patil 0001, Marina Kogan |
CHI | 4 |
| 2026 | Investigating How Types of Data Associated With Smart Home Devices Influence Privacy Concerns and Perceived BenefitsabstractDomestic appliances and objects are increasingly augmented with data-driven “smart” capabilities. Such Smart Home Devices (SHDs) may receive data directly from users, observe their surroundings with sensors, or infer/predict information through computation. We conducted a scenario-based questionnaire study across multiple regions to investigate user perceptions and expectations regarding the handling of these three types of data associated with SHDs. We systematically varied the scenarios across participants to examine whether the level of ambiguity in the description of an SHD influences user perceptions and expectations regarding its data-handling operations. The study included four SHDs that differed in complexity (two complex and two simple) as a within-subjects treatment. We found that reducing ambiguity in describing SHD operations fosters greater user understanding while increasing privacy concerns about data handling, with notable variations in effects across data types, device complexity, and region. Our findings can be applied to enhance user awareness and control of data handling in the SHD context and inform SHD-specific data protection regulation. Sameer Patil 0001, Tom Wenzel, Jens Grossklags |
CHI | 1 |
| 2026 | Strategic misdirection: Attempts to protect privacy with made-up email addressesabstractPeople are often asked to provide their email addresses for identification, authentication, or communication purposes. In many such circumstances, people provide made-up email addresses instead of their own. To understand why people provide made-up email addresses, we interviewed 20 people who reported doing so. We found that the participants provided made-up email addresses to avoid information overload and protect privacy. The participants chose to provide made-up email addresses based on several factors, such as the context, personal benefits and risks, past experiences, and verification requirements. When composing made-up email addresses, the participants employed several common patterns based on their mental models of email address formats and threat models for undesirable uses of their email addresses. The participants reported using these patterns strategically to navigate the social expectations to comply with such requests and to avoid embarrassment from being perceived as deceptive. We connect our findings to email privacy more broadly through the theoretical perspectives of boundary regulation, communication privacy management, contextual integrity, social desirability, and interdependent privacy. Our insight points to design and regulatory suggestions to address the interdependent privacy issues resulting from made-up email addresses and to help users deal more effectively with email overload and email marketing. • Explores how people use made-up email addresses for privacy and information overload. • Describes interdependent privacy issues in using made-up email addresses. • Connects email privacy practices to key privacy-related theories. • Proposes unified client-side management for misdirected and unwanted email messages. • Advocates input validation and double opt-in for email address collection. Sharmin Ahmed, Emilee Rader, Sameer Patil 0001 |
Int. J. Hum. Comput. Stud. | 3 |
| 2026 | ReporTor: Facilitating User Reporting of Issues Encountered in Naturalistic Web Browsing via Tor BrowserabstractThe privacy properties of Tor Browser and the privacy sensitivity of its user base preclude the collection of traditional telemetry and analytics to understand the problems users face. To address the lack of telemetry and analytics, we developed ReporTor, a plugin to facilitate anonymous, voluntary reporting of problems during naturalistic browsing via Tor Browser. We confirmed the utility and effectiveness of ReporTor by reporting the problems we encountered during a month of naturalistic web browsing via Tor Browser. Reports submitted via ReporTor enabled nuanced, in-depth analysis of the causes underlying the reported problems. Integrating ReporTor into Tor Browser can leverage its anonymous user-driven issue reporting to surface the challenges users encounter when visiting websites with Tor Browser. Analyzing and addressing the reports can enhance the user experience of Tor Browser for everyday web browsing. Nicholas Micallef, Cameron Cartier, Kevin Gallagher 0001, Lucas Zagal, Sameer Patil 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Understanding User Prioritization and Comprehension of Smartphone Permissions MHCI035abstractSmartphones allow users to control the sharing of their data with apps according to their privacy preferences. Yet, users struggle to enact their privacy preferences via the available permission settings. To understand whether these difficulties result from inaccurate understanding and/or suboptimal interface design of the permissions manager, we designed and administered an online questionnaire to smartphone users from the United States ( n = 151). We asked the participants to rate and rank the importance of the permissions commonly available on smartphones and to describe their understanding of what each setting controls. We found that a majority of users deem some permissions as important or unimportant, with the importance of other permissions varying across users based on use and privacy concerns. Our findings indicate that users misunderstand several permissions and express unfamiliarity with how some of them operate. We apply the insight from our study to derive suggestions to enhance smartphone permission managers by promoting personalized and efficient user interaction and more accurate user comprehension of functional operation. Manila Devaraja, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2025 | Learning to Work From Home: How Novice and Experienced Software Professionals Compare Online and In-person CollaborationabstractIndustry-sponsored capstone experiences that involve developing software solutions create valuable opportunities for students to engage in teamwork and learn important career skills just prior to joining the software workforce. The collaboration and communication in capstone projects, which typically happen in person, were forced to move online during the COVID-19 pandemic. We leveraged the transition to conduct a two-stage mixed-methods study that compared the in-person and online capstone experiences of students (novice software developers) and project sponsors (experienced industry professionals) to understand how novices engage in online collaboration. We uncovered that novices find online collaboration more challenging compared to experienced professionals. The challenges faced by the novices and the misalignment with experienced professionals point to a number of avenues for training novice software professionals on effective engagement in geographically distributed collaboration, which is increasingly the norm in the software industry. Ying Tang 0005, Hadar Ziv, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | Layering Sociotechnical Cybersecurity Concepts Within Project-Based LearningabstractMotivation: The increasing volume and frequency of cyberattacks have made it necessary that all computing professionals be proficient in security principles. Concurrently, modern technology poses greater threats to privacy, making it important that technological solutions be developed to respect end-user privacy preferences and comply with privacy-related laws and regulations. Just as considering security and privacy must be an integral part of developing any technological solution, teaching security and privacy ought to be a required aspect of computer science education. Objective: We set out to demonstrate that a project-based capstone experience provides an effective mechanism for teaching the foundations of security and privacy. Method: We developed ten learning modules designed to introduce and sensitize students to foundational sociotechnical concepts related to the security and privacy aspects of modern technology. We delivered the modules in the treatment sections of a two-term capstone course involving the development of software solutions for external clients. We asked the students in the course to apply the concepts covered in the modules to their projects. Control sections of the course were taught without the modules as usual. We evaluated the effectiveness of the modules by administering pre-treatment and post-treatment assessments of cybersecurity knowledge and collecting written student reflections after the delivery of each module. Results: We found that the students in the treatment condition exhibited statistically significant increases in their knowledge of foundational security and privacy concepts compared to those in the control condition without the modules. Further, student reflections indicate that they appreciated the content of the modules and were readily able to apply the concepts to their projects. Discussion: The modules we developed facilitate embedding the teaching of security and privacy within any project-based learning experience. Embedding cybersecurity instruction within capstone experiences can help create a software workforce that is more knowledgeable about sociotechnical cybersecurity principles. Brandt Redd, Ying Tang 0005, Hadar Ziv, Sameer Patil 0001 |
ICER (1) | 4 |
| 2024 | Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them
Sachin Kumar Singh, Shreeman Gautam, Cameron Cartier, Sameer Patil 0001, Robert Ricci |
NSDI | 4 |
| 2024 | From the Childhood Past: Views of Young Adults on Parental Sharing of Children's Photos
Tania Ghafourian, Nicholas Micallef, Sameer Patil 0001 |
USENIX Security Symposium | 3 |
| 2024 | Targets of Weaponized Islamophobia: The Impact of Misinformation on the Online Practices of Muslims in the United StatesabstractOnline misinformation about Islam and Muslims has increasingly become a weapon in the arsenal of Islamophobia. Such content typically aims to marginalize and disempower Muslims and sow animosity between them and non-Muslims. However, there has not yet been an investigation of the impact of such targeted misinformation on the online practices of Muslims. Through semi-structured interviews with 19 Muslim participants from diverse backgrounds, we sought to understand how Muslims in the United States navigate and use the very online spaces that are leveraged to spread misinformation targeted at them. Our findings provide a nuanced understanding of how targeted misinformation subjects Muslims to misperceptions from non-Muslims and has the harmful effect of leaving Muslims exhausted and disempowered by the futility of their attempts to correct the misperceptions. In addition, we identify forces that drive Muslims to act or retreat in their online practices in response to being targeted by misinformation. These findings can be useful to industry, civil society organizations, and policymakers in order to curb injustices related to Islamic misinformation. Sadia O. Khan, Tania Ghafourian, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | Still Creepy After All These Years: The Normalization of Affective Discomfort in App UseabstractIt is not well understood why people continue to use privacy-invasive apps they consider creepy. We conducted a scenario-based study (n = 751) to investigate how the intention to use an app is influenced by affective perceptions and privacy concerns. We show that creepiness is one facet of affective discomfort, which is becoming normalized in app use. We found that affective discomfort can be negatively associated with the intention to use a privacy-invasive app. However, the influence is mitigated by other factors, including data literacy, views regarding app data practices, and ambiguity of the privacy threat. Our findings motivate a focus on affective discomfort when designing user experiences related to privacy-invasive data practices. Treating affective discomfort as a fundamental aspect of user experience requires scaling beyond the point where the thumb meets the screen and accounting for entrenched data practices and the sociotechnical landscape within which the practices are embedded. John S. Seberger, Irina Shklovski, Emily Swiatek, Sameer Patil 0001 |
CHI | 4 |
| 2022 | Do Regional Variations Affect the CAPTCHA User Experience? A Comparison of CAPTCHAs in China and the United StatesabstractSystems worldwide deploy CAPTCHAs as a security mechanism to protect from unauthorized automated access. Typically, the effectiveness of CAPTCHAs is evaluated based on their resilience against bots. User perceptions of the interactive experience and effectiveness of CAPTCHAs have received less attention, especially for comparing the variations of CAPTCHAs presented in different regions across the world. As the first step toward filling this gap, we conducted semi-structured interviews with ten participants fluent in Chinese and English to investigate whether user perceptions are affected by variations in CAPTCHAs presented in China and the United States, respectively. We found notable differences in the perceived user experience and effectiveness across the different CAPTCHA types, but not across regional variations of the same type. Our findings point to a number of avenues for making the CAPTCHA user experience more universal and inclusive. Xinyao Ma, Zaiqiao Ye, Sameer Patil 0001 |
ASE | 3 |
| 2022 | True or False: Studying the Work Practices of Professional Fact-CheckersabstractMisinformation has developed into a critical societal threat that can lead to disastrous societal consequences. Although fact-checking plays a key role in combating misinformation, relatively little research has empirically investigated work practices of professional fact-checkers. To address this gap, we conducted semi-structured interviews with 21 fact-checkers from 19 countries. The participants reported being inundated with information that needs filtering and prioritizing prior to fact-checking. The interviews surfaced a pipeline of practices fragmented across disparate tools that lack integration. Importantly, fact-checkers lack effective mechanisms for disseminating the outcomes of their efforts which prevents their work from fully achieving its potential impact. We found that the largely manual and labor intensive nature of current fact-checking practices is a barrier to scale. We apply these findings to propose a number of suggestions that can improve the effectiveness, efficiency, scale, and reach of fact-checking work and its outcomes. Nicholas Micallef, Vivienne Armacost, Nasir Memon, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2022 | Speculative Vulnerability: Uncovering the Temporalities of Vulnerability in People's Experiences of the PandemicabstractPandemic-tracking apps may form a future infrastructure for public health surveillance. Yet, there has been relatively little exploration of the potential societal implications of such an infrastructure. In semi-structured interviews with 23 participants from India, the Middle East and North Africa (MENA), and the United States, we discussed attitudes and preferences regarding the deployment of apps that support contact tracing to contain the spread of COVID-19. Through interpretive analysis, we examined the relationship between persistent discomfort and vulnerability when using such apps. Such an examination yielded three temporal forms of vulnerability: real, anticipatory, and speculative. By identifying and defining the temporalities of vulnerability through an analysis of people's pandemic-related thoughts and experiences, we develop the overlapping discourses of humanistic infrastructure studies and infrastructural speculation. In doing so, we explore the concept of vulnerability itself and present implications for the study of vulnerability in Human-Computer Interaction (HCI) and for the oversight of app-based public health surveillance. John S. Seberger, Ikechukwu Obi, Mariem Loukil, William Liao, David J. Wild 0001, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2022 | Beyond the Pandemic and Privacy Concerns: Perceived Benefit and Expected Use of Pandemic-Tracking Apps in IndiaabstractPandemic-tracking apps could be a viable pandemic-mitigation technique, although their efficacy has been weakened by limited adoption in many places. Therefore, it is important to investigate how the perceptions of such apps are formed in different regions, which may help explain the differences in adoption. We replicated prior work on the adoption of pandemic-tracking apps in the United States with participants from India (n = 236). We identified that the perceptions of pandemic-tracking apps are connected to social orientation, familiarity with health-related technology, and demographics. We found that the perceptions and expected use were uncorrelated with privacy concerns, suggesting that privacy may not necessarily be the most suitable lens for studying the adoption of pandemic-tracking apps in India. Based on the findings, we make several recommendations for future pandemic-preparedness campaigns and identify the need to continue the trend toward contextualizing privacy-centered research with privacy-adjacent individual factors across multiple regions. John S. Seberger, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2022 | Non-literal Communication in Chinese Internet Spaces: A Case Study of FishingabstractIn Chinese Internet spaces, "fishing" is a form of non-literal communication that tries to lure or bait others. We conducted a case study of fishing on a Chinese Q&A platform in which we deconstructed the linguistic structure of the fishing language and identified its features by employing analysis techniques informed by Critical Discourse Analysis (CDA). Additionally, we examined the relationship between fishing practices and the specifics of the underlying communication platform. We found that fishing can be characterized as a reaction to rigid norms of politeness and friendliness imposed on users by platform owners. Our analysis reveals that fishing is organically connected with other social interaction within the community and facilitates autonomous and active negotiation of boundaries and linguistic norms for online discussion of controversial topics. We challenge the characterization of non-literal communication as "abnormal," and contribute a more refined understanding of online linguistic norms, community cohesion, and civil engagement. Huixin Tian, Xinyao Ma, Jeffrey Bardzell, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2022 | A Multi-Region Investigation of the Perceptions and Use of Smart Home DevicesabstractSmart Home Devices are household objects and appliances that are augmented with network connectivity and interactive capabilities. However, the benefits and conveniences of such augmentation are tempered by corresponding increases in privacy and security threats. Studies of user perceptions of these threats and user practices for addressing them are limited mostly to specific devices and/or small samples from a single region. To address this gap, we compared perceptions and practices of people in three geographic regions regarding privacy and security matters related to Smart Home Devices. Across these regions, we found differences in perceived regulatory protection and other regional factors. Our findings suggest that a co-evolution of the design and public policy related to Smart Home Devices could enhance privacy protection and drive increased adoption of these devices. Patrick Bombik, Tom Wenzel, Jens Grossklags, Sameer Patil 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | A Visual Exploration of Cybersecurity ConceptsabstractCybersecurity-related concepts can be difficult to explain or summarise. The complexity associated with these concepts is compounded by the impact of rapid technological changes and the contextual nature of the meaning ascribed to the various themes. Since visual imagery is often employed in articulation and explanation, we conducted a study in which we asked participants to sketch their understanding of cybersecurity concepts. Based on an analysis of these sketches and subsequent discussions with participants, we make the case for the use of sketching and visuals as a tool for cybersecurity research. Our collection of sketches and icons can further serve as the seed for a visual vocabulary for cybersecurity-related interfaces and communication. Miriam Sturdee, Lauren Thornton, Bhagya Wimalasiri, Sameer Patil 0001 |
Creativity & Cognition | 4 |
| 2021 | Empowering Resignation: There's an App for Thatabstract“There’s an app for that” is perhaps the definitive rhetoric of our times. To understand how users navigate the trade-offs involved in using apps that support a variety of everyday activities, we conducted scenario-based semi-structured interviews (n = 25). Despite the technical and regulatory mechanisms that are supposedly meant to empower users to manage their privacy, we found that users express an overarching feeling of resignation regarding privacy matters. Because these apps provide convenience and other benefits, as one participant put it, “there is a very fine line” that marks the divide between feeling empowered in the use of technology and coping with the discomfort and creepiness arising from invasive app behavior. Participants consistently expressed being resigned to disclose data even as they accepted personal responsibility for their own privacy. We apply the findings to discuss the limits of empowerment as a design logic for privacy-oriented solutions. John S. Seberger, Marissel Llavore, Nicholas Nye Wyant, Irina Shklovski, Sameer Patil 0001 |
CHI | 5 |
| 2021 | Us and Them (and It): Social Orientation, Privacy Concerns, and Expected Use of Pandemic-Tracking Apps in the United StatesabstractThe deployment of technologies to track and mitigate the spread COVID-19 has surfaced tensions between individual autonomy and the collective good. These tensions reflect a conflict between two central concerns: (i) effectively controlling the spread of the pandemic and (ii) respecting individual rights, values, and freedoms. We explored these tensions in an online experiment (n = 389) designed to identify the influence of social orientation and communicative framing on perceptions and expected use of pandemic-tracking apps. We found that social orientation is a statistically significant predictor of app perception and expected use, with collectivist social orientation associated with higher levels and individualist social orientation with lower levels for both aspects. We found interactions between social orientation and communicative framing, as well as a connection between privacy concerns and expected duration of app use. Our findings hold important implications for the design, deployment, and adoption of technology for the public good. Shaping the post-pandemic social contract requires considering the long-term sociocultural impact of these technological solutions. John S. Seberger, Sameer Patil 0001 |
CHI | 2 |
| 2021 | Exploring Privacy Aspects of Smartphone NotificationsabstractNotifications are one of the most important features of mobile devices. Users receive multitudes of notifications every day. These notifications often carry sensitive content such as private messages, financial information, authentication tokens, etc. To understand privacy considerations related to notification content and delivery, we conducted a study in which participants (n = 206) described their preferences and practices regarding smartphone notifications. A majority of the participants (61%) reported at least one negative experience connected to notifications. We report on various privacy violations that arise due to notifications, such as unwanted information disclosure, intimacy breach, and inopportune intrusion. Our work contributes to a better understanding of privacy risks presented by notifications on mobile devices and points to several design suggestions for privacy-sensitive notification delivery mechanisms. Sameer Patil 0001 |
MobileHCI | 2 |
| 2021 | Promoting Privacy Considerations in Real-World Projects in Capstone Courses with Ideation CardsabstractNearly all software built today impinges upon end-user privacy and needs to comply with relevant regulations. Therefore, there have been increasing calls for integrating considerations of compliance with privacy regulations throughout the software engineering lifecycle. However, software engineers are typically trained in the technical fields and lack sufficient knowledge and support for sociotechnical considerations of privacy. Privacy ideation cards attempt to address this issue by making privacy compliance understandable and actionable for software developers. However, the application of privacy ideation cards in real-world software projects has not yet been systemically investigated. The effectiveness of ideation cards as a pedagogical tool has not yet been examined either. We address these gaps by studying how teams of undergraduate students applied privacy ideation cards in capstone projects that involved building real-world software for industry sponsors. We found that privacy ideation cards fostered greater consideration and understanding of the extent to which the projects aligned with privacy regulations. We identified three main themes from student discussions of privacy compliance: (i) defining personal data; (ii) assigning responsibility for privacy compliance; and (iii) determining and exercising autonomy. The results suggest that application of the cards for real-world projects requires careful consideration of intersecting factors such as the stage at which the cards are used and the autonomy available to the developers. Pedagogically, ideation cards can facilitate low-level cognitive engagement (especially the cognitive processes of meaning construction and interpretation) for specific components within a project. Higher-level cognitive processes were comparatively rare in ideation sessions. These findings provide important insight to help enhance capstone instruction and to improve privacy ideation cards to increase their impact on the privacy properties of the developed software. Ying Tang 0005, Morgan L. Brockman, Sameer Patil 0001 |
ACM Trans. Comput. Educ. | 3 |
| 2021 | Does This Photo Make Me Look Good?: How Social Media Feedback on Photos Impacts Posters, Outsiders, and FriendsabstractIn recent years, the use and importance of visual communication through photos have grown considerably. However, we have little understanding of the alignment between the intentions of the photo posters and the reactions of viewers. To address this gap, we replicated previous work that studied the alignment of poster and outsider judgments of text posts by extending it to photo posts. In our study of 573 users across four social media platforms, we found that outsiders generally judge photo posts more positively than anticipated by posters. Examining viewer engagement on social media revealed that photos depicting family and friends receive fewer reactions. We apply our insight to propose novel solutions that can help users create a more positive digital presence by aligning their photo posts with the expectations of their audiences. Sanchari Das 0001, Tousif Ahmed, Apu Kapadia, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Won't You Think of Others?: Interdependent Privacy in Smartphone App PermissionsabstractThe ever increasing amount of data on smartphones often contains private information of others that people interact with via the device. As a result, one user's decisions regarding app permissions can expose the information of other parties. However, research typically focuses on consequences of privacy-related decisions only for the user who makes the decisions. Work on the impact of these decisions on the privacy of others is still relatively scant. We fill this gap with an online study that extends prior work on interdependent privacy in social networking sites to the context of smartphone permissions. Our findings indicate that people typically give less consideration to the implications of their actions for the privacy of others compared to the impact on themselves. However, we found that priming people with information that features others can help reduce this discrepancy. We apply this insight to offer suggestions for enhancing permission-specification interfaces and system architectures to accommodate interdependent privacy. Maximilian Marsch, Jens Grossklags, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2021 | Fakey: A Game Intervention to Improve News Literacy on Social MediaabstractWe designed and developed Fakey, a game to improve news literacy and reduce misinformation spread by emulating a social media feed. We analyzed player interactions with articles in the feed collected over 19 months within a real-world deployment of the game. We found that Fakey is effective in priming players to be suspicious of articles from questionable sources. Players who interact with more articles in the game enhance their skills in spotting mainstream content, thus confirming the utility of Fakey for improving news literacy. Semi-structured interviews with those who played the game revealed that players find it simple, fun, and educational. The principles and mechanisms used by Fakey can inform the design of social media functionality to help people distinguish between credible and questionable content in their news feeds. Nicholas Micallef, Mihai Avram 0002, Filippo Menczer, Sameer Patil 0001 |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2020 | How Mandatory Second Factor Affects the Authentication User ExperienceabstractRecent years have seen growing organizational adoption of two-factor authentication as organizations seek to limit the damage caused by password breaches. However, research on the user experience of two-factor authentication in a real-world setting is relatively scant. To fill this gap, we conducted multiple waves of an online survey of users at a large public university during its multi-phase rollout of mandatory two-factor authentication for faculty, staff, and students. In addition, we examined multiple months of logs of all authentication events at the university. We found no significant changes in user experience and acceptance of two-factor authentication when it was mandatory for select systems that dealt with sensitive information. However, these factors degraded when users were forced to use two-factor authentication for logging into every single university resource. Our findings can serve as important guidance for the implementation of two-factor authentication in organizations in a way that can help achieve a balance between security and user experience. Jacob Abbott, Sameer Patil 0001 |
CHI | 2 |
| 2020 | Why Johnny Can't Unsubscribe: Barriers to Stopping Unwanted EmailabstractA large proportion of email messages in an average Internet user's inbox are unwanted commercial messages from mailing lists, bots, and so on. Although such messages often include instructions to unsubscribe, people still struggle with stopping unwanted email. We investigated the user experience of unsubscribing from unwanted email messages by recruiting 18 individuals for via a lab study followed by semi-structured interviews. Based on unsubscribing practices of the study participants, we synthesized eight common unsubscription mechanisms and identified the corresponding user experience challenges. We further uncovered alternative practices aimed at circumventing the need to unsubscribe. Our findings reveal frustration with the prevailing options for limiting access to the self by managing email boundaries. We apply our insight to offer design suggestions that could help commercial providers improve the user experience of unsubscribing and provide users more control over the email they receive. Jayati Dev, Emilee Rader, Sameer Patil 0001 |
CHI | 3 |
| 2020 | Effects of Credibility Indicators on Social Media News Sharing IntentabstractIn recent years, social media services have been leveraged to spread fake news stories. Helping people spot fake stories by marking them with credibility indicators could dissuade them from sharing such stories, thus reducing their amplification. We carried out an online study (N = 1,512) to explore the impact of four types of credibility indicators on people's intent to share news headlines with their friends on social media. We confirmed that credibility indicators can indeed decrease the propensity to share fake news. However, the impact of the indicators varied, with fact checking services being the most effective. We further found notable differences in responses to the indicators based on demographic and personal characteristics and social media usage frequency. Our findings have important implications for curbing the spread of misinformation via social media platforms. Waheeb Yaqub, Otari Kakhidze, Morgan L. Brockman, Nasir Memon, Sameer Patil 0001 |
CHI | 5 |
| 2019 | Local Standards for Anonymization Practices in Health, Wellness, Accessibility, and Aging Research at CHIabstractWhen studying technologies pertaining to health, wellness, accessibility, and aging, researchers are often required to perform a balancing act between controlling and sharing sensitive data of the people in their studies and protecting the privacy of these participants. If the data can be anonymized and shared, it can boost the impact of the research by facilitating replication and extension. Despite anonymization, data reporting and sharing may lead to re-identification of participants, which can be particularly problematic when the research deals with sensitive topics, such as health. We analyzed 509 CHI papers in the domains of health, wellness, accessibility, and aging to examine data reporting and sharing practices. Our analysis revealed notable patterns and trends regarding the reporting of age, gender, participant types, sample sizes, methodology, ethical considerations, anonymization techniques, and data sharing. Based on our findings, we propose several suggestions for community standards and practices that could facilitate data reporting and sharing while limiting the privacy risks for study participants. Jacob Abbott, Haley MacLeod, Novia Nurain, Gustave Ekobe, Sameer Patil 0001 |
CHI | 5 |
| 2019 | Techies Against Facebook: Understanding Negative Sentiment Toward Facebook via User Generated ContentabstractResearchers have recognized the need to pay attention to negative aspects and non-use of social media services to uncover usage barriers and surface shortcomings of these systems. We contribute to these efforts by analyzing comments on posts related to Facebook on two blogs with a technically savvy readership: Slashdot and Schneier on Security. Our analysis indicates that technically savvy individuals exhibit notably large negative sentiment toward Facebook with nearly 45% of the 3,000 reader comments we coded expressing such views. Qualitative coding revealed Privacy and Security, User Experience, and Personal Disposition as key factors underlying the negative views. Our findings suggest that negative sentiment is an explicit higher level factor driving non-use practices. Further, we confirm several non-use practices reported in the literature and identify additional aspects connected to recent technological and societal developments. Our results demonstrate that analysis of user generated content can be useful for surfacing usage practices on a large scale. Abu Saleh Md Noman, Sanchari Das 0001, Sameer Patil 0001 |
CHI | 3 |
| 2019 | It Is About What They Could Do with the Data: A User Perspective on Privacy in Smart MeteringabstractSmart Meters are a key component of increasing the power efficiency of the Smart Grid. To help manage the grid effectively, these meters are designed to collect information on power consumption and send it to third parties. With Smart Metering, for the first time, these cloud-connected sensing devices are legally mandated to be installed in the homes of millions of people worldwide. Via a multi-staged empirical study that utilized an open-ended questionnaire, focus groups, and a design probe, we examined how people characterize the tension between the utility of Smart Metering and its impact on privacy. Our findings show that people seek to make abstract Smart Metering data accountable by connecting it to their everyday practices. Our insight can inform the design of usable privacy configuration tools that help Smart Metering consumers relate abstract data with the real-world implications of its disclosure. Timo Jakobi, Sameer Patil 0001, Dave W. Randall 0001, Gunnar Stevens, Volker Wulf |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2018 | Peeling the Onion's User Experience Layer: Examining Naturalistic Use of the Tor BrowserabstractThe strength of an anonymity system depends on the number of users. Therefore, User eXperience (UX) and usability of these systems is of critical importance for boosting adoption and use. To this end, we carried out a study with 19 non-expert participants to investigate how users experience routine Web browsing via the Tor Browser, focusing particularly on encountered problems and frustrations. Using a mixed-methods quantitative and qualitative approach to study one week of naturalistic use of the Tor Browser, we uncovered a variety of UX issues, such as broken Web sites, latency, lack of common browsing conveniences, differential treatment of Tor traffic, incorrect geolocation, operational opacity, etc. We applied this insight to suggest a number of UX improvements that could mitigate the issues and reduce user frustration when using the Tor Browser. Kevin Gallagher 0001, Sameer Patil 0001, Brendan Dolan-Gavitt, Damon McCoy, Nasir Memon |
CCS | 2 |
| 2017 | New Me: Understanding Expert and Non-Expert Perceptions and Usage of the Tor Anonymity Network
Kevin Gallagher 0001, Sameer Patil 0001, Nasir Memon |
SOUPS | 2 |
| 2016 | Persuasive Information Security: Techniques to Help Employees Protect Organizational Information Security
Marc Busch, Sameer Patil 0001, Georg Regal, Christina Hochleitner, Manfred Tscheligi |
PERSUASIVE | 2 |
| 2015 | Interrupt Now or Inform Later?: Comparing Immediate and Delayed Privacy FeedbackabstractFeedback about privacy-affecting system operations is important for informed end-user privacy management. While feedback is most relevant if provided immediately, such delivery interrupts the user and risks disrupting ongoing tasks. The timing, volume, and nature of feedback is therefore critical for avoiding inopportune interruption. We varied the timing and actionability of feedback regarding accesses to a user's physical location. We found that the sense of privacy violation was heightened when feedback was immediate, but not actionable. While immediate and actionable feedback may sometimes be necessary, our findings suggest that moderately delayed feedback is often acceptable. A moderate delay may serve as a compromise to minimize interruption and avoid overly alarming reaction to immediate feedback. However, immediate and actionable feedback could still be beneficial when privacy sensitivity is high or ambiguous. Sameer Patil 0001, Roberto Hoyle, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 1 |
| 2015 | Engagement and Well-being on Social Network SitesabstractPrior research has reported contradictory findings on the relationship between the use of Social Network Sites (SNS) and psychological well-being. We addressed this shortcoming by incorporating a finer measure of SNS user engagement and hypothesizing a U-shaped rather than purely linear relationship between the two. We tested our hypotheses via a Web based questionnaire administered to 289 Facebook users. Ordinary least squares approach confirmed the hypothesized U-shaped relationship. Our results further show that User Engagement, and in turn well-being, is associated with the number of SNS friends. These findings indicate that well-being derived from SNS usage could be optimized by avoiding underuse as well as overuse. A. K. M. Najmul Islam, Sameer Patil 0001 |
CSCW | 2 |
| 2015 | Give Social Network Users the Privacy They WantabstractSocial Network Sites (SNS) are often characterized as a trade-off where users must give up privacy to gain social benefits. We investigated the alternative viewpoint that users gain the most benefits when SNSs give them the privacy they desire. Applying structural equation modeling to questionnaire data of 303 Facebook users, we examined the complex relationship between privacy and SNS benefits. We found that SNS users whose privacy desires were met reported higher levels of social connectedness (i.e., perceived relational closeness with others) than those who achieved less privacy than they desired. Social connectedness, in turn, played a pivotal role in building social capital (i.e., the benefits derived from relationships with others). These findings suggest that more openness may not always be better; SNSs should aim to achieve 'Privacy Fit' with user needs to enhance user experience and ensure sustained use. Pamela J. Wisniewski, A. K. M. Najmul Islam, Bart P. Knijnenburg, Sameer Patil 0001 |
CSCW | 4 |
| 2014 | Reflection or action?: how feedback and control affect location sharing decisionsabstractOwing to the ever-expanding size of social and professional networks, it is becoming cumbersome for individuals to configure information disclosure settings. We used location sharing systems to unpack the nature of discrepancies between a person's disclosure settings and contextual choices. We conducted an experience sampling study (N = 35) to examine various factors contributing to such divergence. We found that immediate feedback about disclosures without any ability to control the disclosures evoked feelings of oversharing. Moreover, deviation from specified settings did not always signal privacy violation; it was just as likely that settings prevented information disclosure considered permissible in situ. We suggest making feedback more actionable or delaying it sufficiently to avoid a knee-jerk reaction. Our findings also make the case for proactive techniques for detecting potential mismatches and recommending adjustments to disclosure settings, as well as selective control when sharing location with socially distant recipients and visiting atypical locations. Sameer Patil 0001, Roman Schlegel, Apu Kapadia, Adam J. Lee |
CHI | 1 |
| 2013 | Peer-produced privacy protectionabstractPrivacy risks have been addressed through technical solutions such as Privacy-Enhancing Technologies (PETs) as well as regulatory measures including Do Not Track. These approaches are inherently limited as they are grounded in the paradigm of a rational end user who can determine, articulate, and manage consistent privacy preferences. This assumes that self-serving efforts to enact privacy preferences lead to socially optimal outcomes with regard to information sharing. We argue that this assumption typically does not hold true. Consequently, solutions to specific risks are developed - even mandated - without effective reduction in the overall harm of privacy breaches. We present a systematic framework to examine these limitations of current technical and policy solutions. To address the shortcomings of existing privacy solutions, we argue for considering information sharing to be transactions within a community. Outcomes of privacy management can be improved at a lower overall cost if peers, as a community, are empowered by appropriate technical and policy mechanisms. Designing for a community requires encouraging dialogue, enabling transparency, and supporting enforcement of community norms. We describe how peer production of privacy is possible through PETs that are grounded in the notion of information as a common-pool resource subject to community governance. Sameer Patil 0001, Apu Kapadia, L. Jean Camp |
ISTAS | 2 |
| 2012 | Reasons, rewards, regrets: privacy considerations in location sharing as an interactive practiceabstractRapid growth in the usage of location-aware mobile phones has enabled mainstream adoption of location-sharing services (LSS). Integration with social-networking services (SNS) has further accelerated this trend. To uncover how these developments have shaped the evolution of LSS usage, we conducted an online study (N = 362) aimed at understanding the preferences and practices of LSS users in the US. We found that the main motivations for location sharing were to connect and coordinate with one's social and professional circles, to project an interesting image of oneself, and to receive rewards offered for 'checking in.' Respondents overwhelmingly preferred sharing location only upon explicit action. More than a quarter of the respondents recalled at least one instance of regret over revealing their location. Our findings suggest that privacy considerations in LSS are affected due to integration within SNS platforms and by transformation of location sharing into an interactive practice that is no longer limited only to finding people based on their whereabouts. We offer design suggestions, such as delayed disclosure and conflict detection, to enhance privacy-management capabilities of LSS. Sameer Patil 0001, Gregory Norcie, Apu Kapadia, Adam J. Lee |
SOUPS | 1 |
| 2012 | Privacy in instant messaging: an impression management modelabstractInstant messaging (IM) has evolved into an important tool for collaborative work. It supports informal near-synchronous communication and fosters awareness of the online presence of one's communication partners. Like all awareness systems, IM runs into concerns regarding privacy. Drawing upon prior literature and exploratory interviews, we postulate a model that posits impression management as an underlying cause for privacy desires of IM users. We verify our hypotheses using linear structural modelling on data from a large online survey of IM users across the US. The model establishes that the desire for privacy in IM arises due to the desire for impression management (both directly, as well as indirectly through the desire for visibility of one's impression to oneself). Based on this model, we suggest that IM systems could support privacy needs of users better by providing them with more knowledge and control over aspects that affect their IM-conveyed impression on others (i.e. by making impression management functionality available). Specifically, to help convey and sustain appropriate impressions on IM contacts, IM systems should allow for increased visibility of one's actions to oneself, facilitate easy comparison of one's practices with those of others, and allow one to view oneself from the perspective of others and to make finer-grained adjustments to IM settings than is possible today. Alfred Kobsa, Sameer Patil 0001, Bertolt Meyer |
Behav. Inf. Technol. | 2 |
| 2011 | With a little help from my friends: can social navigation inform interpersonal privacy preferences?abstractRecent privacy controversies surrounding social networking sites demonstrate that the mere availability of settings is not enough for effective privacy management. We investigated whether the aggregated privacy choices of one's social circle might guide users in making informed privacy decisions. We conducted an experiment in which users specified preferences for six privacy-relevant settings in Instant Messaging. In one condition, users were provided with information indicating the privacy preferences of the majority of their ``buddies." Our results suggest that while this information did influence user choices, the effect was secondary to that of the ``privacy-sensitivity" of the system feature controlled by the particular setting. Frequency of IM usage was also associated with privacy choices. The experiment data coupled with user comments suggest several usability improvements in interfaces for specifying privacy preferences. Sameer Patil 0001, Xinru Page, Alfred Kobsa |
CSCW | 1 |
| 2011 | Methodological reflections on a field study of a globally distributed software project
Sameer Patil 0001, Alfred Kobsa, Ajita John, Dorée D. Seligmann |
Inf. Softw. Technol. | 1 |
| 2010 | Capstone Project: From Software Engineering to "Informatics"abstractThis paper reports on experiences in transitioning a capstone course from a single-quarter to three-quarters. A single-quarter project course in software design and development had been offered by our department for over twenty years. More recently, upon formation of a new undergraduate degree in Informatics, this course was transformed into a three-quarter capstone course taken by students in their final year. Correspondingly, some aspects of the course projects, such as the business scope and software complexity, grew in proportion to the increase in the project duration. At the same time, a number of ¿costs¿ were reduced, including the time and effort required to set up the development infrastructure and development environments, and learn new tools and languages. Most importantly, several other factors experienced substantial growth. The longer project duration allowed significant increase in the effort and attention paid to usability engineering and user-centered design, leading to systems that were deployable and more usable for the target users. It also enabled better software testing, deployment and release management. As a result, the final outcome was much closer to production quality than the prototypes and proof-of-concept systems typical of earlier single-quarter projects. Hadar Ziv, Sameer Patil 0001 |
CSEE&T | 2 |
| 2010 | Enhancing privacy management support in instant messagingabstractInstant Messaging (IM) is a useful tool for collaborative work. However, the awareness and communication features of IM pose a tension with privacy desires. Inadequate support for managing privacy could lead to suboptimal use of IM and thereby undermine its benefits. We conducted interviews and an Internet survey to understand privacy attitudes and practices in IM usage. Based on the findings from these studies, we designed an IM plugin to improve the support for privacy management in current IM systems. The plugin detects conflicts in privacy preferences, notifies the parties involved, and allows negotiation of a resolution. It also encrypts the communication channels and archives, allows different privacy preferences for different contact groups, and provides visualizations to facilitate the comparison of one’s own IM activities with those of any IM contact group. A usability evaluation of the plugin indicated that it can be expected to succeed in its goal of providing IM users with better privacy management. Sameer Patil 0001, Alfred Kobsa |
Interact. Comput. | 1 |
| 2009 | Interpersonal Privacy Management in Distributed Collaboration: Situational Characteristics and Interpretive Influences
Sameer Patil 0001, Alfred Kobsa, Ajita John, Lynne S. Brotman Karmin, Dorée D. Seligmann |
INTERACT (2) | 1 |
| 2005 | Who gets to know what when: configuring privacy permissions in an awareness applicationabstractWe report on a study (N=36) of user preferences for balancing awareness with privacy. Participants defined permissions for sharing of location, availability, calendar information and instant messaging (IM) activity within an application called mySpace. MySpace is an interactive visualization of the physical workplace that provides dynamic information about people, places and equipment. We found a significant preference for defining privacy permissions at the group level. While "family" received high levels of awareness sharing, interestingly, "team" was granted comparable levels during business hours at work. Surprisingly, presenting participants with a detailed list of all pieces of personal context to which the system had access, did not result in more conservative privacy settings. Although location was the most sensitive aspect of awareness, participants were comfortable disclosing room-level location information to their team members at work. Our findings suggest utilizing grouping mechanisms to balance privacy control with configuration burden, and argue for increased system transparency to build trust. Sameer Patil 0001, Jennifer Lai |
CHI | 1 |
| 2005 | Uncovering privacy attitudes and practices in instant messagingabstractWe present an analysis of privacy attitudes and practices in Instant Messaging based on responses to an online questionnaire. On a 7-point Likert scale, the reported concern about IM privacy spanned the whole range, with the average being slightly below "medium". Respondents' justifications for privacy concerns revealed that the main contributing factors were: sensitivity of content, personal disposition towards privacy, understanding of technology, and potential persistence of conversations. Expectations for various categories of contacts differed significantly. Our findings indicate that it may be useful to leverage grouping functionality for privacy management. We also propose making the underlying technology more transparent. Sameer Patil 0001, Alfred Kobsa |
GROUP | 1 |
| 2005 | "THAT's What I Was Looking For": Comparing User-Rated Relevance with Search Engine Rankings
Sameer Patil 0001, Sherman R. Alpert, John Karat, Catherine G. Wolf |
INTERACT | 1 |