EDBT 2026 Demo / reviewers in the wild / expert
Melanie Volkamer
dblp:v/MelanieVolkamer
· DBLP profile ↗
55ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0003-2674-4043ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 7 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 7 · 3 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Why Johnny Checks but Doesn't Alert: Reporting as the Missing Step in Verifiable Internet VotingabstractEnd-to-end verifiable Internet voting promises that voters can remotely check whether their ballot was recorded correctly and that all ballots were tallied as cast. However, in order to achieve an adequate level of security, voters actually need to perform the first check. Our research focuses on the cast-then-audit approach for this check. We use related work to improve this approach in particular by providing a step-by-step guide. We conducted a deceptive online user study (N = 437) to compare our improved system with a baseline version from an actual election. We also measured the usability and participants confidence in using such systems. Our findings show that participants from the improved system perform significantly better than the baseline w.r.t. manipulation detecting and reporting capabilities. Furthermore, we show that it is important to distinguish between detection and reporting to understand how to further increase the overall security. Tobias Hilt, Christian Mack, Benjamin Berens, Melanie Volkamer |
CHI | 4 |
| 2026 | Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerabstractQR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR’s design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n = 556), where SEQR achieved 93.35% correct answers, compared to 75.24% for the Apple iOS QR code scanner and 65.11% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub. Mattia Mossano, Maxime Veit, Tobias Länge, Benjamin Berens, Filipo Sharevski, Melanie Volkamer |
CHI | 6 |
| 2026 | Implementing and Evaluating the Usability of Reliable Voter Complaints in E2E Verifiable Remote Electronic Voting
Tobias Hilt, Christian Mack, Philipp Matheis, Benjamin Berens, Tobias Länge, Rolf Haenni, Reto E. Koenig, Philipp Locher, Melanie Volkamer |
EuroS&P | 9 |
| 2025 | Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessabstractPhishing warning researchers have proposed two forms of hyperlink restrictions for reducing phishing click-through rates: focused attention, which prevents users from proceeding to a suspicious URL until they click the uncovered link inside the warning; and time delay, which disables link clicking for a short period of time. Both measures aim to draw user attention to the warning and nudge them to carefully evaluate the respective link's URL. However, the effectiveness of these measures has so far not been comparatively evaluated. We conducted a mixed-methods online experiment (n=1,320) to understand differences in the effectiveness of focused attention and time delay both independently and together. Our study used an instrumented email inbox environment, in which participants were asked to assess emails and email hyper-links. We found that, while both focused attention and time delay reduced click-through rates independently, the strength of these effects were significantly different from each other with focused attention being more effective than time delay. Combining both measures reduced CTR even further. We also found that participants who saw a warning with a time delay were more likely to hover over hyperlinks for longer than those who saw a focused attention warning. We discuss the implications of our findings for the design of anti-phishing warnings. Justin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer, Florian Schaub |
SP | 4 |
| 2025 | SoK: The past decade of user deception in emails and today's email clients' susceptibility to phishing techniquesabstractUser deception in emails is still one of the biggest security risks companies and end-users face alike. Attackers try to mislead their victims when assessing whether emails are dangerous to interact with, e.g., by using techniques based on dangerous links, dangerous attachments, or both. In this work, we present a systematic literature research of deception techniques discussed in the scientific literature of the last decade. We systematize the deception techniques, focusing on techniques that use misleading sender, link, and/or attachment information. We identify 23 deception techniques which we classify as either those that email clients should protect users against (13) and those that email clients cannot protect against and thus should be addressed in security awareness measures (10). We propose a security rating for the susceptibility of email clients to these 13 deception techniques and perform an empirical evaluation to analyze the susceptibility of seven representative email clients (web, mobile apps, desktop apps) to these deception techniques. The results of our evaluation indicate that most email clients are in need of improvement to defend against the deception techniques. Hardening email clients against these deception techniques is necessary to increase the resistance against them — without unnecessarily burdening users. Maxime Veit, Oliver Wiese, Fabian Ballreich, Melanie Volkamer, Douglas Engels, Peter Mayer 0001 |
Comput. Secur. | 4 |
| 2024 | Is Personalization Worth It? Notifying Blogs about a Privacy Issue Resulting from Poorly Implemented Consent BannersabstractSeveral websites integrate trackers without users’ consent. Previous research studied whether notifying responsible website operators about such issues is an effective measure, often with limited success. Insights from marketing research suggest that personalizing notification emails may be an effective means to improve remediation rates, with previous research pointing in both directions. We studied this approach using a sample of 119 German fitness and sports blogs employing Google Analytics (GA) without user consent: In a first step, we compare the fix rate of blog operators that received a personalized notification tailored to their blog with the fix rate of operators that received a generic notification. We find that personalized notifications do neither increase remediation rate nor operators’ response behavior. In a second step, we analyzed the reasons not to fix mentioned in (A) the email responses and (B) a survey sent to the blog operators. We find that they mostly center around (I) denial that a data leak exists, (II) a lack of resources to remedy the issue and (III) claims of specifically requiring GA. We hypothesize that an additional reason not to fix could be the so-called moral credentials phenomenon and sketch how to study that in future work. Theresa Kriecherbauer, Richard Schwank, Adrian Krauss, Konstantin Neureither, Lian Remme, Melanie Volkamer, Dominik Herrmann |
ARES | 6 |
| 2024 | Better Together: The Interplay Between a Phishing Awareness Video and a Link-centric Phishing Support ToolabstractTwo popular approaches for helping consumers avoid phishing threats are phishing awareness videos and tools supporting users in identifying phishing emails. Awareness videos and tools have each been shown on their own to increase people’s phishing detection rate. Videos have been shown to be a particularly effective awareness measure; link-centric warnings have been shown to provide effective tool support. However, it is unclear how these two approaches compare to each other. We conducted a between-subjects online experiment (n=409) in which we compared the effectiveness of the NoPhish video and the TORPEDO tool and their combination. Our main findings suggest that the TORPEDO tool outperformed the NoPhish video and that the combination of both performs significantly better than just the tool. We discuss the implications of our findings for the design and deployment of phishing awareness measures and support tools. Benjamin Berens, Florian Schaub, Mattia Mossano, Melanie Volkamer |
CHI | 4 |
| 2024 | Cookie disclaimers: Dark patterns and lack of transparencyabstractWhile cookie disclaimers on websites have been proposed to ensure that users make informed decisions regarding consenting to data collection via cookies, such informed consent is hindered by several factors. One of them is the presence of so-called dark patterns, that is, design elements that are used to lead users to accept more cookies than needed and more than they are aware of. The second factor is lack of transparency on behalf of the service providers with regards to what happens if the user does not consent to cookie usage even despite dark patterns nudging them to do so. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behaviour; (2) identifying users' attitude towards cookie disclaimers including how they decide which cookies to accept or reject; (3) assessing the behaviour of websites regarding storing non-necessary cookies despite user's consent. We show that different visual representation of the reject/accept option have a significant impact on users' decision. We also found that the labelling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users' decision). Our results on users' attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We furthermore show that even without user's explicit consent, the majority of websites we investigated still uses non-necessary cookies. We provide recommendations on how to improve the situation for different stakeholders, namely, for developers and policy makers. Benjamin Berens, Mark Bohlender, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
Comput. Secur. | 6 |
| 2024 | Taking 5 minutes protects you for 5 months: Evaluating an anti-phishing awareness videoabstractPhishing is one of the biggest security threats to organizations. Anti-phishing awareness measures can improve phishing email detection rates. These measures need to be efficient, effective, and have an enduring impact over months, rather than days. Related research provides evidence of their effectiveness in the short term. However, questions remain as to how long this impact endures. We conducted a retention user study in two phases, with almost 200 participants in the first phase and almost 80 in the second phase, to determine whether a five-minute video retains its effectiveness five months after the intervention (similar to related work on more time-intensive measures). Our results suggest that short videos can indeed still exert a positive influence five months later. We also report on the video's influence on phishing detection strategies, as well as on viewers' confidence in this respect. Based on our results, we propose recommendations to inform the content of future awareness refreshment measures. Benjamin Berens, Mattia Mossano, Melanie Volkamer |
Comput. Secur. | 3 |
| 2023 | Usable Security: Security 'Warnings' 2.0
Melanie Volkamer |
ICISSP | 1 |
| 2022 | Cookie Disclaimers: Impact of Design and Users' AttitudeabstractDark patterns in cookie disclaimers are factors that are used to lead users to accept more cookies than needed and more than they are aware of. The contributions of this paper are (1) evaluating the efficacy of several of these factors while measuring actual behavior; (2) identifying users’ attitude towards cookie disclaimers including how they decide which cookies to accept or reject. We show that different visual representation of the reject/accept option have a significant impact on users’ decision. We also found that the labeling of the reject option has a significant impact. In addition, we confirm previous research regarding biasing text (which has no significant impact on users’ decision). Our results on users’ attitude towards cookie disclaimers indicate that for several user groups the design of the disclaimer only plays a secondary role when it comes to decision making. We provide recommendations on how to improve the situation for the different user groups. Benjamin Berens, Heike Dietmann, Chiara Krisam, Oksana Kulyk, Melanie Volkamer |
ARES | 5 |
| 2022 | SoK: A Systematic Literature Review of Knowledge-Based Authentication on Augmented Reality Head-Mounted DisplaysabstractThe adoption of Augmented Reality (AR) technology has increased over the years. AR enhances various activities for consumers and businesses, particularly in industrial contexts. The three-dimensional virtual experience is realized by the usage of Head-Mounted Displays (HMD). These devices provide access to sensitive data and services. Thus, secure and usable authentication schemes are essential to control access to the HMD and the stored data as well as schemes to authenticate to the services one wants to use with the AR device. We conducted a systematic literature review on knowledge-based authentication schemes for AR HMD. 31 different schemes were identified. These schemes were assessed regarding various aspects including the type of AR HMD, the type of secret, how users input their secret, as well as usability and security aspects. We discuss gaps for future work. Reyhan Duezguen, Naheem Noah, Peter Mayer 0001, Sanchari Das 0001, Melanie Volkamer |
ARES | 5 |
| 2021 | How to Increase Smart Home Security and Privacy Risk PerceptionabstractWith continuous technological advancements, our homes become smarter by interconnecting more and more devices. Smart homes provide many advantages. However, they also introduce new privacy and security risks. Recent studies show that only a few people are aware of abstract risks, and most people are not aware of specific negative consequences. We developed a privacy and security awareness intervention for people who want to inform themselves about risks in the smart home context. Our intervention is based on research literature on risk perception and feedback from both lay users and security and privacy experts. We evaluated our intervention regarding its influence on participants' perceived threat, privacy attitude, motivation to avoid threats, willingness to pay, and time commitment to configure protective measures. The results of this evaluation show a significant increase for all these aspects. We also compared our intervention to information that users could obtain during an Internet search on the topic. In this comparison, our intervention evokes a significantly higher perceived threat and privacy attitude. It showed no significant difference for the other three scales. We discuss our findings in light of related work. Reyhan Duezguen, Peter Mayer 0001, Benjamin Berens, Christopher Beckmann, Lukas Aldag, Mattia Mossano, Melanie Volkamer, Thorsten Strufe |
TrustCom | 7 |
| 2019 | I (Don't) See What You Typed There! Shoulder-surfing Resistant Password Entry on GamepadsabstractUsing gamepad-driven devices like games consoles is an activity frequently shared with others. Thus, shoulder-surfing is a serious threat. To address this threat, we present the first investigation of shoulder-surfing resistant text password entry on gamepads by (1) identifying the requirements of this context; (2) assessing whether shoulder-surfing resistant authentication schemes proposed in non-gamepad contexts can be viably adapted to meet these requirements; (3) proposing "Colorwheels", a novel shoulder-surfing resistant authentication scheme specifically geared towards this context; (4) using two different methodologies proposed in the literature for evaluating shoulder-surfing resistance to compare "Colorwheels", on-screen keyboards (the de facto standard in this context), and an existing shoulder-surfing resistant scheme which we identified during our assessment and adapted for the gamepad context; (5) evaluating all three schemes regarding their usability. Having applied different methodologies to measure shoulder-surfing resistance, we discuss their strengths and pitfalls and derive recommendations for future research. Peter Mayer 0001, Nina Gerber, Benjamin Reinheimer, Philipp Rack, Kristoffer Braun, Melanie Volkamer |
CHI | 6 |
| 2019 | Comparing "Challenge-Based" and "Code-Based" Internet Voting Verification Implementations
Oksana Kulyk, Jan Henzel, Karen Renaud, Melanie Volkamer |
INTERACT (1) | 4 |
| 2019 | Investigating People's Privacy Risk PerceptionabstractAbstract Although media reports often warn about risks associated with using privacy-threatening technologies, most lay users lack awareness of particular adverse consequences that could result from this usage. Since this might lead them to underestimate the risks of data collection, we investigate how lay users perceive different abstract and specific privacy risks. To this end, we conducted a survey with 942 participants in which we asked them to rate nine different privacy risk scenarios in terms of probability and severity. The survey included abstract risk scenarios as well as specific risk scenarios, which describe specifically how collected data can be abused, e.g., to stalk someone or to plan burglaries. To gain broad insights into people’s risk perception, we considered three use cases: Online Social Networks (OSN), smart home, and smart health devices. Our results suggest that abstract and specific risk scenarios are perceived differently, with abstract risk scenarios being evaluated as likely, but only moderately severe, whereas specific risk scenarios are considered to be rather severe, but only moderately likely. People, thus, do not seem to be aware of specific privacy risks when confronted with an abstract risk scenario. Hence, privacy researchers or activists should make people aware of what collected and analyzed data can be used for when abused (by the service or even an unauthorized third party). Nina Gerber, Benjamin Reinheimer, Melanie Volkamer |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | Finally Johnny Can Encrypt: But Does This Make Him Feel More Secure?abstractEnd-to-end (E2E) encryption is an effective measure against privacy infringement. In 2016, it was introduced by WhatsApp for all users (of the latest app version) quasi overnight. However, it is unclear how non-expert users perceived this change, whether they trust WhatsApp as a provider of E2E encryption, and how their communication behavior changed. We conducted semi-structured interviews with twenty WhatsApp users to answer these questions. We found that about half of the participants perceived that even with E2E encryption, their messages could still be eavesdropped, for example by hackers and other criminals, governmental institutions, or WhatsApp's employees and cooperation partners. Many participants correctly identified sender and recipient as weakest points after the introduction of E2E encryption, but misconceptions were still present. For instance, users thought that messages were transmitted directly between two devices without being forwarded or stored on a server, or interpreted 'end-to-end' as a temporally end of communication. The majority of users stated to mistrust WhatsApp and its E2E encryption and presumed image-related reasons for the cost-free implementation. While most participants did not change their communication behavior, they reported to use protection strategies such as sending sensitive content via alternative channels even after the introduction of E2E encryption. Nina Gerber, Verena Zimmermann, Birgit Henhapl, Sinem Emeröz, Melanie Volkamer |
ARES | 5 |
| 2018 | On The Systematic Development and Evaluation Of Password Security Awareness-Raising MaterialsabstractText passwords play an important role in protecting the assets of organisations. Thus, it is of the essence, that employees are well aware of possible attacks and defences. To that end, we developed a password security awareness-raising material in a systematic iterative process: The material is based on the literature on password security, feedback of independent experts, and feedback of lay-users. It was evaluated in the field with employees of three organisations. Our results show that the participating employees improved their abilities to (1) discern secure from insecure password-related behaviour in a variety of scenarios relating to different attacks and (2) assess passwords as secure or insecure. These improved abilities of the participants were still present in a retention after six months. Thus, the developed awareness-raising material contributes to improving the password-related security in organisations. Peter Mayer 0001, Christian Schwartz, Melanie Volkamer |
ACSAC | 3 |
| 2018 | What Did I Really Vote For?abstractE-voting has been embraced by a number of countries, delivering benefits in terms of efficiency and accessibility. End-to-end verifiable e-voting schemes facilitate verification of the integrity of individual votes during the election process. In particular, methods for cast-as-intended verification enable voters to confirm that their cast votes have not been manipulated by the voting client. A well-known technique for effecting cast-as-intended verification is the Benaloh Challenge. The usability of this challenge is crucial because voters have to be actively engaged in the verification process. In this paper, we report on a usability evaluation of three different approaches of the Benaloh Challenge in the remote e-voting context. We performed a comparative user study with 95 participants. We conclude with a recommendation for which approaches should be provided to afford verification in real-world elections and suggest usability improvements. Karola Marky, Oksana Kulyk, Karen Renaud, Melanie Volkamer |
CHI | 4 |
| 2018 | Developing and Evaluating a Five Minute Phishing Awareness Video
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Philipp Rack, Marco Ghiglieri, Peter Mayer 0001, Alexandra Kunz, Nina Gerber |
TrustBus | 1 |
| 2018 | Explaining the privacy paradox: A systematic review of literature investigating privacy attitude and behavior
Nina Gerber, Paul Gerber, Melanie Volkamer |
Comput. Secur. | 3 |
| 2018 | Introduction to special issue on e-voting
Jurlind Budurushi, Stephan Neumann, Karen Renaud, Melanie Volkamer |
J. Inf. Secur. Appl. | 4 |
| 2017 | Security Proofs for Participation Privacy, Receipt-Freeness and Ballot Privacy for the Helios Voting SchemeabstractThe Helios voting scheme is well studied including formal proofs for verifiability and ballot privacy. However, depending on its version, the scheme provides either participation privacy (hiding who participated in the election) or verifiability against malicious bulletin board (preventing election manipulation by ballot stuffing), but not both at the same time. It also does not provide receipt-freeness, thus enabling vote buying by letting the voters construct receipts proving how they voted. Recently, an extension to Helios, further referred to as KTV-Helios, has been proposed that claims to provide these additional security properties. However, the authors of KTV-Helios did not prove their claims. Our contribution is to provide formal definitions for participation privacy and receipt-freeness that we applied to KTV-Helios. In order to evaluate the fulfillment of participation privacy and receipt-freeness, we furthermore applied the existing definition of ballot privacy, which was also used for evaluating the security of Helios, in order to show that ballot privacy also holds for KTV-Helios. David Bernhard, Oksana Kulyk, Melanie Volkamer |
ARES | 3 |
| 2017 | Reliable Behavioural Factors in the Information Security ContextabstractUsers do often not behave securely when using information technology. Many studies have tried to identify the factors of behavioural theories which can increase secure behaviour. The goal of this work is to identify which of the factors are reliably associated with secure behaviour across multiple studies. Those factors are of interest to information security professionals since addressing them in security awareness and education campaigns can help improving security related processes of users. To attain our goal, we conducted a systematic literature review and assessed the reliability of the factors based on the effect sizes reported in the literature. Our results indicate that 11 out of the 14 factors from well established behavioural theories can be associated with reliable effects in the information security context. These factors cover very different aspects: influence of the users skills, whether the environment makes it possible to exhibit secure behaviour, the influence of friends or co-workers, and the perceived properties of the secure behaviour (e.g. response cost). Also, we identify areas, where more studies are needed to increase the confidence of the factors' reliability assessment. Peter Mayer 0001, Alexandra Kunz, Melanie Volkamer |
ARES | 3 |
| 2017 | Election-Dependent Security Evaluation of Internet Voting Schemes
Stephan Neumann, Manuel Noll, Melanie Volkamer |
SEC | 3 |
| 2017 | A Second Look at Password Composition Policies in the Wild: Comparing Samples from 2010 and 2016
Peter Mayer 0001, Jan Kirchner, Melanie Volkamer |
SOUPS | 3 |
| 2017 | Don't Be Deceived: The Message Might Be Fake
Stephan Neumann, Benjamin Reinheimer, Melanie Volkamer |
TrustBus | 3 |
| 2017 | Coercion-resistant proxy voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
Comput. Secur. | 5 |
| 2017 | User experiences of TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Alexandra Kunz |
Comput. Secur. | 1 |
| 2017 | Productivity vs security: mitigating conflicting goals in organizationsabstractPurpose This paper aims to contribute to the understanding of goal setting in organizations, especially regarding the mitigation of conflicting productivity and security goals. Design/methodology/approach This paper describes the results of a survey with 200 German employees regarding the effects of goal setting on employees’ security compliance. Based on the survey results, a concept for setting information security goals in organizations building on actionable behavioral recommendations from information security awareness materials is developed. This concept was evaluated in three small- to medium-sized organizations (SMEs) with overall 90 employees. Findings The survey results revealed that the presence of rewards for productivity goal achievement is strongly associated with a decrease in security compliance. The evaluation of the goal setting concept indicates that setting their own information security goals is welcomed by employees. Research limitations/implications Both studies rely on self-reported data and are, therefore, likely to contain some kind of bias. Practical implications Goal setting in organizations has to accommodate for situations, where productivity goals constrain security policy compliance. Introducing the proposed goal setting concept based on relevant actionable behavioral recommendations can help mitigate issues in such situations. Originality/value This work furthers the understanding of the factors affecting employee security compliance. Furthermore, the proposed concept can help maximizing the positive effects of goal setting in organizations by mitigating the negative effects through the introduction of meaningful and actionable information security goals. Peter Mayer 0001, Nina Gerber, Ronja McDermott, Melanie Volkamer, Joachim Vogt 0002 |
Inf. Comput. Secur. | 4 |
| 2017 | The simpler, the better? Presenting the COPING Android permission-granting interface for better privacy-related decisions
Paul Gerber, Melanie Volkamer, Karen Renaud |
J. Inf. Secur. Appl. | 2 |
| 2016 | Introducing Proxy Voting to HeliosabstractProxy voting is a form of voting, where the voters can either vote on an issue directly, or delegate their voting right to a proxy. This proxy might for instance be a trusted expert on the particular issue. In this work, we extend the widely studied end-to-end verifiable Helios Internet voting system towards the proxy voting approach. Therefore, we introduce a new type of credentials, so-called delegation credentials. The main purpose of these credentials is to ensure that the proxy has been authorised by an eligible voter to cast a delegated vote. If voters, after delegating, change their mind and want to vote directly, cancelling a delegation is possible throughout the entire voting phase. We show that the proposed extension preserves the security requirements of the original Helios system for the votes that are cast directly, as well as security requirements tailored toward proxy voting. Oksana Kulyk, Karola Marky, Stephan Neumann, Melanie Volkamer |
ARES | 4 |
| 2016 | POSTER: Towards Collaboratively Supporting Decision Makers in Choosing Suitable Authentication SchemesabstractIn spite of the the issues associated with them, text passwords are the predominant means of user authentication today. To foster the adoption of alternative authentication schemes, Renaud et al. (2014) proposed the ACCESS (Authentication ChoiCE Support System) framework. In prior work, we presented the first implementation of this abstract framework as a decision support system. In this work, we report on the current progress of expanding our prototype implementation into a collaborative authentication research platform. In addition to a decision support system, this platform also includes an interface to systematically access all the information in the knowledge base and collaborative features to facilitate the process of keeping the data for the decision support system current. Peter Mayer 0001, Stephan Neumann, Melanie Volkamer |
CCS | 3 |
| 2016 | ZeTA-Zero-Trust Authentication: Relying on Innate Human Ability, Not TechnologyabstractReliable authentication requires the devices and channels involved in the process to be trustworthy, otherwise authentication secrets can easily be compromised. Given the unceasing efforts of attackers worldwide such trustworthiness is increasingly not a given. A variety of technical solutions, such as utilising multiple devices/channels and verification protocols, has the potential to mitigate the threat of untrusted communications to a certain extent. Yet such technical solutions make two assumptions: (1) users have access to multiple devices and (2) attackers will not resort to hacking the human, using social engineering techniques. In this paper, we propose and explore the potential of using human-based computation instead of solely technical solutions to mitigate the threat of untrusted devices and channels. ZeTA (Zero Trust Authentication on untrusted channels) has the potential to allow people to authenticate despite compromised channels or communications and easily observed usage. Our contributions are threefold: (1) We propose the ZeTA protocol with a formal definition and security analysis that utilises semantics and human-based computation to ameliorate the problem of untrusted devices and channels. (2) We outline a security analysis to assess the envisaged performance of the proposed authentication protocol. (3) We report on a usability study that explores the viability of relying on human computation in this context. Andreas Gutmann, Karen Renaud, Joseph Maguire 0001, Peter Mayer 0001, Melanie Volkamer, Kanta Matsuura, Jörn Müller-Quade |
EuroS&P | 5 |
| 2016 | Coercion-Resistant Proxy Voting
Oksana Kulyk, Stephan Neumann, Karola Marky, Jurlind Budurushi, Melanie Volkamer |
SEC | 5 |
| 2016 | Teaching Phishing-Security: Which Way is Best?
Simon Stockhardt, Benjamin Reinheimer, Melanie Volkamer, Peter Mayer 0001, Alexandra Kunz, Philipp Rack, Daniel Lehmann 0004 |
SEC | 3 |
| 2016 | TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer |
SEC | 1 |
| 2016 | Why don't UK citizens protest against privacy-invading dragnet surveillance?abstractPurpose The purpose of this study was to identify to identify reasons for the lack of protest against dragnet surveillance in the UK. As part of this investigation, a study was carried out to gauge the understanding of “privacy” and “confidentiality” by the well-informed. Design/methodology/approach To perform a best-case study, the authors identified a group of well-informed participants in terms of security. To gain insights into their privacy-related mental models, they were asked first to define the three core terms and then to identify the scenarios. Then, the participants were provided with privacy-related scenarios and were asked to demonstrate their understanding by classifying the scenarios and identifying violations. Findings Although the participants were mostly able to identify privacy and confidentiality scenarios, they experienced difficulties in articulating the actual meaning of the terms privacy, confidentiality and security. Research limitations/implications There were a limited number of participants, yet the findings are interesting and justify further investigation. The implications, even of this initial study, are significant in that if citizens’ privacy rights are being violated and they did not seem to know how to protest this and if indeed they had the desire to do so. Practical implications Had the citizens understood the meaning of privacy, and their ancient right thereto, which is enshrined in law, their response to the Snowden revelations about ongoing wide-scale surveillance might well have been more strident and insistent. Originality/value People in the UK, where this study was carried out, do not seem to protest the privacy invasion effected by dragnet surveillance with any verve. The authors identify a number of possible reasons for this from the literature. One possible explanation is that people do not understand privacy. Thus, this study posits that privacy is unusual in that understanding does not seem to align with the ability to articulate the rights to privacy and their disapproval of such widespread surveillance. This seems to make protests unlikely. Karen Renaud, Stephen Flowerday, Rosanne English, Melanie Volkamer |
Inf. Comput. Secur. | 4 |
| 2016 | Spot the phish by checking the pruned URLabstractPurpose Phishing is still a very popular and effective security threat, and it takes, on average, more than a day to detect new phish websites. Protection by purely technical means is hampered by this vulnerability window. During this window, users need to act to protect themselves. To support users in doing so, the paper aims to propose to first make users aware of the need to consult the address bar. Moreover, the authors propose to prune URL displayed in the address bar. The authors report on an evaluation of this proposal. Design/methodology/approach The paper opted for an online study with 411 participants, judging 16 websites – all with authentic design: half with legitimate and half with phish URLs. The authors applied four popular widely used types of URL manipulation techniques. The authors conducted a within-subject and between-subject study with participants randomly assigned to one of two groups (domain highlighting or pruning). The authors then tested both proposals using a repeated-measures multivariate analysis of variance. Findings The analysis shows a significant improvement in terms of phish detection after providing the hint to check the address bar. Furthermore, the analysis shows a significant improvement in terms of phish detection after the hint to check the address bar for uninitiated participants in the pruning group, as compared to those in the highlighting group. Research limitations/implications Because of the chosen research approach, the research results may lack generalisability. Therefore, researchers are encouraged to test the proposed propositions further. Practical implications This paper confirms the efficacy of URL pruning and of prompting users to consult the address bar for phish detection. Originality/value This paper introduces a classification for URL manipulation techniques used by phishers. We also provide evidence that drawing people’s attention to the address bar makes them more likely to spot phish websites, but does not impair their ability to identify authentic websites. Melanie Volkamer, Karen Renaud, Paul Gerber |
Inf. Comput. Secur. | 1 |
| 2015 | Efficiency Evaluation of Cryptographic Protocols for Boardroom VotingabstractEfficiency is the bottleneck of many cryptographic protocols towards their practical application in different contexts. This holds true also in the context of electronic voting, where cryptographic protocols are used to ensure a diversity of security requirements, e.g. Secrecy and integrity of cast votes. A new and promising application area of electronic voting is boardroom voting, which in practice takes place very frequently and often on simple issues such as approving or refusing a budget. Hence, it is not a surprise that a number of cryptographic protocols for boardroom voting have been already proposed. In this work, we introduce a security model adequate for the boardroom voting context. Further, we evaluate the efficiency of four boardroom voting protocols, which to best of our knowledge are the only boardroom voting protocols that satisfy our security model. Finally, we compare the performance of these protocols in different election settings. Oksana Kulyk, Stephan Neumann, Jurlind Budurushi, Melanie Volkamer, Rolf Haenni, Reto E. Koenig, Philémon von Bergen |
ARES | 4 |
| 2015 | Secure and Efficient Key Derivation in Portfolio Authentication Schemes Using Blakley Secret SharingabstractThe ubiquitous usage of mobile devices in public spaces increases the risk of falling victim to shoulder surfing attacks, i.e. being observed by others during authentication. A promising approach to mitigating such shoulder surfing risks is portfolio authentication. It requires only an authorized subset of the password as input during each authentication attempt. One open challenge regarding portfolio authentication is how to securely and efficiently verify that a user input is actually an authorized subset of the password. In this paper we propose the (t, n)-threshold verification scheme, a novel scheme using Blakley secret sharing to provide secure verification of all authorized subsets of the password. Due to the lack of a viable alternative, we evaluate the efficiency of the (t, n)-threshold verification scheme in comparison to a naive approach. In terms of storage, the (t, n)-threshold verification scheme outperforms the naive approach in all settings and it offers lower computation times in most settings. Peter Mayer 0001, Melanie Volkamer |
ACSAC | 2 |
| 2014 | A Usable Android Application Implementing Distributed Cryptography for Election AuthoritiesabstractAlthough many electronic voting protocols have been proposed, their practical application faces various challenges. One of these challenges is, that these protocols require election authorities to perform complex tasks like generating keys in a distributed manner and decrypting votes in a distributed and verifiable manner. Although corresponding key generation and decryption protocols exist, they are not used in real-world elections for several reasons: The few existing implementations of these protocols and their corresponding interfaces are not designed for people with non technical background and thus not suitable for use by most election authorities. In addition, it is difficult to explain the security model of the protocols, but legal provisions generally require transparency. We implemented a smartphone application for election authorities featuring distributed key generation and verifiable distributed decryption of votes. In addition, we prepared education material throughout based on formulated metaphors for election authorities in order to explain the security of the application. We evaluated the usability of the application and understanding of the underlying security model, concluding that the application is usable for non-experts in computer science. While the participants were able to carry out the tasks, it became clear, that they did not have a clear understanding of the underlying security model, despite having viewed our educational material. We suggest improvements to this material as future work. Stephan Neumann, Oksana Kulyk, Melanie Volkamer |
ARES | 3 |
| 2014 | POSTER: Password Entering and Transmission SecurityabstractThe most popular form of user authentication on websites is the use of passwords. When entering a password, it is crucial that the website uses HTTPS (for the entire content). However, this is often not the case. We propose PassSec - a Firefox Add-On to support users to detect password fields on which their password might be endangered. In addition, PassSec displays a non-blocking warning next to the password field, once users click into the password field. The user is provided with possible consequences of entering a password, recommendations and further information if wanted. Gamze Canova, Melanie Volkamer, Simon Weiler |
CCS | 2 |
| 2014 | Why Doesn't Jane Protect Her Privacy?
Karen Renaud, Melanie Volkamer, Arne Renkema-Padmos |
Privacy Enhancing Technologies | 2 |
| 2014 | Developing and testing SCoP - a visual hash schemeabstractPurpose – The purpose of this study was to develop and test SCoP. Users find comparing long meaningless strings of alphanumeric characters difficult. While visual hashes – where users compare images rather than strings – have been proposed as an alternative, people are unable to sufficiently distinguish more than 30 bits, which does not provide adequate security against collision attacks. Our goal is to improve the situation. Design/methodology/approach – A visual hash scheme was developed using shapes, colours, patterns and position parameters. It was evaluated in a series of pilot user studies and improved iteratively, leading to SCoP, which encodes 60 distinguishable bits. We tested SCoP further in two follow-up studies, simulating verifying in remote electronic voting and https certificate validation. Findings – Participants attained an average accuracy rate of 97 per cent with SCoP when comparing two visual hash images, one placed above the other. From the follow-up studies, SCoP was seen to be more promising for the https certificate validation use case, with direct image comparison, while a low average accuracy rate in simulating verifiability in remote electronic voting limits its applicability in an image-recall use case. Research limitations/implications – Participants achieved high accuracy rates in unrealistic situations, where the images appeared on the screen at the same time and in the same size. Studies in more realistic situations are therefore necessary. Originality/value – We identify a visual hash scheme encoding a higher number of distinguishable bits than previously reported in literature, and extend the testing to realistic scenarios. Maina M. Olembo, Timo Kilian, Simon Stockhardt, Andreas Hülsing, Melanie Volkamer |
Inf. Manag. Comput. Secur. | 5 |
| 2014 | Implementing and evaluating a software-independent voting system for polling station elections
Jurlind Budurushi, Roman Jöris, Melanie Volkamer |
J. Inf. Secur. Appl. | 3 |
| 2013 | Pretty Understandable Democracy - A Secure and Understandable Internet Voting SchemeabstractInternet voting continues to raise interest. A large number of Internet voting schemes are available, both in use, as well as in research literature. While these schemes are all based on different security models, most of these models are not adequate for high-stake elections. Furthermore, it is not known how to evaluate the understandability of these schemes (although this is important to enable voters' trust in the election result). Therefore, we propose and justify an adequate security model and criteria to evaluate understandability. We also describe an Internet voting scheme, Pretty Understandable Democracy, show that it satisfies the adequate security model and that it is more understandable than Pretty Good Democracy, currently the only scheme that also satisfies the proposed security model. Jurlind Budurushi, Stephan Neumann, Maina M. Olembo, Melanie Volkamer |
ARES | 4 |
| 2013 | Are Graphical Authentication Mechanisms As Strong As Passwords?
Karen Renaud, Peter Mayer 0001, Melanie Volkamer, Joseph Maguire 0001 |
FedCSIS | 3 |
| 2013 | Holistic and Law Compatible IT Security Evaluation: Integration of Common Criteria, ISO 27001/IT-Grundschutz and KORAabstractCommon Criteria and ISO 27001/IT-Grundschutz are well acknowledged evaluation standards for the security of IT systems and the organisation they are embedded in. These standards take a technical point of view. In legally sensitive areas, such as processing of personal information or online voting, compliance with the legal specifications is of high importance, however, for the users’ trust in an IT system and thus for the success of this system. This article shows how standards for the evaluation of IT security may be integrated with the KORA approach for law compatible technology design to the benefit of both – increasing confidence IT systems and their conformity with the law on one hand and a concrete possibility for legal requirements to be integrated into technology design from the start. The soundness of this interdisciplinary work will be presented in an exemplary application to online voting. Daniela Simic-Draws, Stephan Neumann, Anna Kahlert, Philipp Richter, Rüdiger Grimm, Melanie Volkamer, Alexander Roßnagel |
Int. J. Inf. Secur. Priv. | 6 |
| 2013 | Usable secure email communications: criteria and evaluation of existing approachesabstractPurpose Email communication has been used for many years, and has begun to replace traditional, physical correspondence more and more. Compared to a traditional postal service, email services are easier, faster, and free of charge. Standard email, however, is, from a security point of view, more comparable to post cards than letters. Some security techniques and services exist, but few people use them due to lack of awareness, low usability, and a lack of understanding of Public Key Infrastructures (PKIs). A comprehensive comparison is missing, which makes it difficult for users to decide which email service to use. The purpose of this paper is to identify evaluation criteria covering security, usability, and interoperability aspects of email, and to apply them to existing email services. Design/methodology/approach The authors first define criteria based on literature review, threat analysis and expert consultation. These criteria are then applied, when applicable, to existing approaches including DKIM, SPF, PGP, S/MIME and Opportunistic Encryption, and to common secure email providers including Gmail, Hushmail, and De‐Mail. Findings None of the existing analysed services meets all the derived criteria. Based on the result of the application of these criteria and the corresponding comparison, the authors propose future directions for usable secure email communication. Originality/value The criteria proposed are original and allow an evaluation and a comparison of different email systems that not only considers security aspects, but also the relation and trade‐offs between security, usability and interoperability. Moreover, the trust assumptions involved are also considered. Cristian Thiago Moecke, Melanie Volkamer |
Inf. Manag. Comput. Secur. | 2 |
| 2012 | Civitas and the Real World: Problems and Solutions from a Practical Point of ViewabstractIn the past, researchers have proposed manyvoting schemes that satisfy a wide range of security properties. These schemes often rely on strong trust assumptionsand do not consider the voter sufficiently, which currentlyrenders them inappropriate for usage in real-world elections. In this paper we focus on the voting scheme Civitas, whichfeatures provably strong security properties, such as end-toend verifiability and coercion-resistance. We identify the strongtrust assumptions and usability weaknesses of the scheme, which currently prevent its usage in real-world elections. Basedon these results, we show how most of these strong trustassumptions can be implemented, e.g., by using eID cards inorder to overcome Civitas' most critical usability problem, namely credential handling. Together with a voter-processdescription and a user-interface, we pave the way for the useof Civitas in real-world elections. Stephan Neumann, Melanie Volkamer |
ARES | 2 |
| 2011 | Introducing Verifiability in the POLYAS Remote Electronic Voting SystemabstractRemote electronic voting continues to attract attention. A greater number of election officials are opting to enable a remote electronic voting channel. More and more scientific papers have been published introducing or improving existing remote electronic voting protocols. However, while the scientific papers focus on different aspects of verifiability, most of the systems in use do not provide verifiability. This gap is closed in this paper by extending a widely used remote electronic voting system, the POLYAS system, to provide verifiability. This approach has been tested in the 2010 election of the German Society for Computer Scientists and will be applied in future elections. Maina M. Olembo, Melanie Volkamer |
ARES | 3 |
| 2010 | A Taxonomy Refining the Security Requirements for Electronic Voting: Analyzing Helios as a Proof of ConceptabstractOver the past years an approved set of security requirements for electronic voting has been established. However, there is no consistent perception of the exact content and scope of these requirements. Therefore, the corner stone for a comprehensive taxonomy refining the security requirements for electronic voting was laid in. In order to verify the validity of this taxonomy, we apply it to the voting schemes Helios 1.0 and 2.0. We provide amendments to the original taxonomy and demonstrate that it successfully distinguishes between different, but related voting schemes, thus supporting its relevance for the study of electronic voting systems. Lucie Langer, Axel Schmidt 0001, Johannes Buchmann 0001, Melanie Volkamer |
ARES | 4 |
| 2007 | Requirements and Evaluation Procedures for eVotingabstractOnly the most trivial computer system can be expected to meet its requirements if those requirements are not specified. Despite the widespread use of electronic voting (evoting), no requirements catalogue exists that expresses the requirements for evoting systems with enough precision to be checkable. Nor do existing catalogues take evaluation techniques and certification procedures into account. This paper takes the first step towards the development of a new catalogue with corresponding assessment procedures, concentrating on a strict subset of evoting systems Melanie Volkamer, Margaret McGaley |
ARES | 1 |
| 2006 | Secrecy forever? Analysis of Anonymity in Internet-based Voting ProtocolsabstractInternet-based elections have become more and more popular. In future a lot of people are probably going to cast their ballot over the Internet. This could be a great benefit. But at the same time new possibilities to manipulate the election will arise: Besides other network specific attacks, sniffing of the network traffic becomes interesting. This paper identifies the problems with respect to temporal unlimited election secrecy against sniffing on the network. The problem is the voter's IP address and the fact that in practice, there is no anonymous communication channel. Thus the voter's anonymity can be broken in future. However, the attacker will not be able to proof his knowledge about the voter's decision. We figure out how this vulnerability is prevented with state of the art technologies. Melanie Volkamer, Robert Krimmer |
ARES | 1 |