HCI.TOPHCI, made easy
HomearXivPapersInstitutionsAuthorsGuidelinesQuestionsHandbookInnovationEvents
HomearXivPapersInstitutionsAuthorsGuidelinesQuestionsHandbookInnovationEvents
Data methodologyHCI conferencesHCI papersAbout Xue ZhirongWelcome to cooperate
search
Active Filters
search
All

Papers

Browse and search HCI research papers from All

Active Filters
Author: 4790
11 results

Not as easy as just update: Survey of System Administrators and Patching Behaviours

Patching software theoretically leads to improvements including security critical changes, but it can also lead to new issues. For System Administrators (sysadmins) new issues can negatively impact operations at their organization. While mitigation options like test environments exist, little is known about their prev…

AJ
Adam D G Jenkins et al.King's College London

Twitter has a Binary Privacy Setting, are Users Aware of How It Works?

Twitter accounts are public by default, but Twitter gives the option to create protected accounts, where only approved followers can see their tweets. The publicly visible information changes based on the account type and the visibility of tweets also depends solely on the poster's account type which can cause uninten…

DK
Dilara Kekulluoglu et al.University of Edinburgh
Privacy

Understanding Privacy Switching Behaviour on Twitter

Changing a Twitter account’s privacy setting between public and protected changes the visibility of past tweets. By inspecting the privacy setting of more than 100K Twitter users over 3 months, we noticed that over 40% of those users changed their privacy setting at least once with around 16% changing it over 5 times.…

DK
Dilara Kekulluoglu et al.University of Edinburgh

Recruiting Participants With Programming Skills: A Comparison of Four Crowdsourcing Platforms and a CS Student Mailing List

Reliably recruiting participants with programming skills is an ongoing challenge for empirical studies involving software development technologies, often leading to the use of crowdsourcing platforms and computer science (CS) students. In this work, we use five existing survey instruments to explore the programming sk…

MT
Mohammad Tahaei et al.University of Edinburgh
AdRecommended

Learn AI Coding at CodeNow

Structured lessons, hands-on projects, and continuous updates for people bringing AI into real development work.

Explore Nowopen_in_new

A Case Study of Phishing Incident Response in an Educational Organization

Malicious communications aimed at tricking employees are a serious threat for organisations, necessitating the creation of procedures and policies for how to quickly respond to ongoing attacks. While automated measures provide some protection, they cannot completely protect an organisation. In this case study, we use…

KA
Kholoud Althobaiti et al.University of Edinburgh
Privacy and Security

Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on Them

Static analysis tools (SATs) have the potential to assist developers in finding and fixing vulnerabilities in the early stages of software development, requiring them to be able to understand and act on tools' notifications. To understand how helpful such SAT guidance is to developers, we ran an online experiment (N=1…

MT
Mohammad Tahaei et al.University of Edinburgh

Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges

Software development teams are responsible for making and implementing software design decisions that directly impact end-user privacy, a challenging task to do well. Privacy Champions---people who strongly care about advocating privacy---play a useful role in supporting privacy-respecting development cultures. To und…

MT
Mohammad Tahaei et al.University of Edinburgh

I don't need an expert! Making URL phishing features human comprehensible

Judging the safety of a URL is something that even security experts struggle to do accurately without additional information. In this work, we aim to make experts' tools accessible to non-experts and assist general users in judging the safety of URLs by providing them with a usable report based on the information prof…

KA
Kholoud Althobaiti et al.University of Edinburgh

RepliCueAuth: Validating the Use of a Lab-Based Virtual Reality Setup for Evaluating Authentication Systems

Evaluating novel authentication systems is often costly and time-consuming. In this work, we assess the suitability of using Virtual Reality (VR) to evaluate the usability and security of real-world authentication systems. To this end, we conducted a replication study and built a virtual replica of CueAuth [52], a rec…

FM
Florian Mathis et al.University of Edinburgh

Understanding Privacy-Related Questions on Stack Overflow

We analyse Stack Overflow (SO) to understand challenges and confusions developers face while dealing with privacy-related topics. We apply topic modelling techniques to 1,733 privacy-related questions to identify topics and then qualitatively analyse a random sample of 315 privacy-related questions. Identified topics…

MT
Mohammad Tahaei et al.University of Edinburgh

What is this URL's Destination? Empirical Evaluation of Users' URL Reading

Common anti-phishing advice tells users to mouse over links, look at the URL, and compare to the expected destination, implicitly assuming that they are able to read the URL. To test this assumption, we conducted a survey with 1929 participants recruited from the Amazon Mechanical Turk and Prolific Academic platforms.…

SA
Sara Albakry et al.University of Edinburgh
Paper TitleAuthorsResearch TopicsPaper DatabaseYear

Not as easy as just update: Survey of System Administrators and Patching Behaviours

Patching software theoretically leads to improvements including security critical changes, but it can also lead to new issues. For System Administrators (sysadmins) new issues can negatively impact operations at their organization. While mitigation options like test environments exist, little is known about their prev…

AJ
Adam D G Jenkins et al.King's College London

Twitter has a Binary Privacy Setting, are Users Aware of How It Works?

Twitter accounts are public by default, but Twitter gives the option to create protected accounts, where only approved followers can see their tweets. The publicly visible information changes based on the account type and the visibility of tweets also depends solely on the poster's account type which can cause uninten…

DK
Dilara Kekulluoglu et al.University of Edinburgh
Privacy

Understanding Privacy Switching Behaviour on Twitter

Changing a Twitter account’s privacy setting between public and protected changes the visibility of past tweets. By inspecting the privacy setting of more than 100K Twitter users over 3 months, we noticed that over 40% of those users changed their privacy setting at least once with around 16% changing it over 5 times.…

DK
Dilara Kekulluoglu et al.University of Edinburgh
emoji_events

Recruiting Participants With Programming Skills: A Comparison of Four Crowdsourcing Platforms and a CS Student Mailing List

Reliably recruiting participants with programming skills is an ongoing challenge for empirical studies involving software development technologies, often leading to the use of crowdsourcing platforms and computer science (CS) students. In this work, we use five existing survey instruments to explore the programming sk…

MT
Mohammad Tahaei et al.University of Edinburgh
AdRecommended

Learn AI Coding at CodeNow

Structured lessons, hands-on projects, and continuous updates for people bringing AI into real development work.

Explore Nowopen_in_new

A Case Study of Phishing Incident Response in an Educational Organization

Malicious communications aimed at tricking employees are a serious threat for organisations, necessitating the creation of procedures and policies for how to quickly respond to ongoing attacks. While automated measures provide some protection, they cannot completely protect an organisation. In this case study, we use…

KA
Kholoud Althobaiti et al.University of Edinburgh
Privacy and Security

Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on Them

Static analysis tools (SATs) have the potential to assist developers in finding and fixing vulnerabilities in the early stages of software development, requiring them to be able to understand and act on tools' notifications. To understand how helpful such SAT guidance is to developers, we ran an online experiment (N=1…

MT
Mohammad Tahaei et al.University of Edinburgh

Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges

Software development teams are responsible for making and implementing software design decisions that directly impact end-user privacy, a challenging task to do well. Privacy Champions---people who strongly care about advocating privacy---play a useful role in supporting privacy-respecting development cultures. To und…

MT
Mohammad Tahaei et al.University of Edinburgh

I don't need an expert! Making URL phishing features human comprehensible

Judging the safety of a URL is something that even security experts struggle to do accurately without additional information. In this work, we aim to make experts' tools accessible to non-experts and assist general users in judging the safety of URLs by providing them with a usable report based on the information prof…

KA
Kholoud Althobaiti et al.University of Edinburgh

RepliCueAuth: Validating the Use of a Lab-Based Virtual Reality Setup for Evaluating Authentication Systems

Evaluating novel authentication systems is often costly and time-consuming. In this work, we assess the suitability of using Virtual Reality (VR) to evaluate the usability and security of real-world authentication systems. To this end, we conducted a replication study and built a virtual replica of CueAuth [52], a rec…

FM
Florian Mathis et al.University of Edinburgh

Understanding Privacy-Related Questions on Stack Overflow

We analyse Stack Overflow (SO) to understand challenges and confusions developers face while dealing with privacy-related topics. We apply topic modelling techniques to 1,733 privacy-related questions to identify topics and then qualitatively analyse a random sample of 315 privacy-related questions. Identified topics…

MT
Mohammad Tahaei et al.University of Edinburgh

What is this URL's Destination? Empirical Evaluation of Users' URL Reading

Common anti-phishing advice tells users to mouse over links, look at the URL, and compare to the expected destination, implicitly assuming that they are able to read the URL. To test this assumption, we conducted a survey with 1929 participants recruited from the Amazon Mechanical Turk and Prolific Academic platforms.…

SA
Sara Albakry et al.University of Edinburgh