| 2009 | Studying location privacy in mobile applications: 'predator vs. prey' probes. | Keerthi Thomas, Clara Mancini, Lukasz Jedrzejczyk, Arosha K. Bandara, Adam N. Joinson, Blaine A. Price, Yvonne Rogers, Bashar Nuseibeh |
| 2009 | How users use access control. | Diana K. Smetters, Nathan Good |
| 2009 | 1 + 1 = you: measuring the comprehensibility of metaphors for configuring backup authentication. | Stuart E. Schechter, Robert W. Reeder |
| 2009 | It's not what you know, but who you know: a social approach to last-resort authentication. | Stuart E. Schechter, Serge Egelman, Robert W. Reeder |
| 2009 | It's no secret: measuring the security and reliability of authentication via 'secret' questions. | Stuart E. Schechter, A. J. Bernheim Brush, Serge Egelman |
| 2009 | Treat 'em like other devices: user authentication of multiple personal RFID tags. | Nitesh Saxena, Md. Borhan Uddin, Jonathan Voris |
| 2009 | Designing and evaluating usable security and privacy technology. | Martina Angela Sasse, Clare-Marie Karat, Roy A. Maxion |
| 2009 | Redirects to login pages are bad, or are they? | Eric Sachs |
| 2009 | A user study of the expandable grid applied to P3P privacy policy visualization. | Robert W. Reeder, Patrick Gage Kelley, Aleecia M. McDonald, Lorrie Faith Cranor |
| 2009 | Capturing social networking privacy preferences: can default policies help alleviate tradeoffs between expressiveness and user burden? | Ramprasad Ravichandran, Michael Benisch, Patrick Gage Kelley, Norman M. Sadeh |
| 2009 | Revealing hidden context: improving mental models of personal firewall users. | Fahimeh Raja, Kirstie Hawkey, Konstantin Beznosov |
| 2009 | Threshold things that think: usable authorization for resharing. | Roel Peeters, Markulf Kohlweiss, Bart Preneel, Nicky Sulmon |
| 2009 | Ecological validity in studies of security and human behaviour. | Andrew Patrick |
| 2009 | Designing for different levels of social inference risk. | Sara Motahari, Sotirios G. Ziavras, Quentin Jones |
| 2009 | Usable deidentification of sensitive patient care data. | Michael McQuaid, Kai Zheng, Nigel P. Melville, Lee Green |
| 2009 | A comparative study of online privacy policies and formats. | Aleecia M. McDonald, Robert W. Reeder, Patrick Gage Kelley, Lorrie Faith Cranor |
| 2009 | Recall-a-story, a story-telling graphical password system. | Yves Maetz, Stphane Onno, Olivier Heen |
| 2009 | flyByNight: mitigating the privacy risks of social networking. | Matthew M. Lucas, Nikita Borisov |
| 2009 | Look into my eyes!: can you guess my password? | Alexander De Luca, Martin Denzel, Heinrich Hussmann |
| 2009 | Ubiquitous systems and the family: thoughts about the networked home. | Linda Little, Elizabeth Sillence, Pamela Briggs |
| 2009 | The family and communication technologies. | Linda Little |
| 2009 | BayeShield: conversational anti-phishing user interface. | Peter Likarish, Donald E. Dunbar, Juan Pablo Hourcade, Eunjin Jung |
| 2009 | School of phish: a real-word evaluation of anti-phishing training. | Ponnurangam Kumaraguru, Justin Cranshaw, Alessandro Acquisti, Lorrie Faith Cranor, Jason I. Hong, Mary Ann Blair, Theodore Pham |
| 2009 | Serial hook-ups: a comparative usability study of secure device pairing methods. | Alfred Kobsa, Rahim Sonawalla, Gene Tsudik, Ersin Uzun, Yang Wang |
| 2009 | Balancing usability and security in a video CAPTCHA. | Kurt Alfred Kluever, Richard Zanibbi |