| 2007 | Privacy implications for single sign-on authentication in a hospital environment. | Rosa R. Heckle, Wayne G. Lutters |
| 2007 | End user concern about security and privacy threats. | Joshua B. Gross, Mary Beth Rosson |
| 2007 | Helping users create better passwords: is this the right approach? | Alain Forget, Sonia Chiasson, Robert Biddle |
| 2007 | Vidalia: towards a usable Tor GUI. | Matthew Edman, Justin Hipple |
| 2007 | Is FacePIN secure and usable? | Paul Dunphy, Jeff Yan |
| 2007 | Modeling user choice in the PassPoints graphical password scheme. | Ahmet Emir Dirik, Nasir D. Memon, Jean-Camille Birget |
| 2007 | An honest man has nothing to fear: user perceptions on web-based information disclosure. | Gregory J. Conti, Edward Sobiesk |
| 2007 | Usability of anonymous web browsing: an examination of Tor interfaces and deployability. | Jeremy Clark, Paul C. van Oorschot, Carlisle Adams |
| 2007 | A second look at the usability of click-based graphical passwords. | Sonia Chiasson, Robert Biddle, Paul C. van Oorschot |
| 2007 | Improving security decisions with polymorphic and audited dialogs. | Jos Carlos Brustoloni, Ricardo Villamarn-Salomn |
| 2007 | Towards understanding IT security professionals and their tools. | David Botta, Rodrigo Werlinger, Andr Gagn, Konstantin Beznosov, Lee Iverson, Sidney S. Fels, Brian D. Fisher |
| 2007 | Establishing darknet connections: an evaluation of usability and security. | John Bethencourt, Wai Yong Low, Isaac Simmons, Matthew Williamson |
| 2007 | Lessons learned from the deployment of a smartphone-based access-control system. | Lujo Bauer, Lorrie Faith Cranor, Michael K. Reiter, Kami Vaniea |
| 2007 | TwoKind authentication: usable authenticators for untrustworthy environments. | Katelin Bailey, Linden Vongsathorn, Apu Kapadia, Chris Masone, Sean W. Smith |
| 2006 | Passpet: convenient password management and phishing protection. | Ka-Ping Yee, Kragen Sitaker |
| 2006 | Web wallet: preventing phishing attacks by revealing user intentions. | Min Wu, Robert C. Miller, Greg Little |
| 2006 | A comparison of perceived and real shoulder-surfing risks between alphanumeric and graphical passwords. | Furkan Tari, A. Ant Ozok, Stephen H. Holden |
| 2006 | Seeing further: extending visualization as a basis for usable security. | Jennifer Ann Rode, Carolina Johansson, Paul DiGioia, Roberto Silveira Silva Filho, Kari Nies, David H. Nguyen, Jie Ren, Paul Dourish, David F. Redmiles |
| 2006 | Protecting domestic power-line communications. | Richard E. Newman, Sherman Gavette, Larry Yonge, Ross J. Anderson |
| 2006 | Human selection of mnemonic phrase-based passwords. | Cynthia Kuo, Sasha Romanosky, Lorrie Faith Cranor |
| 2006 | Privacy and security threat analysis of the federal employee personal identity verification (PIV) program. | Paul A. Karger |
| 2006 | Power strips, prophylactics, and privacy, oh my! | Julia Gideon, Lorrie Faith Cranor, Serge Egelman, Alessandro Acquisti |
| 2006 | Password management strategies for online accounts. | Shirley Gaw, Edward W. Felten |
| 2006 | The methodology and an application to fight against Unicode attacks. | Anthony Y. Fu, Xiaotie Deng, Liu Wenyin, Greg Little |
| 2006 | Decision strategies and susceptibility to phishing. | Julie S. Downs, Mandy B. Holbrook, Lorrie Faith Cranor |