| 2023 | Evolution of Password Expiry in Companies: Measuring the Adoption of Recommendations by the German Federal Office for Information Security. | Eva Gerlitz, Maximilian Hring, Matthew Smith, Christian Tiefenau |
| 2023 | Exploring the Security Culture of Operational Technology (OT) Organisations: the Role of External Consultancy in Overcoming Organisational Barriers. | Stefanos Evripidou, Uchenna Daniel Ani, Stephen Hailes, Jeremy D. McK. Watson |
| 2023 | An Investigation of Teenager Experiences in Social Virtual Reality from Teenagers', Parents', and Bystanders' Perspectives. | Elmira Deldari, Diana Freed, Julio Poveda, Yaxing Yao |
| 2023 | "Stalking is immoral but not illegal": Understanding Security, Cyber Crimes and Threats in Pakistan. | Afaq Ashraf, Afaq Taha, Nida ul Habib Bajwa, Cornelius J. Knig, Mobin Javed, Maryam Mustafa |
| 2023 | "Would You Give the Same Priority to the Bank and a Game? I Do Not!" Exploring Credential Management Strategies and Obstacles during Password Manager Setup. | Sabrina Amft, Sandra Hltervennhoff, Nicolas Huaman, Yasemin Acar, Sascha Fahl |
| 2023 | Prospects for Improving Password Selection. | Joram Amador, Yiran Ma, Summer Hasama, Eshaan Lumba, Gloria Lee, Eleanor Birrell |
| 2023 | Evaluating the Impact of Community Oversight for Managing Mobile Privacy and Security. | Mamtaj Akter, Madiha Tabassum, Md. Nazmus Sakib Miazi, Leena Alghamdi, Jess Kropczynski, Pamela J. Wisniewski, Heather Lipford |
| 2023 | What can central bank digital currency designers learn from asking potential users? | Svetlana Abramova, Rainer Bhme, Helmut Elsinger, Helmut Stix, Martin Summer |
| 2023 | Understanding the Viability of Gmail's Origin Indicator for Identifying the Sender. | Enze Liu, Lu Sun, Alex Bellon, Grant Ho, Geoffrey M. Voelker, Stefan Savage, Imani N. S. Munyaka |
| 2022 | Do Password Managers Nudge Secure (Random) Passwords? | Samira Zibaei, Dinah Rinoa Malapaya, Benjamin Mercier, Amirali Salehi-Abari, Julie Thorpe |
| 2022 | Presenting Suspicious Details in User-Facing E-mail Headers Does Not Improve Phishing Detection. | Sarah Y. Zheng, Ingolf Becker |
| 2022 | DualCheck: Exploiting Human Verification Tasks for Opportunistic Online Safety Microlearning. | Ryo Yoshikawa, Hideya Ochiai, Koji Yatani |
| 2022 | Let The Right One In: Attestation as a Usable CAPTCHA Alternative. | Tara Whalen, Thibault Meunier, Mrudula Kodali, Alex Davidson, Marwan Fayed, Armando Faz-Hernndez, Watson Ladd, Deepak Maram, Nick Sullivan, Benedikt Wolters, Maxime Guerreiro, Andrew Galloni |
| 2022 | Anti-Privacy and Anti-Security Advice on TikTok: Case Studies of Technology-Enabled Surveillance and Control in Intimate Partner and Parent-Child Relationships. | Miranda Wei, Eric Zeng, Tadayoshi Kohno, Franziska Roesner |
| 2022 | Increasing security without decreasing usability: A comparison of various verifiable voting systems. | Melanie Volkamer, Oksana Kulyk, Jonas Ludwig, Niklas Fuhrberg |
| 2022 | Replication: How Well Do My Results Generalize Now? The External Validity of Online Privacy and Security Surveys. | Jenny Tang, Eleanor Birrell, Ada Lerner |
| 2022 | Being Hacked: Understanding Victims' Experiences of IoT Hacking. | Asreen Rostami, Minna Vigren, Shahid Raza, Barry Brown |
| 2022 | Usability and Security of Trusted Platform Module (TPM) Library APIs. | Siddharth Prakash Rao, Gabriela Limonta, Janne Lindqvist |
| 2022 | Normative and Non-Social Beliefs about Sensor Data: Implications for Collective Privacy Management. | Emilee Rader |
| 2022 | Replication: Stories as Informal Lessons about Security. | Katharina Pfeffer, Alexandra Mai, Edgar R. Weippl, Emilee Rader, Katharina Krombholz |
| 2022 | "I don't know why I check this..." - Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks. | Peter Mayer, Damian Poddebniak, Konstantin Fischer, Marcus Brinkmann, Juraj Somorovsky, M. Angela Sasse, Sebastian Schinzel, Melanie Volkamer |
| 2022 | "As soon as it's a risk, I want to require MFA": How Administrators Configure Risk-based Authentication. | Philipp Markert, Theodor Schnitzler, Maximilian Golla, Markus Drmuth |
| 2022 | Runtime Permissions for Privacy in Proactive Intelligent Assistants. | Nathan Malkin, David A. Wagner, Serge Egelman |
| 2022 | Password policies of most top websites fail to follow best practices. | Kevin Lee, Sten Sjberg, Arvind Narayanan |
| 2022 | An open door may tempt a saint: Examining situational and individual determinants of privacy-invading behavior. | Markus Langer, Rudolf Siegel, Michael Schilling, Tim Hunsicker, Cornelius J. Knig |