Searcharxiv⌕ Search

arXiv subjects

Alina Stöver

Publications and source records attributed to Alina Stöver.

3 recordsLinked to original sources

Playful but Persuasive: Deceptive Designs and Advertising Strategies in Popular Mobile Apps for Children

Mobile gaming apps are woven into children's daily lives. Given their ongoing cognitive and emotional development, children are especially vulnerable and depend on designs that safeguard their well-being. When apps feature manipulative interfaces or heavy advertising, they may exert undue influence on young users, contributing to prolonged screen time, disrupted self-regulation, and accidental in-app purchases. In this study, we examined 20 popular, free-to-download children's apps in German-speaking regions to assess the prevalence of deceptive design patterns and advertising. Despite platform policies and EU frameworks like the General Data Protection Regulation and the Digital Services Act, every app contained interface manipulations intended to nudge, confuse, or pressure young users, averaging nearly six distinct deceptive patterns per app. Most also displayed high volumes of non-skippable ads, frequently embedded within core gameplay. These findings indicate a systemic failure of existing safeguards and call for stronger regulation, greater platform accountability, and child-centered design standards.

cs.HC↗

That Depends -- Assessing User Perceptions of Authentication Schemes across Contexts of Use

Choosing authentication schemes for a specific purpose is challenging for service providers, developers, and researchers. Previous ratings of technical and objective aspects showed that available schemes all have strengths and limitations. Yet, the security of authentication also relies on user perceptions which affect acceptance and user behaviour and can deviate from technical aspects. To shine light on the issue and support researchers, developers, and service-providers confronted with authentication choice, we conducted an in-depth analysis of user perceptions of the password, fingerprint, and a smartphone-based scheme in an online study with 201 participants. As authentication is a secondary task that needs to be evaluated in the context of authentication purpose, we also compared perceptions across four contexts of use with varying sensitivity levels: email accounts, online banking, social networks, and smart homes. The results revealed how perceptions of usability, security, privacy, trust, effort, and qualitative features of the schemes are related to user preferences. The results increase awareness for the influence of subjective perceptions and have practical implications for decision-makers. They can inform a) the choice between several adequate schemes, b) the authentication design to reduce concerns or security-related misconceptions, and c) the development of context-dependent authentication.

cs.HC↗

Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and Support

Misconfigurations and outdated software are a major cause of compromised websites and data leaks. Past research has proposed and evaluated sending automated security notifications to the operators of misconfigured websites, but encountered issues with reachability, mistrust, and a perceived lack of importance. In this paper, we seek to understand the determinants of effective notifications. We identify a data protection misconfiguration that affects 12.7 % of the 1.3 million websites we scanned and opens them up to legal liability. Using a subset of 4754 websites, we conduct a multivariate randomized controlled notification experiment, evaluating contact medium, sender, and framing of the message. We also include a link to a public web-based self-service tool that is run by us in disguise and conduct an anonymous survey of the notified website owners (N=477) to understand their perspective. We find that framing a misconfiguration as a problem of legal compliance can increase remediation rates, especially when the notification is sent as a letter from a legal research group, achieving remediation rates of 76.3 % compared to 33.9 % for emails sent by computer science researchers warning about a privacy issue. Across all groups, 56.6 % of notified owners remediated the issue, compared to 9.2 % in the control group. In conclusion, we present factors that lead website owners to trust a notification, show what framing of the notification brings them into action, and how they can be supported in remediating the issue.

cs.CR↗