SearcharxivSearch

arXiv subjects

Christian Eichenmüller

Publications and source records attributed to Christian Eichenmüller.

3 recordsLinked to original sources

"My Whereabouts, my Location, it's Directly Linked to my Physical Security": An Exploratory Qualitative Study of Location-Dependent Security and Privacy Perceptions among Activist Tech Users

Digital-safety research with at-risk users is particularly urgent. At-risk users are more likely to be digitally attacked or targeted by surveillance and could be disproportionately harmed by attacks that facilitate physical assaults. One group of such at-risk users are activists and politically active individuals. For them, as for other at-risk users, the rise of smart environments harbors new risks. Since digitization and datafication are no longer limited to a series of personal devices that can be switched on and off, but increasingly and continuously surround users, granular geolocation poses new safety challenges. Drawing on eight exploratory qualitative interviews of an ongoing research project, this contribution highlights what activists with powerful adversaries think about evermore data traces, including location data, and how they intend to deal with emerging risks. Responses of activists include attempts to control one's immediate technological surroundings and to more carefully manage device-related location data. For some activists, threat modeling has also shaped provider choices based on geopolitical considerations. Since many activists have not enough digital-safety knowledge for effective protection, feelings of insecurity and paranoia are widespread. Channeling the concerns and fears of our interlocutors, we call for more research on how activists can protect themselves against evermore fine-grained location data tracking.

cs.HC

Experiencing Apple's Lockdown Mode -- The Challenges of Providing Technology for At-Risk Users

Lockdown Mode, introduced in 2022 as an optional security hardening setting for Apple's operating systems, aims to protect users from "some of the most sophisticated digital threats". We present the first academic analysis of Lockdown Mode based on a three-month autoethnographic study of its everyday use. Our findings show that Lockdown Mode does not adhere to most principles proposed by Matthews et al. (2025) for technologies supporting prevention and monitoring of digital threats for at-risk users. Apple provides limited information about the underlying threat model and affected functionality, making it difficult for at-risk users to understand and evaluate the tool. Usability challenges further highlight the need for more granular controls, while the high volume of notifications offers little support for attack detection and instead contributes to user annoyance. Although we consider Lockdown Mode an important step toward improving security, we believe Apple should integrate principles for technology used by at-risk users more fully.

cs.CR

Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security Vulnerabilities

The Common Vulnerability Scoring System (CVSS) is a popular method for evaluating the severity of vulnerabilities in vulnerability management. In the evaluation process, a numeric score between 0 and 10 is calculated, 10 being the most severe (critical) value. The goal of CVSS is to provide comparable scores across different evaluators. However, previous works indicate that CVSS might not reach this goal: If a vulnerability is evaluated by several analysts, their scores often differ. This raises the following questions: Are CVSS evaluations consistent? Which factors influence CVSS assessments? We systematically investigate these questions in an online survey with 196 CVSS users. We show that specific CVSS metrics are inconsistently evaluated for widespread vulnerability types, including Top 3 vulnerabilities from the "2022 CWE Top 25 Most Dangerous Software Weaknesses" list. In a follow-up survey with 59 participants, we found that for the same vulnerabilities from the main study, 68% of these users gave different severity ratings. Our study reveals that most evaluators are aware of the problematic aspects of CVSS, but they still see CVSS as a useful tool for vulnerability assessment. Finally, we discuss possible reasons for inconsistent evaluations and provide recommendations on improving the consistency of scoring.

cs.CR