SearcharxivSearch

arXiv subjects

Filipo Sharevski

Publications and source records attributed to Filipo Sharevski.

At least 19 recordsLinked to original sources

How Blind and Low-Vision Users Manage Their Passwords

Managing passwords securely and conveniently is still an open problem for many users. Existing research has examined users' password management strategies and identified pain points, such as security concerns, leading to insecure practices. We investigate how Blind and Low-Vision (BLV) users tackle this problem and how password managers can assist them. This paper presents the results of a qualitative interview study with N = 33 BLV participants. We found that all participants utilize password managers to some extent, which they perceive as fairly accessible. However, the adoption is mainly driven by the convenience of storing and retrieving passwords. The security advantages - generating strong, random passwords - were avoided mainly due to the absence of practical accessibility. Password managers do not adhere to BLV users' underlying needs for agency, which stem from experiences with inaccessible software and vendors who deprioritize accessibility issues. Underutilization of password managers leads BLV users to adopt insecure practices, such as reusing predictable passwords or resorting to 'security through obscurity' by writing important credentials in braille. We conclude our analysis by discussing the need to implement practical accessibility and usability improvements for password managers as a way of establishing trust and secure practices while maintaining BLV users' agency.

cs.CR

'Debunk-It-Yourself': Health Professionals' Strategies for Responding to Misinformation on TikTok

Misinformation is "sticky" in nature, requiring a considerable effort to undo its influence. One such effort is debunking or exposing the falsity of information. As an abundance of misinformation is on social media, platforms do bear some debunking responsibility in order to preserve their trustworthiness as information providers. A subject of interpretation, platforms poorly meet this responsibility and allow dangerous health misinformation to influence many of their users. This open route to harm did not sit well with health professional users, who recently decided to take the debunking into their own hands. To study this individual debunking effort - which we call 'Debunk-It-Yourself (DIY)' - we conducted an exploratory survey n=14 health professionals who wage a misinformation counter-influence campaign through videos on TikTok. We focused on two topics, nutrition and mental health, which are the ones most often subjected to misinformation on the platform. Our thematic analysis reveals that the counterinfluence follows a common process of initiation, selection, creation, and "stitching" or duetting a debunking video with a misinformation video. The 'Debunk-It-Yourself' effort was underpinned by three unique aspects: (i) it targets trending misinformation claims perceived to be of direct harm to people's health; (ii) it offers a symmetric response to the misinformation; and (iii) it is strictly based on scientific evidence and claimed clinical experience. Contrasting the 'Debunk-It-Yourself' effort with the one TikTok and other platforms (reluctantly) put in moderation, we offer recommendations for a structured response against the misinformation's influence by the users themselves.

cs.CR

(Blind) Users Really Do Heed Aural Telephone Scam Warnings

This paper reports on a study exploring how two groups of individuals, legally blind (n=36) and sighted ones (n=36), react to aural telephone scam warnings in naturalistic settings. As spoofing a CallerID is trivial, communicating the context of an incoming call instead offers a better possibility to warn a receiver about a potential scam. Usually, such warnings are visual in nature and fail to cater to users with visual disabilities. To address this exclusion, we developed an aural variant of telephone scam warnings and tested them in three conditions: baseline (no warning), short warning, and contextual warning that preceded the scam's content. We tested the two most common scam scenarios: fraud (interest rate reduction) and identity theft (social security number) by cold-calling participants and recording their action, and debriefing and obtaining consent afterward. Only two participants "pressed one" as the scam demanded, both from the legally blind group that heard the contextual warning for the social security scenario. Upon close inspection, we learned that one of them did so because of accessibility issues with their screen reader and the other did so intentionally because the warning convinced them to waste the scammer's time, so they don't scam vulnerable people. Both the legally blind and the sighted participants found the contextual warnings as powerful usable security cues that, together with STIR/SHAKEN indicators like "Scam Likely", would provide robust protection against any type of scam. We also discussed the potential privacy implications of the contextual warnings and collected recommendations for usably accessible implementation.

cs.CR

"Oh, sh*t! I actually opened the document!": An Empirical Study of the Experiences with Suspicious Emails in Virtual Reality Headsets

This paper reports on a study exploring user experiences with suspicious emails and associated warnings when accessed through virtual reality (VR) headsets in realistic settings. A group of (n=20) Apple Vision Pro and another group of (n=20) Meta Quest 3 users were invited to sort through their own selection of Google mail suspicious emails through the VR headset. We asked them to verbalize the experience relative to how they assess the emails, what cues they use to determine their legitimacy, and what actions they would take for each suspicious email of their choice. We covertly sent a "false positive" suspicious email containing either a URL or an attachment (an email that is assigned a suspicious email warning but, in reality, is a legitimate one) and observed how participants would interact with it. Two participants clicked on the link (Apple Vision Pro), and one participant opened the attachment (Meta Quest 3). Upon close inspection, in all three instances, the participant "fell" for the phish because of the VR headsets' hypersensitive clicking and lack of ergonomic precision during the routine email sorting task. These and the other participants thus offered recommendations for implementing suspicious email warnings in VR environments, considerate of the immersiveness and ergonomics of the headsets' interface.

cs.CR

Older Adults' Experiences with Misinformation on Social Media

Older adults habitually encounter misinformation on social media, but there is little knowledge about their experiences with it. In this study, we combined a qualitative survey (n=119) with in-depth interviews (n=21) to investigate how older adults in America conceptualize, discern, and contextualize social media misinformation. As misinformation on social media in the past was driven towards influencing voting outcomes, we were particularly interested to approach our study from a voting intention perspective. We found that 62% of the participants intending to vote Democrat saw a manipulative political purpose behind the spread of misinformation while only 5% of those intending to vote Republican believed misinformation has a political dissent purpose. Regardless of the voting intentions, most participants relied on source heuristics combined with fact-checking to discern truth from misinformation on social media. The biggest concern about the misinformation, among all the participants, was that it increasingly leads to biased reasoning influenced by personal values and feelings instead of reasoning based on objective evidence. The participants intending to vote Democrat were in 74% of the cases concerned that misinformation will cause escalation of extremism in the future, while those intending to vote Republican, were undecided, or planned to abstain were concerned that misinformation will further erode the trust in democratic institutions, specifically in the context of public health and free and fair elections. During our interviews, we found that 63% of the participants who intended to vote Republican, were fully aware and acknowledged that Republican or conservative voices often time speak misinformation, even though they are closely aligned to their political ideology.

cs.CY

Children, Parents, and Misinformation on Social Media

Children encounter misinformation on social media in a similar capacity as their parents. Unlike their parents, children are an exceptionally vulnerable population because their cognitive abilities and emotional regulation are still maturing, rendering them more susceptible to misinformation and falsehoods online. Yet, little is known about children's experience with misinformation as well as what their parents think of the misinformation's effect on child development. To answer these questions, we combined a qualitative survey of parents (n=87) with semi-structured interviews of both parents and children (n=12). We found that children usually encounter deep fakes, memes with political context, or celebrity/influencer rumors on social media. Children revealed they "ask Siri" whether a social media video or post is true or not before they search on Google or ask their parents about it. Parents expressed discontent that their children are impressionable to misinformation, stating that the burden falls on them to help their children develop critical thinking skills for navigating falsehoods on social media. Here, the majority of parents felt that schools should also teach these skills as well as media literacy to their children. Misinformation, according to both parents and children affects the family relationships especially with grandparents with different political views than theirs.

cs.CY

Usability Assessment of the OnlyKey Hardware Two-Factor Authentication Key Among Low Vision or Blind Users

Hardware security keys undoubtedly have advantage for users as "usability" pain is trivial compared to the maximum "security" gain in authentication. Naturally, the hardware factor in the authentication received a widespread adoption amongst average users, as it is ergonomically less demanding than phone texts or authentication prompts. This ergonomic advantage in particular is essential for users who are blind or low vision, as their interaction with a phone is impractical. However, the "usability" for low vision or blind users pain might be much higher than an average well-bodied user for the same "security" gain. In an effort to learn more we conducted a usability assessment with ten low vision or blind users setting up the OnlyKey two-factor authentication key. First, the setup process was insurmountable for more than half of the participants, resulting in a situation where the hardware key was abandoned. Secondly, the lack of tactile orientation led participants to consider it as both impractical, and prone to difficulties locating or loosing it. We discuss the implications of our findings for future improvements in usable authentication for visually impaired users.

cs.HC

Talking Abortion (Mis)information with ChatGPT on TikTok

In this study, we tested users' perception of accuracy and engagement with TikTok videos in which ChatGPT responded to prompts about "at-home" abortion remedies. The chatbot's responses, though somewhat vague and confusing, nonetheless recommended consulting with health professionals before attempting an "at-home" abortion. We used ChatGPT to create two TikTok video variants - one where users can see ChatGPT explicitly typing back a response, and one where the text response is presented without any notion to the chatbot. We randomly exposed 100 participants to each variant and found that the group of participants unaware of ChatGPT's text synthetization was more inclined to believe the responses were misinformation. Under the same impression, TikTok itself attached misinformation warning labels ("Get the facts about abortion") to all videos after we collected our initial results. We then decided to test the videos again with another set of 50 participants and found that the labels did not affect the perceptions of abortion misinformation except in the case where ChatGPT explicitly responded to a prompt for a lyrical output. We also found that more than 60% of the participants expressed negative or hesitant opinions about chatbots as sources of credible health information.

cs.HC

Fight Fire with Fire: Hacktivists' Take on Social Media Misinformation

In this study, we interviewed 22 prominent hacktivists to learn their take on the increased proliferation of misinformation on social media. We found that none of them welcomes the nefarious appropriation of trolling and memes for the purpose of political (counter)argumentation and dissemination of propaganda. True to the original hacker ethos, misinformation is seen as a threat to the democratic vision of the Internet, and as such, it must be confronted on the face with tried hacktivists' methods like deplatforming the "misinformers" and doxing or leaking data about their funding and recruitment. The majority of the hacktivists also recommended interventions for raising misinformation literacy in addition to targeted hacking campaigns. We discuss the implications of these findings relative to the emergent recasting of hacktivism in defense of a constructive and factual social media discourse.

cs.SI

Abortion Misinformation on TikTok: Rampant Content, Lax Moderation, and Vivid User Experiences

The scientific effort devoted to health misinformation mostly focuses on the implications of misleading vaccines and communicable disease claims with respect to public health. However, the proliferation of abortion misinformation following the Supreme Court's decision to overturn Roe v. Wade banning legal abortion in the US highlighted a gap in scientific attention to individual health-related misinformation. To address this gap, we conducted a study with 60 TikTok users to uncover their experiences with abortion misinformation and the way they conceptualize, assess, and respond to misleading video content on this platform. Our findings indicate that users mostly encounter short-term videos suggesting herbal "at-home" remedies for pregnancy termination. While many of the participants were cautious about scientifically debunked "abortion alternatives," roughly 30% of the entire sample believed in their safety and efficacy. Even an explicit debunking label attached to a misleading abortion video about the harms of "at-home" did not help a third of the participants to dismiss a video about self-administering abortion as misinformation. We discuss the implications of our findings for future participation on TikTok and other polarizing topics debated on social media.

cs.SI

Folk Models of Misinformation on Social Media

In this paper we investigate what folk models of misinformation exist through semi-structured interviews with a sample of 235 social media users. Work on social media misinformation does not investigate how ordinary users - the target of misinformation - deal with it; rather, the focus is mostly on the anxiety, tensions, or divisions misinformation creates. Studying the aspects of creation, diffusion and amplification also overlooks how misinformation is internalized by users on social media and thus is quick to prescribe "inoculation" strategies for the presumed lack of immunity to misinformation. How users grapple with social media content to develop "natural immunity" as a precursor to misinformation resilience remains an open question. We have identified at least five folk models that conceptualize misinformation as either: political (counter)argumentation, out-of-context narratives, inherently fallacious information, external propaganda, or simply entertainment. We use the rich conceptualizations embodied in these folk models to uncover how social media users minimize adverse reactions to misinformation encounters in their everyday lives.

cs.SI

Meaningful Context, a Red Flag, or Both? Users' Preferences for Enhanced Misinformation Warnings on Twitter

Warning users about misinformation on social media is not a simple usability task. Soft moderation has to balance between debunking falsehoods and avoiding moderation bias while preserving the social media consumption flow. Platforms thus employ minimally distinguishable warning tags with generic text under a suspected misinformation content. This approach resulted in an unfavorable outcome where the warnings "backfired" and users believed the misinformation more, not less. In response, we developed enhancements to the misinformation warnings where users are advised on the context of the information hazard and exposed to standard warning iconography. We ran an A/B evaluation with the Twitter's original warning tags in a 337 participant usability study. The majority of the participants preferred the enhancements as a nudge toward recognizing and avoiding misinformation. The enhanced warning tags were most favored by the politically left-leaning and to a lesser degree moderate participants, but they also appealed to roughly a third of the right-leaning participants. The education level was the only demographic factor shaping participants' preferences. We use our findings to propose user-tailored improvements in the soft moderation of misinformation on social media.

cs.CY

"Gettr-ing" Deep Insights from the Social Network Gettr

As yet another alternative social network, Gettr positions itself as the "marketplace of ideas" where users should expect the truth to emerge without any administrative censorship. We looked deep inside the platform by analyzing it's structure, a sample of 6.8 million posts, and the responses from a sample of 124 Gettr users we interviewed to see if this actually is the case. Administratively, Gettr makes a deliberate attempt to stifle any external evaluation of the platform as collecting data is marred with unpredictable and abrupt changes in their API. Content-wise, Gettr notably hosts pro-Trump content mixed with conspiracy theories and attacks on the perceived "left." It's social network structure is asymmetric and centered around prominent right-thought leaders, which is characteristic for all alt-platforms. While right-leaning users joined Gettr as a result of a perceived freedom of speech infringement by the mainstream platforms, left-leaning users followed them in numbers as to "keep up with the misinformation." We contextualize these findings by looking into the Gettr's user interface design to provide a comprehensive insight into the incentive structure for joining and competing for the truth on Gettr.

cs.SI

Gone Quishing: A Field Study of Phishing with Malicious QR Codes

The COVID-19 pandemic enabled "quishing", or phishing with malicious QR codes, as they became a convenient go-between for sharing URLs, including malicious ones. To explore the quishing phenomenon, we conducted a 173-participant study where we used a COVID-19 digital passport sign-up trial with a malicious QR code as a pretext. We found that 67 % of the participants were happy to sign-up with their Google or Facebook credentials, 18.5% to create a new account, and only 14.5% to skip on the sign-up. Convenience was the single most cited factor for the willingness to yield participants' credentials. Reluctance of linking personal accounts with new services was the reason for creating a new account or skipping the registration. We also developed a Quishing Awareness Scale (QAS) and found a significant relationship between participants' QR code behavior and their sign-up choices: the ones choosing to sign-up with Facebook scored the lowest while the one choosing to skip the highest on average. We used our results to propose quishing awareness training guidelines and develop and test usable security indicators for warning users about the threat of quishing.

cs.CR

(Mis)perceptions and Engagement on Twitter: COVID-19 Vaccine Rumors on Efficacy and Mass Immunization Effort

This paper reports the findings of a 606-participant study where we analyzed the perception and engagement effects of COVID-19 vaccine rumours on Twitter pertaining to (a) vaccine efficacy; and (b) mass immunization efforts in the United States. Misperceptions regarding vaccine efficacy were successfully induced through simple content alterations and the addition of popular anti COVID-19 hashtags to otherwise valid Twitter content. Twitter's misinformation contextual tags caused a "backfire effect" for the skeptic, vaccine-hesitant reinforcing their opposition stance. While the majority of the participants staunchly refrain from engaging with the COVID-19 rumours, the skeptic, vaccine-hesitant ones were open to comment, re-tweet, like and share the vaccine efficacy rumors. We discuss the implications of our results in the context of broadening the effort for dispelling rumors about COVID-19 on social media.

cs.SI

Parlermonium: A Data-Driven UX Design Evaluation of the Parler Platform

This paper evaluates Parler, the controversial social media platform, from two seemingly orthogonal perspectives: UX design perspective and data science. UX design researchers explore how users react to the interface/content of their social media feeds; Data science researchers analyze the misinformation flow in these feeds to detect alternative narratives and state-sponsored disinformation campaigns. We took a critical look into the intersection of these approaches to understand how Parler's interface itself is conductive to the flow of misinformation and the perception of "free speech" among its audience. Parler drew widespread attention leading up to and after the 2020 U.S. elections as the "alternative" place for free speech, as a reaction to other mainstream social media platform which actively engaged in labeling misinformation with content warnings. Because platforms like Parler are disruptive to the social media landscape, we believe the evaluation uniquely uncovers the platform's conductivity to the spread of misinformation.

cs.SI

"Hey Alexa, What do You Know About the COVID-19 Vaccine?" -- (Mis)perceptions of Mass Immunization Among Voice Assistant Users

In this paper, we analyzed the perceived accuracy of COVID-19 vaccine information spoken back by Amazon Alexa. Unlike social media, Amazon Alexa doesn't apply soft moderation to unverified content, allowing for use of third-party malicious skills to arbitrarily phrase COVID-19 vaccine information. The results from a 210-participant study suggest that a third-party malicious skill could successful reduce the perceived accuracy among the users of information as to who gets the vaccine first, vaccine testing, and the side effects of the vaccine. We also found that the vaccine-hesitant participants are drawn to pessimistically rephrased Alexa responses focused on the downsides of the mass immunization. We discuss solutions for soft moderation against misperception-inducing or altogether COVID-19 misinformation malicious third-party skills.

cs.CY

Misinformation Warning Labels: Twitter's Soft Moderation Effects on COVID-19 Vaccine Belief Echoes

Twitter, prompted by the rapid spread of alternative narratives, started actively warning users about the spread of COVID-19 misinformation. This form of soft moderation comes in two forms: as a warning cover before the Tweet is displayed to the user and as a warning tag below the Tweet. This study investigates how each of the soft moderation forms affects the perceived accuracy of COVID-19 vaccine misinformation on Twitter. The results suggest that the warning covers work, but not the tags, in reducing the perception of accuracy of COVID-19 vaccine misinformation on Twitter. "Belief echoes" do exist among Twitter users, unfettered by any warning labels, in relationship to the perceived safety and efficacy of the COVID-19 vaccine as well as the vaccination hesitancy for themselves and their children. The implications of these results are discussed in the context of usable security affordances for combating misinformation on social media.

cs.SI