SearcharxivSearch

arXiv subjects

Simon Parkin

Publications and source records attributed to Simon Parkin.

9 recordsLinked to original sources

"Am I Just That Dumb?": Applicability, Action and Verification in Consumer IoT Security Advice

Public campaigns urge people to change default passwords on Internet of Things (IoT) devices and keep them updated, assuming users can independently determine whether the advice applies. We gave 28 participants in the Netherlands two pieces of government-issued advice reflecting guidance in several countries and asked them to try to apply each to three of six consumer devices selected from bestseller lists, not confirmed feature availability (168 sessions). The protocol asked for each action to be demonstrated rather than completed. Of 84 password sessions, 33 reached no password setting, 50 an account-level setting, and one a device-level setting. Of 84 update sessions, 27 reached no update, 19 a companion-app update, and 38 a verified firmware update. No product had a manufacturer-set credential shared across units as described by the advice; the single device-level credential was unique to its unit. We contribute an account of what generic advice and the devices it addresses let users determine, act on, and verify.

cs.HC

"There is literally zero funding": Understanding the Emerging Role of Trusted Flaggers under the EU Digital Services Act

The European Union's Digital Services Act (DSA) introduced regulatory mechanisms which serve as a way to manage harmful content online. The recognition of Trusted Flaggers (TFs) is one such mechanism which accredits entities with experience, platform independence, and skill in identifying and reporting illegal content. With the DSA's TF role being roughly one year old, we interviewed representatives of seven such TF organizations to learn about their experiences of becoming a TF and how it impacts their interactions with online platforms and with individual users. We additionally ran a workshop involving TF representatives, primarily as it was requested by TFs themselves, who collectively wanted to share experiences of their new role and learn from each other rather than be isolated. Notably, we found that accreditation as a TF can be cumbersome, that resources for TFs remain the same despite an increasing workload, and that platforms priorities often diverge from TFs. We conclude with recommendations for future research into understanding user representation within the DSA and the need for standardization measures tailored to the needs and resource constraints of TFs.

cs.CY

"What I'm Interested in is Something that Violates the Law": Regulatory Practitioner Views on Automated Detection of Deceptive Design Patterns

Although deceptive design patterns are subject to growing regulatory oversight, enforcement races to keep up with the scale of the problem. One promising solution is automated detection tools, many of which are developed within academia. We interviewed nine experienced practitioners working within or alongside regulatory bodies to understand their work against deceptive design patterns, including the use of supporting tools and the prospect of automation. Computing technologies have their place in regulatory practice, but not as envisioned in research. For example, investigations require utmost transparency and accountability in all the activities we identify as accompanying dark pattern detection, which many existing tools cannot provide. Moreover, tools need to map interfaces to legal violations to be of use. We thus recommend conducting user requirement research to maximize research impact, supporting ancillary activities beyond detection, and establishing practical tech adoption pathways that account for the needs of both scientific and regulatory activities.

cs.HC

Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service

There is an expectation that users of home IoT devices will be able to secure those devices, but they may lack information about what they need to do. In February 2022, we launched a web service that scans users' IoT devices to determine how secure they are. The service aims to diagnose and remediate vulnerabilities and malware infections of IoT devices of Japanese users. This paper reports on findings from operating this service drawn from three studies: (1) the engagement of 114,747 users between February, 2022 - May, 2024; (2) a large-scale evaluation survey among service users (n=4,103), and; (3) an investigation and targeted survey (n=90) around the remediation actions of users of non-secure devices. During the operation, we notified 417 (0.36%) users that one or more of their devices were detected as vulnerable, and 171 (0.15%) users that one of their devices was infected with malware. The service found no issues for 99% of users. Still, 96% of all users evaluated the service positively, most often for it providing reassurance, being free of charge, and short diagnosis time. Of the 171 users with malware infections, 67 returned to the service later for a new check, with 59 showing improvement. Of the 417 users with vulnerable devices, 151 users revisited and re-diagnosed, where 75 showed improvement. We report on lessons learned, including a consideration of the capabilities that non-expert users will assume of a security scan.

cs.CR

"What Keeps People Secure is That They Met The Security Team": Deconstructing Drivers And Goals of Organizational Security Awareness

Security awareness campaigns in organizations now collectively cost billions of dollars annually. There is increasing focus on ensuring certain security behaviors among employees. On the surface, this would imply a user-centered view of security in organizations. Despite this, the basis of what security awareness managers do and what decides this are unclear. We conducted n=15 semi-structured interviews with full-time security awareness managers, with experience across various national and international companies in European countries, with thousands of employees. Through thematic analysis, we identify that success in awareness management is fragile while having the potential to improve; there are a range of restrictions, and mismatched drivers and goals for security awareness, affecting how it is structured, delivered, measured, and improved. We find that security awareness as a practice is underspecified, and split between messaging around secure behaviors and connecting to employees, with a lack of recognition for the measures that awareness managers regard as important. We discuss ways forward, including alternative indicators of success, and security usability advocacy for employees.

cs.CR

Easier Said Than Done: The Failure of Top-Level Cybersecurity Advice for Consumer IoT Devices

Consumer IoT devices are generally assumed to lack adequate default security, thus requiring user action. However, it may not be immediately clear to users what action to take and how. This uncertainty begs the question of what the minimum is that the user-base can reliably be asked to do as a prompt to secure their devices. To explore this question, we analyze security actions advocated at a national level and how these connect to user materials for a range of specific devices. We identify four pieces of converging advice across three nation-level initiatives. We then assess the extent to which these pieces of advice are aligned with instruction materials for 40 different IoT devices across five device classes (including device manuals and manufacturer websites). We expose a disconnect between the advice and the device materials. A stunning finding is that there is not a single assessed device to which all four top pieces of converging advice can be applied. At best, the supporting materials for 36 of the 40 devices provide sufficient information to apply just two of the four pieces of advice, typically the installation and enabling of (auto)updates. As something of a contradiction, it is necessary for a non-expert user to assess whether expert advice applies to a device. This risks additional user burden and proxy changes being made without the proposed security benefits. We propose recommendations, including that governments and researchers alike should declare their own working models of IoT devices when considering the user view.

cs.CR

Difficult for Thee, But Not for Me: Measuring the Difficulty and User Experience of Remediating Persistent IoT Malware

Consumer IoT devices may suffer malware attacks, and be recruited into botnets or worse. There is evidence that generic advice to device owners to address IoT malware can be successful, but this does not account for emerging forms of persistent IoT malware. Less is known about persistent malware, which resides on persistent storage, requiring targeted manual effort to remove it. This paper presents a field study on the removal of persistent IoT malware by consumers. We partnered with an ISP to contrast remediation times of 760 customers across three malware categories: Windows malware, non-persistent IoT malware, and persistent IoT malware. We also contacted ISP customers identified as having persistent IoT malware on their network-attached storage devices, specifically QSnatch. We found that persistent IoT malware exhibits a mean infection duration many times higher than Windows or Mirai malware; QSnatch has a survival probability of 30% after 180 days, whereby most if not all other observed malware types have been removed. For interviewed device users, QSnatch infections lasted longer, so are apparently more difficult to get rid of, yet participants did not report experiencing difficulty in following notification instructions. We see two factors driving this paradoxical finding: First, most users reported having high technical competency. Also, we found evidence of planning behavior for these tasks and the need for multiple notifications. Our findings demonstrate the critical nature of interventions from outside for persistent malware, since automatic scan of an AV tool or a power cycle, like we are used to for Windows malware and Mirai infections, will not solve persistent IoT malware infections.

cs.CR

Measurement of refractive index of single microparticles

The refractive index of single microparticles is derived from precise measurement and rigorous modeling of the stiffness of a laser trap. We demonstrate the method for particles of four different materials with diameters from 1.6 to 5.2 microns and achieve an accuracy of better than 1%. The method greatly contributes as a new characterization technique because it works best under conditions (small particle size, polydispersion) where other methods, such as absorption spectroscopy, start to fail. Particles need not be transferred to a particular fluid, which prevents particle degradation or alteration common in index matching techniques. Our results also show that advanced modeling of laser traps accurately reproduces experimental reality.

physics.optics

Measurement of the total optical angular momentum transfer in optical tweezers

We describe a way to determine the total angular momentum, both spin and orbital, transferred to a particle trapped in optical tweezers. As an example an LG02 mode of a laser beam with varying degrees of circular polarisation is used to trap and rotate an elongated particle with a well defined geometry. The method successfully estimates the total optical torque applied to the particle. For this technique, there is no need to measure the viscous drag on the particle, as it is an optical measurement. Therefore, knowledge of the particle's size and shape, as well as the fluid's viscosity, is not required.

physics.optics