Symposium on Usable Privacy and Security (SOUPS 2026)
Welcome to the Symposium on Usable Security and Privacy happening in Hannover, Germany and being hosted by CISPA.
Authentication & Credentials
An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites
Presenter: Alexander Krause
Updating passwords is something many people do. But do websites always support password resets and how easy is it to reset passwords?
Users have many situations where they might want to change their password:
- Maybe they just want to feel more secure
- Maybe they lost their password
- Maybe they want to make it more challenges
Goal of the work is to look at three questions:
- How do websites implement password update processes?
- How doe sit go wrong?
- How can we do it better?
The researchers looked through the password reset processes on a large number of websites. There is also a W3P password reset link that they tested.
The path is long - finding and resetting passwords is not easy. 3-6 clicks. And the setting is hiding in many differently-named locations.
- Only 1 of 111 check the new passwords against leaked ones
- Only 2 have a generator built into the site
- Only 9 can fil the form correctly with a password manager
There is not much feedback either. Some feedback only shows for 1-2 seconds. Some give no feedback at all. Leaving a user to ask “did it work”? 34 of 96 change flows and 46 of 109 reset flows sends no email.
- Note that the lack of email is bad for abuse situations as it means that an attacker could change someone’s password without their immediate knowledge
Recommendations
- End other user sessions when a password challenges
- Always send an email which includes a “if you didn’t do this, how to fix” link
- Make the W3C password URL work by default
Passkeys in the Wild:
Presenter: Michael Clark
Passkeys are a phishing-resistant authentication built off the FIDO2 (WebAuthn + CTAP) technology. It is built on top of public/private key technology. The general idea is that the client computer creates and protects a private key. It then gives the public key to websites during authentication setup. The client prooves its identity by signing a challenge using its private key. The workflow often also involves a user providing a biometiric to the local client device.
Passkey usability dpends on UX consistency - users spend most of their time on other webisstes, so they expect your site to work like all the other sites they already know. (Jakob’s law)
Evaluated 111 websites, looked at user paths through the websites. Looked at 28 different features and used it to measure similarity.
- Discovery
- Promotion, priority, educatinal resources, naming of the feature
- Setup
- Usage
- Deletion
- Super important for recovery after attack by in-home attackers or malware
Found that there was a lack of full support for the full lifecycle.
- Only 3% use PassKeys during password recovery
- Only 23% told the user to also delete a deleted passkey from their local passkey manager
Missmatch in that websites let you use passkeys, but non gave information on how to create one.
Mobile apps are not letting users use a passkey that was originally setup on the website.
How Users Enter Generated Passwords on Non-Desktop Devices
Presenter: John Sadik
Password managers are super useful, but it can be challenging for users to use them.
Kami got distracted….
Not All Is Lost: Partial Recovery & Memorability in Self-Sovereign Digital Identity
Presenter: Sushanth Ambati, Rowan University
Digital identity management can be challenging. Self-soverenty where users are fully in charge of their own identity management can be empowering and allow great things like flexibility and freedome from government decisions. But it also makes it harder for the user who now has to handle issues like backup, loss, storage, and all these issues.
Contributions:
- Baseline Evaluation of 128-bit Keys
- Partial Key Recovery
- Cognitive-Driven Key Recovery
It would be wonderful if people could memorize 128-bit keys which are massively better than passwords. But well, human memory does not work like that. Humans are very good at memorizing other information though, like location of objects in spaces, sets of images, and lots of others.
Idea is to create a type of graphical approach to key recovery. An imporant realization is that memory is not normally completely wrong, it is normlly partially wrong and partially right.
Session 2: Families & Shared Devices
SoK: The Design Space of Usable Privacy Interventions for Parents: A Systematization of Knowledge
Presenter: Ann-Kristin Lieberknecht, Goethe University Frankfurt
Manging privacy and security is a challenge for parents and there is quite a bit of fragmented reserach on this topic.
How is knowlege about parental privacy actually translated into intervention design.
Reviewed 22 research papers that looked at active interventions by parents on the topic of security and privacy.
Found a very wide range of interventions ranging from parents to schools, to how the delivery happened or what content was in it. The research in this area is very fragmented and similarly the design of intervetions is quite fragmented.
Design space tensions
- Supporting action without oversimplifying
- Individual responsibility with distributed family expertise
- Families with children grow over time whith knowledge and expertise changing across time.
- Scalablility Constraints
- Depth, adaptation and scalability hard to do all at the same time
The research field is better developed in problem articulation than in intervention validation.
“They are not my children to post”: Examining Non-Parental Sharenting Practices in In-home Childcare
Presenter: Franziska Roesner, University of Washington on behalf of Meghna Gupta
The practice of sharing photos, videos, or other information about their own parent’s own children via online platforms. They share to:
- Document memorieis and milestones
- Showcasing their parental identity
- Seeking community support
There are also online harms and risks to sharing:
- Offline harms: bullying, embarasment
- Online harms: identity theft
Non-parents also create and share information about children like Grandparents, extende family, and professional caregivers (coaches, teachers, daycare workers)
Research focus is on in-home childcare workers. This group forms a deep bond with a family and is very involved.
Semi-structured interviews with 8 parents, 7 in-home childcare workers. Goal was to understand prevaleng norms, perceptions and negotiations that occur.
In-home childcare workers often take photos:
- Children request that photos be taken
- Parents ask for photos
- Documentation request
- Documentation as proof of work
- Childcare workers want to record moments
Privacy norms are not normally explicitly stated. Sometimes contracts will state about sharing, but parents are downloading a template of employment contract and maybe not thinking about it. More experience childcare workers were more explicit about establishing boundaries. Most of the workers had to interpret what the parents wanted.
No consistent norm for what to do when a child care worker stopped employment. Deleting photos requests can be taken personally because the childcare worker is deeply involved in raising the child. Who owns these photos is also confusing and who gets to judge.
Sharing Digital Devices is Normal and Cultural: Privacy and Security Challenges in Collectivist Immigrant Households
Presenter: S. Shanza, University of Waterloo
Immigrants are intersting to study. 1 in 4 Canadians is an immigrant, many from “collectivist” cultures where objects, including devices, are viewed a communally owned.
In collectivist households sharing of devices is normal as many things are owned by “the family” as opposed to by an individual. But many devices are designed to be owned by a single user. Or at least to have one user behind one each account.
Interviewed 18 families (at least one parent and one child) who had immigrated in the last 20 years. 41 participants in total.
Device sharing is used as a form of control over children behavior. Because the device is shared the parents can see. Devices are meant to be kept in a “clean” state. Even parent devices are kept like that.
Device sharing does cause stress. Children described being stressed about having fights about content with parents. And parents were stressed about things like having their own work disrupted because tools or internet access were removed so students would not have them. Also about how to keep children safe and give them good vlaues.
Shared devices also mean shared security practices. If anyone, even children, clicks on the wrong thing and gets malware, it impacts the whole family because all the access is happening via a shared devices, even banking.
While tools like profiles exist to support different users on one device, they were hidden behind lots of settings so they were not used.
From Thrift Stores to Digital Storefronts: Users’ Perspectives on Privacy and Security of Online Second-Hand Shopping in Germany
Presneter: Darya Zarkalam, Paderborn University