<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Usable Security and Privacy | Kami Vaniea</title>
    <link>https://vaniea.com/tag/usable-security-and-privacy/</link>
      <atom:link href="https://vaniea.com/tag/usable-security-and-privacy/index.xml" rel="self" type="application/rss+xml" />
    <description>Usable Security and Privacy</description>
    <generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Tue, 25 Aug 2026 03:08:19 -0400</lastBuildDate>
    <image>
      <url>https://vaniea.com/media/icon_hu1994206880166008227.png</url>
      <title>Usable Security and Privacy</title>
      <link>https://vaniea.com/tag/usable-security-and-privacy/</link>
    </image>
    
    <item>
      <title>Symposium on Usable Privacy and Security (SOUPS 2026) - Day 2</title>
      <link>https://vaniea.com/post/2026/soups-day2/</link>
      <pubDate>Tue, 25 Aug 2026 03:08:19 -0400</pubDate>
      <guid>https://vaniea.com/post/2026/soups-day2/</guid>
      <description>&lt;p&gt;Welcome to the &lt;a href=&#34;https://soups.page&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Symposium on Usable Security and Privacy&lt;/a&gt; happening in Hannover, Germany and being hosted by CISPA.&lt;/p&gt;
&lt;p&gt;Blog posts:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day1/&#34;&gt;Day 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day2/&#34;&gt;Day 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day3/&#34;&gt;Day 3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&#34;session-1-privacy-notices-permissions--labels&#34;&gt;Session 1: Privacy Notices, Permissions &amp;amp; Labels&lt;/h1&gt;
&lt;h2 id=&#34;how-effective-are-privacy-labels-at-informing-users-about-app-data-handling-practiceshttpswwwusenixorgconferencesoups2026presentationwalsh&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/walsh&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;How Effective are Privacy Labels at Informing Users About App Data Handling Practices?&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Sophia Walsh&lt;/strong&gt;, University of Bristol&lt;/p&gt;
&lt;p&gt;Do the short data notices on app stores properly inform users?&lt;/p&gt;
&lt;p&gt;The study looks at users ability to understand the labels in app store notices. They used a card matching approach where they gave users popular apps on one set of cards and a print-out of the short privacy notice icons on another. They then asked the participants to try and match the two sets while doing a think aloud.&lt;/p&gt;
&lt;p&gt;Unsupprisingly, they find that users do not know how to map the permissions information to the features that exist in apps. They also find that the information can be overwhelming and causes users to give up.&lt;/p&gt;
&lt;h2 id=&#34;i-dont-know-what-ive-all-granted-does-it-really-matter--understanding-users-awareness-of-different-permission-types-on-androidhttpswwwusenixorgconferencesoups2026presentationwinterhalter&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/winterhalter&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;I don&amp;rsquo;t know what I&amp;rsquo;ve all granted. Does it really matter? – Understanding Users&amp;rsquo; Awareness of Different Permission Types on Android&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Verena Winterhalter&lt;/strong&gt;, LMU Munich&lt;/p&gt;
&lt;p&gt;More than 372 apps installed on a given phone.&lt;/p&gt;
&lt;p&gt;Each of these apps has permissions that control how it can collect and use user data. Users&amp;rsquo; awareness of these permissions is poor to start with and can get worse with time since permissions can change over time.&lt;/p&gt;
&lt;p&gt;Studied users understandings of what permissions that the user has installed and uses.&lt;/p&gt;
&lt;p&gt;Recommends:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Focus on permissions where user has agency&lt;/li&gt;
&lt;li&gt;Improve visabiliity &amp;amp; reviwability of installtime permissions&lt;/li&gt;
&lt;li&gt;App usage recency as indicator for suggesting app deletion&lt;/li&gt;
&lt;li&gt;Different intervention approach per type of misconception&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;nudging-developers-toward-privacy-evaluating-the-impact-of-personalized-app-review-reportshttpswwwusenixorgconferencesoups2026presentationpeddinti&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/peddinti&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Nudging Developers Toward Privacy: Evaluating the Impact of Personalized App Review Reports&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Nina Taft&lt;/strong&gt;, Google&lt;/p&gt;
&lt;p&gt;It can be challenging for developers who are building an app to get privacy right. They use libraries, but may not know what those libraries do. But users sometimes have allot to say about the topic in reviews.&lt;/p&gt;
&lt;p&gt;This project attempts to give developers personalized reports about their app.&lt;/p&gt;
&lt;p&gt;Study is multi-stage. Stage-1: survey of developers about their concerns, privacy perceptions, and odds of taking action. Stage-2: showed them a personalized privacy report. Stage-3: measured their understanding.&lt;/p&gt;
&lt;p&gt;The report:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Top 3 privacy concerns from their users&amp;rsquo; reviews&lt;/li&gt;
&lt;li&gt;Focused on one of those concerns, showed them Volume and Trends&lt;/li&gt;
&lt;li&gt;Peer benchmark - compared their app to their peers&lt;/li&gt;
&lt;li&gt;Emotions - emotion words&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Studied people who work in the privacy field, or at least someone who can make decisions involving the privacy design of the app.&lt;/p&gt;
&lt;p&gt;Asked developers about the approaches they have for lookimg at their own reviews, particularly privacy-related. Some read the 1 star reviews. Some have software that reads and summarizes reviews, though not specifically for privacy.&lt;/p&gt;
&lt;p&gt;76% of respondants found it useful. The remaining 24% had a &amp;ldquo;I already knew that&amp;rdquo; response. 69% say that they are likely to do something about the user concerns after seeing the report.&lt;/p&gt;
&lt;h1 id=&#34;session-2-security-operations--practitioners&#34;&gt;Session 2: Security Operations &amp;amp; Practitioners&lt;/h1&gt;
&lt;h2 id=&#34;like-a-hammer-it-can-build-it-can-break-large-language-model-uses-perceptions-and-adoption-in-cybersecurity-operations-on-reddithttpswwwusenixorgconferencesoups2026presentationnath&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/nath&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Souradip Nath&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Looking at how security operations are using LLMs. The reasearch used Reddit to understand usagage. Used mix of Qualtiative and Quantitative.&lt;/p&gt;
&lt;p&gt;The AI vender landscape is wide and growing. But awareness of them are fragmented.&lt;/p&gt;
&lt;p&gt;Security focused LLMs integrated with Triage and Response while general purpose were more for code writing.&lt;/p&gt;
&lt;p&gt;There was a large amount of range in autonomy granted to the agents.&lt;/p&gt;
&lt;p&gt;Developers are finding LLMs to be very helpful in doing things like digging through logs and alerts. Agentic AI, in particular, was seen as valuable to find information and quickly answer questions like &amp;ldquo;does this log line happen every time a user logs in, or is this a new alert?&amp;rdquo; That said, they were concerned about the accuracy of the tools.&lt;/p&gt;
&lt;p&gt;Lots of concerns about how much agency should be given to the tools. The costs of the tools also came up as a serious issue, equating the costs to things like a full time employee salary.&lt;/p&gt;
&lt;h2 id=&#34;the-impact-of-emerging-ai-practices-on-the-cybersecurity-workforcehttpswwwusenixorgconferencesoups2026presentationwong&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/wong&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;The Impact of Emerging AI Practices on the Cybersecurity Workforce&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Miuyin Yong Wong&lt;/strong&gt;, University of Maryland&lt;/p&gt;
&lt;p&gt;Are LLMs making people more efficient? Are they benefiting productivity of cybersecurity professionals? This field particuarly susceptible to burnout.&lt;/p&gt;
&lt;p&gt;RQs (terse version):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What policies and guidance for LLMs are organizations providing&lt;/li&gt;
&lt;li&gt;What challenges and risks when using LLMs&lt;/li&gt;
&lt;li&gt;How do peer perceptions impact views&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Conducted interviews 28 participants from 26 organizations spanning 16 job roles.&lt;/p&gt;
&lt;h4 id=&#34;the-current-landscape&#34;&gt;The current landscape&lt;/h4&gt;
&lt;p&gt;Quite a range of policies avaiable. Many did not have a policy or had a relaxed or generic policy. A few had very restricted policy, such as not allowing training on local company data. Participants mostly relied on exsisting data loss measures. Most of the burdon for being safe falls on the individual to not do the wrong thing.&lt;/p&gt;
&lt;h4 id=&#34;barriers-to-adoption-and-mitigations&#34;&gt;Barriers to adoption and mitigations&lt;/h4&gt;
&lt;p&gt;Issues like data leakage, hallucinations, lack of confidence in promoting skills, and wasting time.&lt;/p&gt;
&lt;p&gt;People were also afraid of other people using the AI. Concerns that less experienced people would use the AI poorly, or loose the ability to learn.&lt;/p&gt;
&lt;p&gt;&amp;ldquo;What will others think of me if I use AI?&amp;rdquo; The cybersecurity community is an open community that shares knowledge, but AI may be changing that. People are worried about what others will think about their AI use which is causing a lack of communication about it.&lt;/p&gt;
&lt;h2 id=&#34;from-preventive-to-reactive-how-ai-coding-assistants-transform-developers-security-awarenesshttpswwwusenixorgconferencesoups2026presentationbappy&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/bappy&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;From Preventive to Reactive: How AI Coding Assistants Transform Developers&amp;rsquo; Security Awareness&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Faisal Haque Bappy&lt;/strong&gt;, University of Maryland Baltimore County&lt;/p&gt;
&lt;p&gt;Did a coding session using thinking aloud. Divided participants based on the date they were trained, before AI, during the AI boom, or were native to AI use. They also did an interview and a post-task reflection.&lt;/p&gt;
&lt;p&gt;the good news is that AI ouptputs are treated as reference rather than a final code state. People talked about the AI like a junior collegue, but they also didn&amp;rsquo;t explicitly make security requirements to the AI.&lt;/p&gt;
&lt;h2 id=&#34;i-see-dns-people-dns-resolver-security-through-operator-perspectives-and-practiceshttpswwwusenixorgconferencesoups2026presentationobinna&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/obinna&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;I See DNS People: DNS Resolver Security, Through Operator Perspectives and Practices&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Katharina Barlage&lt;/strong&gt;, LMU Munich&lt;/p&gt;
&lt;p&gt;DNS converts human-friendly URLs like &amp;ldquo;vaniea.com&amp;rdquo; to an IP address (205.196.221.231) which is where the computer establishes a connection. A successful DNS attack can route traffic to somewhere else. Or it could stop users from visiting the site. Having security on DNS servers is vital, but not universally deployed.&lt;/p&gt;
&lt;p&gt;DNS &amp;ldquo;just works&amp;rdquo; so no one cares untill there is a problem. So upper management does not give resources. Security is often assumed but not assessed. Uptime is a seroius concern and can outrank security.&lt;/p&gt;
&lt;p&gt;Some DNS opperators are buying software to run, and assuming that security is there because it should be. They do not assess. Because everything looks fine there is no percieved need to go adjust things. The danger is also abstract and not seem real because there have not been any DNS incidents that they know of. But if they adjust DNS wrong, everything will break, so the short term risk seems more risky. Turning on security is similar, turning on security seems risky and not worth that risk.&lt;/p&gt;
&lt;h1 id=&#34;session-phishing--social-engineering&#34;&gt;Session: Phishing &amp;amp; Social Engineering&lt;/h1&gt;
&lt;h2 id=&#34;i-didnt-know-i-would-be-this-excited-not-to-be-scammed-exploring-emotional-and-behavioral-responses-during-phishing-attacks&#34;&gt;“I didn’t know I would be this excited not to be scammed.” Exploring Emotional and Behavioral Responses During Phishing Attacks&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Raphael Weidhaas&lt;/strong&gt;, Aalto University&lt;/p&gt;
&lt;p&gt;People are still clicking on phising despite lots of training. There is limited research on how phishing impacts the emotion state of the person who gets the phishing.&lt;/p&gt;
&lt;p&gt;Lab study where users were put in an office setting. They were given a set of tasks. After about 45 minutes they were sent a simulated phishing email. It was mildly associated with a task, but had some clear indicators like three &amp;lsquo;o&amp;rsquo; on zooom. Followed by an interview.&lt;/p&gt;
&lt;p&gt;22 participants identified the phishing, 7 clicked, 8 avoided but didn&amp;rsquo;t realize it was a phishing. 4 fell for the phishing and entered data. The clickers tended to think they had made an error and were trying to correct it, but did realize that it was a problem. Phished people felt that they had solved the problem and felt positive afterwards.&lt;/p&gt;
&lt;p&gt;People who fell for phishing had the most positive emotions. Detectors were the most annoyed.&lt;/p&gt;
&lt;h2 id=&#34;anxious-and-aware-examining-the-effects-of-social-anxiety-on-social-engineering-resilience-and-vulnerabilityhttpswwwusenixorgconferencesoups2026presentationdechant&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/dechant&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Anxious and Aware: Examining the Effects of Social Anxiety on Social Engineering Resilience and Vulnerability&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Martin Dechant&lt;/strong&gt;, University College London&lt;/p&gt;
&lt;p&gt;How does having Social Anxiety impact how people process and think about phishing.&lt;/p&gt;
&lt;p&gt;People with social anxiety are worried about situations were they are around large groups of others where they might stand out or be criticised by those peers. 4.7% of children, and 8.3% of adolescents have social anxiety globally.&lt;/p&gt;
&lt;p&gt;Asked a group of people about a recent social engineering attack that they had experienced. Scammers exploit trust and desires by creating a sense of familiarity, then manipulating with the promises of materialistic or financial gains. Perpetrators weaponized any shared material. Perpetrators fabricate a crisese or urgent situation.&lt;/p&gt;
&lt;p&gt;Studied three scams where participants experienced a scenario as a role play.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Job Scam (Trust and Desires)&lt;/li&gt;
&lt;li&gt;Extortion (Compromising material)&lt;/li&gt;
&lt;li&gt;Romance Scam (Empathy and Urgency)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Participants did not want to reach out for help due to structural barriers. Social Anxiety people didn&amp;rsquo;t want to talk about it, they were worried about judgement, assumed that others would laugh.&lt;/p&gt;
&lt;p&gt;Scammers used language to give affirmation that the social anxious person craved like &amp;ldquo;you are great&amp;rdquo; and &amp;ldquo;you are amazing&amp;rdquo;.&lt;/p&gt;
&lt;h2 id=&#34;quantifying-risk-perception-and-scam-response-among-international-and-domestic-us-university-students&#34;&gt;Quantifying Risk Perception and Scam Response Among International and Domestic US University Students&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Elijah Bouma-Sims&lt;/strong&gt;, Carnegie Mellon University;&lt;/p&gt;
&lt;p&gt;International students may be more vulnerable to scams for reasons like: unfamiliarity with US legal, lingustic, and cultural norms, pressures for post-graduation employment.&lt;/p&gt;
&lt;p&gt;Surveyed about 1000 international and domestic students from 5 universities. Each person saw a scenario describing a scam from a set of sources like phone call, sms, email. They were also asked about prior scam experience.&lt;/p&gt;
&lt;h2 id=&#34;experiences-with-digital-scams-post-incarceration-in-the-us&#34;&gt;Experiences with Digital Scams Post-Incarceration in the U.S.&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Yael Eiger&lt;/strong&gt;, University of Washington&lt;/p&gt;
&lt;p&gt;Incarcerated people are more commmen than you might realize. It is in the millions. 7.6 millions times a year people are sent to jail because they cannot make bail and must stay there till their case is resolved. More people are Incarcerated than are convited of any crime.&lt;/p&gt;
&lt;p&gt;Research looks at how previously Incarcerated people experience scams. The research is interesting in pointing out what it is like to experience all of technology all at once, including setting up accounts. This population is also at great risk from things like parking tickets, which makes scams more scary.&lt;/p&gt;
&lt;p&gt;This group also have to register their existance, so they are in public databases which scammers then use.&lt;/p&gt;
&lt;h1 id=&#34;session-at-risk-and-vulnerable-users&#34;&gt;Session: At risk and vulnerable users&lt;/h1&gt;
&lt;h2 id=&#34;usability-determines-safety-for-at-risk-users-evaluating-hidden-device-detectors-for-intimate-partner-surveillance&#34;&gt;Usability Determines Safety for At-Risk Users: Evaluating Hidden Device Detectors for Intimate Partner Surveillance&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Akhil Polamarasetty&lt;/strong&gt;, University College London (UCL)&lt;/p&gt;
&lt;p&gt;Trackers are now cheap to obtain, and easy to buy. There are also lots of detectors. Physical dtectors use things like RF Signal Detection, Magnetometer, Lens Detection. There are also mobile apps that do things like scanning wifi and bluetooth.&lt;/p&gt;
&lt;p&gt;The researchers did several rounds of testing of various devices, such as testing in an anechoic chapber and dark room to see what the detectors could do in opitmal conditions. Then had users try them in a fake living room.&lt;/p&gt;
&lt;p&gt;Users searched the room in two ways:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intuitive: looked for sply-looking objects like clocks&lt;/li&gt;
&lt;li&gt;Systematic: Divide a room into a grid and looked at most objects. This tactic was more common for people with law enforcement background&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Having a physical detector tended to make people feel more vulnerable, even though they were in a safe lab space.&lt;/p&gt;
&lt;h2 id=&#34;goals-risks-and-safety-practices-in-online-labor-abuse-disclosureshttpswwwusenixorgconferencesoups2026presentationriveraf&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/riveraf&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Goals, Risks, and Safety Practices in Online Labor Abuse Disclosures&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Tarini Saka&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Recovery from serious security issues is challenges. Many people turn to online support. But the online communities themselves have minimal security.&lt;/p&gt;
&lt;p&gt;This work looks at the context of labor abuse. For this group Human Resource departments, which are the reporting destination, may not help and re-traumitize instead. Instead people try to find groups to communicate with safely about what they can do.&lt;/p&gt;
&lt;p&gt;Labor abuse survivers form networks across platforms where they are forming an audience. Compare them to activists who have nation-state abilities. Labor abuse victim face locally powerful adversaries that have financial and direct ability to impact the victim, but they have less ability to impact the technology world.&lt;/p&gt;
&lt;p&gt;This is an interview and thematic analysis study.&lt;/p&gt;
&lt;p&gt;Many people reached out to understand if their situation was indeedproblematic or if they were just &amp;ldquo;crazy&amp;rdquo;. The researchres group into four types of communication groups: feed-based groups, publicly visible threads, Messaging groups, ???&lt;/p&gt;
&lt;h2 id=&#34;i-feel-as-though-my-privacy-is-being-violated-privacy-risks-and-barriers-in-instant-messaging-for-blind-and-low-vision-usershttpswwwusenixorgconferencesoups2026presentationakter&#34;&gt;[]“I feel as though my privacy is being violated”: Privacy Risks and Barriers in Instant Messaging for Blind and Low-Vision Users](&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/akter&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://www.usenix.org/conference/soups2026/presentation/akter&lt;/a&gt;)&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Sohana Akter&lt;/strong&gt;, University of Texas at San Antonio&lt;/p&gt;
&lt;p&gt;Instant messsaging is used for a large parts of personal and professional life. The same is true for the Blind and Partially Sighted users.&lt;/p&gt;
&lt;p&gt;Blind and low vision people may have further issues like tryingn to understand an image, others might hear a screen reader, and then there are privacy controls&amp;hellip;.&lt;/p&gt;
&lt;p&gt;Just moving a mouse into some spaces can activate things, but a blind user has no way to know that will or has happened. Tags like &amp;ldquo;last seen&amp;rdquo; are intended to be seen at a glance, but that is more challenging for partially sighted.&lt;/p&gt;
&lt;p&gt;Some information entry is irreversible, which is more challenging when using a screen reader which may not properly explain what information is entered or why.&lt;/p&gt;
&lt;h2 id=&#34;dont-let-them-get-to-you-understanding-the-role-of-tiktok-as-a-source-of-support-for-cyberbullying-victimshttpswwwusenixorgconferencesoups2026presentationiqbal&#34;&gt;[]&amp;ldquo;Don&amp;rsquo;t Let Them Get To You&amp;rdquo;: Understanding the Role of TikTok as a Source of Support for Cyberbullying Victims](&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/iqbal&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://www.usenix.org/conference/soups2026/presentation/iqbal&lt;/a&gt;)&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Daniel Zappala&lt;/strong&gt;, Brigham Young University, on behalf of Saba Iqbal&lt;/p&gt;
&lt;p&gt;Cyberbulling is increasing as a problem in the US.&lt;/p&gt;
&lt;p&gt;Prior work shows that sorting through security and privacy advice is challenging and users strugggle to prioritize it.&lt;/p&gt;
&lt;p&gt;This work looks at the cyberbulling advice that exists on TicTok and how accurate that advice is.&lt;/p&gt;
&lt;p&gt;Looked through lots of TicTok videos and found, that there were roughly 5 categories of advice:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Coping strategies
&lt;ul&gt;
&lt;li&gt;Things like: don&amp;rsquo;t respond, block and report, take a break, comfort the bully&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Emotional Support
&lt;ul&gt;
&lt;li&gt;Reassuring that bulling is not acceptable, not true, projection of bully insecurities, empower yourself.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Mental Health Advice
&lt;ul&gt;
&lt;li&gt;Set boundaries, don&amp;rsquo;t take it personal, exercise, journaling, get sleep,&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Spiritual Support
&lt;ul&gt;
&lt;li&gt;Support based on faith things like: Turn the other cheek, god is watching over you,&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Seeking support
&lt;ul&gt;
&lt;li&gt;Guidance on where to turn to. Like get evidence, contact law enforcement&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Survey was then run where asked about experiences, and asked them the rate the content of the videos (text transcription). Rated baed on: comprhensibility, efficacy, actionability.&lt;/p&gt;
&lt;p&gt;Most advice was rated as comprehensible. Most advice was considered effective. The spiritual category was rated lower for being helpful. About 1/3 of advice was considered actionable. Confrunting the bully, for example, were not seen as actionable.&lt;/p&gt;
&lt;h2 id=&#34;reproductive-security--privacy-advice-on-tiktok-after-the-overturn-of-roe&#34;&gt;Reproductive Security &amp;amp; Privacy Advice on TikTok after the Overturn of Roe&lt;/h2&gt;
&lt;p&gt;Presenters: &lt;strong&gt;Harshini Sri Ramulu and Rachel Gonzalez Rodriguez&lt;/strong&gt;, Paderborn University&lt;/p&gt;
&lt;p&gt;The overturning of Roe vs Wade in the US lead to many women suddenly loosing reproductive care and requests for information about how to protect themselves.&lt;/p&gt;
&lt;p&gt;Study looked at TikToc videos that gave advice on protect yourself as a woman in the US. The covered issues like how to not track mentration (delete period tracking apps). There were lots of contradictory advice, such as using apps in Europe or not using apps because they were in Europe. Some advice also suggested creating a fake data.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Symposium on Usable Privacy and Security (SOUPS 2026) - Day 1</title>
      <link>https://vaniea.com/post/2026/soups-day1/</link>
      <pubDate>Mon, 24 Aug 2026 07:02:13 -0400</pubDate>
      <guid>https://vaniea.com/post/2026/soups-day1/</guid>
      <description>&lt;p&gt;Welcome to the &lt;a href=&#34;https://soups.page&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Symposium on Usable Security and Privacy&lt;/a&gt; happening in Hannover, Germany and being hosted by CISPA. The SOUPS community is made up of researchers that care about understanding and improving peoples&amp;rsquo; interactions with security and privacy technologies. Research in this area represents a very wide range of cybersecurity and privacy topics with a focus on people.&lt;/p&gt;
&lt;p&gt;Blog posts:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day1/&#34;&gt;Day 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day2/&#34;&gt;Day 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://vaniea.com/post/2026/soups-day3/&#34;&gt;Day 3&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&#34;authentication--credentials&#34;&gt;Authentication &amp;amp; Credentials&lt;/h1&gt;
&lt;h2 id=&#34;an-analysis-of-the-security-usability-and-automation-capabilities-of-password-update-processes-on-top-ranked-websiteshttpswwwusenixorgconferencesoups2026presentationkrause&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/krause&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Alexander Krause&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Updating passwords is something many people do. But do websites always support password resets and how easy is it to reset passwords?&lt;/p&gt;
&lt;p&gt;Users have many situations where they might want to change their password:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Maybe they just want to feel more secure&lt;/li&gt;
&lt;li&gt;Maybe they lost their password&lt;/li&gt;
&lt;li&gt;Maybe they want to make it more challenges&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Goal of the work is to look at three questions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How do websites implement password update processes?&lt;/li&gt;
&lt;li&gt;How doe sit go wrong?&lt;/li&gt;
&lt;li&gt;How can we do it better?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The researchers looked through the password reset processes on a large number of websites. There is also a &lt;a href=&#34;https://w3c.github.io/webappsec-change-password-url/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;W3P password reset link&lt;/a&gt; that they tested.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The path is long&lt;/em&gt; - finding and resetting passwords is not easy. 3-6 clicks. And the setting is hiding in many differently-named locations.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Only 1 of 111 check the new passwords against leaked ones&lt;/li&gt;
&lt;li&gt;Only 2 have a generator built into the site&lt;/li&gt;
&lt;li&gt;Only 9 can fil the form correctly with a password manager&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is not much feedback either. Some feedback only shows for 1-2 seconds. Some give no feedback at all. Leaving a user to ask &amp;ldquo;did it work&amp;rdquo;? 34 of 96 change flows and 46 of 109 reset flows sends no email.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Note that the lack of email is bad for abuse situations as it means that an attacker could change someone&amp;rsquo;s password without their immediate knowledge&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Recommendations&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;End other user sessions when a password challenges&lt;/li&gt;
&lt;li&gt;Always send an email which includes a &amp;ldquo;if you didn&amp;rsquo;t do this, how to fix&amp;rdquo; link&lt;/li&gt;
&lt;li&gt;Make the W3C password URL work by default&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;passkeys-in-the-wild&#34;&gt;Passkeys in the Wild:&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Michael Clark&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Passkeys are a phishing-resistant authentication built off the FIDO2 (WebAuthn + CTAP) technology. It is built on top of public/private key technology. The general idea is that the client computer creates and protects a private key. It then gives the public key to websites during authentication setup. The client prooves its identity by signing a challenge using its private key. The workflow often also involves a user providing a biometiric to the local client device.&lt;/p&gt;
&lt;p&gt;Passkey usability dpends on UX consistency - users spend most of their time on other webisstes, so they expect your site to work like all the other sites they already know. (Jakob&amp;rsquo;s law)&lt;/p&gt;
&lt;p&gt;Evaluated 111 websites, looked at user paths through the websites. Looked at 28 different features and used it to measure similarity.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Discovery
&lt;ul&gt;
&lt;li&gt;Promotion, priority, educatinal resources, naming of the feature&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Setup&lt;/li&gt;
&lt;li&gt;Usage&lt;/li&gt;
&lt;li&gt;Deletion
&lt;ul&gt;
&lt;li&gt;Super important for recovery after attack by  in-home attackers or malware&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Found that there was a lack of full support for the full lifecycle.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Only 3% use PassKeys during password recovery&lt;/li&gt;
&lt;li&gt;Only 23% told the user to also delete a deleted passkey from their local passkey manager&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Missmatch in that websites let you use passkeys, but non gave information on how to create one.&lt;/p&gt;
&lt;p&gt;Mobile apps are not letting users use a passkey that was originally setup on the website.&lt;/p&gt;
&lt;h2 id=&#34;how-users-enter-generated-passwords-on-non-desktop-deviceshttpswwwusenixorgconferencesoups2026presentationsadik&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/sadik&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;How Users Enter Generated Passwords on Non-Desktop Devices&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;John Sadik&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Password managers are super useful, but it can be challenging for users to use them.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Kami got distracted&amp;hellip;.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&#34;not-all-is-lost-partial-recovery--memorability-in-self-sovereign-digital-identityhttpswwwusenixorgconferencesoups2026presentationambati&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/ambati&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Not All Is Lost: Partial Recovery &amp;amp; Memorability in Self-Sovereign Digital Identity&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Sushanth Ambati, Rowan University&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Digital identity management can be challenging. Self-soverenty where users are fully in charge of their own identity management can be empowering and allow great things like flexibility and freedome from government decisions. But it also makes it harder for the user who now has to handle issues like backup, loss, storage, and all these issues.&lt;/p&gt;
&lt;p&gt;Contributions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Baseline Evaluation of 128-bit Keys&lt;/li&gt;
&lt;li&gt;Partial Key Recovery&lt;/li&gt;
&lt;li&gt;Cognitive-Driven Key Recovery&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It would be wonderful if people could memorize 128-bit keys which are massively better than passwords. But well, human memory does not work like that. Humans are very good at memorizing other information though, like location of objects in spaces, sets of images, and lots of others.&lt;/p&gt;
&lt;p&gt;Idea is to create a type of graphical approach to key recovery. An imporant realization is that memory is not normally completely wrong, it is normlly partially wrong and partially right.&lt;/p&gt;
&lt;h1 id=&#34;session-2-families--shared-devices&#34;&gt;Session 2: Families &amp;amp; Shared Devices&lt;/h1&gt;
&lt;h2 id=&#34;sok-the-design-space-of-usable-privacy-interventions-for-parents-a-systematization-of-knowledgehttpswwwusenixorgconferencesoups2026presentationlieberknecht&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/lieberknecht&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;SoK: The Design Space of Usable Privacy Interventions for Parents: A Systematization of Knowledge&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Ann-Kristin Lieberknecht&lt;/strong&gt;, Goethe University Frankfurt&lt;/p&gt;
&lt;p&gt;Manging privacy and security is a challenge for parents and there is quite a bit of fragmented reserach on this topic.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;How is knowlege about parental privacy actually translated into intervention design.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Reviewed 22 research papers that looked at active interventions by parents on the topic of security and privacy.&lt;/p&gt;
&lt;p&gt;Found a very wide range of interventions ranging from parents to schools, to how the delivery happened or what content was in it. The research in this area is very fragmented and similarly the design of intervetions is quite fragmented.&lt;/p&gt;
&lt;p&gt;Design space tensions&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Supporting action without oversimplifying&lt;/li&gt;
&lt;li&gt;Individual responsibility with distributed family expertise&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;Families with children grow over time whith knowledge and expertise changing across time.&lt;/li&gt;
&lt;/ul&gt;
&lt;ol start=&#34;3&#34;&gt;
&lt;li&gt;Scalablility Constraints&lt;/li&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;Depth, adaptation and scalability hard to do all at the same time&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The research field is better developed in &lt;em&gt;problem articulation&lt;/em&gt; than in &lt;em&gt;intervention validation&lt;/em&gt;.&lt;/p&gt;
&lt;h2 id=&#34;they-are-not-my-children-to-post-examining-non-parental-sharenting-practices-in-in-home-childcarehttpswwwusenixorgconferencesoups2026presentationgupta&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/gupta&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;&amp;ldquo;They are not my children to post&amp;rdquo;: Examining Non-Parental Sharenting Practices in In-home Childcare&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;Franziska Roesner, University of Washington&lt;/strong&gt; on behalf of Meghna Gupta&lt;/p&gt;
&lt;p&gt;The practice of sharing photos, videos, or other information about their own parent&amp;rsquo;s own children via online platforms. They share to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Document memorieis and milestones&lt;/li&gt;
&lt;li&gt;Showcasing their parental identity&lt;/li&gt;
&lt;li&gt;Seeking community support&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are also online harms and risks to sharing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Offline harms: bullying, embarasment&lt;/li&gt;
&lt;li&gt;Online harms: identity theft&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Non-parents also create and share information about children like Grandparents, extende family, and professional caregivers (coaches, teachers, daycare workers)&lt;/p&gt;
&lt;p&gt;Research focus is on in-home childcare workers. This group forms a deep bond with a family and is very involved.&lt;/p&gt;
&lt;p&gt;Semi-structured interviews with 8 parents, 7 in-home childcare workers. Goal was to understand prevaleng norms, perceptions and negotiations that occur.&lt;/p&gt;
&lt;p&gt;In-home childcare workers often take photos:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Children request that photos be taken&lt;/li&gt;
&lt;li&gt;Parents ask for photos
&lt;ul&gt;
&lt;li&gt;Documentation request&lt;/li&gt;
&lt;li&gt;Documentation as proof of work&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Childcare workers want to record moments&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Privacy norms are not normally explicitly stated. Sometimes contracts will state about sharing, but parents are downloading a template of employment contract and maybe not thinking about it. More experience childcare workers were more explicit about establishing boundaries. Most of the workers had to interpret what the parents wanted.&lt;/p&gt;
&lt;p&gt;No consistent norm for what to do when a child care worker stopped employment. Deleting photos requests can be taken personally because the childcare worker is deeply involved in raising the child. Who owns these photos is also confusing and who gets to judge.&lt;/p&gt;
&lt;h2 id=&#34;sharing-digital-devices-is-normal-and-cultural-privacy-and-security-challenges-in-collectivist-immigrant-householdshttpswwwusenixorgconferencesoups2026presentationshanza&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/shanza&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Sharing Digital Devices is Normal and Cultural: Privacy and Security Challenges in Collectivist Immigrant Households&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presenter: &lt;strong&gt;S. Shanza, University of Waterloo&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Immigrants are intersting to study. 1 in 4 Canadians is an immigrant, many from &amp;ldquo;collectivist&amp;rdquo; cultures where objects, including devices, are viewed a communally owned.&lt;/p&gt;
&lt;p&gt;In collectivist households sharing of devices is normal as many things are owned by &amp;ldquo;the family&amp;rdquo; as opposed to by an individual. But many devices are designed to be owned by a single user. Or at least to have one user behind one each account.&lt;/p&gt;
&lt;p&gt;Interviewed 18 families (at least one parent and one child) who had immigrated in the last 20 years. 41 participants in total.&lt;/p&gt;
&lt;p&gt;Device sharing is used as a form of control over children behavior. Because the device is shared the parents can see. Devices are meant to be kept in a &amp;ldquo;clean&amp;rdquo; state. Even parent devices are kept like that.&lt;/p&gt;
&lt;p&gt;Device sharing does cause stress. Children described being stressed about having fights about content with parents. And parents were stressed about things like having their own work disrupted because tools or internet access were removed so students would not have them. Also about how to keep children safe and give them good vlaues.&lt;/p&gt;
&lt;p&gt;Shared devices also mean shared security practices. If anyone, even children, clicks on the wrong thing and gets malware, it impacts the whole family because all the access is happening via a shared devices, even banking.&lt;/p&gt;
&lt;p&gt;While tools like profiles exist to support different users on one device, they were hidden behind lots of settings so they were not used.&lt;/p&gt;
&lt;h2 id=&#34;from-thrift-stores-to-digital-storefronts-users-perspectives-on-privacy-and-security-of-online-second-hand-shopping-in-germanyhttpswwwusenixorgconferencesoups2026presentationshanza&#34;&gt;&lt;a href=&#34;https://www.usenix.org/conference/soups2026/presentation/shanza&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;From Thrift Stores to Digital Storefronts: Users&amp;rsquo; Perspectives on Privacy and Security of Online Second-Hand Shopping in Germany&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Presneter: &lt;strong&gt;Darya Zarkalam&lt;/strong&gt;, Paderborn University&lt;/p&gt;
&lt;p&gt;Offline second-hand shopping has existed for a long time. These platforms have moved online, for example eBay or Vinted. These markets are unique in that they provid features like messaging, ratings, payment and shippment. But ultipmately users decide how to complete the transactions.&lt;/p&gt;
&lt;p&gt;Scammers are definitely use these platforms too.&lt;/p&gt;
&lt;p&gt;Study looked at how people think about and use these platforms from a security and privacy perspective.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Users security and privacy concerns&lt;/li&gt;
&lt;li&gt;Users perceptions&lt;/li&gt;
&lt;li&gt;Users strategies for avoiding loss&lt;/li&gt;
&lt;li&gt;How users build and establish trust&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Participants were concerned about security and privacy. They worried about sharing data about themselves like their phone number.&lt;/p&gt;
&lt;p&gt;Users tried to protect themselves. They tried to use payment methods they considered safe like cash, or paypal where there is documentation. Integrated payment features were seen as reducing odds of financial loss, platform can be involved if something goes wrong.&lt;/p&gt;
&lt;p&gt;They avoid sharing sensitive details. They shared data progressively as it was needed.&lt;/p&gt;
&lt;p&gt;Reputation signals were used. Such as not talking to people who had lower reputation scores.&lt;/p&gt;
&lt;p&gt;Platforms provide little guidance&lt;/p&gt;
&lt;h1 id=&#34;keynote-usable-security-in-practice---how-tuta-makes-email-encryption-usable&#34;&gt;Keynote: Usable Security in Practice - How Tuta Makes Email Encryption Usable&lt;/h1&gt;
&lt;p&gt;Presenter: Carmela Troncoso&lt;/p&gt;
&lt;p&gt;&amp;ldquo;Turn on privacy&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://tuta.com/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Tuta&lt;/a&gt; provides end-to-end encrypted email services using quantum-secure encryption. It enables automatic encryption between Tula users. For communications with non-Tula accounts a password is shared in advance and then can be used for all future communications.&lt;/p&gt;
&lt;p&gt;Tuta aims to enable Digital Sovereignty or just alow people to have control over their own digital life.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://cic.iacr.org/p/3/2/15&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Migrating to Hybrid Cryptography in Practice: The TutaCrypt Protocol and Its Security&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Seamless encryption is more than just who possesses the private key. Issues like groups communicating (group keys).&lt;/p&gt;
&lt;p&gt;Keeping up with tech is also non-trivial. If only a user has a key (or the password to unlock the key) then by definition the company does not have it. That makes it hard to do things like update encryption algorithums to the latest quantum-protected ones. Now it is only possible to update the algorithums when each user logs in when the keys become available.&lt;/p&gt;
&lt;p&gt;Legal protections are also a serious concern. Tuta is hosted in Germany allowing them to benifit from German laws and the GDPR which gives users legal protection not just technical protection.&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>
