Maass, Max Jakob (2021)
Improving Online Privacy and Security Through Crowdsourced Transparency Platforms and Operator Notifications.
Technische Universität Darmstadt
doi: 10.26083/tuprints-00019190
Dissertation, Erstveröffentlichung, Verlagsversion
Kurzbeschreibung (Abstract)
Modern life relies on the internet for everything from communicating and shopping to banking and seeking medical advice. However, this growth of internet-based services also leads to a higher risk of security and privacy issues. Finding and remediating these issues is an important challenge which cannot be addressed through purely technical means, as legal, economic, and psychological factors can also play a role in how these issues are created and resolved. This dissertation approaches this challenge from two sides: we discuss how to collect data and detect issues in the web and email ecosystems, and how the operators of affected systems can be convinced to address them.
Today, efforts to understand internet ecosystems frequently rely on automated large-scale scans. These can efficiently investigate large numbers of systems, but cannot access some ecosystems that require manual actions (e.g., signing up for a newsletter or account). To gather research data and gain access to new ecosystems, we propose and develop two public transparency platforms for use by internet users which collect information about security and privacy issues in the web and email ecosystems using a crowdsourcing approach. We consult with legal experts to ensure the adherence of our platforms to the relevant legislation. Over the 4 years of operation the platforms collected over 3 million scan results, which can serve as a basis for future research.
Our platforms also revealed a number of privacy, security and compliance issues, which should be addressed by the operators of the affected systems. Past research has shown that notifying operators about issues and convincing them to make changes is a challenging problem and frequently results in unsatisfactory remediation rates. We thus investigate the factors influencing the success of large-scale notification campaigns. For this purpose, we conduct three notification studies that evaluate different methods to incentivize system operators to address the issues, like inducing a competitive pressure (leveraging our existing public platform), highlighting the security threat an issue poses, or informing the operators that their systems are not compliant with relevant legislation. We also evaluate the choice of the message medium and the sender as factors in the success of a notification campaign. We collaborate with researchers from economics, law, and psychology to gain additional insights into the behavior of organizations and individual operators. Finally, we derive organizational and methodological recommendations for future notification campaigns based on our experience.
Typ des Eintrags: | Dissertation | ||||
---|---|---|---|---|---|
Erschienen: | 2021 | ||||
Autor(en): | Maass, Max Jakob | ||||
Art des Eintrags: | Erstveröffentlichung | ||||
Titel: | Improving Online Privacy and Security Through Crowdsourced Transparency Platforms and Operator Notifications | ||||
Sprache: | Englisch | ||||
Referenten: | Hollick, Prof. Matthias ; Herrmann, Prof. Dominik | ||||
Publikationsjahr: | 2021 | ||||
Ort: | Darmstadt | ||||
Kollation: | xxii, 197 Seiten | ||||
Datum der mündlichen Prüfung: | 2 Juli 2021 | ||||
DOI: | 10.26083/tuprints-00019190 | ||||
URL / URN: | https://tuprints.ulb.tu-darmstadt.de/19190 | ||||
Kurzbeschreibung (Abstract): | Modern life relies on the internet for everything from communicating and shopping to banking and seeking medical advice. However, this growth of internet-based services also leads to a higher risk of security and privacy issues. Finding and remediating these issues is an important challenge which cannot be addressed through purely technical means, as legal, economic, and psychological factors can also play a role in how these issues are created and resolved. This dissertation approaches this challenge from two sides: we discuss how to collect data and detect issues in the web and email ecosystems, and how the operators of affected systems can be convinced to address them. Today, efforts to understand internet ecosystems frequently rely on automated large-scale scans. These can efficiently investigate large numbers of systems, but cannot access some ecosystems that require manual actions (e.g., signing up for a newsletter or account). To gather research data and gain access to new ecosystems, we propose and develop two public transparency platforms for use by internet users which collect information about security and privacy issues in the web and email ecosystems using a crowdsourcing approach. We consult with legal experts to ensure the adherence of our platforms to the relevant legislation. Over the 4 years of operation the platforms collected over 3 million scan results, which can serve as a basis for future research. Our platforms also revealed a number of privacy, security and compliance issues, which should be addressed by the operators of the affected systems. Past research has shown that notifying operators about issues and convincing them to make changes is a challenging problem and frequently results in unsatisfactory remediation rates. We thus investigate the factors influencing the success of large-scale notification campaigns. For this purpose, we conduct three notification studies that evaluate different methods to incentivize system operators to address the issues, like inducing a competitive pressure (leveraging our existing public platform), highlighting the security threat an issue poses, or informing the operators that their systems are not compliant with relevant legislation. We also evaluate the choice of the message medium and the sender as factors in the success of a notification campaign. We collaborate with researchers from economics, law, and psychology to gain additional insights into the behavior of organizations and individual operators. Finally, we derive organizational and methodological recommendations for future notification campaigns based on our experience. |
||||
Alternatives oder übersetztes Abstract: |
|
||||
Status: | Verlagsversion | ||||
URN: | urn:nbn:de:tuda-tuprints-191903 | ||||
Sachgruppe der Dewey Dezimalklassifikatin (DDC): | 000 Allgemeines, Informatik, Informationswissenschaft > 004 Informatik | ||||
Fachbereich(e)/-gebiet(e): | 20 Fachbereich Informatik 20 Fachbereich Informatik > Sichere Mobile Netze DFG-Graduiertenkollegs DFG-Graduiertenkollegs > Graduiertenkolleg 2050 Privacy and Trust for Mobile Users |
||||
Hinterlegungsdatum: | 28 Jul 2021 08:14 | ||||
Letzte Änderung: | 03 Aug 2021 06:59 | ||||
PPN: | |||||
Referenten: | Hollick, Prof. Matthias ; Herrmann, Prof. Dominik | ||||
Datum der mündlichen Prüfung / Verteidigung / mdl. Prüfung: | 2 Juli 2021 | ||||
Export: | |||||
Suche nach Titel in: | TUfind oder in Google |
Frage zum Eintrag |
Optionen (nur für Redakteure)
Redaktionelle Details anzeigen |