Skip to main content
arXiv is now an independent nonprofit! Learn more

Showing 1–20 of 20 results for author: Ruoti, S

Searching in archive cs. Search in all archives.
.
  1. arXiv:2604.14330  [pdf, ps, other

    cs.CR

    Understanding Student Experiences with TLS Client Authentication

    Authors: Abubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott Ruoti

    Abstract: Mutual TLS (mTLS) provides strong, certificate-based authentication for both clients and servers, yet its adoption for user-facing websites remains rare. This paper presents a longitudinal study of mTLS usability, tracking 46 senior and graduate computer science students who configured client certificates from scratch, used them for routine authentication over a semester-long course, and managed c… ▽ More

    Submitted 30 April, 2026; v1 submitted 15 April, 2026; originally announced April 2026.

    Comments: 17 pages, 5 figures, 2 tables. Longitudinal usability study with 46 participants over one semester. Preprint

  2. arXiv:2604.14014  [pdf, ps, other

    cs.SE cs.CR

    Analysis of Commit Signing on Github

    Authors: Abubakar Sadiq Shittu, John Sadik, Farzin Gholamrezae, Scott Ruoti

    Abstract: Securing the open-source software supply chain requires verifying the provenance of every code contribution. While end-to-end (E2E) cryptographic commit signing is widely promoted to achieve this, little is known about how developers actually use it at scale. We fill this gap by analyzing 2,737,649 GitHub accounts, identifying 71,694 active contributors, and examining 16,112,439 commits across 874… ▽ More

    Submitted 23 July, 2026; v1 submitted 15 April, 2026; originally announced April 2026.

  3. Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web Browsers

    Authors: Anuj Gautam, Tarun Yadav, Garrett Smith, Kent Seamons, Scott Ruoti

    Abstract: Password managers provide significant security benefits to users. However, malicious client-side scripts and browser extensions can steal passwords after the manager has autofilled them into the web page. In this paper, we extend prior work by Stock and Johns, showing how password autofill can be hardened to prevent these local attacks. We implement our design in the Firefox browser and conduct ex… ▽ More

    Submitted 15 October, 2025; v1 submitted 2 September, 2025; originally announced September 2025.

    Comments: Extended version of paper published at CCS 2025: https://doi.org/10.1145/3719027.3765195

  4. arXiv:2409.04676  [pdf, other

    cs.HC

    Exploring Crowdworkers' Perceptions, Current Practices, and Desired Practices Regarding Using Non-Workstation Devices for Crowdwork

    Authors: Senjuti Dutta, Scott Ruoti, Rhema Linder, Alex C. Williams, Anastasia Kuzminykh

    Abstract: Despite a plethora of research dedicated to designing HITs for non-workstations, there is a lack of research looking specifically into workers' perceptions of the suitability of these devices for managing and completing work. In this work, we fill this research gap by conducting an online survey of 148 workers on Amazon Mechanical Turk to explore 1. how crowdworkers currently use their non-worksta… ▽ More

    Submitted 6 September, 2024; originally announced September 2024.

  5. arXiv:2409.04658  [pdf, other

    cs.HC

    Unveiling the Inter-Related Preferences of Crowdworkers: Implications for Personalized and Flexible Platform Design

    Authors: Senjuti Dutta, Rhema Linder, Alex C. Williams, Anastasia Kuzminykh, Scott Ruoti

    Abstract: Crowdsourcing platforms have traditionally been designed with a focus on workstation interfaces, restricting the flexibility that crowdworkers need. Recognizing this limitation and the need for more adaptable platforms, prior research has highlighted the diverse work processes of crowdworkers, influenced by factors such as device type and work stage. However, these variables have largely been stud… ▽ More

    Submitted 6 September, 2024; originally announced September 2024.

  6. arXiv:2409.03044  [pdf, ps, other

    cs.HC cs.CY

    A Large-Scale Survey of Password Entry Practices on Non-Desktop Devices

    Authors: John Sadik, Scott Ruoti

    Abstract: Password managers encourage users to generate passwords to improve their security. However, research has shown that users avoid generating passwords, often giving the rationale that it is difficult to enter generated passwords on devices without a password manager. In this paper, we conduct a survey ($n=999$) of individuals from the US, UK, and Europe, exploring the range of devices on which they… ▽ More

    Submitted 4 September, 2024; originally announced September 2024.

    Comments: 12 pages, 4 figures, 8 tables

  7. arXiv:2402.06159  [pdf, other

    cs.CR

    Passwords Are Meant to Be Secret: A Practical Secure Password Entry Channel for Web Browsers

    Authors: Anuj Gautam, Tarun Kumar Yadav, Kent Seamons, Scott Ruoti

    Abstract: Password-based authentication faces various security and usability issues. Password managers help alleviate some of these issues by enabling users to manage their passwords effectively. However, malicious client-side scripts and browser extensions can steal passwords after they have been autofilled by the manager into the web page. In this paper, we explore what role the password manager can take… ▽ More

    Submitted 8 February, 2024; originally announced February 2024.

  8. arXiv:2402.03255  [pdf, other

    cs.SI cs.CY cs.HC

    Security Advice for Parents and Children About Content Filtering and Circumvention as Found on YouTube and TikTok

    Authors: Ran Elgedawy, John Sadik, Anuj Gautam, Trinity Bissahoyo, Christopher Childress, Jacob Leonard, Clay Shubert, Scott Ruoti

    Abstract: In today's digital age, concerns about online security and privacy have become paramount. However, addressing these issues can be difficult, especially within the context of family relationships, wherein parents and children may have conflicting interests. In this environment, parents and children may turn to online security advice to determine how to proceed. In this paper, we examine the advice… ▽ More

    Submitted 5 February, 2024; originally announced February 2024.

    Comments: 15 pages, 5 figures, 8 tables

  9. arXiv:2402.00689  [pdf, ps, other

    cs.CR cs.AI

    Ocassionally Secure: A Comparative Analysis of Code Generation Assistants

    Authors: Ran Elgedawy, Porter Dosch, John Sadik, Senjuti Dutta, Anuj Gautam, Konstantinos Georgiou, Farzin Gholamrezae, Fujiao Ji, Kyungchan Lim, Qian Liu, Scott Ruoti

    Abstract: $ $Large Language Models (LLMs) are being increasingly utilized in various applications, with code generations being a notable example. While previous research has shown that LLMs have the capability to generate both secure and insecure code, the literature does not take into account what factors help generate secure and effective code. Therefore in this paper we focus on identifying and understan… ▽ More

    Submitted 29 September, 2025; v1 submitted 1 February, 2024; originally announced February 2024.

    Comments: 12 pages, 2 figures

  10. The Emperor's New Autofill Framework: A Security Analysis of Autofill on iOS and Android

    Authors: Sean Oesch, Anuj Gautam, Scott Ruoti

    Abstract: Password managers help users more effectively manage their passwords, encouraging them to adopt stronger passwords across their many accounts. In contrast to desktop systems where password managers receive no system-level support, mobile operating systems provide autofill frameworks designed to integrate with password managers to provide secure and usable autofill for browsers and other apps insta… ▽ More

    Submitted 28 September, 2021; v1 submitted 20 April, 2021; originally announced April 2021.

    Comments: 12 pages, 3 pages appendix, published at ACSAC 2021

  11. arXiv:1909.12454  [pdf, other

    cs.CR cs.CY cs.SE

    SoK: Blockchain Technology and Its Potential Use Cases

    Authors: Scott Ruoti, Ben Kaiser, Arkady Yerukhimovich, Jeremy Clark, Robert Cunningham

    Abstract: Bitcoin's success has led to significant interest in its underlying components, particularly Blockchain technology. Over 10 years after Bitcoin's initial release, the community still suffers from a lack of clarity regarding what properties defines Blockchain technology, its relationship to similar technologies, and which of its proposed use-cases are tenable and which are little more than hype. In… ▽ More

    Submitted 26 September, 2019; originally announced September 2019.

    Comments: Technical report

  12. arXiv:1908.03296  [pdf, other

    cs.CR

    That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Thirteen Password Managers

    Authors: Sean Oesch, Scott Ruoti

    Abstract: Password managers have the potential to help users more effectively manage their passwords and address many of the concerns surrounding password-based authentication, however prior research has identified significant vulnerabilities in existing password managers. Since that time, five years has passed, leaving it unclear whether password managers remain vulnerable or whether they are now ready for… ▽ More

    Submitted 10 December, 2019; v1 submitted 8 August, 2019; originally announced August 2019.

    Comments: Appearing at USENIX Security 2020

  13. arXiv:1804.07706  [pdf, other

    cs.CR

    SoK: Securing Email -- A Stakeholder-Based Analysis (Extended Version)

    Authors: Jeremy Clark, P. C. van Oorschot, Scott Ruoti, Kent Seamons, Daniel Zappala

    Abstract: While email is the most ubiquitous and interoperable form of online communication today, it was not conceived with strong security guarantees, and the ensuing security enhancements are, by contrast, lacking in both ubiquity and interoperability. This situation motivates our research. We begin by identifying a variety of stakeholders who have an interest in the current email system and in efforts t… ▽ More

    Submitted 22 October, 2021; v1 submitted 20 April, 2018; originally announced April 2018.

    Comments: Extended version of paper published at Financial Cryptography 2021. Under submission at CSUR

  14. arXiv:1610.08570  [pdf, other

    cs.CR

    TrustBase: An Architecture to Repair and Strengthen Certificate-based Authentication

    Authors: Mark O'Neill, Scott Heidbrink, Jordan Whitehead, Scott Ruoti, Dan Bunker, Kent Seamons, Daniel Zappala

    Abstract: We describe TrustBase, an architecture that provides certificate-based authentication as an operating system service. TrustBase enforces best practices for certificate validation for all applications and transparently enables existing applications to be strengthened against failures of the CA system. The TrustBase system allows simple deployment of authentication systems that harden the CA system.… ▽ More

    Submitted 26 October, 2016; originally announced October 2016.

    Comments: 15 pages, 4 figures

  15. arXiv:1510.08943  [pdf, other

    cs.CR

    MessageGuard: A Browser-based Platform for Usable, Content-Based Encryption Research

    Authors: Scott Ruoti, Jeff Andersen, Tyler Monson, Daniel Zappala, Kent Seamons

    Abstract: This paper describes MessageGuard, a browser-based platform for research into usable content-based encryption. MessageGuard is designed to enable collaboration between security and usability researchers on long-standing research questions in this area. It significantly simplifies the effort required to work in this space and provides a place for research results to be shared, replicated, and compa… ▽ More

    Submitted 16 May, 2016; v1 submitted 29 October, 2015; originally announced October 2015.

  16. arXiv:1510.08555  [pdf, other

    cs.CR cs.HC

    Why Johnny Still, Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

    Authors: Scott Ruoti, Jeff Andersen, Daniel Zappala, Kent Seamons

    Abstract: This paper presents the results of a laboratory study involving Mailvelope, a modern PGP client that integrates tightly with existing webmail providers. In our study, we brought in pairs of participants and had them attempt to use Mailvelope to communicate with each other. Our results shown that more than a decade and a half after \textit{Why Johnny Can't Encrypt}, modern PGP tools are still unusa… ▽ More

    Submitted 13 January, 2016; v1 submitted 28 October, 2015; originally announced October 2015.

    Comments: This is the Mailvelope study discussed in the CHI 2016 paper arXiv:1510.08554 "We're on the Same Page": A Usability Study of Secure Email Using Pairs of Novice Users"

  17. "We're on the Same Page": A Usability Study of Secure Email Using Pairs of Novice Users

    Authors: Scott Ruoti, Jeff Andersen, Scott Heidbrink, Mark O'Neil, Elham Vaziripour, Justin Wu, Daniel Zappala, Kent Seamons

    Abstract: Secure email is increasingly being touted as usable by novice users, with a push for adoption based on recent concerns about government surveillance. To determine whether secure email is for grassroots adoption, we employ a laboratory user study that recruits pairs of novice to install and use several of the latest systems to exchange secure messages. We present quantitative and qualitative result… ▽ More

    Submitted 11 January, 2016; v1 submitted 28 October, 2015; originally announced October 2015.

    Comments: 34th Annual ACM Conference on Human Factors in Computing Systems (CHI 2016)

    ACM Class: H.1.2; H.5.2

  18. Private Webmail 2.0: Simple and Easy-to-Use Secure Email

    Authors: Scott Ruoti, Jeff Andersen, Travis Hendershot, Daniel Zappala, Kent Seamons

    Abstract: Private Webmail 2.0 (Pwm 2.0) improves upon the current state of the art by increasing the usability and practical security of secure email for ordinary users. More users are able to send and receive encrypted emails without mistakenly revealing sensitive information. In this paper we describe user interface traits that positively affect the usability and security of Pwm 2.0: (1) an artificial del… ▽ More

    Submitted 8 August, 2016; v1 submitted 28 October, 2015; originally announced October 2015.

    Comments: 29th ACM Conference on User Interface Software and Technology (UIST '16)

    ACM Class: H.5.2; H.1.2

  19. arXiv:1510.04921  [pdf, other

    cs.CR cs.CY cs.HC

    User Attitudes Toward the Inspection of Encrypted Traffic

    Authors: Scott Ruoti, Mark O'Neil, Daniel Zappala, Kent Seamons

    Abstract: This paper reports the results of a survey of 1,976 individuals regarding their opinions on TLS inspection, a controversial technique that can be used for both benevolent and malicious purposes. Responses indicate that participants hold nuanced opinions on security and privacy trade-offs, with most recognizing legitimate uses for the practice, but also concerned about threats from hackers or gover… ▽ More

    Submitted 10 June, 2016; v1 submitted 16 October, 2015; originally announced October 2015.

    Comments: 12th Annual Symposium on Usable Privacy and Security (SOUPS 2016)

  20. arXiv:1407.7146  [pdf, other

    cs.CR cs.NI

    TLS Proxies: Friend or Foe?

    Authors: Mark O'Neill, Scott Ruoti, Kent Seamons, Daniel Zappala

    Abstract: The use of TLS proxies to intercept encrypted traffic is controversial since the same mechanism can be used for both benevolent purposes, such as protecting against malware, and for malicious purposes, such as identity theft or warrantless government surveillance. To understand the prevalence and uses of these proxies, we build a TLS proxy measurement tool and deploy it via Google AdWords campaign… ▽ More

    Submitted 28 May, 2015; v1 submitted 26 July, 2014; originally announced July 2014.

    ACM Class: E.3; C.2.6