Best Practices for Notification Studies for Security and Privacy Issues on the Internet

06/15/2021
by   Max Maass, et al.
0

Researchers help operators of vulnerable and non-compliant internet services by individually notifying them about security and privacy issues uncovered in their research. To improve efficiency and effectiveness of such efforts, dedicated notification studies are imperative. As of today, there is no comprehensive documentation of pitfalls and best practices for conducting such notification studies, which limits validity of results and impedes reproducibility. Drawing on our experience with such studies and guidance from related work, we present a set of guidelines and practical recommendations, including initial data collection, sending of notifications, interacting with the recipients, and publishing the results. We note that future studies can especially benefit from extensive planning and automation of crucial processes, i.e., activities that take place well before the first notifications are sent.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/25/2020

Best Practices for IoT Security: What Does That Even Mean?

Best practices for Internet of Things (IoT) security have recently attra...
research
02/18/2022

Improving Test Automation Maturity: a Multivocal Literature Review

Mature test automation is key for achieving software quality at speed. I...
research
09/15/2022

Two case studies on implementing best practices for Software Process Improvement

Software Process Improvement requires significant effort related not onl...
research
12/15/2021

Best Privacy Practice Recommendations for Global Audio Streaming Platforms

Spoon Radio is a rapidly growing global audio streaming platform which c...
research
05/07/2018

Security and Privacy Analyses of Internet of Things Toys

This paper investigates the security and privacy of Internet-connected c...
research
09/18/2023

How to Data in Datathons

The rise of datathons, also known as data or data science hackathons, ha...
research
04/27/2023

Guidance note on best statistical practices for TOAR analyses

The aim of this guidance note is to provide recommendations on best stat...

Please sign up or login with your details

Forgot password? Click here to reset