Jan Tolsdorf received the Doctoral Thesis Award 2022 by the Bonn-Rhein-Sieg University Society
Congratulations to Jan Tolsdorf for receiving the the Doctoral Thesis Award 2022 by the Bonn-Rhein-Sieg University Society (“Promotionspreis Hochschulgesellschaft Bonn-Rhein-Sieg 2022”), funded by the Industrie- und Handelsclub Bonn e. V.
With this award the society honors Jan Tolsdorf’s work in the context of his dissertation “Investigation of Information Privacy in Employment: Fundamental Knowledge and Practical Solutions for the Human-Centered Design of Measures to Preserve the Right to Informational Self-Determination in Employment”.
More information on the award is available here.
Credits photo: H-BRS/Nathan Dreessen
January 27, 2023Stephan Wiefling gives a talk at the Stammtisch of the Cyber Security Cluster Bonn
Stephan Wiefling will give an invited talk (in German) on how risk-based authentication (RBA) can protect our accounts with better usability. Participation is free and online.
The presentation shows
- how popular online services use RBA
- how users perceive it
- how you can implement it in a privacy-compliant way
- and how it can be configured for best possible security and usability on a large online service.
Date and time: January 17, 2023 at 4pm - 5:30 pm
Further information and registration can be found here.
January 10, 2023Open Data Impact Award for Members of DAS Group
The Stifterverband awarded Stephan Wiefling and Luigi Lo Iacono with the Open Data Impact Award 2022. The award recognizes the release of our open Login Data Set for Risk-Based Authentication (RBA), and its innovation potential for science and society. The prize money of 10,000 euros will be used to move RBA forward. You can download the data set and the corresponding publication at our RBA website.
November 9, 2022New article accepted for publication in IEEE Security & Privacy
The article “Eight Lightweight Usable Security Principles for Developers” by Peter Leo Gorski, Luigi Lo Iacono, and Matthew Smith has been accepted for inclusion in IEEE Security & Privacy. The article proposes eight usable security principles that provide software developers with a lightweight framework to help them integrate security in a user-friendly way. The principles are supposed to help developers who must weigh usability and security tradeoffs to facilitate adoption.
October 7, 2022Paper on an interview study with data protection officers on privacy challenges in digital ecosystems accepted for presentation at SPOSE 2022
The paper entitled “Data Protection Officers’ Perspectives on Privacy Challenges in Digital Ecosystems” by Stephan Wiefling, Jan Tolsdorf, and Luigi Lo Iacono has been accepted for presentation at the 4th Workshop on Security, Privacy, Organizations, and Systems Engineering (SPOSE). The paper presents the result of an interview study with seven data protection officers from Germany on challenges in implementing data protection requirements and data subject rights in digital ecosystems.
September 30, 2022Jan Tolsdorf successfully defended his dissertation
Jan Tolsdorf successfully defended his dissertation entitled “Investigation of Information Privacy in Employment: Fundamental Knowledge and Practical Solutions for the Human-Centered Design of Measures to Preserve the Right to Informational Self-Determination in Employment” in Göttingen on 08 August 2022. His dissertation project was carried out as part of a collaboration between the DAS-Group of Prof. Luigi Lo Iacono at H-BRS and the Computer Security and Privacy Research Group of Prof. Delphine Reinhardt at the University of Göttingen. Here Jan has undergone the PhD Programme in Computer Science at the Georg-August University School of Science. Congratulations!
August 11, 2022Risk-Based Authentication (RBA) Studied on 3.3 Million Users: Paper and Data Set Published
The DAS Group cooperated with the multinational telecommunications provider Telenor to study how RBA behaves on a large-scale online service with 3.3 million users and more than 30 million login attempts per year. The results of this study are published in the ACM Transactions on Privacy and Security journal.
To foster RBA development and research in the wild, we published the data set in synthesized form on GitHub and Kaggle. This data set, which is based on real-world data, can be used to improve and test RBA implementations.
You can get the paper and the data set on the official website.
June 30, 2022Article reporting on a study on the human-centered design of a GDPR-compliant data protection tool for data processors was accepted for publication in Behaviour & Information Technology
Our work entitled “Data Cart - Designing a tool for the GDPR-compliant handling of personal data by employees” by Jan Tolsdorf, Florian Dehling and Prof. Dr.-Ing. Luigi Lo Iacono has been accepted for publication in Behaviour & Information Technology under the special issue “Usable Security and Privacy with User-Centered Interventions and Transparency Mechanisms”.
The article addresses the issue of usable tools for the data protection compliant processing of personal data by employees acting under the authority of a data controller. We report on a user-centered design study in which we developed a concept and tool incorporating Privacy by Design. Working with 19 employees of two public organizations in Germany, we present a concept that supports employees in handling personal data and complying with data protection laws. Through a series of workshops and usability tests, we demonstrate the solution’s potential for improving the usability of data protection compliant tools for managing personal data. At the same time, we show how data controllers benefit from improved compliance.
April 1, 2022The DAS Group attends the USP Day 2022 with two presentations
The DAS Group is pleased to attend this year’s USP Day with two presentations:
“Data Cart - Designing a tool for the GDPR-compliant handling of personal data by employees.” - Jan Tolsdorf
“Usable Security and Privacy of Risk-based Authentication” - Stephan Wiefling
Details about the event
USP Day 2022
February 11, 2022
Start 9 a.m.
Click here to register for the event - participation is free of charge!
February 7, 2022OpenStack RBA Plugin Coming Soon
Risk-Based Authentication can strengthen password security while maintaining usability. However, there is a current lack of available Open Source RBA solutions which provide good security and usability. Our OpenStack plugin aims to close this gap. This also allows websites with small budget to protect their users with RBA.
We will release the plugin to the public soon. Until then, you can find first information about the plugin at the official GitHub project.
February 3, 2022