{"id":"5866f254-0ba8-4dd5-97c6-f3d2d15f1f90","arxiv_id":"2501.16885","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Activists with powerful adversaries treat location data as a physical safety issue and respond with spatial control, device separation, and provider choices driven by threat models.","lead":"Eight activists and politically active people from several countries were interviewed about how location data and smart environments affect their security and privacy. The interviews show they manage device placement, separate phones for actions, choose providers by geopolitical threat models, and often feel insecure because digital-safety knowledge is hard to come by.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Population-level phrasing outruns the data: 'many activists lack knowledge' and 'widespread' paranoia cannot be established from eight network-recruited, security-conscious interviewees; the central themes remain sample-grounded.","rationale":"Good-faith reading: this is a careful, safety-conscious exploratory study with a transparent interview guide, a detailed codebook, and appropriately hedged methodology. The empirical core--that some activists treat location data as a physical-safety issue and respond by controlling surroundings, separating devices, and choosing providers on geopolitical grounds--is grounded in direct quotes and concrete practices. The reader's weakest-assumption diagnosis is correct: the sample is small, network-recruited, and not saturated. I agree and sharpen the point by showing that the problem is not only statistical representativeness but internal scope: the abstract's 'many activists' and 'widespread' wording, and the conclusion's 'at-risk users' phrasing, exceed what an eight-interview purposive sample can support. The sample's high security sophistication actually cuts against the knowledge-deficit claim. This is a presentational and inferential-scope issue rather than a fabrication or internal contradiction, so it does not warrant rejection; it does warrant the conditional disposition the reader already chose, with the concrete revision that population-level claims be reworded as sample-limited claims.","tokens_in":15368,"tokens_out":8450,"duration_ms":85242,"concrete_test":"Perform a claim-traceability audit on the final manuscript: list every abstract and conclusion generalization and map each to specific interviewee IDs and Appendix B codes (Paranoia, Physical_safety, Space_risky, TM_anticipatory_data_practice). For 'many activists have not enough digital-safety knowledge,' Appendix B has only IT_security_resources and IT_security_training, not a code for knowledge deficits, so the claim must be traceable to explicit coded statements by at least three distinct interviewees or it should be removed or rescoped. For Section 5's 'at-risk users,' check whether the authors present any evidence from non-activist at-risk populations; since none is described, the phrase should become 'the activists we interviewed.' If the audit confirms these two phrase-level failures but the underlying quotes remain, the verdict stays conditional with a required revision.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing premise is that eight interviews, recruited through the researchers' own networks and explicitly not saturated, can support the paper's population-level framing. The abstract claims 'many activists have not enough digital-safety knowledge for effective protection' and 'feelings of insecurity and paranoia are widespread,' and Section 5 generalizes to 'at-risk users' as a whole. These are prevalence and scope claims that an exploratory grounded-theory design cannot carry. The sample skews toward security-savvy activists: all use end-to-end encrypted messengers, almost all use VPNs, many use Tor. Such a sample cannot ground a claim that activists broadly lack knowledge; at most it shows that even comparatively sophisticated activists feel insecure. The conclusion's 'at-risk users' phrasing also silently expands from the studied population (activists and politically active individuals) to refugees, sex workers, IPV survivors, and other at-risk groups for whom no evidence is presented. The location-specific observations themselves are supported by quotes and detailed practices, so the flaw is not the descriptions but the scope of the central claim.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an exploratory qualitative interview study with eight activists and politically active individuals located in five countries, examining how location-dependent security and privacy perceptions shape everyday technology practices. Using semi-structured interviews, iterative coding, an appendix codebook, and an interpretation workshop, it identifies three response patterns: attempts to control one's immediate technological surroundings, more careful management of device-related location data, and, for some interviewees, geopolitical considerations in provider and device choices. The paper also proposes an analytical schema distinguishing data-rich and data-poor environments and private versus public spaces, and it calls for more research on location-aware digital safety for at-risk users. The study is transparent about its safety protocols and explicitly acknowledges that data saturation has not been reached.","tokens_in":15547,"tokens_out":4101,"duration_ms":40891,"significance":"The study makes a useful spatial contribution to at-risk user research by foregrounding geolocation and location-dependent risk assessments, an angle that is often only implicit in prior work. Its strengths include a published interview guide and codebook, careful attention to researcher and participant safety, and concrete interview excerpts that illustrate anticipatory data practices, device separation, and provider-related threat modeling. If the findings are treated as hypothesis-generating rather than population-descriptive, they can productively extend Warford et al.'s at-risk user framework and Kazansky's anticipatory data practices to the domain of location data. The main limitation is that the evidence base does not support the prevalence and scope claims made in the abstract and conclusion.","major_comments":[{"comment":"The abstract claims that \"many activists have not enough digital-safety knowledge for effective protection\" and that \"feelings of insecurity and paranoia are widespread,\" and §5 generalizes to \"the response of at-risk users.\" These are prevalence and scope claims, but the paper explicitly states in §4.3 that data saturation is not reached, and §3.1 describes the eight interviewees as comparatively sophisticated: all use end-to-end encrypted messengers, almost all use VPNs, and many use Tor. A non-saturated, network-recruited sample of security-conscious activists cannot establish what \"many activists\" lack or what is \"widespread\"; it can establish that these participants report such feelings and practices. The authors should rephrase these claims to refer to the interviewees or state them as hypotheses for future, larger samples.","section":"Abstract; §4.3; §5"},{"comment":"The conclusion moves from the studied population of activists and politically active individuals to \"at-risk users\" as a whole, a category that, as the paper notes in §1.2, also includes refugees, sex workers, and survivors of intimate partner violence. No evidence is presented for these latter groups in this study, so \"the response of at-risk users\" overstates what the interview data can support. The conclusion should say \"the response of the activists we interviewed\" or explicitly frame broader applicability as a conjecture for future research rather than a finding.","section":"§5 Conclusion"},{"comment":"The treatment of \"paranoia\" as a major theme deserves more analytic care. The paper notes in §4.1 that all interviewees mention the term and recounts an \"intense paranoid phase,\" but it also reports realistic threat contexts, including one interviewee who received anonymous warnings (§3.2) and interviewees who describe genuine adversary capabilities. Without further discussion, the label \"paranoia\" risks pathologizing threat assessments that may be rational. The authors should either use a more neutral term such as \"hypervigilance\" or \"anticipatory anxiety,\" or clarify that they are reporting the participants' own word and not endorsing it as a clinical or psychological diagnosis.","section":"§3.1 and §4.1"}],"minor_comments":[{"comment":"The title shows apparent typesetting artifacts (\"Q_ualitative\" and \"aman g\") that should be corrected before publication.","section":"Title"},{"comment":"The data-rich versus data-poor schema is introduced as \"we can analytically distinguish,\" but the paper does not show which codes or repeated interviewee statements motivated this distinction; linking the schema to specific codebook entries or excerpts would strengthen its grounded-theory credentials.","section":"§4.2"},{"comment":"The authors withhold recruitment details for safety reasons, which is understandable, but they could state in non-identifying terms how many potential interviewees were approached or declined, and what inclusion criteria were used beyond \"possessing some knowledge or access.\" This would help readers assess volunteer bias without compromising safety.","section":"§2.3"},{"comment":"The observation that all interviewees are security conscious is presented as a general feature of the sample, but the paper does not discuss how this may interact with the claim that activists lack digital-safety knowledge; a sentence acknowledging that the sample is likely more sophisticated than the broader activist population would make the scope limitation explicit.","section":"§3.1"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"First: this is a solid, carefully reported exploratory qualitative study, not a breakthrough. What is genuinely new is the spatial lens: no one has looked at activists' security and privacy perceptions as location-dependent in the way this paper does. The method is transparent — interview guide and codebook are in appendices, coding was iterative and shared, an interpretation workshop was held — and the authors are appropriately careful about research safety. The quotes support the central themes: activists control their immediate technological surroundings, separate devices, and make provider choices based on geopolitical threat models. That is a useful contribution to at-risk user research.\n\nThe main soft spot is the gap between the data and some of the claims. Eight interviews, recruited through the authors' networks, deliberately not saturated, cannot support \"many activists have not enough digital-safety knowledge\" or \"feelings of insecurity and paranoia are widespread\" in the abstract. The sample is also security-savvy — everyone uses E2E encrypted messengers, almost all use VPNs, many use Tor — so if anything it shows that even sophisticated activists feel insecure, not that knowledge is lacking. The conclusion silently expands \"activists\" to \"at-risk users\" broadly (refugees, sex workers, IPV survivors), which the evidence doesn't cover. None of this breaks the core finding; it is a scope claim problem, and the paper itself admits saturation is not reached. A revision should soften the language and keep claims at the sample level.\n\nThe citation pattern looks fine. The argument doesn't rest on a hidden assumption or a fitted model; it's an empirical interview study. The risk of circularity is minimal. The small sample is normal for at-risk user research given safety constraints, and the withheld recruitment details are justified.\n\nThis paper is for readers in HCI, usable security, and privacy who work with at-risk groups. It deserves a serious referee; it would benefit from revisions that align the abstract and conclusion with the actual scope. I'd send it to review.","headline":"A transparent, well-conducted exploratory interview study with a genuinely novel spatial lens; the abstract overclaims prevalence, but the core findings stand and the paper deserves peer review.","tokens_in":16048,"tokens_out":2198,"would_cite":false,"duration_ms":20491,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that activists with powerful adversaries experience location data as a direct physical-safety issue and respond by controlling their immediate technological surroundings, managing device-related location data, and making…","keywords":["at-risk users","location data","activists","digital security","privacy","ubiquitous computing","threat modeling","qualitative interviews"],"falsifier":"A subsequent study with a broader, more representative sample that found most at-risk activists do not connect location data to physical safety, do not separate or delete location-bearing devices, and do not factor geopolitical provider choice into their threat models would show the pattern does not generalize beyond the eight interviewees.","tokens_in":15178,"feed_emoji":"📍","tokens_out":4327,"duration_ms":38777,"temperature":0.7,"pith_summary":"This paper asks how activists and politically active people who face powerful adversaries think about the location data that smart devices and online services generate about them, and what they do to protect themselves. Drawing on eight exploratory interviews across five countries, it argues that these users experience location data not as an abstract privacy problem but as a direct physical-safety issue: one activist states that 'my whereabouts, my location' is 'directly linked to my physical security.' The paper reports three recurring responses: controlling immediate technological surroundings, managing device-related location data through separation and deletion, and letting geopolitical threat models shape provider and device choices. It also finds that feelings of insecurity and paranoia are widespread because many activists lack enough digital-safety knowledge, and it closes with a call for more research on protecting activists from ever more granular location tracking.","feed_headline":"For activists, location data is a physical safety issue","feed_subtitle":"Eight interviews show device separation, route detours, and geopolitical provider choices as defenses.","key_machinery":"The central objects are location-dependent security and privacy perceptions, analyzed through a spatial schema the paper introduces: environments can be data-rich (sensors and devices continuously generating transmittable information) or data-poor (minimal data production, sometimes a self-made or imposed 'digital desert'), and spaces can be private or public, which determines how much control a user has over risk mitigation. The schema does the argument's work by showing that at-risk users' threat models are modified by the assumed technological surroundings, and that safety strategies such as banning devices from meetings or avoiding CCTV are only possible when the user controls the space. Also load-bearing is the concept of 'anticipatory data practices' from prior research, which the interviews extend by showing that activists manage not only future risks but also current location data that reveals their whereabouts in the present.","core_discovery":"The paper's central claim is that the rise of smart, continuously sensing environments has turned geolocation into a first-order safety problem for at-risk activists. The interviews show activists responding with spatial and device practices: they know where devices are, create non-electronic safe spaces, scan homes for bugs, leave phones behind during civil disobedience, take detours to avoid recognizable movement patterns, and separate 'action' phones from private ones, sometimes with non-personalized SIM cards. The paper further claims that threat modeling extends to provider choices based on geopolitics, such as preferring US-based companies over Chinese ones or distrusting services like Telegram because of the interests that shape them. These responses are framed through a two-axis analytical schema: data-rich versus data-poor environments, and private versus public spaces.","pith_inferences":["If the pattern holds, 'spatial control' could become a design requirement for mainstream privacy: all users, not only activists, may want device-free zones and predictable data-poor environments.","The same location-safety logic likely extends to other at-risk populations, such as journalists, refugees, sex workers, and survivors of intimate partner violence, since the mechanism of adversary access to whereabouts enabling physical harm is not activist-specific.","The data-rich/data-poor and private/public axes could be operationalized as a checklist for privacy-by-design evaluations of ubiquitous computing systems, testable through walkthroughs or user studies in each cell.","A testable extension would be to measure whether the reported practices, such as device separation and route deviation, actually reduce adversary success or simply restore a sense of control, since the interviews cannot distinguish the two."],"forward_implications":["Location data should be treated as safety-critical information for at-risk users, meaning privacy tools and device settings need to expose and control geolocation at a granular level.","Designers of smart homes, smart cities, and smart mobility should offer data-poor modes and physical off-switches, because activists create digital deserts to reduce attack surfaces.","Digital-safety training for activists should address location-tailored threats, including pattern-of-life analysis, CCTV, and border crossings.","Threat-modeling guidance should include geopolitical provider choice, since activists assess companies like Google, Apple, Huawei, and Telegram through the lens of who their adversary is.","Research ethics for at-risk-user studies must account for location data itself, as the paper's own decision not to interview one participant when two phones in the same room could retroactively identify them shows."],"supporting_citations":[{"why":"Supplies the definition of at-risk users that frames the paper's scope and identifies the research gap.","marker":"[61]"},{"why":"Provides the concept of anticipatory data practices that the paper extends to location data in the present.","marker":"[24]"},{"why":"Establishes the safety-conscious research methods the paper follows with at-risk participants.","marker":"[6]"},{"why":"Documents location-privacy mechanisms in location-based services that underpin the technical risk landscape.","marker":"[23]"},{"why":"Offers the human-centered threat-modeling framework used to interpret provider and device choices.","marker":"[59]"},{"why":"Demonstrates the capabilities of state-grade spyware such as Pegasus, grounding activists' geopolitical threat perceptions.","marker":"[32]"}],"fun_headline_variants":["Activists see location data as a physical threat","Location data puts activists at risk: their defense tactics","For activists, GPS traces are a safety hazard","How activists fight location tracking risks","Geolocation: a new frontline for activist security"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that eight interviewees, recruited through the researchers' own networks and willing to talk, are enough to reveal patterns shared across activist populations.","fun_headline_variants_meta":{"raw":{"variants":["Activists see location data as a physical threat","Location data puts activists at risk: their defense tactics","For activists, GPS traces are a safety hazard","How activists fight location tracking risks","Geolocation: a new frontline for activist security"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000228,"raw_usage":{"total_tokens":1467,"prompt_tokens":932,"completion_tokens":535,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":548,"completion_tokens_details":{"reasoning_tokens":465}},"tokens_in":548,"tokens_out":535,"duration_ms":5267,"temperature":1.0,"reasoning_tokens":465,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T05:51:40.783365+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A subsequent study with a broader, more representative sample that found most at-risk activists do not connect location data to physical safety, do not separate or delete location-bearing devices, and do not factor geopolitical provider choice into their threat models would show the pattern does not generalize beyond the eight interviewees.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the definition of at-risk users that frames the paper's scope and identifies the research gap."},{"cited_title":"It depends on your threat model","cited_arxiv_id":null,"evidence_quote":"Provides the concept of anticipatory data practices that the paper extends to location data in the present."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Establishes the safety-conscious research methods the paper follows with at-risk participants."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Documents location-privacy mechanisms in location-based services that underpin the technical risk landscape."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Offers the human-centered threat-modeling framework used to interpret provider and device choices."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates the capabilities of state-grade spyware such as Pegasus, grounding activists' geopolitical threat perceptions."}],"review_version":1}