Pith. sign in

REVIEW 3 major objections 5 minor 1 cited by

I Blame Apple in Part for My False Expectations: An Autoethnographic Study of Apple's Lockdown Mode in iOS

T0 review · 3 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read A three-month self-experiment with Apple's Lockdown Mode finds that the feature's undisclosed threat model and feature list leave at-risk users unable to judge its protection, which can breed a false sense of security.

desk verdict A careful first autoethnography of Lockdown Mode with genuinely new observations, but the abstract's 'lulled into a false sense of security' harm claim is contradicted by the author's own experience of unease and under-confidence. read the letter →

arxiv 2411.13249 v1 pith:HZQYWYEM submitted 2024-11-20 cs.CR cs.HC

classification cs.CRcs.HC
keywords LockdownModeiOSsecurityautoethnographyat-riskusersuserexperiencecommunicationthreatmodelinformeddecision
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper is the first academic study of Apple's Lockdown Mode, a hardening setting introduced in iOS 16 to protect users at risk of sophisticated digital attacks. Based on a three-month autoethnographic field study by a technically skilled user who kept a structured journal, it argues that Apple never explains the underlying threat model or the exact features Lockdown Mode blocks. That information gap, the authors contend, makes it hard for users to assess the feature and decide whether to use it, and can leave at-risk users with a false sense of security. The study documents undocumented restrictions (such as blocked destination and contact sharing), both notification overload and invisibility of protection, and users misattributing unrelated problems to Lockdown Mode.

What carries the argument

The argument is carried by an autoethnographic field study in which the first author used an iPhone in Lockdown Mode as their primary device for three months while recording structured journal entries (415 entries total, 203 during Lockdown Mode) and discussing observations weekly with co-authors. This method generates first-person evidence of the gap between Apple's advertised feature list and actual system behavior, and it grounds two central concepts: the 'information void' (Apple's failure to specify the threat model) and the 'visibility of protection' (the tension between too many notifications and too little sense of active protection). The journaling plus thematic clustering of audio reflections supplies the evidence for the paper's conclusion that users cannot properly assess Lockdown Mode.

What would settle it

A concrete test: recruit a sample of actual at-risk users (for example journalists or activists), give them Apple's current Lockdown Mode support page, and ask them to list which features are blocked and which threats Lockdown Mode does not cover; if the majority can answer accurately and articulate a reasoned use-or-not decision, the paper's claim that the information void prevents informed assessment would be falsified.

Watch

Extended reading notes

Core claim

The paper's central claim is that Apple's failure to provide precise information about Lockdown Mode's intended user group, its threat model, and its affected features prevents users from properly assessing the feature and making an informed decision about using it. In the authors' words, this approach is 'harmful, because without detailed knowledge about technical capabilities and boundaries, at-risk users may be lulled into a false sense of security.' The claim is grounded in the first author's three-month autoethnographic experience, which revealed restrictions not documented by Apple, inconsistencies across devices, an excess of notifications, and a general invisibility of protection that made the user uneasy. The paper frames this as 'authoritarian' or 'paternalistic' security, borrowing from prior work on security communication, and argues that a more transparent information policy would empower at-risk users.

Load-bearing premise

The study's conclusions about at-risk users rest on the assumption that the experiences of one 23-year-old technically proficient computer-science graduate student who is not at risk can be extrapolated to the diverse population that Lockdown Mode is meant to protect.

Editorial extensions

If this is right

  • If Apple published a precise threat model and a complete, per-feature list of what Lockdown Mode blocks, at-risk users could judge whether the feature fits their situation and would not have to guess.
  • If undocumented restrictions remain, at-risk users such as journalists may be blocked from receiving important files or calls and may decide to switch Lockdown Mode off entirely, removing its protection.
  • If the notification overload persists, users may become desensitized to security warnings and dismiss them, weakening the safety signal that the warnings are meant to send.
  • If protection visibility is made more consistent (as the Safari 'Lockdown Enabled' indicator already does), users would feel protected without the constant interruption of notifications, improving trust in the feature.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Extension: The information void likely also slows independent security research, because Lockdown Mode behaves as a black box; if Apple published the threat model, external researchers could verify effectiveness and propose improvements more efficiently.
  • Extension: The same paternalistic communication pattern may extend to other Apple security features (for example, threat notifications and app tracking transparency), suggesting a broader design philosophy that trades informed consent for presumed safety; this could be tested by analyzing Apple's documentation across features.
  • Extension: The observed misattribution of unrelated problems to Lockdown Mode implies that a measurable cost of the information gap is distorted trust: a calibrated documentation would likely reduce false blame and improve user confidence, an effect that could be quantified in an A/B test with real users.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This paper reports a three-month autoethnographic study of Apple's Lockdown Mode. The first author used an iPhone XR in Lockdown Mode from August to October 2023, preceded by a journaling practice phase and a baseline iOS phase, producing 203 Lockdown-Mode journal entries, 84 screenshots, and 56 audio-recorded reflections. The manuscript documents undocumented feature restrictions (e.g., contact and destination sharing), notification overload, weak visibility of protection, and a mismatch between expected and experienced restrictions. It concludes that Apple's vague information policy makes informed decisions about Lockdown Mode difficult, deems the paternalistic approach harmful because at-risk users may be lulled into a false sense of security, and proposes improvements in information policy, user control, and notification design.

Significance. This is a timely and methodologically self-aware first exploration of a security feature whose everyday user experience is understudied. The autoethnographic corpus is a genuine strength: journal entries, screenshots, audio-recorded reflections, a metajournal, weekly team meetings, and a transparent clustering tree in Appendix A are described in unusual detail, and the method is appropriate for generating hypotheses about a high-risk security setting. However, the abstract and contribution list elevate two conclusions beyond what a single, non-at-risk subject can support: the claim that observations can be extrapolated to at-risk users, and the specific claim that opaque information lulls at-risk users into a false sense of security. With those claims reframed as hypotheses for future work, the paper would be a valuable contribution to the usable-security and digital-safety literature.

major comments (3)
  1. [Abstract and §1, contribution (3a)] The conclusion that Lockdown Mode is 'harmful' because at-risk users 'may be lulled into a false sense of security' requires a causal mechanism: missing technical detail produces overconfidence, and overconfidence leads to riskier behavior. The study's own observations in §4.5 point in the opposite direction: the first author recorded 'Could as well not be active' (Aug 05), expected more restrictions than existed, felt 'uneasy' about the invisibility of protection, and asked whether users would 'really feel more secure' (Aug 16). These are expressions of uncertainty and under-confidence about the level of protection, not documented complacency. The literature cited in §5.3 ([2], [22]) supports the general claim that poor information harms security, but it does not establish the specific direction or magnitude for Lockdown Mode. Because 'harmful' is a central contribution, it must either be removed, weakened to a hypothesis, or supported by additional evidence.
  2. [§1, contribution (2) and §5.5] The claim that observations 'can be extrapolated to achieve improvements for this user group' is too strong for the evidence presented. Section 5.5 concedes that the first author is not an at-risk user and has above-average technical expertise, and §2.1 itself warns against generalizing across heterogeneous at-risk populations. The study can inform design hypotheses and generate concrete issues to test with at-risk users, but the extrapolation claim as stated is not supported by the data. The abstract and contributions should carry the same caveat that appears in §5.5.
  3. [§5.3, 'Reducing Notification Load'] The characterization of Lockdown Mode's warnings as 'designed to scare and bully users into submission' goes beyond the study's evidence. The only direct observation is the Sep 25 journal entry, which notes that the insecure-Wi-Fi warning was not very intimidating because red was not used and the connect-anyway button was the default. That is a finding about ineffective warning design, not evidence of a scare-and-bully strategy; the citation to Sasse [58] is a general argument, not evidence about Apple's design intent. This normative claim in the recommendations should be toned down to fit the data.
minor comments (5)
  1. [§3.4 and Appendix B] Section 3.4 says that 'we achieved almost complete coverage' of affected functionality, but Appendix B, Table 2 lists six features that were not covered (2G, third-party app stores, Apple Cash, HomeKit, and two uncertain cases); the phrase should be softened to avoid an internal inconsistency.
  2. [Figure 2] The timeline in Figure 2 appears to have 'DecemberNovember' as a single label; the month labels should be separated.
  3. [§5.3] There is a typo in 'This is a conceptional weakness of Lockdown Mode'; it should be 'conceptual weakness'.
  4. [§3.3] The persona description states that the first author is male, and the rest of the paper uses 'they/their' pronouns; this is likely deliberate pseudonymization, but it should be stated explicitly to avoid confusing readers.
  5. [§2.2] The claim that this is the first academic study of Lockdown Mode would be more verifiable if the authors described their literature search protocol (databases, dates, and search terms), especially since the surrounding text cites several non-academic sources.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper is a qualitative autoethnographic study with no fitted parameters, no equations, and no derivation chain that reduces to its inputs.

full rationale

The paper makes no mathematical predictions and fits no parameters, so the main circularity patterns (self-definitional equations, fitted inputs called predictions, uniqueness theorems) do not apply. Its central claims are interpretive: the authors argue from documented first-person experiences (e.g., Section 4.2's 'Trust Me, Bro' and Section 4.5's 'Could As Well Not Be Active') to conclusions about Apple's information policy and possible effects on at-risk users. The observations and the conclusions are distinct: the journal entries report unease, under-confidence, and uncertainty about whether Lockdown Mode is active, while the abstract's 'lulled into a false sense of security' is a separately argued inference about a different user population, not a restatement of the data. The only self-citation is reference [23] (Dennis Eckhardt, 2023), used to support the practice of ethnographic field note-taking in Section 2.3; this is a methodological citation and is not load-bearing for the paper's central claims. The acknowledged limitations in Section 5.5 explicitly separate the single subject's experience from generalizable conclusions, which further shows the authors are not treating the autoethnographic account as equivalent to the target conclusion. Whether the 'false sense of security' inference is well supported is a question of evidence strength and correctness risk, not circularity. Therefore the appropriate finding is no significant circularity, score 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

No numerical free parameters are fitted. The central claims rest on the representativeness of a single autoethnographic subject, the completeness of Apple's public documentation as a baseline, and the methodological validity of autoethnography. These are stated or acknowledged in the paper, but the first is the weakest.

assumptions (3)
  • ad hoc to paper The first author's experiences can be extrapolated to at-risk users.
    The abstract and contribution (2) generalize from one non-at-risk subject to at-risk user groups; Section 5.5 concedes this is a limitation.
  • domain assumption Apple's public Lockdown Mode documentation is sufficiently complete that unlisted restrictions are genuinely undocumented.
    The claim about undocumented restrictions (e.g., destination sharing in Section 4.3) treats Apple's support pages and activation screens as the full disclosure baseline.
  • domain assumption Autoethnography is a valid method for producing scientific knowledge about user experience.
    The paper relies on autoethnography as its primary method and justifies it via prior HCI literature in Section 2.3.

how reviews work

0 comments
Cite this review

Pith. "Pith review of I Blame Apple in Part for My False Expectations: An Autoethnographic Study of Apple's Lockdown Mode in iOS." pith.science (2026). https://pith.science/paper/HZQYWYEM

@misc{pith2026241113249,
  author       = {Pith},
  title        = {Pith review of: I Blame Apple in Part for My False Expectations: An Autoethnographic Study of Apple's Lockdown Mode in iOS},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/HZQYWYEM}},
  note         = {Machine review of arXiv:2411.13249}
}
read the original abstract

Lockdown Mode was introduced in 2022 as a hardening setting for Apple's operating systems, designed to strengthen the protection against ``some of the most sophisticated digital threats''. However, Apple never explained these threats further. We present the first academic exploration of Lockdown Mode based on a 3-month autoethnographic study. We obtained a nuanced understanding of user experience and identified issues that can be extrapolated to larger user groups. The lack of information from Apple about the underlying threat model and details on affected features may hinder adequate assessment of Lockdown Mode, making informed decisions on its use challenging. Besides encountering undocumented restrictions, we also experienced both too much and too little visibility of protection during Lockdown Mode use. Finally, we deem the paternalistic security approach by Apple's Lockdown Mode harmful, because without detailed knowledge about technical capabilities and boundaries, at-risk users may be lulled into a false sense of security.

Figures

Figures reproduced from arXiv: 2411.13249 by the authors.

Figure 1
Figure 1. Screenshots of activating Lockdown Mode in iOS 16, [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Road map of the different study phases and the associated actions; months on the timeline correspond to the year [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. Example of journaling script in action. (4) What was the social situation? Who was involved? (5) Did you have any conflicts or problems? (6) Do you have any additional thoughts or explanations? For each entry, the date, and the number of the activity for the day were recorded. A set of abbreviations was created to speed up the answering of questions 2–4. Questions 4–6 could be left blank if not required. To create t… view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Screenshots of encountered functionality breaking [PITH_FULL_IMAGE:figures/full_fig_p008_4.png]
Figure 5
Figure 5. Figure 5: Screenshots of occurred notifications and warnings while using Lockdown Mode in chronological order. [PITH_FULL_IMAGE:figures/full_fig_p009_5.png]
Figure 6
Figure 6. Figure 6: Visualisation of the clustering process of audio recordings regarding journal entries. [PITH_FULL_IMAGE:figures/full_fig_p016_6.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. "My Whereabouts, my Location, it's Directly Linked to my Physical Security": An Exploratory Qualitative Study of Location-Dependent Security and Privacy Perceptions among Activist Tech Users

    cs.HC 2025-01 conditional novelty 5.0 of 10

    Activists with powerful adversaries treat location data as a physical safety issue and respond with spatial control, device separation, and provider choices driven by threat models.

Reference graph

Works this paper leans on

75 extracted references · 57 canonical work pages · cited by 1 Pith paper

  1. [2]

    Anne Adams and Martina Angela Sasse. 1999. Users are not the enemy. Com- munications of the ACM, 42, 12, 40–46

  2. [22]

    Steve Dodier-Lazaro, Ruba Abu-Salma, Ingolf Becker, and M Angela Sasse

  3. [58]

    Angela Sasse. 2015. Scaring and Bullying People into Security Won’t Work. IEEE Security & Privacy , 13, 3, 80–83. doi: 10.1109/MSP.2015.65

  4. [1]

    Line Kryger Aagaard, Toke Haunstrup Christensen, and Kirsten Gram-Hanssen

  5. [3]

    Adams, Carolyn Ellis, and Stacy Holman Jones

    Tony E. Adams, Carolyn Ellis, and Stacy Holman Jones. 2017. Autoethnography. The International Encyclopedia of Communication Research Methods , 1–11. doi: 10.1002/9781118901731.iecrm0011

  6. [4]

    Albrecht, Jorge Blasco, Rikke Bjerg Jensen, and Lenka Mareková

    Martin R. Albrecht, Jorge Blasco, Rikke Bjerg Jensen, and Lenka Mareková

  7. [5]

    Apple. 2024. About alternative app distribution in the European Union. (May 13, 2024). Retrieved Aug. 20, 2024 from https://web.archive.org/web/202408202309 46/https://support.apple.com/en-us/118110

  8. [6]

    Apple. 2023. About Lockdown Mode. (Aug. 16, 2023). https://web.archive.org /web/20230816053100/https://support.apple.com/en-us/HT212650

Show all 75 references
  1. [7]

    Apple. 2023. About Lockdown Mode. (Nov. 7, 2023). https://web.archive.org/w eb/20231107020829/https://support.apple.com/en-us/HT212650

  2. [8]

    Apple. 2024. Documentation: Entitlements. (2024). Retrieved June 6, 2024 from https://developer.apple.com/documentation/bundleresources/entitlements

  3. [9]

    Apple. 2023. Privacy: Features. (Dec. 11, 2023). https://web.archive.org/web/20 231211081936/https://www.apple.com/privacy/features/

  4. [10]

    Apple. 2024. Set up and use Apple Cash in Wallet on iPhone. (May 31, 2024). Retrieved June 6, 2024 from https://support.apple.com/en-ph/guide/iphone/ip h385cf0980/ios

  5. [11]

    Paulo Bala, Pedro Sanches, Vanessa Cesário, Sarah Leão, Catarina Rodrigues, Nuno Jardim Nunes, and Valentina Nisi. 2023. Towards Critical Heritage in the Wild: Analysing Discomfort through Collaborative Autoethnography. In CHI Conference on Human Factors in Computing Systems ....

  6. [12]

    Brown, Jeremy Shaffer, Rasika Bhalerao, and Thomas Ristenpart

    Rosanna Bellini, Kevin Lee, Megan A. Brown, Jeremy Shaffer, Rasika Bhalerao, and Thomas Ristenpart. 2023. The Digital-Safety Risks of Financial Technolo- gies for Survivors of Intimate Partner Violence. In 32nd USENIX Security Sym- posium (USENIX Security ’23) , 87–104

  7. [13]

    Mazurek, Dana Cuomo, Nicola Dell, and Thomas Ristenpart

    Rosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla, Tara Matthews, Sunny Consolvo, Jill Palzkill Woelfer, Patrick Gage Kelley, Michelle L. Mazurek, Dana Cuomo, Nicola Dell, and Thomas Ristenpart. 2023. SoK: Safer Digital- Safety Research Involving At-Risk Users. In IEEE...

  8. [14]

    Boyd, Jamar L

    Maia J. Boyd, Jamar L. Sullivan Jr., Marshini Chetty, and Blase Ur. 2021. Un- derstanding the Security and Privacy Advice Given to Black Lives Matter Protesters. In CHI Conference on Human Factors in Computing Systems . ACM, 549:1–549:18. doi: 10.1145/3411764.3445061

  9. [15]

    Waller, Matthew Seita, Christian Vogler, Raja S

    Si Chen, James M. Waller, Matthew Seita, Christian Vogler, Raja S. Kushal- nagar, and Qi Wang. 2024. Towards Co-Creating Access and Inclusion: A Group Autoethnography on a Hearing Individual’s Journey Towards Effective Communication in Mixed-Hearing Ability Higher Education Se...

  10. [16]

    Cryptee. 2023. iOS Lockdown Mode Detection Test Proof of Concept. (2023). Retrieved June 6, 2024 from https://crypt.ee/ios-lockdown-mode-test

  11. [17]

    Carter Dack. 2023. Pegasus: A Technical Look at Highly Advanced Mobile Spyware. (2023). Retrieved June 6, 2024 from https://www.carterdack.com/Peg asus/Pegasus.html

  12. [18]

    Alaa Daffalla, Lucy Simko, Tadayoshi Kohno, and Alexandru G. Bardas. 2021. Defensive Technology Use by Political Activists During the Sudanese Revolu- tion. In IEEE Symposium on Security and Privacy (SP) , 372–390

  13. [19]

    Piet De Koning, Lenneke Kuijer, and Joep Frens. 2023. A Sensory Autoethnog- raphy of Energy Practices in the Home: An Exploration of Combining Smart Meter Data with Situated accounts of What Energy is For. InExtended Abstracts of the CHI Conference on Human Factors in Computin...

  14. [20]

    Philip Di Salvo. 2021. We Have to act Like our Devices are Already Infected: Investigative Journalists and Internet Surveillance. Journalism Practice, 1849– 1866

  15. [21]

    Roenne, Peter YA Ryan, and Vincent Koenig

    Verena Distler, Marie-Laure Zollinger, Carine Lallemand, Peter B. Roenne, Peter YA Ryan, and Vincent Koenig. 2019. Security-visible, yet unseen? In CHI Conference on Human Factors in Computing Systems , 1–13

  16. [23]

    Dennis Eckhardt. 2023. Ethnografisches Feldnotieren in digitalen Feldern: Per- spektiven einer Wissens-und Arbeitspraxis. Kulturanthropologie Notizen, 85, 52–77

  17. [24]

    2004.The ethnographic I: A methodological novel about autoethnog- raphy

    Carolyn Ellis. 2004.The ethnographic I: A methodological novel about autoethnog- raphy. Vol. 13. Rowman Altamira

  18. [25]

    Adams, and Arthur P

    Carolyn Ellis, Tony E. Adams, and Arthur P. Bochner. 2011. Autoethnography: An Overview. Historical Social Research / Historische Sozialforschung, 36, 4 (138), 273–290

  19. [26]

    Matthias Fassl and Katharina Krombholz. 2023. Why I Can’t Authenticate - Understanding the Low Adoption of Authentication Ceremonies with Au- toethnography. In CHI Conference on Human Factors in Computing Systems . ACM, 72:1–72:15. doi: 10.1145/3544548.3581508

  20. [27]

    Gartner. 2023. Number of Smartphones Sold to End Users Worldwide from 2007 to 2023. (Jan. 2023). Retrieved June 6, 2024 from https://www.statista.com /statistics/263437/

  21. [28]

    William Gaver and Frances Gaver. 2023. Living with Light Touch: An Au- toethnography of a Simple Communication Device in Long-Term Use. In CHI Conference on Human Factors in Computing Systems . ACM, 633:1–633:14. doi: 10.1145/3544548.3580807

  22. [29]

    Luis Gomez-Miralles and Joan Arnedo-Moreno. 2015. Lockup: A Software Tool to Harden iOS by Disabling Default Lockdown Services. In 10th International Conference on P2P, Parallel, Grid, Cloud and Internet Computing (3PGCIC) . IEEE, 718–723. doi: 10.1109/3PGCIC.2015.57

  23. [30]

    Dan Goodin. 2022. Got Attack Surface? — Why Lockdown mode from Apple is one of the coolest security ideas ever. (July 7, 2022). Retrieved June 6, 2024 from https://arstechnica.com/information-technology/2022/07/introducing-l ockdown-from-apple-the-coolest-defense-youll-probabl...

  24. [31]

    Hacker News. 2022. About Lockdown Mode. (Sept. 14, 2022). Retrieved June 6, 2024 from https://news.ycombinator.com/item?id=32842749

  25. [32]

    Angela Sasse

    Franziska Herbert, Steffen Becker, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Dürmuth, Yixin Zou, and M. Angela Sasse. 2024. Digital Security — A Question of Perspective: A Large-Scale Tele- phone Survey with Four At-Risk User Groups. In IEEE S...

  26. [33]

    Christine Hine. 2020. Strategies for reflexive ethnography in the smart home: Autoethnography of silence and emotion. Sociology, 54, 1, 22–36

  27. [34]

    Sarah Homewood. 2023. Self-Tracking to Do Less: An Autoethnography of Long COVID That Informs the Design of Pacing Technologies. In CHI Conference on Human Factors in Computing Systems . ACM, 656:1–656:14. doi: 10.1145/354454 8.3581505

  28. [35]

    Jamf Threat Labs. 2023. Fake Lockdown Mode: A post-exploitation tampering technique. (Dec. 5, 2023). Retrieved June 6, 2024 from https://www.jamf.com/b log/fake-lockdown-mode/

  29. [36]

    Annika Kaltenhauser, Evropi Stefanidi, and Johannes Schöning. 2024. Playing with Perspectives and Unveiling the Autoethnographic Kaleidoscope in HCI - A Literature Review of Autoethnographies. In CHI Conference on Human Factors in Computing Systems. ACM, 819:1–819:20. doi: 10....

  30. [37]

    Makayla Lewis, Miriam Sturdee, Mafalda Gamboa, and Denise Lengyel. 2023. Doodle Away: An Autoethnographic Exploration of Doodling as a Strategy for Self-Control Strength in Online Spaces. In Extended Abstracts of the CHI Conference on Human Factors in Computing Systems . ACM, ...

  31. [38]

    Priscilla Y. Lo. 2024. An Autoethnographic Reflection of Prompting a Custom GPT Based on Oneself. In Extended Abstracts of the CHI Conference on Human Factors in Computing Systems . ACM, 40:1–40:9. doi: 10.1145/3613905.3651096. 14 I Blame Apple in Part for My False Expectation...

  32. [39]

    Bill Marczak. 2023. Triangulation: Did the NSA fail to learn the lessons of NSO? (June 3, 2023). Retrieved June 6, 2024 from https://medium.com/@billmarczak /triangulation-did-the-nsa-fail-to-learn-the-lessons-of-nso-5f36d251d02e

  33. [40]

    Bill Marczak, John Scott-Railton, Bahr Abdul Razzak, and Ron Deibert. 2023. Triple Threat: NSO Group’s Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains. (Apr. 18, 2023). Retrieved June 6, 2024 from https://citizenlab.ca/2023/04/nso-gro...

  34. [41]

    Mazurek, Florian Schaub, and Elissa M

    Allison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub, and Elissa M. Redmiles. 2021. It’s stressful having all these phones: Investigating Sex Workers’ Safety Goals, Risks, and Practices Online. In30th USENIX Security Symposium (USENIX Security ’21) , 375–392

  35. [42]

    McGregor, Polina Charters, Tobin Holliday, and Franziska Roesner

    Susan E. McGregor, Polina Charters, Tobin Holliday, and Franziska Roesner

  36. [43]

    McGregor, Elizabeth Anne Watkins, Mahdi Nasrullah Al-Ameen, Kelly Caine, and Franziska Roesner

    Susan E. McGregor, Elizabeth Anne Watkins, Mahdi Nasrullah Al-Ameen, Kelly Caine, and Franziska Roesner. 2017. When the Weakest Link is Strong: Secure Collaboration in the Case of the Panama Papers. In26th USENIX Security Symposium (USENIX Security ’17) , 505–522

  37. [44]

    Shishir Nagaraja and Ross Anderson. 2009. The snooping dragon: social- malware surveillance of the Tibetan movement. Tech. rep. University of Cam- bridge, Computer Laboratory

  38. [45]

    Lily Hay Newman. 2024. What It’s Like to Use Apple’s Lockdown Mode. (Jan. 2, 2024). Retrieved June 6, 2024 from https://www.wired.com/story/apple-lockdo wn-mode-hands-on/

  39. [46]

    Steve North. 2019. Imaginary Studies: A Science Fiction Autoethnography Con- cerning the Design, Implementation and Evaluation of a Fictional Quantitative Study to Evaluate the Umamimi Robotic Horse Ears. In Extended Abstracts of the CHI Conference on Human Factors in Computin...

  40. [47]

    Blandford

    Aisling Ann O’Kane, Yvonne Rogers, and Ann E. Blandford. 2014. Gaining Empathy for Non-Routine Mobile Device Use Through Autoethnography. In Conference on Human Factors in Computing Systems . ACM, 987–990. doi: 10.11 45/2556288.2557179

  41. [48]

    OpenAI. 2023. Whisper. (2023). Retrieved June 6, 2024 from https://github.com /openai/whisper

  42. [49]

    Andrea Peterson, Emily Yahr, and Joby Warrick. 2014. Leaks of nude celebrity photos raise concerns about security of the cloud, (Sept. 1, 2014). Retrieved June 6, 2024 from https://www.washingtonpost.com/59dcd37e-3219-11e4-8f02 -03c644b2d7d0_story.html

  43. [50]

    Petri IT Knowledgebase. 2022. Apple iOS 16 Lockdown Mode Boosts Security But It Comes at a Price. (July 13, 2022). Retrieved June 6, 2024 from https://ww w.youtube.com/watch?v=I0uwWZyPUsk

  44. [51]

    Privacy Guides. 2023. Apple’s Lockdown Mode is nothing special. (Dec. 20, 2023). Retrieved June 6, 2024 from https://discuss.privacyguides.net/t/15743/1

  45. [52]

    Alec Radford, Jong Wook Kim, Tao Xu, Greg Brockman, Christine McLeavey, and Ilya Sutskever. 2022. Robust Speech Recognition via Large-Scale Weak Supervision. en, (Sept. 2022). Retrieved Sept. 11, 2024 from https://cdn.openai.c om/papers/whisper.pdf

  46. [53]

    Reddit. 2022. Review of lockdown mode. (Sept. 21, 2022). Retrieved June 6, 2024 from https://www.reddit.com/r/ios/comments/xjushk/review_of_lockdown_m ode/

  47. [54]

    Thomas Reisinger, Isabel Wagner, and Eerke Albert Boiten. 2023. Unified Communication: What do Digital Activists need? In IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) , 141–149. doi: 10.1109/EUROS PW59978.2023.00021

  48. [55]

    Reuters. 2024. Apple drops term ’state-sponsored’ attacks from its threat noti- fication policy. (Apr. 11, 2024). Retrieved June 6, 2024 from https://www.reuter s.com/technology/cybersecurity/apple-warns-users-mercenary-spyware-att ack-91-countries-including-india-et-2024-04-11/

  49. [56]

    Rene Ritchie. 2022. Lockdown Mode comes to iOS 16! (July 6, 2022). https://w ww.youtube.com/watch?v=JycrqFbahkc

  50. [57]

    Patrawat Samermit, Anna Turner, Patrick Gage Kelley, Tara Matthews, Vanessia Wu, Sunny Consolvo, and Kurt Thomas. 2023. Millions of people are watching you: Understanding the Digital-Safety Needs and Practices of Creators. In32nd USENIX Security Symposium (USENIX Security ’23)...

  51. [59]

    John Scott-Railton. 2016. Security for the High-Risk User: Separate and Unequal. IEEE Security & Privacy , 14, 2, 79–87. doi: 10.1109/MSP.2016.22

  52. [60]

    Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner, and Tadayoshi Kohno. 2018. Computer Security and Privacy for Refugees in the United States. In IEEE Symposium on Security and Privacy (SP) , 409–423. doi: 10.1109/SP.2018 .00023

  53. [62]

    Julia Slupska and Leonie Maria Tanczer. 2021. Threat Modeling Intimate Partner Violence: Tech Abuse as a Cybersecurity Challenge in the Internet of Things. In The Emerald International Handbook of Technology-Facilitated Violence and Abuse. Emerald Publishing Ltd. doi: 10.1108/...

  54. [63]

    StatCounter. 2024. Percentage of Mobile Device Website Traffic Worldwide from 1st Quarter 2015 to 4th Quarter 2023. (Jan. 2024). Retrieved June 6, 2024 from https://www.statista.com/statistics/277125/

  55. [64]

    Statista. 2023. Global Mobile Device Market Share in 2017 and 2022 by Ship- ments of Device Type. (Feb. 2023). Retrieved June 6, 2024 from https://www.st atista.com/statistics/183530/

  56. [65]

    Deibert, Didier Bigo, MI Franklin, Lucas Mel- gaço, David Lyon, Becky Kazansky, and Stefania Milan

    Leonie Maria Tanczer, Ronald J. Deibert, Didier Bigo, MI Franklin, Lucas Mel- gaço, David Lyon, Becky Kazansky, and Stefania Milan. 2020. Online Surveil- lance, Censorship, and Encryption in Academia. International Studies Perspec- tives, 21, 1, 1–36. doi: 10.1093/isp/ekz016

  57. [66]

    Techlore. 2023. I Used Apple’s Lockdown Mode So You Don’t Have To. (Jan. 11, 2023). Retrieved June 6, 2024 from https://www.youtube.com/watch?v=ENu GWhz10UY

  58. [67]

    Lokman Tsui and Francis Lee. 2021. How journalists understand the threats and opportunities of new technologies: a study of security mind-sets and its implications for press freedom. Journalism, 22, 6, 1317–1339. doi: 10.1177/1464 884919849418

  59. [68]

    Sarah Turner, Jason RC Nurse, and Shujun Li. 2022. It was hard to find the words: Using an Autoethnographic Diary Study to Understand the Difficulties of Smart Home Cyber Security Practices. In Extended Abstracts of the CHI Conference on Human Factors in Computing Systems . AC...

  60. [69]

    Mekler, and Janne Lindqvist

    Jaakko Väkevä, Elisa D. Mekler, and Janne Lindqvist. 2024. From Disorienta- tion to Harmony: Autoethnographic Insights into Transformative Videogame Experiences. In CHI Conference on Human Factors in Computing Systems . ACM, 808:1–808:20. doi: 10.1145/3613904.3642543

  61. [70]

    Mazurek, Manya Sleeper, and Kurt Thomas

    Noel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul, Sunny Consolvo, Patrick Gage Kelley, Nathan Malkin, Michelle L. Mazurek, Manya Sleeper, and Kurt Thomas. 2022. SoK: A Framework for Unifying At-Risk User Research. In IEEE Symposium on Security and Privacy (SP) , 2344–2360...

  62. [71]

    Zack Whittaker. 2022. Hands-on with Lockdown Mode in iOS 16. (Aug. 12, 2022). Retrieved June 6, 2024 from https://techcrunch.com/2022/08/12/apple-lo ckdown-mode-ios-16/

  63. [72]

    Communication

    Shaomei Wu, Jingjin Li, and Gilly Leshed. 2024. Finding My Voice over Zoom: An Autoethnography of Videoconferencing Experience for a Person Who Stutters. In CHI Conference on Human Factors in Computing Systems . ACM, 916:1–916:16. doi: 10.1145/3613904.3642746. A CLUSTERING OF ...

  64. [2015]

    In 24th USENIX Security Symposium (USENIX Security ’15) , 399–414

    Investigating the Computer Security Practices and Needs of Journalists. In 24th USENIX Security Symposium (USENIX Security ’15) , 399–414

  65. [2017]

    In CHI 2017 Workshop on Values in Computing

    From paternalistic to user-centred security: putting users first with value- sensitive design. In CHI 2017 Workshop on Values in Computing . Values In Computing

  66. [2021]

    In30th USENIX Security Symposium (USENIX Security ’21), 3363– 3380

    Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong. In30th USENIX Security Symposium (USENIX Security ’21), 3363– 3380

  67. [2023]

    Personal and Ubiquitous Computing , 27, 6, 2121–2131

    My smart home: an auto-ethnography of learning to live with smart technologies. Personal and Ubiquitous Computing , 27, 6, 2121–2131. doi: 10.100 7/S00779-023-01725-0

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.