Pith. sign in

REVIEW 3 major objections 4 minor 67 references

"My Whereabouts, my Location, it's Directly Linked to my Physical Security": An Exploratory Qualitative Study of Location-Dependent Security and Privacy Perceptions among Activist Tech Users

T0 review · 3 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read This paper claims that activists with powerful adversaries experience location data as a direct physical-safety issue and respond by controlling their immediate technological surroundings, managing device-related location data, and making…

desk verdict A transparent, well-conducted exploratory interview study with a genuinely novel spatial lens; the abstract overclaims prevalence, but the core findings stand and the paper deserves peer review. read the letter →

arxiv 2501.16885 v1 pith:LIM4BAIN submitted 2025-01-28 cs.HC cs.CY

classification cs.HCcs.CY
keywords at-riskuserslocationdataactivistsdigitalsecurityprivacyubiquitouscomputingthreatmodelingqualitativeinterviews
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper asks how activists and politically active people who face powerful adversaries think about the location data that smart devices and online services generate about them, and what they do to protect themselves. Drawing on eight exploratory interviews across five countries, it argues that these users experience location data not as an abstract privacy problem but as a direct physical-safety issue: one activist states that 'my whereabouts, my location' is 'directly linked to my physical security.' The paper reports three recurring responses: controlling immediate technological surroundings, managing device-related location data through separation and deletion, and letting geopolitical threat models shape provider and device choices. It also finds that feelings of insecurity and paranoia are widespread because many activists lack enough digital-safety knowledge, and it closes with a call for more research on protecting activists from ever more granular location tracking.

What carries the argument

The central objects are location-dependent security and privacy perceptions, analyzed through a spatial schema the paper introduces: environments can be data-rich (sensors and devices continuously generating transmittable information) or data-poor (minimal data production, sometimes a self-made or imposed 'digital desert'), and spaces can be private or public, which determines how much control a user has over risk mitigation. The schema does the argument's work by showing that at-risk users' threat models are modified by the assumed technological surroundings, and that safety strategies such as banning devices from meetings or avoiding CCTV are only possible when the user controls the space. Also load-bearing is the concept of 'anticipatory data practices' from prior research, which the interviews extend by showing that activists manage not only future risks but also current location data that reveals their whereabouts in the present.

What would settle it

A subsequent study with a broader, more representative sample that found most at-risk activists do not connect location data to physical safety, do not separate or delete location-bearing devices, and do not factor geopolitical provider choice into their threat models would show the pattern does not generalize beyond the eight interviewees.

Watch

Extended reading notes

Core claim

The paper's central claim is that the rise of smart, continuously sensing environments has turned geolocation into a first-order safety problem for at-risk activists. The interviews show activists responding with spatial and device practices: they know where devices are, create non-electronic safe spaces, scan homes for bugs, leave phones behind during civil disobedience, take detours to avoid recognizable movement patterns, and separate 'action' phones from private ones, sometimes with non-personalized SIM cards. The paper further claims that threat modeling extends to provider choices based on geopolitics, such as preferring US-based companies over Chinese ones or distrusting services like Telegram because of the interests that shape them. These responses are framed through a two-axis analytical schema: data-rich versus data-poor environments, and private versus public spaces.

Load-bearing premise

The load-bearing premise is that eight interviewees, recruited through the researchers' own networks and willing to talk, are enough to reveal patterns shared across activist populations.

Editorial extensions

If this is right

  • Location data should be treated as safety-critical information for at-risk users, meaning privacy tools and device settings need to expose and control geolocation at a granular level.
  • Designers of smart homes, smart cities, and smart mobility should offer data-poor modes and physical off-switches, because activists create digital deserts to reduce attack surfaces.
  • Digital-safety training for activists should address location-tailored threats, including pattern-of-life analysis, CCTV, and border crossings.
  • Threat-modeling guidance should include geopolitical provider choice, since activists assess companies like Google, Apple, Huawei, and Telegram through the lens of who their adversary is.
  • Research ethics for at-risk-user studies must account for location data itself, as the paper's own decision not to interview one participant when two phones in the same room could retroactively identify them shows.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the pattern holds, 'spatial control' could become a design requirement for mainstream privacy: all users, not only activists, may want device-free zones and predictable data-poor environments.
  • The same location-safety logic likely extends to other at-risk populations, such as journalists, refugees, sex workers, and survivors of intimate partner violence, since the mechanism of adversary access to whereabouts enabling physical harm is not activist-specific.
  • The data-rich/data-poor and private/public axes could be operationalized as a checklist for privacy-by-design evaluations of ubiquitous computing systems, testable through walkthroughs or user studies in each cell.
  • A testable extension would be to measure whether the reported practices, such as device separation and route deviation, actually reduce adversary success or simply restore a sense of control, since the interviews cannot distinguish the two.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper reports an exploratory qualitative interview study with eight activists and politically active individuals located in five countries, examining how location-dependent security and privacy perceptions shape everyday technology practices. Using semi-structured interviews, iterative coding, an appendix codebook, and an interpretation workshop, it identifies three response patterns: attempts to control one's immediate technological surroundings, more careful management of device-related location data, and, for some interviewees, geopolitical considerations in provider and device choices. The paper also proposes an analytical schema distinguishing data-rich and data-poor environments and private versus public spaces, and it calls for more research on location-aware digital safety for at-risk users. The study is transparent about its safety protocols and explicitly acknowledges that data saturation has not been reached.

Significance. The study makes a useful spatial contribution to at-risk user research by foregrounding geolocation and location-dependent risk assessments, an angle that is often only implicit in prior work. Its strengths include a published interview guide and codebook, careful attention to researcher and participant safety, and concrete interview excerpts that illustrate anticipatory data practices, device separation, and provider-related threat modeling. If the findings are treated as hypothesis-generating rather than population-descriptive, they can productively extend Warford et al.'s at-risk user framework and Kazansky's anticipatory data practices to the domain of location data. The main limitation is that the evidence base does not support the prevalence and scope claims made in the abstract and conclusion.

major comments (3)
  1. [Abstract; §4.3; §5] The abstract claims that "many activists have not enough digital-safety knowledge for effective protection" and that "feelings of insecurity and paranoia are widespread," and §5 generalizes to "the response of at-risk users." These are prevalence and scope claims, but the paper explicitly states in §4.3 that data saturation is not reached, and §3.1 describes the eight interviewees as comparatively sophisticated: all use end-to-end encrypted messengers, almost all use VPNs, and many use Tor. A non-saturated, network-recruited sample of security-conscious activists cannot establish what "many activists" lack or what is "widespread"; it can establish that these participants report such feelings and practices. The authors should rephrase these claims to refer to the interviewees or state them as hypotheses for future, larger samples.
  2. [§5 Conclusion] The conclusion moves from the studied population of activists and politically active individuals to "at-risk users" as a whole, a category that, as the paper notes in §1.2, also includes refugees, sex workers, and survivors of intimate partner violence. No evidence is presented for these latter groups in this study, so "the response of at-risk users" overstates what the interview data can support. The conclusion should say "the response of the activists we interviewed" or explicitly frame broader applicability as a conjecture for future research rather than a finding.
  3. [§3.1 and §4.1] The treatment of "paranoia" as a major theme deserves more analytic care. The paper notes in §4.1 that all interviewees mention the term and recounts an "intense paranoid phase," but it also reports realistic threat contexts, including one interviewee who received anonymous warnings (§3.2) and interviewees who describe genuine adversary capabilities. Without further discussion, the label "paranoia" risks pathologizing threat assessments that may be rational. The authors should either use a more neutral term such as "hypervigilance" or "anticipatory anxiety," or clarify that they are reporting the participants' own word and not endorsing it as a clinical or psychological diagnosis.
minor comments (4)
  1. [Title] The title shows apparent typesetting artifacts ("Q_ualitative" and "aman g") that should be corrected before publication.
  2. [§4.2] The data-rich versus data-poor schema is introduced as "we can analytically distinguish," but the paper does not show which codes or repeated interviewee statements motivated this distinction; linking the schema to specific codebook entries or excerpts would strengthen its grounded-theory credentials.
  3. [§2.3] The authors withhold recruitment details for safety reasons, which is understandable, but they could state in non-identifying terms how many potential interviewees were approached or declined, and what inclusion criteria were used beyond "possessing some knowledge or access." This would help readers assess volunteer bias without compromising safety.
  4. [§3.1] The observation that all interviewees are security conscious is presented as a general feature of the sample, but the paper does not discuss how this may interact with the claim that activists lack digital-safety knowledge; a sentence acknowledging that the sample is likely more sophisticated than the broader activist population would make the scope limitation explicit.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: interview-derived themes are grounded in quotes and coding, with no fitted parameter, equation, or load-bearing self-citation.

full rationale

This is an exploratory qualitative interview study. The central claims that activists with powerful adversaries treat location data as a physical-safety issue and respond by controlling surroundings, managing device location data, and making geopolitical provider choices are derived from semi-structured interviews via iterative coding (Sections 2.2, 2.3, 3.1-3.4), supported by direct participant quotes (e.g., 'my whereabouts, my location, because it is directly linked to my physical security'). No equation, fitted parameter, or imposed ansatz is present, so none of the identified circularity patterns applies. Definitions imported from Bellini et al. and Warford et al. are external conceptual scaffolding, not conclusions. The only self-citations ([16], [30]) are background context and do not carry the analytic weight of the findings. The manuscript explicitly flags its limitations: 'data saturation is not reached' and 'there is no guarantee that interviewees feel comfortable enough to share all' - these are external-validity caveats, not circular reasoning. The abstract's generalizing phrases ('many activists have not enough digital-safety knowledge'; 'widespread' insecurity) outrun the eight-interview purposive sample, but that is a scope/representativeness risk, not circularity, because the qualitative themes are not defined in terms of the conclusions they support.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

This is a qualitative exploratory study with no quantitative fitting and no invented technical entities. The central claim rests on standard domain assumptions about at-risk users and on the validity of qualitative interview self-reports. The data-rich/data-poor and private/public schema is an analytical framing rather than an invented entity.

assumptions (3)
  • domain assumption At-risk users face heightened digital attack and harm risk, as defined by Warford et al.
    Used in Section 1.1 to justify the urgency and framing of the study; it is background knowledge from the cited SoK rather than something tested by this paper.
  • domain assumption Semi-structured interviews with eight participants can surface transferable patterns about security and privacy perceptions.
    Grounded theory approach in Section 2.2 assumes qualitative depth can compensate for sample size; the paper itself notes data saturation is not reached, making this assumption partially fragile.
  • domain assumption Interviewees' self-reports accurately describe their security practices and perceptions.
    The analysis in Section 3 relies entirely on participants' accounts during interviews; there is no independent verification through device logs, observation, or other means.

how reviews work

0 comments
Cite this review

Pith. "Pith review of "My Whereabouts, my Location, it's Directly Linked to my Physical Security": An Exploratory Qualitative Study of Location-Dependent Security and Privacy Perceptions among Activist Tech Users." pith.science (2026). https://pith.science/paper/LIM4BAIN

@misc{pith2026250116885,
  author       = {Pith},
  title        = {Pith review of: "My Whereabouts, my Location, it's Directly Linked to my Physical Security": An Exploratory Qualitative Study of Location-Dependent Security and Privacy Perceptions among Activist Tech Users},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/LIM4BAIN}},
  note         = {Machine review of arXiv:2501.16885}
}
read the original abstract

Digital-safety research with at-risk users is particularly urgent. At-risk users are more likely to be digitally attacked or targeted by surveillance and could be disproportionately harmed by attacks that facilitate physical assaults. One group of such at-risk users are activists and politically active individuals. For them, as for other at-risk users, the rise of smart environments harbors new risks. Since digitization and datafication are no longer limited to a series of personal devices that can be switched on and off, but increasingly and continuously surround users, granular geolocation poses new safety challenges. Drawing on eight exploratory qualitative interviews of an ongoing research project, this contribution highlights what activists with powerful adversaries think about evermore data traces, including location data, and how they intend to deal with emerging risks. Responses of activists include attempts to control one's immediate technological surroundings and to more carefully manage device-related location data. For some activists, threat modeling has also shaped provider choices based on geopolitical considerations. Since many activists have not enough digital-safety knowledge for effective protection, feelings of insecurity and paranoia are widespread. Channeling the concerns and fears of our interlocutors, we call for more research on how activists can protect themselves against evermore fine-grained location data tracking.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

67 extracted references · 67 canonical work pages

  1. [1]

    Azadeh Akbari. 2020. Follow the thing: data: Contestati ons over data from the global south. Antipode, 52, 2, 408–429

  2. [2]

    Martin R Albrecht, Jorge Blasco, Rikke Bjerg Jensen, and Lenka Mareková

  3. [3]

    Arjun Appadurai. 2001. Disjuncture and difference in the global cultural econ- omy. The new social theory reader , 253–266

  4. [4]

    Arjun Arunasalam, Habiba Farrukh, Eliz Tekcan, and Z Ber kay Celik. 2024. Understanding the security and privacy implications of onl ine toxic content on refugees. In USENIX Security Symposium

  5. [5]

    Rosanna Bellini, Kevin Lee, Megan A Brown, Jeremy Shaffer , Rasika Bhalerao, and Thomas Ristenpart. 2023. The digital-safety risks of financial technologies for survivors of intimate partner violence. In Proceedings of the 32nd USENIX Conference on Security Symposium , 87–104

  6. [6]

    Rosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffall a, Tara Matthews, Sunny Consolvo, Jill Palzkill Woelfer, Patrick Gage Kelley, Michelle L Mazurek, Dana Cuomo, et al. 2023. SoK: Safer digital-safety research involving at-risk users. In 2024 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 71–71

  7. [7]

    Alastair R Beresford and Frank Stajano. 2003. Location p rivacy in pervasive computing. IEEE Pervasive computing , 2, 1, 46–55

  8. [8]

    Kiran Vinod Bhatia, Mariam Elhussein, Ben Kreimer, and T revor Snapp. 2023. Protests, internet shutdowns, and disinformation in a tran sitioning state. Me- dia, Culture & Society , 01634437231155568

Show all 67 references
  1. [9]

    Evangelos Bitsikas, Theodor Schnitzler, Christina Pöp per, and Aanjhan Ran- ganathan. 2023. Freaky leaky SMS: Extracting user locations by analyzing SMS timings. In 32nd USENIX Security Symposium (USENIX Security 23), 2151–2168

  2. [10]

    Maia J Boyd, Jamar L Sullivan Jr, Marshini Chetty, and Bl ase Ur. 2021. Under- standing the security and privacy advice given to Black Lives Matter protesters. In Proceedings of the 2021 CHI Conference on Human Factors in Com puting Sys- tems, 1–18

  3. [11]

    Behlül Çalışkan. 2019. Digital security awareness and practices of journalists in Turkey: A descriptive study. Conflict & Communication , 18, 1

  4. [12]

    Kathy Charmaz. 2017. Constructivist grounded theory. The journal of positive psychology, 12, 3, 299–300

  5. [13]

    Rahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sa m Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, a nd Thomas Ristenpart. 2018. The spyware used in intimate partner viol ence. In 2018 IEEE Symposium on Security and Privacy (SP) . IEEE, 441–458

  6. [14]

    I would have to evaluate the ir objections

    Camille Cobb, Sruti Bhagavatula, Kalil Anderson Garre tt, Alison Hoffman, Varun Rao, and Lujo Bauer. 2021. "I would have to evaluate the ir objections": Privacy tensions between smart home device owners and incid ental users. Proc. Priv. Enhancing Technol., 2021, 4, 54–75

  7. [15]

    Alaa Daffalla, Lucy Simko, Tadayoshi Kohno, and Alexand ru G Bardas. 2021. Defensive technology use by political activists during theSudanese revolution. In 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 372–390

  8. [16]

    digital governmentality

    Finn Dammann, Christian Eichenmüller, and Georg Glasz e. 2022. Geographies of "digital governmentality": Platform-based governing t hrough adaptive en- vironments. Digital Geography and Society , 3, 100034

  9. [17]

    Ronald J Deibert. 2023. The autocrat in your iPhone: How mercenary spyware threatens democracy. Foreign Affairs, 102, 72–88

  10. [18]

    We have to act like our devices ar e already infected

    Philip Di Salvo. 2021. "We have to act like our devices ar e already infected": Investigative journalists and internet surveillance. Journalism Practice, 1–18

  11. [19]

    A stalker’s paradise

    Diana Freed, Jackeline Palmer, Diana Minchala, Karen L evy, Thomas Risten- part, and Nicola Dell. 2018. “A stalker’s paradise”: How intimate partner abusers exploit technology. InProceedings of the 2018 CHI Conference on Human Factors in Computing Systems , 1–13

  12. [20]

    Diana Freed, Jackeline Palmer, Diana Elizabeth Mincha la, Karen Levy, Thomas Ristenpart, and Nicola Dell. 2017. Digital technologies an d intimate partner violence: A qualitative analysis with multiple stakeholde rs. Proceedings of the ACM on human-computer interaction , 1, CSCW, 1–22

  13. [21]

    Laura Gianna Guntrum. 2024. Keyboard fighters: The use o f ICTs by activists in times of military coup in Myanmar. In Proceedings of the 2024 CHI Confer- ence on Human Factors in Computing Systems , 1–19

  14. [22]

    Franziska Herbert, Steffen Becker, Annalina Buckmann, Marvin Kowalewski, Jonas Hielscher, Yasemin Acar, Markus Dürmuth, Yixin Zou, a nd M Angela Sasse. 2023. Digital security—a question of perspective. Alarge-scale telephone survey with four at-risk user groups. In 2024 IEEE Sy...

  15. [23]

    Hongbo Jiang, Jie Li, Ping Zhao, Fanzi Zeng, Zhu Xiao, an d Arun Iyengar

  16. [24]

    It depends on your threat model

    Becky Kazansky. 2021. "It depends on your threat model" : The anticipatory dimensions of resistance to data-driven surveillance. Big Data & Society , 8, 1, 2053951720985557

  17. [25]

    ACM Computing Surveys (CSUR), 54, 1, 1–36

    Location privacy-preserving mechanisms in location -based services: A comprehensive survey. ACM Computing Surveys (CSUR), 54, 1, 1–36

  18. [26]

    Hao-Ping Lee, Yu-Ju Yang, Thomas Serban Von Davier, Jod i Forlizzi, and Sauvik Das. 2024. Deepfakes, phrenology, surveillance, and more! A taxonomy of AI privacy risks. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems, 1–19. 6 Location-Dependent ...

  19. [27]

    Joon-Seok Kim, Hyunjee Jin, Hamdi Kavak, Ovi Chris Roul y, Andrew Crooks, Dieter Pfoser, Carola Wenk, and Andreas Züfle. 2020. Locatio n-based social network data generation based on patterns of life. In 2020 21st IEEE Interna- tional Conference on Mobile Data Management (MDM) ...

  20. [28]

    Yue Lin. 2024. Moving beyond anonymity: Embracing a col lective approach to location privacy in data-intensive geospatial analytics. Environment and Plan- ning F, 26349825231224029

  21. [29]

    Zi Li, Qingqi Pei, Ian Markwood, Yao Liu, Miao Pan, and Ho ngning Li. 2018. Location privacy violation via GPS-agnostic smart phone ca r tracking. IEEE Transactions on Vehicular Technology, 67, 6, 5042–5053

  22. [30]

    I blame Apple in part for my fals e expectations

    Benedikt Mader, Christian Eichenmüller, Gaston Pugli ese, Dennis Eckhardt, and Zinaida Benenson. 2024. "I blame Apple in part for my fals e expectations": An autoethnographic study of Apple’s Lockdown Mode in iOS.arXiv:2411.13249

  23. [31]

    Sebastian Linxen, Christian Sturm, Florian Brühlmann , Vincent Cassau, Klaus Opwis, and Katharina Reinecke. 2021. How weird is CHI? In Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems , 1–14

  24. [32]

    Bill Marczak, John Scott-Railton, Sarah McKune, Bahr A bdul Razzak, and Ron Deibert. 2018. Hide and seek: Tracking NSO group’s Pegasus s pyware to op- erations in 45 countries. Tech. rep. Citizen Lab

  25. [33]

    Nathan Malkin. 2022. Contextual integrity, explained : A more usable privacy definition. IEEE Security & Privacy , 21, 1, 58–65

  26. [34]

    You offer privacy like you offer tea

    Karola Marky, Nina Gerber, Michelle Gabriela Pelzer, M ohamed Khamis, and Max Mühlhäuser. 2022. "You offer privacy like you offer tea": I nvestigating mechanisms for improving guest privacy in IoT-equipped hou seholds. Pro- ceedings on Privacy Enhancing Technologies , 4, 400–420

  27. [35]

    William R Marczak, John Scott-Railton, Morgan Marquis -Boire, and Vern Pax- son. 2014. When governments hack opponents: A look at actors and technol- ogy. In 23rd USENIX Security Symposium (USENIX Security 14) , 511–525

  28. [36]

    Viktor Mayer-Schönberger. 2011. Delete: The virtue of forgetting in the digital age. Princeton University Press

  29. [37]

    Tara Matthews, Kathleen O’Leary, Anna Turner, Manya Sl eeper, Jill Palzkill Woelfer, Martin Shelton, Cori Manthorne, Elizabeth F Churc hill, and Sunny Consolvo. 2017. Stories from survivors: Privacy & securitypractices when cop- ing with intimate partner abuse. In Proceedings ...

  30. [38]

    I did watch ‘ The Handmaid’s Tale’

    Nora McDonald and Nazanin Andalibi. 2023. "I did watch ‘ The Handmaid’s Tale’": Threat modeling privacy post-Roe in the United Stat es. ACM Transac- tions on Computer-Human Interaction , 30, 4, 1–34

  31. [39]

    It’s stressful having all thes e phones

    Allison McDonald, Catherine Barwulor, Michelle L Mazu rek, Florian Schaub, and Elissa M Redmiles. 2021. "It’s stressful having all thes e phones": Investi- gating sex workers’ safety goals, risks, and practices onli ne. In 30th USENIX Security Symposium (USENIX Security 21) , 375–392

  32. [40]

    Susan E McGregor, Polina Charters, Tobin Holliday, and Franziska Roesner

  33. [41]

    Mazure k, and Nazanin Andalibi

    Nora McDonald, Alan Luo, Phoebe Moh, Michelle L. Mazure k, and Nazanin Andalibi. 2024. Threat modeling healthcare privacy in the U nited States. ACM Transactions on Computer-Human Interaction

  34. [42]

    Marko Milanovic. 2020. The murder of Jamal Khashoggi: I mmunities, inviola- bility and the human right to life. Human Rights Law Review , 20, 1, 1–49

  35. [43]

    Shishir Nagaraja and Ross Anderson. 2009. The snooping dragon: Social-malware surveillance of the Tibetan movement. Tech. rep. Universit y of Cambridge, Computer Laboratory

  36. [44]

    Susan E McGregor, Elizabeth Anne Watkins, Mahdi Nasrul lah Al-Ameen, Kelly Caine, and Franziska Roesner. 2017. When the weakest link is strong: Secure collaboration in the case of the Panama Papers. In 26th USENIX Security Sym- posium (USENIX Security 17) , 505–522

  37. [45]

    Muhammad Sadi Adamu. 2021. Problematising identity, p ositionality, and ad- equacy in HCI4D fieldwork: A reflection. In 3rd African Human-Computer In- teraction Conference: Inclusiveness and Empowerment , 65–74

  38. [46]

    Millions of p eople are watching you

    Patrawat Samermit, Anna Turner, Patrick Gage Kelley, T ara Matthews, Vanes- sia Wu, Sunny Consolvo, and Kurt Thomas. 2023. “Millions of p eople are watching you”: Understanding the digital-safety needs and practices of cre- ators. In 32nd USENIX Security Symposium (USENIX Secu...

  39. [47]

    Thomas Reisinger, Isabel Wagner, and Eerke Albert Boit en. 2023. Unified com- munication: What do digital activists need? In 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) . IEEE, 141–149

  40. [48]

    John Scott-Railton. 2016. Security for the high-risk u ser: Separate and unequal. IEEE Security & Privacy , 14, 2, 79–87

  41. [49]

    Lucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesn er, and Tadayoshi Kohno. 2018. Computer security and privacy for refugees in t he United States. In 2018 IEEE Symposium on Security and Privacy (SP) . IEEE, 409–423

  42. [50]

    Ari Schlesinger, W Keith Edwards, and Rebecca E Grinter . 2017. Intersectional HCI: Engaging identity through gender, race, and class. In Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems , 5412–5427

  43. [51]

    They look at vulnerabilit y and use that to abuse you

    Julia Slupska, Selina Cho, Marissa Begonia, Ruba Abu-S alma, Nayanatara Prakash, and Mallika Balakrishnan. 2022. "They look at vulnerabilit y and use that to abuse you": Participatory threat modelling with migrant domestic workers. In 31st USENIX Security Symposium (USENIX Sec...

  44. [52]

    Julia Slupska, Scarlet Dawson Duckworth, Linda Ma, and Gina Neff. 2021. Par- ticipatory threat modelling: Exploring paths to reconfigur e cybersecurity. In Extended Abstracts of the 2021 CHI Conference on Human Facto rs in Computing Systems, 1–6

  45. [53]

    Julia Slupska and Megan Lindsay Brown. 2022. Aiding int imate violence sur- vivors in lockdown: Lessons about digital security in the Co vid-19 pandemic. In Extended Abstracts of the 2022 CHI Conference on Human Facto rs in Comput- ing Systems, 1–5

  46. [54]

    Leonie Maria Tanczer, Ronald J Deibert, Didier Bigo, MI Franklin, Lucas Mel- gaço, David Lyon, Becky Kazansky, and Stefania Milan. 2020. Online surveil- lance, censorship, and encryption in academia. International Studies Perspec- tives, 21, 1, 1–36

  47. [55]

    Nirmalya Thakur and Chia Y Han. 2021. An ambient intelli gence-based human behavior monitoring framework for ubiquitous environments. Information, 12, 2, 81

  48. [56]

    Julia Slupska and Leonie Maria Tanczer. 2021. Threat mo deling intimate part- ner violence: Tech abuse as a cybersecurity challenge in the internet of things. In The Emerald International Handbook of Technology-Facilit ated Violence and Abuse. Emerald Publishing Limited

  49. [57]

    Mindy Tran, Collins W Munyendo, Harshini Sri Ramulu, Ra chel Gonzalez Ro- driguez, Luisa Ball Schnell, Cora Sula, Lucy Simko, and Yasemin Acar. 2023. Se- curity, privacy, and data-sharing trade-offs when moving to the United States: Insights from a qualitative study. In 2024 IE...

  50. [58]

    Lokman Tsui and Francis Lee. 2021. How journalists unde rstand the threats and opportunities of new technologies: A study of security m ind-sets and its implications for press freedom. Journalism, 22, 6, 1317–1339

  51. [59]

    Stuart A Thompson and Charlie Warzel. 2022. Twelve mill ion phones, one dataset, zero privacy. In Ethics of data and analytics . Auerbach Publications, 161–169

  52. [60]

    Kandrea Wade, Jed R Brubaker, and Casey Fiesler. 2021. P rotest privacy recom- mendations: An analysis of digital surveillance circumven tion advice during Black Lives Matter protests. In Extended Abstracts of the 2021 CHI Conference on Human Factors in Computing Systems , 1–6

  53. [61]

    Noel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul, Sunny Consolvo, Patrick Gage Kelley, Nathan Malkin, Michelle L Mazurek, Man ya Sleeper, and Kurt Thomas. 2022. SoK: A framework for unifying at-risk use r research. In 2022 IEEE Symposium on Security and Privacy (SP) . IEE...

  54. [62]

    Warda Usman and Daniel Zappala. 2025. SoK: A framework a nd guide for human-centered threat modeling in security and privacy res earch. In 2025 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 33–33

  55. [63]

    Shoshana Zuboff. 2019. The age of surveillance capitalism: The fight for a human future at the new frontier of power . PublicAffairs. 7 Eichenmüller et al. A SUPPLEMENT: INTERVIEW GUIDE A.1 Introduction • Informed consent • Assure anonymity • Assure careful handling of data - res...

  56. [65]

    Yaxing Yao, Justin Reed Basdeo, Oriana Rosata Mcdonoug h, and Yang Wang

  57. [2015]

    In 24th USENIX Security Symposium (USENIX Security 15) , 399–414

    Investigating the computer security practices and ne eds of journalists. In 24th USENIX Security Symposium (USENIX Security 15) , 399–414

  58. [2019]

    Proceed- ings of the ACM on Human-Computer Interaction , 3, CSCW, 1–24

    Privacy perceptions and designs of bystanders in smar t homes. Proceed- ings of the ACM on Human-Computer Interaction , 3, CSCW, 1–24

  59. [2021]

    In30th USENIX Security Symposium (USENIX Security 21), 3363– 3380

    Collective information security in large-scale urba n protests: The case of Hong Kong. In30th USENIX Security Symposium (USENIX Security 21), 3363– 3380

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.