Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data Exports
Julia Nonnenkamp, Naman Gupta, Abhimanyu Dev Gupta, Rahul Chatterjee
摘要
When survivors of technology-facilitated abuse (TFA) suspect someone has accessed their online accounts, they often rely on built-in account security interfaces (ASIs), such as trusted device lists within settings, to assess account compromise. However, these interfaces typically offer limited or ambiguous details about past account accesses and security-critical events. Under right of access provisions in data protection laws, users can request structured exports of their personal data from online services. In this study, we explore whether and how data exports can supplement ASIs to support compromise investigations, particularly in interpersonal threat contexts. We simulated four types of account compromise attacks across six popular platforms, analyzing the resulting data exports and ASIs. Our findings show that data exports consistently contain more granular login histories and richer device/network identifiers than interfaces. Some even link security-related actions (e.g., password changes) and other post-authentication activity to specific devices, offering forensic value for identifying compromise. We discuss usability and other practical challenges of using data exports during TFA interventions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh 等S&P 2021 · 被引用 175 次
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron 等S&P 2018 · 被引用 167 次
- Trauma-Informed Computing: Towards Safer Technology Experiences for AllJanet X. Chen, Allison McDonald, Yixin Zou, Emily Tseng 等CHI 2022 · 被引用 163 次
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy 等USENIX Security 2019 · 被引用 118 次
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi 等CHI 2022 · 被引用 77 次
相关 Paper
- Account Security Interfaces: Important, Unintuitive, and UntrustworthyAlaa Daffalla, Marina Sanusi Bohuk, Nicola Dell, Rosanna Bellini 等USENIX Security 2023
- Inconsistent, Incomplete, and Insecure: A Survey of Account Security InterfacesArkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini 等USENIX Security 2026
- "I really just leaned on my community for support": Barriers, Challenges and Coping Mechanisms Used by Survivors of Technology-Facilitated Abuse to Seek Social SupportNaman Gupta, Kate Walsh, Sanchari Das, Rahul ChatterjeeUSENIX Security 2024 · 被引用 7 次
- Legal Evidence of Technology-Facilitated Abuse in Wisconsin: Surfacing Barriers Within and Beyond the CourtroomSophie Stephenson, Naman Gupta, Akhil Polamarasetty, Kyle Huang 等CSCW 2025 · 被引用 2 次
- Encrypted Access Logging for Online Accounts: Device Attributions without Device TrackingCarolina Ortega Pérez, Alaa DaffallaUSENIX Security 2025
