To Cloud or not to Cloud: A Qualitative Study on Self-Hosters' Motivation, Operation, and Security Mindset
Lea Gröber, Rafael Mrowczynski, Nimisha Vijay, Daphne A. Muller, Adrian Dabrowski, Katharina Krombholz
摘要
Despite readily available cloud services, some people decide to self-host internal or external services for themselves or their organization. In doing so, a broad spectrum of commercial, institutional, and private self-hosters take responsibility for their data, security, and reliability of their operations.
Currently, little is known about what motivates these selfhosters, how they operate and secure their services, and which challenges they face. To improve the understanding of selfhosters' security mindsets and practices, we conducted a largescale survey (N S =994) with users of a popular self-hosting suite and in-depth follow-up interviews with selected commercial, non-profit, and private users (N I =41).
We found exemplary behavior in all user groups; however, we also found a significant part of self-hosters who approach security in an unstructured way, regardless of social or organizational embeddedness. Vague catch-all concepts such as firewalls and backups dominate the landscape, without proper reflection on the threats they help mitigate. At times, self-hosters engage in creative tactics to compensate for a potential lack of expertise or experience.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityJiaxun Cao, Abhinaya S. B., Anupam Das, Pardis Emami NaeiniS&P 2024 · 被引用 19 次
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz 等NDSS 2026 · 被引用 3 次
- "Privacy across the boundary": Examining Perceived Privacy Risk Across Data Transmission and Sharing Ranges of Smart Home Personal AssistantsShuning Zhang, Shixuan Li, Haobin Xing, Jiarui Liu 等CHI 2026 · 被引用 1 次
- Towards Privacy and Security in Private Clouds: A Representative Survey on the Prevalence of Private Hosting and Administrator CharacteristicsLea Gröber, Simon Lenau, Rebecca Weil, Elena Groben 等USENIX Security 2024 · 被引用 1 次
它引用的顶会 Paper5
- Don't You Know That You're Toxic: Normalization of Toxicity in Online GamingNicole A. Beres, Julian Frommel, Elizabeth Reid, Regan L. Mandryk 等CHI 2021 · 被引用 235 次
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 等S&P 2019 · 被引用 105 次
- Helping Users Automatically Find and Manage Sensitive, Expendable Files in Cloud StorageMohammad Taha Khan, Christopher Tran, Shubham Singh, Dimitri Vasilkov 等USENIX Security 2021 · 被引用 16 次
- KondoCloud: Improving Information Management in Cloud Storage via Recommendations Based on File SimilarityWill Brackenbury, Andrew M. McNutt, Kyle Chard, Aaron J. Elmore 等UIST 2021 · 被引用 2 次
- Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate ContextVeroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters 等USENIX Security 2022
相关 Paper
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providersReethika Ramesh, Anjali Vyas, Roya EnsafiUSENIX Security 2023
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Understanding Home Router Configuration Habits & AttitudesJunjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu 等CHI 2025 · 被引用 1 次
- Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingSamaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian 等CCS 2017 · 被引用 48 次
