"My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security Software
Jonah Stegman, Patrick J. Trottier, Caroline Hillier, Hassan Khan, Mohammad Mannan
摘要
Employees are often required to use Enterprise Security Software ("ESS") on corporate and personal devices. ESS products collect users' activity data including users' location, applications used, and websites visited - operating from employees' device to the cloud. To the best of our knowledge, the privacy implications of this data collection have yet to be explored. We conduct an online survey (n=258) and a semi-structured interview (n=22) with ESS users to understand their privacy perceptions, the challenges they face when using ESS, and the ways they try to overcome those challenges. We found that while many participants reported receiving no information about what data their ESS collected, those who received some information often underestimated what was collected. Employees reported lack of communication about various data collection aspects including: the entities with access to the data and the scope of the data collected. We use the interviews to uncover several sources of misconceptions among the participants. Our findings show that while employees understand the need for data collection for security, the lack of communication and ambiguous data collection practices result in the erosion of employees' trust on the ESS and employers. We obtain suggestions from participants on how to mitigate these misconceptions and collect feedback on our design mockups of a privacy notice and privacy indicators for ESS. Our work will benefit researchers, employers, and ESS developers to protect users' privacy in the growing ESS market.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Investigating Novice Researchers' Perceptions of Research Privacy Within LLM-Assisted WorkflowsShuning Zhang, Changxi Wen, Eve He, Ying Ma 等CCS 2026 · 被引用 1 次
- Quantifying Security Training in Organizations Through the Analysis of U.S. SEC 10-K FilingsJonas Hielscher, Maximilian GollaCCS 2025
它引用的顶会 Paper5
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili 等CCS 2019 · 被引用 134 次
相关 Paper
- Understanding Fitness Tracker Users' Security and Privacy Knowledge, Attitudes and BehavioursSandra Gabriele, Sonia ChiassonCHI 2020 · 被引用 61 次
- Boss is aWare - Are you? Employee Comprehension and Legal Awareness of Workplace MonitoringTeshan S. Bunwaree, Katarzyna Stawarz, Philippa Collins, Sandy J. J. GouldCHI 2025 · 被引用 6 次
- A World Full of Privacy and Security (Mis)conceptions? Findings of a Representative Survey in 12 CountriesFranziska Herbert, Steffen Becker, Leonie Schaewitz, Jonas Hielscher 等CHI 2023 · 被引用 36 次
- "It doesn't tell me anything about how my data is used": User Perceptions of Data Collection PurposesLin Kyi, Abraham Mhaidli, Cristiana Teixeira Santos, Franziska Roesner 等CHI 2024 · 被引用 22 次
- Selling Satisfaction: A Qualitative Analysis of Cybersecurity Awareness Vendors' PromisesJonas Hielscher, Markus Schöps, Jens Opdenbusch, Felix Reichmann 等CCS 2024 · 被引用 4 次
