Professor Stefan Katzenbeisser holds the Chair of Computer Engineering at the University of Passau. In recent years, he has served as spokesperson for the Bavarian collaborative research centre ForDaySec, which aims to improve cybersecurity in everyday digital life. The focus was not only on the technical perspective, but rather on practical solutions tailored to people’s everyday lives and working environments. In addition to computer scientists, the consortium also involved researchers from the fields of sociology, ethnography and law from across Bavaria. The consortium was funded by the Bavarian State Ministry of Science and the Arts.
Which finding from ForDaySec surprised you the most?
I think we were all astonished by just how diverse the IT infrastructures in households are. We saw a mix of very old systems – old PCs, for example, which have actually long since reached the end of their useful life but are still in use. At the same time, there are small smart-home devices that are combined to form larger infrastructures. And we also see hacks that have been put together by the owners themselves – using knowledge obtained from YouTube videos or from AI.
How did you go about researching everyday digital life?
We took an interdisciplinary approach to the project. For example, sociologists from Friedrich-Alexander University Erlangen-Nuremberg were involved. As a first step, they visited households to gather information on the ground. How is the technology used? What are the problems in everyday life? Based on these field studies, we then defined overarching issues within the research consortium.
A video recap (in German) of the closing event of the Bavarian Research Network ForDaySec, featuring, amongst others, comments from Professor Stefan Katzenbeisser (University of Passau), tech journalist Eva Wolfangel, Professor Thomas Riehm (University of Passau), Professor Dominik Herrmann (University of Bamberg) and Mirjam Hauck, business editor at the "Süddeutsche Zeitung". Read the wrap-up report
What are the most common vulnerabilities in everyday cybersecurity?
The most serious problem is a lack of updates – that is, cases where devices remain in use beyond their end-of-life, so that manufacturers no longer provide updates. These devices are completely unprotected. Another challenge is the heterogeneous infrastructure. Added to this is a lack of knowledge on the part of users on how to build secure systems. Many would certainly be motivated to do so, but efforts often fail due to a lack of knowledge and limited resources.
Where have you identified gaps in research? What are the key areas in need of fundamental research?
Through ForDaySec, we have gained a good understanding of where the problems lie. There is a lack of security solutions that can be easily integrated into people’s everyday lives. A great deal of research is still needed in this area. The whole field of human-centred design – that is, the development of practical solutions that take people’s usage habits into account – is still significantly underdeveloped in the context of everyday cybersecurity.
In ForDaySec, you have developed an initial prototype for this: the Security Monitor. What is the idea behind it?
The approach aims to isolate devices that no longer receive security updates or are considered insecure from the network – in other words, to encapsulate them from the outside. In this way, they can continue to be used without posing a security risk. It is a concept with great potential, and one that I hope it will be taken up.
Private households as a security risk – the German Federal Office for the Protection of the Constitution recently issued a specific warning about old routers. What makes them an attractive target for attackers?
Attackers are primarily interested in the computing power available in these devices, and so are mainly keen to use them for so-called distributed denial-of-service attacks. A botnet comprising millions of domestic devices can send a concentrated barrage of requests to a target system in order to overload and cripple it. This is a typical scenario: an old router becomes a point of entry from which attackers can launch further criminal activities.
So are private households a gateway for attacks on critical infrastructure?
Yes, that is possible.
What can households do to protect themselves? Do they need expensive software?
In principle, you do not need to invest a lot of money to stay secure. A great deal of security can be achieved with simple precautions. For example, you can set up multiple networks within the home: IoT devices can be placed on a separate network that has no access to critical areas, such as PCs or hard drives. That alone would be a major step forward. Updates are essential, as software bugs remain the biggest vulnerability. Anyone who consistently eliminates these bugs through patches and updates will achieve a level of security that is significantly higher than the usual household standards.
ForDaySec has found that technical warnings alone are not very effective. What would need to happen for households to become aware of the security risks they face?
I think a package of measures is needed. On the user side, there needs to be greater awareness of the issues, but also more support to help people manage their home networks securely – for example, through best practices, clear instructions and, in some cases, automation, so that people can act securely even with little prior knowledge.
Of course, manufacturers also have a role to play. They should deliver systems that are secure by default – in other words, with security firmly built in – and provide updates throughout the product’s entire lifecycle. Here, we will benefit from the European Union’s Cyber Resilience Act, which will come into full effect from December 2027 and enshrines precisely this: manufacturers will be obliged to develop all products containing digital elements securely and to keep them secure throughout their intended lifespan. This will hopefully significantly raise the level of security in everyday life.
Considering the recent headlines about AI systems that have broken out of their test environments and are acting in an unrestricted manner: what role does generative AI play in everyday digital security?
These incidents show that we must take this issue very seriously. Generative AI will have a significant impact on cybersecurity – both positive and negative. On the positive side, access to information will become easier. Particularly when AI is combined with a search function, even people without prior knowledge can obtain useful instructions and guidance using simple language.
The downside is that attacks will be easier to carry out. Current language models – as demonstrated by the latest incidents – are already quite good at generating code that specifically targets vulnerable software. We a’re bound to see more of this. The good news, however, is that AI hasn’t has not yet found any fundamentally new methods of attack – in principle, everything we’re we were seeing could also have been discovered by a human. Although AI accelerates and scales these processes, truly novel attacks have so far failed to materialise. And we need to protect ourselves against these threats in any case.
Have you ever fallen for a phishing email?
In fact, I have never lost any sensitive data such as credit card numbers, even though AI makes that much easier. But we are also much better at protecting ourselves against it, for example through measures such as multi-factor authentication. A new phenomenon worries me more: attacks by telephone. Messages are played out that pretend to come from a specific person but are entirely AI-generated. The tricky thing about this is that we tend to regard the telephone as more trustworthy than the internet – which is, of course, nonsense. However, this increases the likelihood of falling victim to such a personalised attack.
This text was machine-translated from German.
How can we make our everyday digital life secure? In the established research area "Cybersecurity and Data Protection", our researchers examine the technical, economic and legal aspects of IT security. More information on the topics and the participating researchers