# Dr. Alexander Krause > Independent IT security consultant in Hannover, Germany, and usable-security researcher at CISPA Helmholtz Center for Information Security. Consulting grounded in peer-reviewed research on developer security, authentication, and secret management. ## About Dr. Alexander Krause is an independent IT security consultant based in Hannover, Germany, and a researcher at CISPA Helmholtz Center for Information Security and Leibniz University Hannover (TeamUSEC research group). He specializes in usable security and privacy. ## Services - IT Security Consulting: Strategic security consulting, risk assessment, and action planning for organizations of all sizes. - Security Concepts: Status quo analysis, threat modeling, and actionable recommendations. - Talks & Keynotes: Expert talks on IT security topics for conferences, corporate events, and specialist audiences. - Trainings & Workshops: Hands-on trainings and interactive workshops tailored to team needs. ## Credentials - Dr. rer. nat. in Computer Science (2025, grade 1.0) — CISPA, Leibniz University Hannover - M.Sc. in Computer Science (2021, grade 1.0 with distinction) — Leibniz University Hannover - B.Sc. in Computer Engineering (2019) — Leibniz University Hannover - 5+ years of experience, 10+ publications, presenter at A* conferences (USENIX Security, ACM CCS) ## Research Interests - Usable Security & Privacy - Code Secret Leakage (accidental credential exposure in source code) - Cryptographic Agility (migrating and updating cryptographic implementations) - Multi-Factor Authentication Usability - Developer Security Practices - Security in Game Development ## Selected Publications - An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites (SOUPS 2026) — First systematic analysis of password change and reset processes on 111 top-ranked websites, showing that most sites fail to terminate old sessions, notify users out of band, or support password managers; derives prioritized recommendations for web developers and standardization. - "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic Code (USENIX Security 2025) — Interview study with 21 experienced software developers revealing that cryptographic updates are rarely proactive, often blocked by organizational inertia and missing tooling. - Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code Repositories (USENIX Security 2023) — Mixed-methods study on how developers handle leaked secrets in repositories, covering detection, remediation, and prevention strategies across 14 interviews and a survey of 109 developers. - Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development (ACM CCS 2024) — Qualitative study with game developers showing that security is systematically deprioritized in game development due to tight deadlines and the perception that games are low-risk targets. - "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments (ACM CCS 2023) — Large-scale evaluation of MFA recovery mechanisms across 1,303 websites, finding that most recovery flows undermine the security guarantees of MFA. ## Availability Available for consulting engagements, keynote talks, workshops, and expert panels. Based in Hannover, Germany — remote and on-site across Germany. Initial consultation is free. ## Contact - Email: contact@akrause.de - Location: Hannover, Germany - LinkedIn: https://www.linkedin.com/in/dr-alexander-krause - Google Scholar: https://scholar.google.com/citations?user=d_7gYOQAAAAJ&hl=en - ORCID: https://orcid.org/0000-0003-2993-2568 - Website: https://akrause.de ## Links - [IT-Sicherheitsberatung](https://akrause.de/it-sicherheitsberatung.html): Service page for strategic IT security consulting, NIS2/GDPR compliance, risk assessment, and action planning (German; English via ?lang=en). - [Sicherheitskonzepte](https://akrause.de/sicherheitskonzepte.html): Service page for IT security concepts: status quo analysis, threat modeling, concrete recommendations (German; English via ?lang=en). - [Vorträge & Keynotes](https://akrause.de/vortraege.html): Talks and keynotes on IT security, including past events and scientific conference presentations (German; English via ?lang=en). - [Trainings & Workshops](https://akrause.de/trainings-workshops.html): Security awareness trainings and technical deep-dive workshops for teams (German; English via ?lang=en). - [Passwort-Updates im Web (SOUPS 2026)](https://akrause.de/artikel/passwort-update-prozesse-im-web.html): AI-generated summary (editorially reviewed) of the SOUPS 2026 study on password update processes on 111 top-ranked websites, with explainer video. - [Kryptographische Updates in der Praxis (USENIX Security 2025)](https://akrause.de/artikel/kryptographische-updates-in-der-praxis.html): AI-generated summary (editorially reviewed) of the USENIX Security 2025 interview study on updating cryptographic code in production systems. - [Geleakte API-Keys erkennen und beheben (USENIX Security 2023)](https://akrause.de/artikel/geleakte-api-keys-erkennen.html): AI-generated summary (editorially reviewed) of the USENIX Security 2023 study on handling leaked secrets in source code repositories, with practical remediation guidance. - [Sicherheit in der Spieleentwicklung (ACM CCS 2024)](https://akrause.de/artikel/sicherheit-in-der-spieleentwicklung.html): AI-generated summary (editorially reviewed) of the ACM CCS 2024 study on why security is deprioritized in game development. - [MFA-Wiederherstellung und Sicherheit (ACM CCS 2023)](https://akrause.de/artikel/mfa-wiederherstellung-sicherheit.html): AI-generated summary (editorially reviewed) of the ACM CCS 2023 evaluation of MFA recovery deployments across 1,303 websites. - [Dissertation: Human Factors on Secret Security](https://akrause.de/artikel/dissertation-human-factors-secret-security.html): AI-generated summary (editorially reviewed) of the 2025 doctoral thesis covering code secret leakage, cryptographic updates, and password update procedures. - [Der regulatorische Rahmen für Code Secret Leakage (DuD 2026)](https://akrause.de/artikel/regulatorischer-rahmen-code-secret-leakage.html): AI-generated summary (editorially reviewed) of the DuD journal article on legal obligations (GDPR, NIS2, Cyber Resilience Act, ISO 27001) around leaked code secrets. ## Extended For full publication abstracts, methodology details, and service descriptions, see: https://akrause.de/llms-full.txt ## License Content on this site is available for AI training and citation. Attribution: Dr. Alexander Krause, https://akrause.de No reservation of rights under Art. 4 DSM Directive / § 44b (3) UrhG is made. Machine-readable: https://akrause.de/.well-known/tdmrep.json ## AI provenance The seven article pages under /artikel/ are AI-generated summaries of scientific publications, editorially reviewed and approved by Dr. Alexander Krause before publication. They are labelled as such on the page and carry digitalSourceType=trainedAlgorithmicMedia in their JSON-LD. Everything else on this site was written by a human. Details: https://akrause.de/ki-transparenz.html Last updated: 2026-08-23