← Back to Blogs

"what are the most important problems in your field?"

tldr: I want to build new methods and validate existing ones for studying security and privacy among understudied populations, starting with low socioeconomic status (SES) communities in Pakistan. It took some sort of a process for me to get to this point, and in this blog, i talk about it too.

A couple of months before my Qualifying Exam, which took place early this month, I was wrestling with several anxious thoughts. I had to speak in front of three professors about my progress so far in the PhD program and lay out my future PhD vision to convince them that I can do (good) research. These professors, having decades of research experience between them, had the ability to pull apart my arguments to identify a foundational question I had not deliberated over before.

What is a PhD, anyway, I wondered.

Arvind Narayanan, a professor at Princeton, wrote a LinkedIn post1 in 2025 arguing that research is more effective when we pick projects, not problems, because a project is defined by "a change we want to see in the world." It shifts the researcher's focus away from narrow research questions and toward something larger.

I feel a PhD can be understood the same way, a project where each publication becomes a rung on a ladder climbing toward a solution. We may never finish the project within a single PhD, but we can reach a point where the solution is finally in sight. It's Newton's line, turned inward: "If I have seen further than others, it is because I've stood on the shoulders of giants [i.e. your own, in this case]."

A natural follow up question occurred to me: what change do I want to make in this world? I sat with that for a while. Richard Hamming used to ask his colleagues at Bell Labs what's now known as the Hamming Question, "What are the important problems of your field?". Then he'd follow up with, "What important problems are you working on?" If the answer to the second didn't match the first, Hamming would say, "If what you are doing is not important, and if you don't think it is going to lead to something important, why are you at Bell Labs working on it?"

The Hamming Question is a great question to sit with, but I felt the 'importance' of a problem is purely subjective. What I find important may not matter to someone else, and that's fine. All kinds of research are worth doing, regardless of how important they seem to anyone else. So instead of chasing some external definition of importance, I chose to anchor my PhD in something I could actually own i.e. my personal values.2

But then, what are the values that I (un)consciously return to? I tried to draw a narrative around my prior publications to figure out a connection between them. I found none. Worse, I realized I had simply jumped at whatever opportunity came next, without asking why. To give myself some credit though, I was never afforded the opportunity to think this way throughout my life. I was guided toward whichever option best supported the status quo.

I felt stuck.

This was also the time when I was reading a lot: news and articles on digital safety, investigative journalism like Susan Abulhawa's anthology Every Moment Is a Life, and histories of colonialism like William Dalrymple's The Anarchy. The more I read about the state of the world and humanity's past, the more pessimistic I became about its present and future.

This is when I started writing.

In one of his essays,3 Henrik Karlsson talks about how by "making things more rigid [through writing], it's easier to break them." I put my tangled thoughts into words, looking for a suitable attack to carve my way in. At the same time, I started talking more openly with friends about what was going on in my head.

The more I wrote and talked, the more a belief began to crystallize that research for me was a form of advocacy. I wanted my work to amplify the voices of marginalized and at-risk communities, through research aimed at improving their digital safety. My previous publications, I realized, were already a product of those values.

But I also noticed a critical gap in usable security and privacy research. The field doesn't have well-validated methods to even study the marginalized communities I wanted to speak for, such as people from low socioeconomic status backgrounds or immigrants. Most of what we know about how people create passwords, respond to warnings, or make privacy decisions comes from a narrow slice of the world, the Western, Educated, Industrialized, Rich, and Democratic populations. WEIRD,4 for short.

A 2024 survey by Hasegawa et al. found that between 2017 and 2021, around 79% of usable security and privacy papers drew on Western participant samples, largely because geographic and linguistic barriers make it hard for researchers, who are predominantly affiliated with Western institutions, to reach anyone else.5

And even when we do bridge that gap, even when we collaborate with local researchers from non-WEIRD populations, I believe we do not have validated methods that actually translate to non-WEIRD contexts.

Usable security and privacy borrows its methods from HCI at large (which in turn from social sciences), predominantly relying on interviews, experiments, and surveys.6 Linxen et al. found that 73% of CHI's own published findings rest on Western samples.7 So when we import methods built and validated almost entirely in WEIRD contexts, we import their untested assumptions along with them.

Take something as basic as establishing a shared vocabulary with our participants. Prior work has shown that low SES populations in Pakistan do not recognize the word "smartphone," and reach for words like "mobile" or "phone" instead.8 Terms like "security" are perceived just as differently. So before we can even begin recruiting, we first need to build a shared vocabulary with our participants, through conversations that let us find the language they're actually comfortable with.

More personally, when piloting our harassment study9 with low-literate, low-income women, we hit a wall. Several women told us that simply being seen discussing harassment could get them labeled besharam or shameless, risking their livelihood. We made the responsible call not to recruit them. But that gap, not knowing, and not yet having a safe way to ask, is what I wish to close with my work in the space of usable security and privacy.

I want my PhD to address this gap by extending usable security and privacy research beyond WEIRD populations. Not by simply recruiting more diverse participants, but by building new methods and validating existing ones, so our science can finally reach and represent communities it currently has limited valid ways to study.

I consider this work as a version of my advocacy, an effort to make methods accessible so more and more research could leverage these methods to amplify the voices of those systematically suppressed.

This matters for two reasons. First, for the people themselves: once we can properly study non-WEIRD communities, we can build systems that give them agency over their own security and privacy. And that agency leads to better safety. Second, for our science: once our methods hold up outside WEIRD populations, usable security and privacy research can be far more generalizable.

This is a huge project, and one PhD can only scratch the surface. So to start, I want to work specifically with low SES communities in Pakistan, to understand how they perceive and enact security and privacy. Low SES communities are marginalized by low income, limited literacy, limited digital exposure, and predominantly informal occupations, among other factors.

They matter to this work for three reasons. First, they make up a significant and growing share of the world's mobile userbase.10 Second, designing for their constraints tends to produce systems that are more robust for everyone, sometimes called the curb-cut effect.11 And third, addressing their digital exclusion is a necessary step toward closing the digital divide.12

So the first stage of my PhD is understanding the challenges of doing usable security and privacy research with low SES populations in the first place. That means going into the field, building trust with communities, developing a shared vocabulary with them, understanding how they actually enact privacy and security, and documenting how to navigate the challenges that come up along the way.

The second stage of my PhD turns from understanding the problem to building new methods, giving the research community better tools to actually study low SES populations. I've already planned some studies toward that goal, which I am very excited to pursue.

I can already see how much this PhD is going to shape me as I go through it. I got my first paper rejection less than a year in. I've already been to my first PhD conference where I mustered up the courage to talk with researchers in my field I looked up to.

Forrest Gump said it best: "Life was like a box of chocolates. You never know what you're gonna get." I suspect my PhD is going to keep handing me unprecedented challenges, and I guess I'm excited, for now, to take them on, even the ones that turn out to be a dark chocolate (howcanpeopleeatthose).

  1. Arvind Narayanan, Princeton. LinkedIn post (2025)
  2. Personal Values: How to Know Who You Really Are — Mark Manson
  3. Henrik Karlsson, "How to think in writing"
  4. Henrich et al. (2010), "The WEIRDest people in the world?"
  5. Hasegawa et al. (2024), "How WEIRD is Usable Privacy and Security Research?"
  6. Distler et al. (2021), "A Systematic Literature Review of Empirical Methods and Risk Representation in Usable Privacy and Security Research"
  7. Linxen et al. (2021), "How WEIRD is CHI?"
  8. Hashmi & Sarfaraz et al. (2025), "Understanding the Security Advice Mechanisms of Low Socioeconomic Pakistanis"
  9. Usman et al. (2026), "Understanding Gendered Experiences of Harassment Among Pakistani Young Adults Using Human-Centered Threat Modeling"
  10. GSMA (2025), "The Mobile Economy"
  11. Dorsey et al. (2020), "Racial Equity and Philanthropy: Disparities in Funding for Leaders of Color Leave Impact on the Table"
  12. Redmiles et al. (2017), "Where is the Digital Divide?: A Survey of Security, Privacy, and Socioeconomics"