Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Users Rationally Rejecting Security Advice
November 24, 2009 20:40



    

This paper, by Cormac Herley at Microsoft Research, sounds like me:

Abstract: It is often suggested that users are hopelessly lazy and unmotivated on security questions. They chose weak passwords, ignore security warnings, and are oblivious to certicates errors. We argue that users' rejection of the security advice they receive is entirely rational from an economic perspective. The advice offers to shield them from the direct costs of attacks, but burdens them with far greater indirect costs in the form of effort. Looking at various examples of security advice we find that the advice is complex and growing, but the benefit is largely speculative or moot. For example, much of the advice concerning passwords is outdated and does little to address actual threats, and fully 100% of certificate error warnings appear to be false positives. Further, if users spent even a minute a day reading URLs to avoid phishing, the cost (in terms of user time) would be two orders of magnitude greater than all phishing losses. Thus we find that most security advice simply offers a poor cost-benefit tradeoff to users and is rejected. Security advice is a daily burden, applied to the whole population, while an upper bound on the benefit is the harm suffered by the fraction that become victims annually. When that fraction is small, designing security advice that is beneficial is very hard. For example, it makes little sense to burden all users with a daily task to spare 0.01% of them a modest annual pain.

Sounds like me.


All news for July 29, 2010
  19:30  Martin McKeay: BHDC2010: Mary Landesman, Cisco
  14:16  Schneier on Security: Security Vulnerabilities of Smart Electricity Meters

All news for July 28, 2010
  19:12  Schneier on Security: DNSSEC Root Key Split Among Seven People
  18:15  MSRC: Community-Based Defense: Looking Outward, Moving Forward

All news for July 27, 2010
  20:33  Schneier on Security: Pork-Filled Counter-Islamic Bomb Device
  17:31  Martin McKeay: Headed to Vegas!
  14:43  Schneier on Security: WPA Cracking in the Cloud

All news for July 26, 2010
  20:30  Schneier on Security: 1921 Book on Profiling
  14:12  Schneier on Security: Technology is Making Life Harder for Spies
Keywords: users, rationally, rejecting, security, advice

All news for July, 2010


All news for 2008


All news for 2009


All news for 2010