Skip to Main Content
Failures of security technology are often attributed to individual fault. The lack of adoption of privacy enhancing technologies is explained as a societal failure, i.e., that people don't care. Security designers consider the individual user to be rational, certain, and self-optimizing. Thus, academic and practitioner efforts have focused on incentive alignment and education. But even the effectiveness of initiatives such as security education can be improved if well-known human decision heuristics are taken as initial inputs to improve technical solutions, rather than sources of failure to be bemoaned.