Why Do Street-Smart People Do Stupid Things Online?
Bratus, S.
Masone, C.
Smith, S.W.
This paper appears in: Security & Privacy, IEEE
Publication Date: May-June 2008
Volume: 6,
Issue: 3
On page(s): 71-74
ISSN: 1540-7993
INSPEC Accession Number: 10090468
Digital Object Identifier: 10.1109/MSP.2008.79
Current Version Published: 2008-05-23
Abstract
The systems we worry about securing include the people who use them. In everyday offline life, an average person's "security policy" consists of a few simple, intuitive rules. We believe that the majority of users continuously employ risk analysis heuristics to plan both their online and offline actions; the overwhelming problem of online security is that this analysis, in the online case, is based primarily on entirely wrong assumptions, intuitively derived from incorrect interpretation of GUI elements and processes. We propose a core user interface design principle for the designers to follow when considering and building trust-decision-related user interface features.
Index
Terms
Available to subscribers and IEEE members.
References
Available to subscribers and IEEE members.
Citing Documents
Available to subscribers and IEEE members.