Sonia Chiasson

dblp:26/2669 · DBLP profile ↗
← Back
63ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0001-7314-2198ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 34 · 7 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 32 · 3 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Understanding Deception: A qualitative study of children's interactions with deceptive design in digital games
Muhammad Zaid Arif, Asra Sakeen Wani, Ananta Chowdhury, Sana Maqsood, Sonia Chiasson
IDC5
2026 User Authentication: A Yet Unresolved Problem from the Users' Perspective
abstract
In this talk, I will present recent work from our usable security groups at Carleton University reflecting how user authentication is experienced by different user groups and exploring how design decisions around user authentication impact user behaviour.
Sonia Chiasson
SACMAT1
2026 The privacy triad: Understanding the influence of perceived social agency on privacy attitudes
abstract
The Computers Are Social Actors (CASA) paradigm proposes that users’ interactions with computers follow the same social psychology principles as their interactions with people. CASA has potential value in guiding privacy design and research, but this has never been explicitly studied. To investigate how CASA may affect users’ privacy attitudes towards computers, smartphones, and digital assistants, we conducted a two-part investigation. First, we surveyed 400 participants. We identify that CASA is relevant in some, but not all, privacy contexts. Next, we interviewed 12 participants using Grounded Theory methods to understand to what extent CASA shaped their privacy attitudes. Overall, our study revealed that CASA by itself is insufficient to explain users’ privacy attitudes. Interpreting our results, we propose the Privacy Triad: users either consider their device to be a social agent , a conduit for outside actors, or a tool over which they have full control. These roles impact users’ privacy attitudes and expectations towards the device. We describe the practical applications of the Privacy Triad for designers. The triad can help designers implement privacy systems and technologies that foster interactions that naturally align with users’ expectations. It can also help designers think through potential risks arising from these interactions (e.g., phishing or inadvertent privacy disclosures).
Maxwell Keleher, Khadija Baig, Sonia Chiasson
Int. J. Hum. Comput. Stud.3
2025 Workshop on Cybersecurity and Sustainability
David Barrera 0003, Maxwell Keleher, Sonia Chiasson
COMPASS3
2025 "Sign in with ... Privacy": Timely Disclosure of Privacy Differences among Web SSO Login Options
abstract
The number of login options on websites has increased since the introduction of web single sign-on (SSO) protocols. Web SSO services allow users to grant websites or relying parties (RPs) access to their personal profile information from identity provider (IdP) accounts. Many RP sites fail to provide sufficient privacy-related information to allow users to make informed login decisions. Moreover, privacy differences in permission requests across login options are largely hidden from users and are time-consuming to manually extract and compare. In this article, we present an empirical analysis of popular RP implementations supporting three major IdP login options (Facebook, Google, and Apple) and categorize RPs in the top 500 sites into four client-side code patterns. Informed by these RP patterns, we design and implement SSOPrivateEye (SPEye), a browser extension prototype that extracts and displays to users permission request information from SSO login options in RPs covering the three IdPs.
Srivathsan G. Morkonda, Sonia Chiasson, Paul C. van Oorschot
ACM Trans. Priv. Secur.2
2024 Balancing Security and Longevity: Benefits of Modular IoT Infrastructure
abstract
IoT device disposal involves all of the challenges associated with disposal of non-IoT devices, and introduces the additional challenge of purging sensitive data from the IoT components. These challenges push IoT device owners to make decisions with negative environmental, security, and privacy consequences. This paper investigates the extent to which security and privacy play a role in users’ decisions to retire home IoT devices. Through an online questionnaire administered to 195 users, we seek to understand motivations and behaviours surrounding disposal of IoT devices. We find that security is not a direct motivator for owners to cease using IoT devices of all types; in many cases loss of functionality is a greater motivator to dispose of a device. We argue that a new modular security paradigm can allow both increased security for users and longer lasting devices.
Maxwell Keleher, David Barrera 0003, Sonia Chiasson
NSPW3
2024 Influences of displaying permission-related information on web single sign-on login decisions
Srivathsan G. Morkonda, Sonia Chiasson, Paul C. van Oorschot
Comput. Secur.2
2023 "A Solution to a Problem that Didn't Exist?": Exploring Attitudes Towards Smart Streetlight Systems
Anna-Lena Theus, Sonia Chiasson
INTERACT (3)2
2023 Security and Privacy Perceptions of Mental Health Chatbots
abstract
Mental health chatbots are AI chatbots that aim to mimic human conversations about how a user feels, help a user work through issues they are facing, suggest wellness exercises to complete, and help track a user’s mood over time. We compare the information disclosure practices and security and privacy concerns of adopters and non-adopters of mental health chatbots. We conducted a survey with 180 participants (30 adopters, 150 non-adopters), collecting data about what information they would hypothetically disclose to mental health chatbots, and concerns they had related to chatbots. We found that compared to non-adopters, adopters were more trusting of chatbots, were willing to reveal more information, perceived security and privacy risks to be less likely, and took fewer precautions.
Paulina Chametka, Sana Maqsood, Sonia Chiasson
PST3
2022 Understanding individual differences: factors affecting secure computer behaviour
abstract
Understanding users' individual differences may provide clues to help identify computer users who are prone to act insecurely. We examine factors that impact home users' reported computer security behaviour. We conducted two online surveys with a total of 650 participants to investigate the relationship between self-reported security behaviour and users' knowledge, motivation, confidence, risk propensity and sex-typed characteristics. We found that all of these factors impacted security behaviour, with knowledge as the most important predictor. We further show that a user's affinity to feminine or masculine characteristics is a better determinant of security behaviour than using binary male/female descriptors. Our study enabled us to confirm earlier results in the literature in a non-organisational setting, and to extend the literature by studying additional factors and by comparing the relative importance of each factor as a predictor of security behaviour.
Matthew Hull, Leah Zhang-Kennedy, Khadija Baig, Sonia Chiasson
Behav. Inf. Technol.4
2022 Privacy and Safety on Social Networking Sites: Autistic and Non-Autistic Teenagers' Attitudes and Behaviors
abstract
Autistic teenagers are suspected to be more vulnerable to privacy and safety threats on social networking sites (SNS) than the general population. However, there are no studies comparing these users’ privacy and safety concerns and protective strategies online with those reported by non-autistic teenagers. Furthermore, researchers have yet to identify possible explanations for autistic teenagers’ increased risk of online harms. To address these research gaps, we conducted semi-structured interviews with 12 autistic and 16 non-autistic teenagers assessing their privacy- and safety-related attitudes and behaviors on SNS, and factors affecting them. We used videos demonstrating relevant SNS scenarios as prompts to engage participants in conversation. Through our thematic analyses, we found evidence that autistic teenagers may be more averse to taking risks on SNS than non-autistic teenagers. Yet, several personal, social, and SNS design factors may make autistic teenagers more vulnerable to cyberbullying and social exclusion online. We provide recommendations for making SNS safer for autistic teenagers. Our research highlights the need for more inclusive usable privacy and security research with this population.
Jessica Nicole Rocheleau, Sonia Chiasson
ACM Trans. Comput. Hum. Interact.2
2021 "They think it's totally fine to talk to somebody on the internet they don't know": Teachers' perceptions and mitigation strategies of tweens' online risks
abstract
Teachers play a key role in educating children about digital security and privacy. They are often at the forefront, witnessing incidents, dealing with the consequences, and helping children handle the technology-related risks. However, little is reported about teachers’ lived classroom experiences and their challenges in this regard. We conducted semi-structured interviews with 21 Canadian elementary school teachers to understand the risks teachers witness children aged 10–13 facing on digital media, teachers’ mitigation strategies, and how prepared teachers are to help children. Our results show that teachers regularly help children deal with digital risks outside of teaching official curriculum, ranging from minor privacy violations to severe cases of cyberbullying. Most issues reported by teachers were the result of typical behaviours which became risky because they took place over digital media. We use the results to highlight implications for how elementary schools address digital security and privacy.
Sana Maqsood, Sonia Chiasson
CHI2
2021 "It's So Difficult to Sever that Connection": The Role of FoMO in Users' Reluctant Privacy Behaviours
abstract
This paper provides empirical evidence of a link between the Fear of Missing Out (FoMO) and reluctant privacy behaviours, to help explain a gap between users’ privacy attitudes and their behaviours online (also known as the Privacy Paradox). Using Grounded Theory, we interviewed 25 participants and created a high-level empirically-grounded theory of the relationship between FoMO and reluctant privacy behaviours. We identify three main dimensions in which users feel pressured to participate even when they have privacy concerns, to avoid missing out. We discuss the implications of these results on the design of technologies, and how they may indicate systemic dark design.
Fiona Westin, Sonia Chiasson
CHI2
2021 Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols
Enis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson, Srdjan Capkun
USENIX Security Symposium4
2021 Design, Development, and Evaluation of a Cybersecurity, Privacy, and Digital Literacy Game for Tweens
abstract
Tweens are avid users of digital media, which exposes them to various online threats. Teachers are primarily expected to teach children safe online behaviours, despite not necessarily having the required training or classroom tools to support this education. Using the theory of procedural rhetoric and established game design principles, we designed a classroom-based cybersecurity, privacy, and digital literacy game for tweens that has since been deployed to over 300 Canadian elementary schools. The game, A Day in the Life of the JOs , teaches children about 25 cybersecurity, privacy, and digital literacy topics and allows them to practice what they have learned in a simulated environment. We employed a user-centered design process to create the game, iteratively testing its design and effectiveness with children and teachers through five user studies (with a total of 63 child participants and 21 teachers). Our summative evaluation with children showed that the game improved their cybersecurity, privacy, and digital literacy knowledge and behavioural intent and was positively received by them. Our summative evaluation with teachers also showed positive results. Teachers liked that the game represented the authentic experiences of children on digital media and that it aligned with their curriculum requirements; they were interested in using it in their classrooms. In this article, we discuss our process and experience of designing a production quality game for children and provide evidence of its effectiveness with both children and teachers.
Sana Maqsood, Sonia Chiasson
ACM Trans. Priv. Secur.2
2020 "I'm hoping they're an ethical company that won't do anything that I'll regret": Users Perceptions of At-home DNA Testing Companies
abstract
At-home DNA testing has become increasingly popular due to the ability to be able to gain both ancestry and health information, as well as connect with others who share your DNA. Do users have reasonable mental models of how these systems work? Do users have privacy concerns and what do they understand as the benefits and risks involved? We conducted 27 interviews with Canadian users of at-home DNA testing companies. Our interviews covered perceived and desired data use, data management, data sharing practices, control over data, and any regrets. Our qualitative analysis revealed that many users have inconsistencies in their mental models and liken their DNA data to their data stored with existing technologies, such as social media, rather than health data. They are generally either dismissive of privacy concerns towards themselves or their relatives or they had not considered privacy in their choice. We discuss our findings and propose possible future work in this area.
Khadija Baig, Reham Mohamed 0001, Anna-Lena Theus, Sonia Chiasson
CHI4
2020 Understanding Fitness Tracker Users' Security and Privacy Knowledge, Attitudes and Behaviours
abstract
Personal data collected by fitness trackers can leave users open to security and privacy threats, often without their knowledge. Using an online survey with 212 fitness tracker users, we asked questions to understand participants' knowledge, attitudes and behaviours related to security and privacy, associated with the use of their fitness trackers. We found that users do little to protect their data. While they seem confident about the type of data being collected, they are unsure about how it is being used. Understandably, users are more comfortable sharing their data with friends and work colleagues. We also found that users differentiate between the types of data they are willing to share, suggesting a need for improved sharing preferences. When considering scenarios describing data uses with security and privacy implications, participants recognized that many scenarios were plausible but frequently felt that the scenarios were unlikely to occur. Overall, our findings lead us to believe that fitness tracker users require a greater awareness of the collection, ownership, storage, and sharing practices related to the tracking of their data.
Sandra Gabriele, Sonia Chiasson
CHI2
2020 'Lime', 'Open Lock', and 'Blocked': Children's Perception of Colors, Symbols, and Words in Cybersecurity Warnings
abstract
Cybersecurity warnings are frequently ignored or misinterpreted by even experienced adults. While studies have been conducted to examine warning design for adults, there is little data to establish recommendations for children. We conducted user studies with 22 children (ages 10-12) and with 22 adults. We compare their risk perception of warning design parameters (signal colors, symbols, words) via card sorting and ranking activities followed by interviews. While our findings suggest similarities in how both groups interpret the design parameters (e.g., red, skull, and fatal convey danger), we also uncovered potential concerns with items currently used as security indicators (e.g., both groups had mixed interpretations of the open lock and police officer symbols). Individual risk perception, particularly for children, appears dependent on personal preferences and experience. Our findings suggest implications and future research directions for the design of cybersecurity warnings for children.
Rebecca Jeong, Sonia Chiasson
CHI2
2020 The Influence of Decaying the Representation of Older Social Media Content on Simulated Hiring Decisions
abstract
Decaying representations gradually make social media content less visible to readers over time, which can help users disassociate from past online activities. We explore whether shrinking, one decaying representation, influences managers' assessments and simulated hiring decisions of job candidates, compared to seeing a full profile or an empty profile with no posts. Our 3 x 2 between-subjects crowdsourced survey (N = 360 US managers) shows that shrunk or empty profiles led to more positive decisions than profiles in their original full format. However, shrunk profiles also further contributed to more positive impressions of the candidates. Shrinking did not help the candidate of either gender more than the other and demographics of managers had limited impact on their assessment. Further, our managers regularly search job candidates' social media profiles in real life, suggesting that shrinking could support users' privacy. We finally present implications for individuals' privacy on social media.
Reham Mohamed 0001, Paulina Chametka, Sonia Chiasson
CHI3
2019 'Think secure from the beginning': A Survey with Software Developers
abstract
Vulnerabilities persist despite existing software security initiatives and best practices. This paper focuses on the human factors of software security, including human behaviour and motivation. We conducted an online survey to explore the interplay between developers and software security processes, e.g., we looked into how developers influence and are influenced by these processes. Our data included responses from 123 software developers currently employed in North America who work on various types of software applications. Whereas developers are often held responsible for security vulnerabilities, our analysis shows that the real issues frequently stem from a lack of organizational or process support to handle security throughout development tasks. Our participants are self-motivated towards software security, and the majority did not dismiss it but identified obstacles to achieving secure code. Our work highlights the need to look beyond the individual, and take a holistic approach to investigate organizational issues influencing software security.
Hala Assal, Sonia Chiasson
CHI2
2019 Opt out of privacy or "go home": understanding reluctant privacy behaviours through the FoMO-centric design paradigm
abstract
This paper explores how the design of online technology influences social factors and manipulates users' online privacy behaviours. In short, users reveal information and participate in online activities even when reluctant due to the influence of dark patterns. We propose FoMO-Centric Design as a paradigm for explaining how dark pattern-infused design may lead users to reluctantly behave in a less secure or privacy-preserving way than their attitudes reflect. We review the literature for evidence pointing to the existence of such design and for potential explanations for how it works. We then discuss the implications, present a list of preliminary recommendations, and offer an agenda for the research community based on our findings.
Fiona Westin, Sonia Chiasson
NSPW2
2019 End-Users and Service Providers: Trust and Distributed Responsibility for Account Security
abstract
In a between-subjects study design, we compared responses from 170 online account users of two major service providers to explore issues relating to responsibility and trust for account security. Participants attributed clear roles between themselves and their service providers for preventing attacks, monitoring their accounts, and recovering their accounts. The emerging mental model of distributed responsibility does not match service providers stated terms of use. Users identified a variety of reasons for trusting different service providers, but reputation was viewed as especially important.
Yomna Abdelaziz, Daniela Napoli, Sonia Chiasson
PST3
2019 Mixed Pictures: Mental Models of Malware
abstract
Malware is a serious problem for users, who become affected as a result of the decisions they make online. This paper presents a study examining mental models related to malware and regular software, in hopes of finding clues to that will help us understand what users know about malware, and what we can do to help them make better decisions online. The study involved two drawing tasks, where participants were asked to draw their understanding of how a word processor and malware work, respectively. Several concerning patterns emerged. Participants seemed to regard malware as a fundamentally different kind of entity than regular software. They make black-and-white distinctions between malware and regular software in terms of whether the software is helpful or harmful, who the software serves, and who controls it. Finally, participants showed lesser knowledge of malware compared to regular software.
Eric Spero 0001, Milica Stojmenovic, Zahra Hassanzadeh, Sonia Chiasson, Robert Biddle
PST4
2018 An exploratory study of children's online password behaviours
abstract
With increasing use of technology and the Internet among children, we explore how they create passwords to protect their personal information. We conducted a study with children 11 to 13 years to understand their password practices. The results of the study indicated that these children create simple passwords consisting of their personal information, believe that these passwords are hard for a stranger to guess and do not have good understanding of creating strong passwords.
Sumbal Maqsood, Robert Biddle, Sana Maqsood, Sonia Chiasson
IDC4
2018 A day in the life of jos: a web-based game to increase children's digital literacy
abstract
Digital literacy is an important educational topic because most children consume and create digital media regularly. We used procedural rhetoric to iteratively design an educational game for 11--13 year olds about digital literacy topics. We conducted three empirical user studies to evaluate the game's usability and effectiveness throughout the design process. Results from our summative study showed that children's digital literacy knowledge and intended behavior improved significantly immediately after playing the game and one week later. They also found the game usable, fun, and relatable. We present a case study of our design process, and use insights from our work to propose recommendations for designing children's educational games using procedural rhetoric.
Sana Maqsood, Christine Mekhail, Sonia Chiasson
IDC3
2018 Assessing Non-Visual SSL Certificates with Desktop and Mobile Screen Readers
abstract
Effective SSL warnings can point out network attacks or potential phishing sites. Much focus has been placed on tweaking text, colours, and symbols to improve users' comprehension and adhesion. These optimized visualizations do not necessarily aid people with visual disabilities who hear warnings rather than see them. To assess the non-visual aspects of these security warnings, we conducted an expert evaluation of Google Chrome and Mozilla Firefox's SSL certificate dialogues with JAWS and Apple VoiceOver screen readers. Our findings suggest that warnings are mostly unreadable with assistive technology and, when accessible, do not effectively describe threat sources, at-risk data, or false positives. Future work will explore the effectiveness of potential non-visual redesigns through usability studies with visually impaired screen reader users.
Daniela Napoli, Sonia Chiasson
CCS2
2018 The aftermath of a crypto-ransomware attack at a large academic institution
Leah Zhang-Kennedy, Hala Assal, Jessica Nicole Rocheleau, Reham Mohamed 0001, Khadija Baig, Sonia Chiasson
USENIX Security Symposium6
2018 Technological and Human Factors of Malware Attacks: A Computer Security Clinical Trial Approach
abstract
The success (or failure) of malware attacks depends upon both technological and human factors. The most security-conscious users are susceptible to unknown vulnerabilities, and even the best security mechanisms can be circumvented as a result of user actions. Although there has been significant research on the technical aspects of malware attacks and defence, there has been much less research on how users interact with both malware and current malware defences. This article describes a field study designed to examine the interactions between users, antivirus (AV) software, and malware as they occur on deployed systems. In a fashion similar to medical studies that evaluate the efficacy of a particular treatment, our experiment aimed to assess the performance of AV software and the human risk factors of malware attacks. The 4-month study involved 50 home users who agreed to use laptops that were instrumented to monitor for possible malware attacks and gather data on user behaviour. This study provided some very interesting, non-intuitive insights into the efficacy of AV software and human risk factors. AV performance was found to be lower under real-life conditions compared to tests conducted in controlled conditions. Moreover, computer expertise, volume of network usage, and peer-to-peer activity were found to be significant correlates of malware attacks. We assert that this work shows the viability and the merits of evaluating security products, techniques, and strategies to protect systems through long-term field studies with greater ecological validity than can be achieved through other means.
Fanny Lalonde Lévesque, Sonia Chiasson, Anil Somayaji, José M. Fernandez 0001
ACM Trans. Priv. Secur.2
2017 No passwords needed: the iterative design of a parent-child authentication mechanism
abstract
Even though the vast majority of children are online, our exploration of the user authentication literature and available tools revealed few alternatives specifically for authenticating children. We create an authentication mechanism that reduces the password burden for children and adds customizable parental oversight to increase security. With Bluink, our industry partner, we iteratively designed and user tested three parent-child prototypes, with each iteration addressing issues raised in the previous iteration. Our final design is a parent-child authentication mechanism based on OpenID and FIDO U2F which allows children to log in to websites without requiring a password and enables parents using their mobile device to remotely determine whether a login request should be granted.
Kalpana Hundlani, Sonia Chiasson, Larry Hamid
MobileHCI2
2017 Cross-National Privacy Concerns on Data Collection by Government Agencies (Short Paper)
abstract
We conducted an online survey with 366 participants from Canada, India, the UK, and the US to compare privacy concerns and opinions about the collection of personal data by law enforcement and government agencies. We investigated what data participants were willing to share, in what circumstances participants were willing to allow data collection, what procedures companies should follow when they receive requests for customer information, and participants' general concern about their privacy. Statistical analysis showed that nationality and gender had significant impacts on participants' trust and perceptions of their governments, while nationality also impacted participants' willingness to share data under various circumstances. While participants were, on the whole, moderately amendable to data collection by government agencies given a court-ordered warrant, they also indicated a strong desire for increased transparency, and reported a lacklustre knowledge about privacy legislation.
Rebecca Cooper, Hala Assal, Sonia Chiasson
PST3
2016 Teaching with an Interactive E-book to Improve Children's Online Privacy Knowledge
abstract
We designed the Cyberheroes interactive e-book and conducted a preliminary user study to test its effectiveness in educating children aged 7 to 9 about online privacy risks. Children and parents found the book to be fun and engaging. Our study included pre and post interviews and knowledge assessment. It showed that the interactive e-book successfully improved children's understanding of privacy risks while exhibiting excellent retention in knowledge after one week.
Leah Zhang-Kennedy, Sonia Chiasson
IDC2
2016 From Nosy Little Brothers to Stranger-Danger: Children and Parents' Perception of Mobile Threats
abstract
The rise in mobile media use by children has heightened parents' concerns for their online safety. Through semi-structured interviews of parent-child dyads, we explore the perceived privacy and security threats faced by children aged seven to eleven along with the protection mechanisms employed. We identified four models of privacy held by children. Furthermore, we found that children's concerns fit into four child-adversary threat models: child-peers, child-media, child-strangers, and child-parents. Their concerns differed from the five threat models held by the parents: child-peers, child-media, child-strangers, child-technology, and child-self. Parents used a variety of protection strategies to minimize children's exposure to external threats. In reality, however, our results suggest that security and privacy risks from an internal family member or a friend are far more common than harm from outsiders.
Leah Zhang-Kennedy, Christine Mekhail, Yomna Abdelaziz, Sonia Chiasson
IDC4
2016 An Eye-tracking Evaluation of Driver Distraction and Unfamiliar Road Signs
abstract
It is difficult enough for drivers to handle distractions when they are in a familiar environment, but what happens when drivers are placed in a new environment? We explore drivers' behaviour when they encounter road signs from three countries. We conducted two eye-tracking studies with 50 participants. Participants spent increased time looking at unfamiliar road signs. Misinterpretation occurred due to the influence of previous experience and many drivers drove at reduced speeds throughout to compensate for the anticipated cognitive load.
Stephanie Hurtado, Sonia Chiasson
AutomotiveUI2
2016 Cesar: Visual representation of source code vulnerabilities
abstract
Code analysis tools are not widely accepted by developers, and software vulnerabilities are detected by the thousands every year. We take a user-centered approach to that problem, starting with analyzing one of the popular open source static code analyzers, and uncover serious usability issues facing developers. We then design Cesar, a system offering developers a visual analysis environment to support their quest to rid their code of vulnerabilities. We present a prototype implementation of Cesar, and perform a usability analysis of the prototype and the visualizations it employs. Our analysis shows that the prototype is promising in promoting collaboration, exploration, and enabling developers to focus on the overall quality of their code as well as inspect individual vulnerabilities. We finally provide general recommendations to guide future designs of code review tools to enhance their usability.
Hala Assal, Sonia Chiasson, Robert Biddle
VizSEC2
2016 The Role of Instructional Design in Persuasion: A Comics Approach for Improving Cybersecurity
abstract
Although computer security technologies are the first line of defense to secure users, their success is dependent on individuals’ behavior. It is therefore necessary to persuade users to practice good computer security. This interview analysis of users’ conceptualization of security password guessing attacks, antivirus protection, and mobile online privacy shows that poor understanding of security threats influences users’ motivation and ability to practice safe behaviors. An online interactive comic series called Secure Comics was designed and developed based on instructional design principles to address this problem. An eye-tracking experiment suggests that the graphical and interactive components of the comics direct users’ attention and facilitate comprehension of the information. In the evaluations of Secure Comics, results from several user studies show that the comics improve understanding and motivate positive changes in security management behavior. The implication of the findings to better understand the role of instructional design and persuasion in education technology are discussed.
Leah Zhang-Kennedy, Sonia Chiasson, Robert Biddle
Int. J. Hum. Comput. Interact.2
2016 Bend Passwords: using gestures to authenticate on flexible devices
Sana Maqsood, Sonia Chiasson, Audrey Girouard
Pers. Ubiquitous Comput.2
2015 What's the deal with privacy apps?: a comprehensive exploration of user perception and usability
abstract
We explore mobile privacy through a survey and through usability evaluation of three privacy-preserving mobile applications. Our survey explores users' knowledge of privacy risks, as well as their attitudes and motivations to protect their privacy on mobile devices. We found that users have incomplete mental models of privacy risks associated with such devices. And, although participants believe they are primarily responsible for protecting their own privacy, there is a clear gap between their perceived privacy risks and the defenses they employ. For example, only 6% of participants use privacy-preserving applications on their mobile devices, but 83% are concerned about privacy. Our usability studies show that mobile privacy-preserving tools fail to fulfill fundamental usability goals such as learnability and intuitiveness---potential reasons for their low adoption rates. Through a better understanding of users' perception and attitude towards privacy risks, we aim to inform the design of privacy-preserving mobile applications. We look at these tools through users' eyes, and provide recommendations to improve their usability and increase user-acceptance.
Hala Assal, Stephanie Hurtado, Ahsan Imran, Sonia Chiasson
MUM4
2015 Choose Your Own Authentication
abstract
To solve the long-standing problems users have in creating and remembering text passwords, a wide variety of alternative authentication schemes have been proposed. Some of these schemes outperform others by various metrics in various contexts. However, none unilaterally outperform all others, and so text passwords persist as the main scheme applications depend upon. In this paper, we challenge the long-standing assumption that only one authentication scheme can be offered by an application service. We propose Choose Your Own Authentication (CYOA): a novel authentication architecture that enables users to choose a scheme amongst several available alternatives. CYOA would enable users to select whichever scheme best suits their preferences, abilities, and usage context. Existing text password systems could easily be replaced. Furthermore, the three-party architecture would enable delegating the management of authentication systems to trusted-third parties. The architecture allows rapid deployment and testing of novel authentication technologies. Our two-week usability study suggests that participants were willing to leverage alternative schemes. Participants were confident that CYOA could keep their financial information secure.
Alain Forget, Sonia Chiasson, Robert Biddle
NSPW2
2015 User Perceptions of Sharing, Advertising, and Tracking
Farah Chanchary, Sonia Chiasson
SOUPS2
2015 Quantifying the security advantage of password expiration policies
Sonia Chiasson, Paul C. van Oorschot
Des. Codes Cryptogr.1
2015 Why phishing still works: User strategies for combating phishing attacks
Mohamed Alsharnouby, Furkan Alaca, Sonia Chiasson
Int. J. Hum. Comput. Stud.3
2015 User-centred authentication feature framework
abstract
Purpose – This paper aims to propose that more useful novel schemes could develop from a more principled examination and application of promising authentication features. Text passwords persist despite several decades of evidence of their security and usability challenges. It seems extremely unlikely that a single scheme will globally replace text passwords, suggesting that a diverse ecosystem of multiple authentication schemes designed for specific environments is needed. Authentication scheme research has thus far proceeded in an unstructured manner. Design/methodology/approach – This paper presents the User-Centred Authentication Feature Framework, a conceptual framework that classifies the various features that knowledge-based authentication schemes may support. This framework can used by researchers when designing, comparing and innovating authentication schemes, as well as administrators and users, who can use the framework to identify desirable features in schemes available for selection. Findings – This paper illustrates how the framework can be used by demonstrating its applicability to several authentication schemes, and by briefly discussing the development and user testing of two framework-inspired schemes: Persuasive Text Passwords and Cued Gaze-Points. Originality/value – This framework is intended to support the increasingly diverse ecosystem of authentication schemes by providing authentication researchers, professionals and users with the increased ability to design, develop and select authentication schemes better suited for particular applications, environments and contexts.
Alain Forget, Sonia Chiasson, Robert Biddle
Inf. Comput. Secur.2
2014 Stop Clicking on "Update Later": Persuading Users They Need Up-to-Date Antivirus Protection
Leah Zhang-Kennedy, Sonia Chiasson, Robert Biddle
PERSUASIVE2
2014 Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in Motion
abstract
We explore the robustness and usability of moving-image object recognition (video) CAPTCHAS, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image CAPTCHAS involving rigid objects. We first present an attack that defeats instances of such a CAPTCHA (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely, randomly changing the font of individual characters, or even randomly varying the number of characters in the codeword). We implement the modified CAPTCHAS and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets. Worse yet, our GPU-based implementation shows that our automated approach can decode these captchas faster than humans can, and we can do so at a relatively low cost of roughly 50 cents per 1,000 captchas solved based on Amazon EC2 rates circa 2012. To further demonstrate the challenges in designing usable captchas, we also implement and test another variant of moving text strings using the known emerging images concept. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images idea resist our current attack where others fail.
Yi Xu 0006, Gerardo Reynaga, Sonia Chiasson, Jan-Michael Frahm, Fabian Monrose, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.3
2013 A clinical study of risk factors related to malware infections
abstract
The success of malicious software (malware) depends upon both technical and human factors. The most security conscious users are vulnerable to zero-day exploits; the best security mechanisms can be circumvented by poor user choices. While there has been significant research addressing the technical aspects of malware attack and defense, there has been much less research reporting on how human behavior interacts with both malware and current malware defenses.
Fanny Lalonde Lévesque, Jude Nsiempba, José M. Fernandez 0001, Sonia Chiasson, Anil Somayaji
CCS4
2013 Passwords on flexible display devices
abstract
Flexible display devices allow users to interact with the device by deforming the surface of the display to trigger a command. When these devices become mainstream, for example as smart phones, e-readers, or tablets, they will require a means of authenticating legitimate users. In this poster, we present an authentication scheme for flexible display devices, its implementation on a flexible display prototype and an ongoing user study evaluating the usability and security of our system.
Sana Maqsood, Sonia Chiasson, Audrey Girouard
CCS2
2013 Improving user authentication on mobile devices: a touchscreen graphical password
abstract
Typing text passwords is challenging when using touchscreens on mobile devices and this is becoming more problematic as mobile usage increases. We designed a new graphical password scheme called Touchscreen Multi-layered Drawing (TMD) specifically for use with touchscreens. We conducted an exploratory user study of three existing graphical passwords on smart phones and tablets with 31 users. From this, we set our design goals for TMD to include addressing input accuracy issues without having to memorize images, while maintaining an appropriately secure password space. Design features include warp cells which allow TMD users to continuously draw their passwords across multiple layers in order to create more complex passwords than normally possible on a small screen. We compared the usability of TMD to Draw A Secret (DAS) on a tablet computer and a smart phone with 90 users. Results show that TMD improves memorability, addresses the input accuracy issues, and is preferred as a replacement for text passwords on mobile devices.
Hsin-Yi Chiang, Sonia Chiasson
Mobile HCI2
2013 U-PriSM 2: the second usable privacy and security for mobile devices workshop
abstract
The Second Usable Privacy and Security for Mobile Devices Workshop (U-PriSM 2) was held with MobileHCI'13. The U-PriSM 2 workshop was an opportunity for researchers and practitioners to discuss research challenges and experiences around the usable privacy and security of mobile devices (smart phones and tablets). Security often involves having non-security experts, or even novice users, regularly making important security decisions while their main focus is on other primary tasks. This is especially true for mobile devices where users can quickly and easily install apps, where user interfaces are minimal due to space constraints, and where users are often distracted by their environment.
Sonia Chiasson, Heather Crawford, Serge Egelman, Pourang Irani
Mobile HCI1
2013 Writing down your password: Does it help?
abstract
Users are able to remember their phone numbers and postal codes, their student numbers, PIN numbers, and social insurance numbers. Why, then, do users have trouble remembering their passwords? This paper considers the hypothesis that being able to access written notes when needed would eventually help users to memorize the password. Further we hypothesize that writing down passwords encourages the use of passwords that are more complex than their unwritten (memorized) counterparts. We surveyed 31 participants on their opinions and experiences with writing down passwords and tested whether these participants created more complex passwords when they were encouraged to write them down. Finally, we observed whether written passwords had higher login success rates when tested again at least one week later. Results indicate that regardless of the experimental condition, users preferred to memorize their passwords than to take the extra step of referring to their written notes. Additionally, memorized and written passwords were remembered equally well. Finally, we found that users who had difficulty logging in had passwords with significantly higher mean entropy, which confirms the heuristic that complex passwords are harder to remember. We also unexpectedly found that users password habits are so strongly ingrained that they often ignored our instructions about writing or memorizing their password and continued to use their preestablished strategy. This observation is noteworthy for anyone conducting user authentication research.
Vanessa Boothroyd, Sonia Chiasson
PST2
2013 The Usability of CAPTCHAs on Smartphones
Gerardo Reynaga, Sonia Chiasson
SECRYPT2
2012 Tapas: design, implementation, and usability evaluation of a password manager
abstract
Passwords continue to prevail on the web as the primary method for user authentication despite their well-known security and usability drawbacks. Password managers offer some improvement without requiring server-side changes. In this paper, we evaluate the security of dual-possession authentication, an authentication approach offering encrypted storage of passwords and theft-resistance without the use of a master password. We further introduce Tapas, a concrete implementation of dual-possession authentication leveraging a desktop computer and a smartphone. Tapas requires no server-side changes to websites, no master password, and protects all the stored passwords in the event either the primary or secondary device (e.g., computer or phone) is stolen. To evaluate the viability of Tapas as an alternative to traditional password managers, we perform a 30 participant user study comparing Tapas to two configurations of Firefox's built-in password manager. We found users significantly preferred Tapas. We then improve Tapas by incorporating feedback from this study, and reevaluate it with an additional 10 participants.
Daniel McCarney, David Barrera 0003, Jeremy Clark, Sonia Chiasson, Paul C. van Oorschot
ACSAC4
2012 Security and Usability Challenges of Moving-Object CAPTCHAs: Decoding Codewords in Motion
Yi Xu 0006, Gerardo Reynaga, Sonia Chiasson, Jan-Michael Frahm, Fabian Monrose, Paul C. van Oorschot
USENIX Security Symposium3
2012 Persuasive Cued Click-Points: Design, Implementation, and Evaluation of a Knowledge-Based Authentication Mechanism
abstract
This paper presents an integrated evaluation of the Persuasive Cued Click-Points graphical password scheme, including usability and security evaluations, and implementation considerations. An important usability goal for knowledge-based authentication systems is to support users in selecting passwords of higher security, in the sense of being from an expanded effective security space. We use persuasion to influence user choice in click-based graphical passwords, encouraging users to select more random, and hence more difficult to guess, click-points.
Sonia Chiasson, Elizabeth Stobert, Alain Forget, Robert Biddle, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.1
2010 Exploring usability effects of increasing security in click-based graphical passwords
abstract
Graphical passwords have been proposed to address known problems with traditional text passwords. For example, memorable user-chosen text passwords are predictable, but random system-assigned passwords are difficult to remember. We explore the usability effects of modifying system parameters to increase the security of a click-based graphical password system. Generally, usability tests for graphical passwords have used configurations resulting in password spaces smaller than that of common text passwords. Our two-part lab study compares the effects of varying the number of click-points and the image size, including when different configurations provide comparable password spaces. For comparable spaces, no usability advantage was evident between more click-points, or a larger image. This is contrary to our expectation that larger image size (with fewer click-points) might offer usability advantages over more click-points (with correspondingly smaller images). The results suggest promising opportunities for better matching graphical password system configurations to device constraints, or capabilities of individual users, without degrading usability. For example, more click-points could be used on smart-phone displays where larger image sizes are not possible.
Elizabeth Stobert, Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
ACSAC3
2010 Shoulder-surfing resistance with eye-gaze entry in cued-recall graphical passwords
abstract
We present Cued Gaze-Points (CGP) as a shoulder-surfing resistant cued-recall graphical password scheme where users gaze instead of mouse-click. This approach has several advantages over similar eye-gaze systems, including a larger password space and its cued-recall nature that can help users remember multiple distinct passwords. Our 45-participant lab study is the first evaluation of gaze-based password entry via user-selected points on images. CGP's usability is potentially acceptable, warranting further refinement and study.
Alain Forget, Sonia Chiasson, Robert Biddle
CHI2
2009 Multiple password interference in text passwords and click-based graphical passwords
abstract
The underlying issues relating to the usability and security of multiple passwords are largely unexplored. However, we know that people generally have difficulty remembering multiple passwords. This reduces security since users reuse the same password for different systems or reveal other passwords as they try to log in. We report on a laboratory study comparing recall of multiple text passwords with recall of multiple click-based graphical passwords. In a one-hour session (short-term), we found that participants in the graphical password condition coped significantly better than those in the text password condition. In particular, they made fewer errors when recalling their passwords, did not resort to creating passwords directly related to account names, and did not use similar passwords across multiple accounts. After two weeks, participants in the two conditions had recall success rates that were not statistically different from each other, but those with text passwords made more recall errors than participants with graphical passwords. In our study, click-based graphical passwords were significantly less susceptible to multiple password interference in the short-term, while having comparable usability to text passwords in most other respects.
Sonia Chiasson, Alain Forget, Elizabeth Stobert, Paul C. van Oorschot, Robert Biddle
CCS1
2008 Persuasion for Stronger Passwords: Motivation and Pilot Study
Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
PERSUASIVE2
2008 Improving text passwords through persuasion
abstract
Password restriction policies and advice on creating secure passwords have limited effects on password strength. Influencing users to create more secure passwords remains an open problem. We have developed Persuasive Text Passwords (PTP), a text password creation system which leverages Persuasive Technology principles to influence users in creating more secure passwords without sacrificing usability. After users choose a password during creation, PTP improves its security by placing randomly-chosen characters at random positions into the password. Users may shuffle to be presented with randomly-chosen and positioned characters until they find a combination they feel is memorable. In this paper, we present an 83-participant user study testing four PTP variations. Our results show that the PTP variations significantly improved the security of users' passwords. We also found that those participants who had a high number of random characters placed into their passwords would deliberately choose weaker pre-improvement passwords to compensate for the memory load. As a consequence of this compensatory behaviour, there was a limit to the gain in password security achieved by PTP.
Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
SOUPS2
2007 Graphical Password Authentication Using Cued Click Points
Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
ESORICS1
2007 A second look at the usability of click-based graphical passwords
abstract
Click-based graphical passwords, which involve clicking a set of user-selected points, have been proposed as a usable alternative to text passwords. We conducted two user studies: an initial lab study to revisit these usability claims, explore for the first time the impact on usability of a wide-range of images, and gather information about the points selected by users; and a large-scale field study to examine how click-based graphical passwords work in practice. No such prior field studies have been reported in the literature. We found significant differences in the usability results of the two studies, providing empirical evidence that relying solely on lab studies for security interfaces can be problematic. We also present a first look at whether interference from having multiple graphical passwords affects usability and whether more memorable passwords are necessarily weaker in terms of security.
Sonia Chiasson, Robert Biddle, Paul C. van Oorschot
SOUPS1
2007 Helping users create better passwords: is this the right approach?
abstract
Users tend to form their own mental models of good passwords regardless of any instructions provided. They also tend to favour memorability over security. In our study comparing two mnemonic phrase-based password schemes, we found a surprising number of participants misused both schemes. Intentional or not, they misused the system such that their task of password creation and memorization became easier. Thus, we believe that instead of better instructions or password schemes, a new approach is required to convince users to create more secure passwords. One possibility may lie in employing Persuasive Technology.
Alain Forget, Sonia Chiasson, Robert Biddle
SOUPS2
2006 A Usability Study and Critique of Two Password Managers
Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
USENIX Security Symposium1
2005 Testing the media equation with children
abstract
Designers of children's technology are often more interested in user motivation than those who design systems for adults. Since children's technology often has aims such as education or practice, keeping the user engaged and interested is an important objective. The Media Equation - the idea that people respond socially to computers - shows potential for improving engagement and motivation. Studies have shown that people are more positive about both themselves and the computer when software exhibits certain social characteristics. To explore the possible value of the Media Equation as a design concept for children's software, we replicated two of the original Media Equation studies, concerning the effects of praise and team formation. Our results, however, were contrary to our expectations: we did not find evidence that children were significantly affected by social characteristics in software, and adults were influenced in only a few cases. These results raise questions about using the Media Equation as a design principle for children's software.
Sonia Chiasson, Carl Gutwin
CHI1