Karen Renaud

dblp:r/KarenRenaud · also Karen Vera Renaud · DBLP profile ↗
← Back
71ranked-venue papers
31as first author
24since 2021 · last 2026
0000-0002-7187-6531ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 41 · 16 first-author · 16 since 2021Human-computer interaction and ubiquitous computing · 19 · 8 first-author · 6 since 2021Software engineering, systems software and programming languages · 5 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Revealing privacy needs during life's significant transitions
abstract
Abstract Abstract: People experience transitional events during their lives that are significant, disruptive, and potentially challenging to navigate. Emotions usually run high, and the central actor may seek personalized support from “others” who are often identified online. An increased online presence, however, can also exacerbate vulnerabilities, making it challenging for individuals to preserve their privacy. Privacy-Enhancing Technologies (PETs) can support people undergoing transitions to have more control over their online identity and related disclosures. Nevertheless, available tools of this kind do not explicitly cater to the needs of such populations, leading to low uptake. To inform the future development of bespoke PETs, we carried out a survey to understand the population characteristics and online behaviors of four transition groups: (1) leaving the Armed Forces; (2) Relationship Breakdown (Romantic); (3) Serious Illness (Cancer); and (4) LGBTQ+ (“coming out” or gender transition). Our findings suggest that bespoke PETs should engender resilience and a sense of control over what is shared online via the identification, creation, and maintenance of “safe spaces” in which network members are restricted to trusted others who are deemed supportive of the actor’s transition.
Ryan Colin Gibson, Karen Renaud, Wendy Moncur, Irina Cojuharenco, Zhou Hu, Diane Morrow, Lorraine Wright, Nick Hulbert-Williams
Interact. Comput.2
2025 Achieving Resilience: Data Loss and Recovery on Devices for Personal Use in Three Countries
Julia Wunder, Rick Wash, Karen Renaud, Daniela A Oliveira, Zinaida Benenson
CHI3
2025 A Value-Driven Approach to the Online Consent Conundrum: A Study with the Unemployed
abstract
Online services are required to gain informed consent from users to collect, store and analyse their personal data, both intentionally divulged and derived during their use of the service. There are many issues with these forms: they are too long, too complex and demand the user's attention too frequently. Many users consent without reading so do not know what they are agreeing to. As such,granted consent is effectively uninformed. In this paper, we report on two studies we carried out to arrive at a value-driven approach to inform efforts to reduce the length of consent forms. The first study interviewed unemployed users to identify the values they want these forms to satisfy. The second survey study helped us to quantify the values and value creators. To ensure that we understood the particular valuation of the unemployed, we compared their responses to those of an employed demographic and observed no significant differences between their prioritisation on any of the values. However, we did find substantial differences between values and value creators, with effort minimisation being most valued by our participants.
Paul van Schaik, Karen Renaud
ICISSP (1)2
2025 Would 'Secure' Users Lead to Secure Commons? Surprisingly Not! A framework to evaluate effective power and collective outcomes in cybersecurity
abstract
Individuals are often held responsible when adverse cyber incidents occur. The ensuing narrative, explaining the occurrence, points to confounding factuals e.g., inability to act securely, a convincingly deceptive attack, or selfishness/laziness. The underlying assumption is that: if only humans were different (acted securely), such adverse events would not occur. In this paper, we use a game theoretic approach to investigate the counterfactual in cyber: what would happen if individuals were indeed different? To that end, we propose a generic framework drawing upon two games. Our proposed framework can help move the field towards judicious responsibilization of individuals and eliminate knee-jerk scapegoating. We use this framework to examine a specific social harm — data pollution. Our explorations show that even if individuals always behaved securely, this would not necessarily improve collective outcomes. We show that individuals are sometimes not in a position to change security outcomes, however secure their behaviours. The proposed framework can be applied to highlight those entities that are indeed in a position to influence security outcomes in the wider aggregate harm landscape. Future research should build on our work to assign responsibilities in the cyber domain, explore ways to operationalise the games to carry out empirical research, and contribute to novel paradigms such as ethical responsibilization in the context of data breaches.
Partha Das Chowdhury, Karen Renaud, Ingrid Ott
NSPW2
2025 Unpacking the Social and Emotional Dimensions of Security and Privacy User Engagement
Nina Gerber, Verena Zimmermann, Alexandra von Preuschen, Karen Renaud
SOUPS4
2024 Nudging Using Autonomous Agents: Risks and Ethical Considerations
abstract
This position paper briefly discusses nudging, its use by autonomous agents, potential risks and ethical considerations while creating such systems. Instead of taking a normative approach that guides all situations, the paper proposes a risk-driven questions-and-answer approach. The paper takes the position that this is a pragmatic method, that is transparent about beneficial intentions, foreseeable risks, and mitigations. Given the uncertainty in AI and autonomous agent capabilities, we believe that such pragmatic methods offer a plausibly safe path, without sacrificing flexibility in domain and technology.
Vivek Nallur, Karen Renaud, Aleksei Gudkov
EUMAS2
2024 "When Data Breaches Happen, Where Does the Buck Stop?... and where should it stop?"
abstract
A digital-first society requires its citizens to carry out essential activities online e.g., applying for a passport, managing pension funds or scheduling medical appointments. Sensitive and personal information is requested and provided in the hope that the confidentiality, integrity and availability thereof will be preserved. In reality, data breaches occur with distressing regularity. When this occurs, ‘second’ victims are created: the customers whose data has been leaked. In many cases, service providers demonstrate very little care or concern for these victims, responsibilizing instead of supporting them. We surveyed 175 respondents, including second victims, non-victims and managers. It becomes clear that a ‘feudal security’ paradigm informs organisations’ responses to data breaches. Indeed, the buck seems to stop with second victims, instead of with the breached service provider. We propose an ‘Ethical Responsibilization’ paradigm which would see second victims treated more equitably and fairly.
Partha Das Chowdhury, Karen Renaud, Awais Rashid
NSPW2
2024 Privacy policy analysis: A scoping review and research agenda
abstract
Online users often neglect the importance of privacy policies - a critical aspect of digital privacy and data protection. This scoping review addresses this oversight by delving into privacy policy analysis, aiming to establish a comprehensive research agenda. The study's objective was to explore the analytic techniques employed in privacy policy analysis and to identify the associated challenges. Following the Preferred Reporting Items for Systematic Reviews and Meta-Analyses for Scoping Reviews (PRISMA-ScR) checklist, the review selected n = 97 relevant studies. The findings reveal a diverse array of techniques used, encompassing automated machine learning and natural language processing, and manual content analysis. Notably, researchers grapple with challenges like linguistic nuances, ambiguity, and complex data harvesting methods. Additionally, the lack of privacy-centric theoretical frameworks and a dearth of user evaluations in many studies limit their real-world applicability. The review concludes by proposing a set of research recommendations to shape the future research agenda in privacy policy analysis.
Karl van der Schyff, Suzanne Prior, Karen Renaud
Comput. Secur.3
2024 VISTA: An inclusive insider threat taxonomy, with mitigation strategies
abstract
Insiders have the potential to do a great deal of damage, given their legitimate access to organisational assets and the trust they enjoy. Organisations can only mitigate insider threats if they understand what the different kinds of insider threats are, and what tailored measures can be used to mitigate the threat posed by each of them. Here, we derive VISTA (inclusiVe InSider Threat tAxonomy) based on an extensive literature review and a survey with C-suite executives to ensure that the VISTA taxonomy is not only scientifically grounded, but also meets the needs of organisations and their executives. To this end, we map each VISTA category of insider threat to tailored mitigations that can be deployed to reduce the threat.
Karen Renaud, Merrill Warkentin, Ganna Pogrebna, Karl van der Schyff
Inf. Manag.1
2024 Getting users to click: a content analysis of phishers' tactics and techniques in mobile instant messaging phishing
abstract
Purpose This study aims to investigate how phishers apply persuasion principles and construct deceptive URLs in mobile instant messaging (MIM) phishing. Design/methodology/approach In total, 67 examples of real-world MIM phishing attacks were collected from various online sources. Each example was coded using established guidelines from the literature to identify the persuasion principles, and the URL construction techniques employed. Findings The principles of social proof, liking and authority were the most widely used in MIM phishing, followed by scarcity and reciprocity. Most phishing examples use three persuasion principles, often a combination of authority, liking and social proof. In contrast to email phishing but similar to vishing, the social proof principle was the most commonly used in MIM phishing. Phishers implement the social proof principle in different ways, most commonly by claiming that other users have already acted (e.g. crafting messages that indicate the sender has already benefited from the scam). In contrast to email, retail and fintech companies are the most commonly targeted in MIM phishing. Furthermore, phishers created deceptive URLs using multiple URL obfuscation techniques, often using spoofed domains, to make the URL complex by adding random characters and using homoglyphs. Originality/value The insights from this study provide a theoretical foundation for future research on the psychological aspects of phishing in MIM apps. The study provides recommendations that software developers should consider when developing automated anti-phishing solutions for MIM apps and proposes a set of MIM phishing awareness training tips.
Rufai Ahmad, Sotirios Terzis, Karen Renaud
Inf. Comput. Secur.3
2024 "We're Not That Gullible!" Revealing Dark Pattern Mental Models of 11-12-Year-Old Scottish Children
abstract
Deceptive techniques known as dark patterns specifically target online users. Children are particularly vulnerable as they might lack the skills to recognise and resist these deceptive attempts. To be effective, interventions to forewarn and forearm should build on a comprehensive understanding of children’s existing mental models. To this end, we carried out a study with 11- to 12-year-old Scottish children to reveal their mental models of dark patterns. They were acutely aware of online deception, referring to deployers as being ‘up to no good.’ Yet, they were overly vigilant and construed worst-case outcomes, with even a benign warning triggering suspicion. We recommend that rather than focusing on specific instances of dark patterns in awareness raising, interventions should prioritise improving children’s understanding of the characteristics of, and the motivations behind, deceptive online techniques. By so doing, we can help them to develop a more robust defence against these deceptive practices.
Karen Renaud, Cigdem Sengul, Kovila P. L. Coopamootoo, Bryan Clift, Jacqui Taylor, Mark V. Springett, Benjamin Alan Morrison
ACM Trans. Comput. Hum. Interact.1
2023 'Ought' should not assume 'Can'? Basic Capabilities in Cybersecurity to Ground Sen's Capability Approach
abstract
We inhabit a ‘digital first’ society, which is only viable if everyone, regardless of ability and capacity, is able to benefit from online offerings in a safe and secure way. However, disabled individuals, people living under oppressive regimes, elderly citizens and individuals fleeing conflict can be excluded, because they might not have the opportunity to implement cybersecurity hygiene measures. To reduce this potential exclusion, it is crucial to make all users’ situated realities focal variables in policy debates and provisioning efforts. This requires a validated set of basic minimum capabilities which reflect individuals’ diverse personal and social realities. In this paper, we report on a scoping literature review intended to reveal the state of play with respect to capabilities-related research in the cyber domain. We motivate our initial focus on the over 65s for this investigation. We used advice from online government cybersecurity advisories to arrive at a set of five recommended cybersecurity hygiene tasks. These fed into a survey with sixty senior citizens to elicit the barriers they could envisage someone of their age encountering, in acting upon cybersecurity hygiene advice. The final deliverable is a candidate list of basic capabilities (cybersecurity) for seniors. This enables us to start measuring security and privacy poverty, an essential step in recognising and mitigating exclusion, as well as informing threat modelling efforts.
Partha Das Chowdhury, Karen Renaud
NSPW2
2023 Hybrid password meters for more secure passwords - a comprehensive study of password meters including nudges and password information
abstract
Supporting users with secure password creation is a well-explored yet unresolved research topic. A promising intervention is the password meter, i.e. providing feedback on the user's password strength as and when it is created. However, findings related to the password meter's effectiveness are varied. An extensive literature review revealed that, besides password feedback, effective password meters often include: (a) feedback nudges to encourage stronger passwords choices and (b) additional guidance. A between-subjects study was carried out with 645 participants to test nine variations of password meters with different types of feedback nudges exploiting various heuristics and norms. This study explored differences in resulting passwords: (1) actual strength, (2) memorability, and (3) user perceptions. The study revealed that password feedback, in combination with a feedback nudge and additional guidance, labelled a hybrid password meter, was generally more efficacious than either intervention on its own, on all three metrics. Yet, the type of feedback nudge targeting either the person, the password creation task, or the social context, did not seem to matter much. The meters were nearly equally efficacious. Future work should explore the long-term effects of hybrid password meters in real-life settings to confirm the external validity of these findings.
Verena Zimmermann, Karola Marky, Karen Renaud
Behav. Inf. Technol.3
2023 Cybersecurity Insights Gleaned from World Religions
abstract
Organisations craft and disseminate security policies, encoding the actions they want employees to take to preserve and protect organisational information resources. They engage in regular cybersecurity awareness and training drives to ensure that employees know what to do, and how to do it. Despite these efforts, employees make mistakes or do not comply with policy dictates, triggering cybersecurity incidents. The reality is that whereas cyber professionals propose, human nature disposes. In addressing this kind of conundrum, researchers suggest that it could be beneficial to learn from the established practices of other domains that also grapple with erratic human behaviours. This seems reasonable, given that cybersecurity is a relatively young field, and not yet particularly successful in accommodating human nature and fallibility, whereas other fields have years of experience coping with these kinds of problems. Here, we consider learning from religions, which have been around for millennia. The one aspect that all understand is human nature, and the tendency of humans to make mistakes and behave ill-advisedly, sometimes despite knowing better. Religions have developed a number of practices to accommodate human frailties, and to care for their adherents. This might well be a fruitful domain for cybersecurity professionals to learn from, in terms of harnessing effective mechanisms to encourage secure behaviours. To this end, we explored the literature on religions, and interviewed a number of religious leaders to produce a ‘vision for cybersecurity’. The vision was evaluated by cybersecurity professionals, its target audience. We provide our vision here, in the hope that it will launch a debate into a more equitable new era of ‘best practice’ in the cybersecurity domain.
Karen Renaud, Marc J. Dupuis
Comput. Secur.1
2023 Would US citizens accept cybersecurity deresponsibilization? Perhaps not
abstract
Responsibilizing governments provide advice about how to manage a variety of risks. If citizens do not heed the advice and things go wrong, they are expected to accept the adverse consequences without complaint. However, in some cases, citizens are unable or unwilling to embrace these government-assigned responsibilities and to act on the advice, for a variety of valid reasons. It may be appropriate for governments to provide more direct support: in essence, deresponsibilizing citizens who struggle to embrace the responsibility. In this paper, we explore whether US citizens would be willing to accept more help from their government in the cyber realm. Using two studies, we find that perceptions related to the government's competence and benevolence are necessary pre-requisites for a willingness to be deresponsibilized, and also that many respondents did not have confidence that either of these were sufficient. This deficiency might well render governments’ well-intended deresponsibilization endeavours futile. We conclude by proposing deresponsibilization strategies that acknowledge and accommodate this.
Karen Renaud, Karl van der Schyff, Stuart Macdonald
Comput. Secur.1
2023 Smart home cybersecurity awareness and behavioral incentives
abstract
Purpose Smart-home security involves multilayered security challenges related to smart-home devices, networks, mobile applications, cloud servers and users. However, very few studies focus on smart-home users. This paper aims to fill this gap by investigating the potential interests of adult smart-home users in cybersecurity awareness training and nonfinancial rewards that may encourage them to adopt sound cybersecurity practices. Design/methodology/approach A total of 423 smart-home users between the ages of 25 and 64 completed a survey questionnaire for this study, with 224 participants from Japan and 199 from the UK. Findings Cultural factors considerably influence adult smart-home users’ attitudes toward cybersecurity. Specifically, cultural differences impact their willingness to participate in cybersecurity awareness training, their views on the importance of cybersecurity training for children and senior citizens and their preference for nonfinancial rewards as an incentive for good cybersecurity behavior. These results highlight the need to consider cultural differences and their potential impact when developing and implementing cybersecurity programs that target smart-home users. Practical implications This research has two main implications. First, it provides insights for information security professionals on the importance of designing cost-effective and time-efficient cybersecurity awareness training programs for smart-home users. Second, the findings may assist governments in establishing nonfinancial incentives to encourage greater uptake of cybersecurity practices among smart-home users. Originality/value The paper investigates whether adult smart-home users are willing to spend time and money to engage in cybersecurity awareness training and to encourage their children and elderly parents to participate in training, as well. In addition, the paper examines incentives, especially nonfinancial rewards, that may motivate adult smart-home users to adopt cybersecurity behaviors at home. Furthermore, the paper analyses demographic differences among smart-home users in Japan and the UK.
N'guessan Yves-Roland Douha, Karen Renaud, Yuzo Taenaka, Youki Kadobayashi
Inf. Comput. Secur.2
2023 People want reassurance when making privacy-related decisions - Not technicalities
abstract
Online service users sometimes need support when making privacy-related decisions. Humans make decisions either slowly, by painstakingly consulting all possible information, or quickly, by relying on cues to trigger heuristics. Human emotions elicited by the decision context affects decisions, often without the decision maker being aware of it. We wanted to determine how an information-based decision can be supported, and also to understand which cues are used by a heuristics-based approach. Our first study enhanced understanding of underlying encryption mechanisms using metaphors. Our participants objected to efforts to make them ‘technical experts’, expressing a need for reassurance instead. We fed their free-text responses into a Q-sort, to determine which cues they rely on to make heuristic-based decisions. We confirmed the desire for reassurance. Our third study elicited ‘cyber stories’: Unprompted narratives about cyber-related experiences to detect emotional undertones in this domain. Responses revealed a general negativity, which is bound to influence cybersecurity-related decisions.
Oksana Kulyk, Karen Renaud, Stefan Costica
J. Syst. Softw.2
2022 Cybersecurity Regrets: I've had a few.... Je Ne Regrette
abstract
James Baldwin says: “though we would like to live without regrets, and sometimes proudly insist that we have none, this is not really possible, if only because we are mortal”. The field of cybersecurity has its fair share of poor outcomes, some of which are bound to be due to regrettable actions. Similar to other negative emotions, such as fear and shame, it is likely that organisations are using anticipated regret as a behavioural control mechanism in the cybersecurity domain. We explore the nature and characteristics of cyber-related regrets, and the extent to which regret (both anticipated and experienced) influences future cybersecurity decisions. We derive a process model of regret and report on the way cybersecurity regrets occur, what their outcomes are, and how people experience them. We conclude with suggested directions for future research.
Karen Renaud, Rosalind Searle, Marc J. Dupuis
NSPW1
2022 A quantification mechanism for assessing adherence to information security governance guidelines
abstract
Purpose Boards of Directors and other organisational leaders make decisions about the information security governance systems to implement in their companies. The increasing number of cyber-breaches targeting businesses makes this activity inescapable. Recently, researchers have published comprehensive lists of recommended cyber measures, specifically to inform organisational boards. However, the young cybersecurity industry has still to confirm and refine these guidelines. As a starting point, it would be helpful for organisational leaders to know what other organisations are doing in terms of using these guidelines. In an ideal world, bespoke surveys would be developed to gauge adherence to guidelines, but this is not always feasible. What we often do have is data from existing cybersecurity surveys. The authors argue that such data could be repurposed to quantify adherence to existing information security guidelines, and this paper aims to propose, and test, an original methodology to do so. Design/methodology/approach The authors propose a quantification mechanism to measure the degree of adherence to a set of published information security governance recommendations and guidelines targeted at organisational leaders. The authors test their quantification mechanism using a data set collected in a survey of 156 Italian companies on information security and privacy. Findings The evaluation of the proposed mechanism appears to align with findings in the literature, indicating the validity of the present approach. An analysis of how different industries rank in terms of their adherence to the selected set of recommendations and guidelines confirms the usability of our repurposed data set to measure adherence. Originality/value To the best of the authors’ knowledge, a quantification mechanism as the one proposed in this study has never been proposed, and tested, in the literature. It suggests a way to repurpose survey data to determine the extent to which companies are implementing measures recommended by published cybersecurity guidelines. This way, the proposed mechanism responds to increasing calls for the adoption of research practices that minimise waste of resources and enhance research sustainability.
Ivano Bongiovanni, Karen Renaud, Humphrey Brydon, Rénette J. Blignaut, Angelo Cavallo
Inf. Comput. Secur.2
2021 Accessible Cyber Security: The Next Frontier?
abstract
Researchers became aware of the need to pay attention to the usability of cyber security towards the end of the 20th century. This need is widely embraced now, by both academia and industry, as it has become clear that users are a very important link in the security perimeter of organisations. Two decades later, I will make the case for the inclusion and importance of a third dimension of human-centred security, that of accessibility. I will argue that technical measures, usability and accessibility should be equally important considerations during the design of security systems. Unless we do this, we risk ignoring the needs of vast swathes of the population with a range of disabilities. For many of these, security measures are often exasperatingly inaccessible. This talk is a call to action to the community of human-centred security researchers, all of whom have already made huge strides in improving the usability of security mechanisms.
Karen Renaud
ICISSP1
2021 Shame in Cyber Security: Effective Behavior Modification Tool or Counterproductive Foil?
abstract
Organizations often respond to cyber security breaches by blaming and shaming the employees who were involved. There is an intuitive natural justice to using such strategies in the belief that the need to avoid repeated shaming occurrences will encourage them to exercise more care. However, psychology highlights significant short- and long-term impacts and harmful consequences of felt shame. To explore and investigate this in the cyber domain, we asked those who had inadvertently triggered an adverse cyber security incident to tell us about their responses and to recount the emotions they experienced when this occurred. We also examined the impact of the organization’s management of the incident on the “culprit’s” future behaviors and attitudes. We discovered that those who had caused a cyber security incident often felt guilt and shame, and their employers’ responses either exacerbated or ameliorated these negative emotions. In the case of the former, there were enduring unfavorable consequences, both in terms of employee well-being and damaged relationships. We conclude with a set of recommendations for employers, in terms of responding to adverse cyber security incidents. The aim is to ensure that negative emotions, such as shame, do not make the incident much more damaging than it needs to be.
Karen Renaud, Rosalind Searle, Marc J. Dupuis
NSPW1
2021 Accessible authentication: dyslexia and password strategies
abstract
Purpose The purpose of this paper is to reveal the lived experiences of dyslexics in engaging with all kinds of alphanumeric authentication mechanisms. Design/methodology/approach A significant proportion of the world’s population experiences some degree of dyslexia, which can lead to spelling, processing, sequencing and retention difficulties. Passwords, being essentially sequences of alphanumeric characters, make it likely that dyslexics will struggle with these, even more so than the rest of the population. Here, this study explores the difficulties people with dyslexia face, their general experiences with passwords, the coping strategies they use and the advice they can provide to developers and others who struggle with passwords. This paper collects empirical data through semi-structured interviews with 13 participants. Thematic analysis was used to provide an in-depth view of each participant’s experience. Findings The main contribution of this paper is to provide evidence related to the inaccessibility dimensions of passwords as an authentication mechanism, especially for dyslexics and to recommend a solution direction. Research limitations/implications There is a possible volunteer bias, as this study is dealing with self-reported data including historical and reflective elements and this paper is seeking information only from those with self-declared or diagnosed dyslexia. Furthermore, many expressed interest or curiosity in the relationship between dyslexia and password difficulties, for some a motivation for their participation. Finally, given that the participants told us that dyslexics might hide, it is possible that the experiences of those who do hide are different from those who chose to speak to us and thus were not hiding. Originality/value A few authors have written about the difficulties dyslexics face when it comes to passwords, but no one has asked dyslexics to tell them about their experiences. This paper fills that gap.
Karen Renaud, Graham Johnson, Jacques Ophoff
Inf. Comput. Secur.1
2021 The "three M's" counter-measures to children's risky online behaviors: mentor, mitigate and monitor
abstract
Purpose The purpose of this paper is to scope the field of child-related online harms and to produce a resource pack to communicate all the different dimensions of this domain to teachers and carers. Design/methodology/approach With children increasingly operating as independent agents online, their teachers and carers need to understand the risks of their new playground and the range of risk management strategies they can deploy. Carers and teachers play a prominent role in applying the three M’s: mentoring the child, mitigating harms using a variety of technologies (where possible) and monitoring the child’s online activities to ensure their cybersecurity and cybersafety. In this space, the core concepts of “cybersafety” and “cybersecurity” are substantively different and this should be acknowledged for the full range of counter-measures to be appreciated. Evidence of core concept conflation emerged, confirming the need for a resource pack to improve comprehension. A carefully crafted resource pack was developed to convey knowledge of risky behaviors for three age groups and mapped to the appropriate “three M’s” to be used as counter-measures. Findings The investigation revealed key concept conflation, and then identified a wide range of harms and countermeasures. The resource pack brings clarity to this domain for all stakeholders. Research limitations/implications The number of people who were involved in the empirical investigation was limited to those living in Scotland and Nigeria, but it is unlikely that the situation is different elsewhere because the internet is global and children’s risky behaviors are likely to be similar across the globe. Originality/value Others have investigated this domain, but no one, to the authors’ knowledge, has come up with the “Three M’s” formulation and a visualization-based resource pack that can inform educators and carers in terms of actions they can take to address the harms.
Karen Renaud, Suzanne Prior
Inf. Comput. Secur.1
2021 The Nudge Puzzle: Matching Nudge Interventions to Cybersecurity Decisions
abstract
Nudging is a promising approach, in terms of influencing people to make advisable choices in a range of domains, including cybersecurity. However, the processes underlying the concept and the nudge’s effectiveness in different contexts, and in the long term, are still poorly understood. Our research thus first reviewed the nudge concept and differentiated it from other interventions before applying it to the cybersecurity area. We then carried out an empirical study to assess the effectiveness of three different nudge-related interventions on four types of cybersecurity-specific decisions. Our study demonstrated that the combination of a simple nudge and information provision, termed a “hybrid nudge,” was at least as, and in some decision contexts even more effective in encouraging secure choices as the simple nudge on its own. This indicates that the inclusion of information when deploying a nudge, thereby increasing the intervention’s transparency, does not necessarily diminish its effectiveness. A follow-up study explored the educational and long-term impact of our tested nudge interventions to encourage secure choices. The results indicate that the impact of the initial nudges, of all kinds, did not endure. We conclude by discussing our findings and their implications for research and practice.
Verena Zimmermann, Karen Renaud
ACM Trans. Comput. Hum. Interact.2
2020 Cyber Diplomacy: A Systematic Literature Review
abstract
Diplomatic action in international relations is a global security priority in the inter-connected world. The birth of cyber diplomacy, occurred in the year 2007, which will always be remembered due to a wide-ranging cyber attack on Estonia. Indeed, Estonia is known for being one of the most wired countries in Europe. The attack consisted of crippled computer networks because of hackers which paralysed numerous amount of government and corporates sites. The escalation in these kinds of attacks highlighted the need for governments to formulate national cyber strategies. This sprang from the realisation that cyberspace, like the physical world, also has military and strategic dimensions and requires countries to work together to defeat cyber opponents. Attacks within cyberspace are subject to strategically-formulated threats, which go beyond the usual physical terrorist-type threats. Global progress, democracy and peace are at stake. This makes cyber diplomacy a major issue for countries' foreign policies, due to the interdisciplinary nature of the domain. A number of aspects are relevant in this respect: policies, politics and sociology (dread), diplomacy, digital/cyber science, multilateralism and world history. This paper reports on a systematic literature review that was carried out to reveal the dimensions of current cyber diplomacy research. While a number of studies have introduced and defined "Cyber Diplomacy" and its associated diplomatic actions, none have sought to distinguish this field from the more traditional and well established diplomacy concept. This is a significant gap in the literature, which will be the topic of future research.
Amel Attatfa, Karen Renaud
KES2
2020 The privacy paradox applies to IoT devices too: A Saudi Arabian study
Noura Aleisa, Karen Renaud, Ivano Bongiovanni
Comput. Secur.2
2020 Risk as affect: The affect heuristic in cybersecurity
Paul van Schaik, Karen Renaud, Christopher J. Wilson, Jurjen Jansen, Joseph A. Onibokun
Comput. Secur.2
2019 "I do it because they do it": Social-Neutralisation in Information Security Practices of Saudi Medical Interns
Saad Altamimi, Karen Renaud, Tim Storer
CRiSIS2
2019 Comparing "Challenge-Based" and "Code-Based" Internet Voting Verification Implementations
Oksana Kulyk, Jan Henzel, Karen Renaud, Melanie Volkamer
INTERACT (1)3
2019 Cyber security fear appeals: unexpectedly complicated
abstract
Cyber security researchers are starting to experiment with fear appeals, with a wide variety of designs and reported efficaciousness. This makes it hard to derive recommendations for designing and deploying these interventions. We thus reviewed the wider fear appeal literature to arrive at a set of guidelines to assist cyber security researchers. Our review revealed a degree of dissent about whether or not fear appeals are indeed helpful and advisable. Our review also revealed a wide range of fear appeal experimental designs, in both cyber and other domains, which confirms the need for some standardized guidelines to inform practice in this respect. We propose a protocol for carrying out fear appeal experiments, and we review a sample of cyber security fear appeal studies, via this lens, to provide a snapshot of the current state of play. We hope the proposed experimental protocol will prove helpful to those who wish to engage in future cyber security fear appeal research.
Karen Renaud, Marc J. Dupuis
NSPW1
2019 "This is the way 'I' create my passwords" ... does the endowment effect deter people from changing the way they create their passwords?
Karen Renaud, Robert F. Otondo, Merrill Warkentin
Comput. Secur.1
2019 Moving from a 'human-as-problem" to a 'human-as-solution" cybersecurity mindset
Verena Zimmermann, Karen Renaud
Int. J. Hum. Comput. Stud.2
2019 Refining the PoinTER "human firewall" pentesting framework
abstract
Purpose Penetration tests have become a valuable tool in the cyber security defence strategy in terms of detecting vulnerabilities. Although penetration testing has traditionally focussed on technical aspects, the field has started to realise the importance of the human in the organisation, and the need to ensure that humans are resistant to cyberattacks. To achieve this, some organisations “pentest” their employees, testing their resilience and ability to detect and repel human-targeted attacks. In a previous paper, the authors reported on PoinTER (Prepare TEst Remediate), a human pentesting framework, tailored to the needs of SMEs. This paper aims to propose improvements to refine the framework. The improvements are based on a derived set of ethical principles that have been subjected to ethical scrutiny Design/methodology/approach The authors conducted a systematic literature review of academic research, a review of actual hacker techniques, industry recommendations and official body advice related to social engineering techniques. To meet the requirements to have an ethical human pentesting framework, the authors compiled a list of ethical principles from the research literature which they used to filter out techniques deemed unethical. Findings Drawing on social engineering techniques from academic research, reported by the hacker community, industry recommendations and official body advice and subjecting each technique to ethical inspection, using a comprehensive list of ethical principles, the authors propose the refined GDPR-compliant and privacy respecting PoinTER framework. The list of ethical principles, as suggested, could also inform ethical technical pentests. Originality/value Previous work has considered penetration testing humans, but few have produced a comprehensive framework such as PoinTER. PoinTER has been rigorously derived from multiple sources and ethically scrutinised through inspection, using a comprehensive list of ethical principles derived from the research literature.
Jacqueline Archibald, Karen Renaud
Inf. Comput. Secur.2
2018 What Did I Really Vote For?
abstract
E-voting has been embraced by a number of countries, delivering benefits in terms of efficiency and accessibility. End-to-end verifiable e-voting schemes facilitate verification of the integrity of individual votes during the election process. In particular, methods for cast-as-intended verification enable voters to confirm that their cast votes have not been manipulated by the voting client. A well-known technique for effecting cast-as-intended verification is the Benaloh Challenge. The usability of this challenge is crucial because voters have to be actively engaged in the verification process. In this paper, we report on a usability evaluation of three different approaches of the Benaloh Challenge in the remote e-voting context. We performed a comparative user study with 95 participants. We conclude with a recommendation for which approaches should be provided to afford verification in real-world elections and suggest usability improvements.
Karola Marky, Oksana Kulyk, Karen Renaud, Melanie Volkamer
CHI3
2018 Privacy in Crowdsourcing: A Systematic Review
Abdulwhab Alkharashi, Karen Renaud
ISC2
2018 Developing and Evaluating a Five Minute Phishing Awareness Video
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Philipp Rack, Marco Ghiglieri, Peter Mayer 0001, Alexandra Kunz, Nina Gerber
TrustBus2
2018 Is the responsibilization of the cyber security risk reasonable and judicious?
Karen Renaud, Stephen Flowerday, Merrill Warkentin, W. Paul Cockshott, Craig P. Orgeron
Comput. Secur.1
2018 Ethical guidelines for nudging in information security & privacy
Karen Renaud, Verena Zimmermann
Int. J. Hum. Comput. Stud.1
2018 Introduction to special issue on e-voting
Jurlind Budurushi, Stephan Neumann, Karen Renaud, Melanie Volkamer
J. Inf. Secur. Appl.3
2017 Yes, I know this IoT Device Might Invade my Privacy, but I Love it Anyway! A Study of Saudi Arabian Perceptions
abstract
The Internet of Things (IoT) ability to monitor our every move raises many privacy concerns. This paper reports on a study to assess current awareness of privacy implications of IoT devices amongst Saudi Arabians. We found that even when users are aware of the potential for privacy invasion, their need for the convenience these devices afford leads them to discount this potential and to ignore any concerns they might initially have had. We then conclude by making some predictions about the direction the IoT field will take in the next 5-7 years, in terms of privacy invasion, protection and awareness.
Noura Aleisa, Karen Renaud
IoTBDS2
2017 Risk Homeostasis in Information Security: Challenges in Confirming Existence and Verifying Impact
abstract
The central premise behind risk homeostasis theory is that humans adapt their behaviors, based on external factors, to align with a personal risk tolerance level. In essence, this means that the safer or more secure they feel, the more likely it is that they will behave in a risky manner. If this effect exists, it serves to restrict the ability of risk mitigation techniques to effect improvements.
Karen Renaud, Merrill Warkentin
NSPW1
2017 User experiences of TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer, Alexandra Kunz
Comput. Secur.2
2017 The simpler, the better? Presenting the COPING Android permission-granting interface for better privacy-related decisions
Paul Gerber, Melanie Volkamer, Karen Renaud
J. Inf. Secur. Appl.3
2017 Human-centred cyber security
Karen Renaud, Stephen Flowerday
J. Inf. Secur. Appl.1
2017 Contemplating human-centred security & privacy research: Suggesting future directions
Karen Renaud, Stephen Flowerday
J. Inf. Secur. Appl.1
2016 ZeTA-Zero-Trust Authentication: Relying on Innate Human Ability, Not Technology
abstract
Reliable authentication requires the devices and channels involved in the process to be trustworthy, otherwise authentication secrets can easily be compromised. Given the unceasing efforts of attackers worldwide such trustworthiness is increasingly not a given. A variety of technical solutions, such as utilising multiple devices/channels and verification protocols, has the potential to mitigate the threat of untrusted communications to a certain extent. Yet such technical solutions make two assumptions: (1) users have access to multiple devices and (2) attackers will not resort to hacking the human, using social engineering techniques. In this paper, we propose and explore the potential of using human-based computation instead of solely technical solutions to mitigate the threat of untrusted devices and channels. ZeTA (Zero Trust Authentication on untrusted channels) has the potential to allow people to authenticate despite compromised channels or communications and easily observed usage. Our contributions are threefold: (1) We propose the ZeTA protocol with a formal definition and security analysis that utilises semantics and human-based computation to ameliorate the problem of untrusted devices and channels. (2) We outline a security analysis to assess the envisaged performance of the proposed authentication protocol. (3) We report on a usability study that explores the viability of relying on human computation in this context.
Andreas Gutmann, Karen Renaud, Joseph Maguire 0001, Peter Mayer 0001, Melanie Volkamer, Kanta Matsuura, Jörn Müller-Quade
EuroS&P2
2016 TORPEDO: TOoltip-poweRed Phishing Email DetectiOn
Melanie Volkamer, Karen Renaud, Benjamin Reinheimer
SEC2
2016 Why don't UK citizens protest against privacy-invading dragnet surveillance?
abstract
Purpose The purpose of this study was to identify to identify reasons for the lack of protest against dragnet surveillance in the UK. As part of this investigation, a study was carried out to gauge the understanding of “privacy” and “confidentiality” by the well-informed. Design/methodology/approach To perform a best-case study, the authors identified a group of well-informed participants in terms of security. To gain insights into their privacy-related mental models, they were asked first to define the three core terms and then to identify the scenarios. Then, the participants were provided with privacy-related scenarios and were asked to demonstrate their understanding by classifying the scenarios and identifying violations. Findings Although the participants were mostly able to identify privacy and confidentiality scenarios, they experienced difficulties in articulating the actual meaning of the terms privacy, confidentiality and security. Research limitations/implications There were a limited number of participants, yet the findings are interesting and justify further investigation. The implications, even of this initial study, are significant in that if citizens’ privacy rights are being violated and they did not seem to know how to protest this and if indeed they had the desire to do so. Practical implications Had the citizens understood the meaning of privacy, and their ancient right thereto, which is enshrined in law, their response to the Snowden revelations about ongoing wide-scale surveillance might well have been more strident and insistent. Originality/value People in the UK, where this study was carried out, do not seem to protest the privacy invasion effected by dragnet surveillance with any verve. The authors identify a number of possible reasons for this from the literature. One possible explanation is that people do not understand privacy. Thus, this study posits that privacy is unusual in that understanding does not seem to align with the ability to articulate the rights to privacy and their disapproval of such widespread surveillance. This seems to make protests unlikely.
Karen Renaud, Stephen Flowerday, Rosanne English, Melanie Volkamer
Inf. Comput. Secur.1
2016 Spot the phish by checking the pruned URL
abstract
Purpose Phishing is still a very popular and effective security threat, and it takes, on average, more than a day to detect new phish websites. Protection by purely technical means is hampered by this vulnerability window. During this window, users need to act to protect themselves. To support users in doing so, the paper aims to propose to first make users aware of the need to consult the address bar. Moreover, the authors propose to prune URL displayed in the address bar. The authors report on an evaluation of this proposal. Design/methodology/approach The paper opted for an online study with 411 participants, judging 16 websites – all with authentic design: half with legitimate and half with phish URLs. The authors applied four popular widely used types of URL manipulation techniques. The authors conducted a within-subject and between-subject study with participants randomly assigned to one of two groups (domain highlighting or pruning). The authors then tested both proposals using a repeated-measures multivariate analysis of variance. Findings The analysis shows a significant improvement in terms of phish detection after providing the hint to check the address bar. Furthermore, the analysis shows a significant improvement in terms of phish detection after the hint to check the address bar for uninitiated participants in the pruning group, as compared to those in the highlighting group. Research limitations/implications Because of the chosen research approach, the research results may lack generalisability. Therefore, researchers are encouraged to test the proposed propositions further. Practical implications This paper confirms the efficacy of URL pruning and of prompting users to consult the address bar for phish detection. Originality/value This paper introduces a classification for URL manipulation techniques used by phishers. We also provide evidence that drawing people’s attention to the address bar makes them more likely to spot phish websites, but does not impair their ability to identify authentic websites.
Melanie Volkamer, Karen Renaud, Paul Gerber
Inf. Comput. Secur.2
2015 Regulating Access to Adult Content (with Privacy Preservation)
abstract
In the physical world we have well-established mechanisms for keeping children out of adult-only areas. In the virtual world this is generally replaced by self declaration. Some service providers resort to using heavy-weight identification mechanisms, judging adulthood as a side effect thereof. Collection of identification data arguably constitutes an unwarranted privacy invasion in this context, if carried out merely to perform adulthood estimation. This paper presents a mechanism that exploits the adult's more extensive exposure to public media, relying on the likelihood that they will be able to recall details if cued by a carefully chosen picture. We conducted an online study to gauge the viability of this scheme. With our prototype we were able to predict that the user was a child 99% of the time. Unfortunately the scheme also misclassified too many adults. We discuss our results and suggest directions for future research.
Karen Renaud, Joseph Maguire 0001
CHI1
2014 jCAPTCHA: Accessible Human Validation
Matthew Davidson, Karen Renaud, Shujun Li 0001
ICCHP (1)2
2014 Why Doesn't Jane Protect Her Privacy?
Karen Renaud, Melanie Volkamer, Arne Renkema-Padmos
Privacy Enhancing Technologies1
2013 Are Graphical Authentication Mechanisms As Strong As Passwords?
Karen Renaud, Peter Mayer 0001, Melanie Volkamer, Joseph Maguire 0001
FedCSIS1
2013 Designing Mobile Phone Interfaces for Age Diversity in South Africa: "One-World" versus Diverse "Islands"
Karen Renaud, Rénette J. Blignaut, Isabella Margarethe Venter
INTERACT (3)1
2013 Introducing computing students to scientific experimentation
abstract
It is a truth universally acknowledged, at least by educators, that doing coursework is beneficial to students. Yet the coursework must be designed with the end-goal in mind: what is it, particularly, that we want students to learn. Equally important is the need to construct coursework in the context of the overall degree programme, to ensure that computing students develop all the skills they need to. This paper reports on coursework that required computing students, thus far accustomed to a predominantly engineering approach to computing, to carry out a scientific investigation. This coursework, and the use of a bespoke simulation engine, appears to have been a successful strategy in achieving the desired learning outcomes. Furthermore, there is some evidence to suggest that this kind of coursework would be particularly suitable for courses where students' intuitive and misguided thinking needs to be challenged.
Karen Renaud
ITiCSE1
2013 Encouraging second thoughts: Obstructive user interfaces for raising security awareness
abstract
We propose a suite of user interface widgets to intuitively inform a user of a mobile device's sense of comfort at the user's proposed actions.
Tim Storer, Stephen Marsh 0001, Sylvie Noël, Babak Esfandiari, Khalil El-Khatib, Pamela Briggs, Karen Renaud, Mehmet Vefa Bicakci
PST7
2013 A framework for continuous, transparent mobile device authentication
Heather Crawford, Karen Renaud, Tim Storer
Comput. Secur.2
2013 Teaching human-centered security using nontraditional techniques
Karen Renaud, Quintin I. Cutts
ACM Trans. Comput. Educ.1
2012 Using insights from email users to inform organisational email management policy
abstract
One would expect email substantially to increase organisational productivity and efficiency. There is little empirical evidence of this since email use is such a complex tool that it would be well nigh impossible to attribute efficiency increases solely to email. There is anecdotal evidence of the positive aspects of email (Phillips, S.R. and Eisenberg, E.M., 1996. Strategic uses of electronic mail in organisations. The Public, 3 (4), 67–81; Virji, A., et al., 2006. Use of email in a family practice setting: opportunities and challenges in patient- and physician-initiated communication. BMC Medicine, 4 (18), doi: 10.1186/1741-7015-4-18), and of aspects of email usage that cause aggravation and concern (Whittaker, S. and Sidner, C., 1996. Email overload: exploring personal information. Management of email. In: Proceedings of the ACM conference on human factors in computer systems, Atlanta, Georgia, USA. New York: ACM, 276283; Fischer, D., et al., 2006. Revisiting Whittaker and Sidner's “email overload” ten years later. In: Proceedings of the 2006 20th anniversary conference on computer supported cooperative work, 4–8 November 2006 Banff, Alberta, Canada. New York: ACM, 309–312). Such anecdotal evidence is of limited use in assessing efficiency gains but serves to prompt studies into the impact of the pervasiveness of organisational email on individual employees. To study this, we spoke to email users about their experiences through a series of reflective semi-structured interviews to gauge the effects of email on the individual user. We linked our findings to a number of behavioural principles and assessed whether the identified email-related behaviours should be encouraged, forbidden or modified. We propose one way of addressing unhelpful emailing behaviours to maximise email's potential for enhancing productivity. We argue that such insights from the level of the individual emailer are the key to maximising email's potential to fulfil its original purpose as a productivity enhancer.
Judith Ramsay, Karen Renaud
Behav. Inf. Technol.2
2009 Musipass: authenticating me softly with "my" song
abstract
The modern world increasingly requires us to prove our identity. When this has to be done remotely, as is the case when people make use of web sites, the most popular technique is the password. Unfortunately the profusion of web sites and the associated passwords reduces their efficacy and puts severe strain on users' limited cognitive resources. There is clearly a need for some creativity in terms of providing viable alternatives to passwords. This paper reports experiences of the use of a musical password, one composed of melodies instead of alphanumerics. Music is universal all over the globe and humans have superior memory for music.
Marcia Gibson, Karen Renaud, Marc Conrad, Carsten Maple
NSPW2
2009 Guidelines for designing graphical authentication mechanism interfaces
abstract
The password era is drawing to a close. The latest technology is being released without keyboards, which makes password entry insecure and arduous. Furthermore, everyone is straining under the burden of multiple passwords and Personal Identification Numbers (PINs), and a viable knowledge-based alternative is urgently required. In the last few years a number of innovative graphical authentication mechanisms, which use pictures instead of alphanumeric strings, have been proposed. There is long-standing evidence that people remember pictures far better than they remember alphanumeric strings, so in terms of easing the memory load, pictures seem to offer a viable alternative. However, what is emerging from current research is that the design of such a graphical authentication mechanism interface can either make or break it, both in terms of security and usability. This paper will discuss various design options and make recommendations about how such systems should be designed in order to make them maximally efficacious while considering the level of risk associated with the resource being protected by the mechanism.
Karen Renaud
Int. J. Inf. Comput. Secur.1
2009 A Mechanism for Filtering Distractors for Doodle Passwords
abstract
Graphical authentication holds some potential as an alternative to the ubiquitous password. Graphical authentication mechanisms typically present users with one or more challenge sets composed of a number of images: one target image surrounded by distractor images. Unfortunately, this means it tends to be more time-consuming than password entry and to alleviate this, we need to streamline the process as much as possible to maximize efficiency. The distractors must be chosen with care so as to ensure that users do not become confused by similarities with the target image. It is especially challenging to achieve this filtering with minimalist image types, such as hand-drawn doodles. This paper explores the issues related to filtering the distractor images used in graphical authentication mechanisms using minimalist images. We present an algorithm for automatically classifying minimalist images in terms of visual similarity. The principles outlined here can also be used to assess the similarity of other minimalist image types such as signatures and handwritten numerals.
Ron Poet, Karen Renaud
Int. J. Pattern Recognit. Artif. Intell.2
2007 Now what was that password again? A more flexible way of identifying and authenticating our seniors
abstract
The Web offers facilities which can make a huge difference to the lives of users with reduced mobility, something that affects many older users. Users have to be authorized to access restricted websites. This involves a two-step process: identification and authentication. These issues have received scant attention when considering the needs of specific user groups. Web identification and authentication is often treated as a one-size-fits-all problem with ubiquitous use of the password as an authenticator and a variety of different identification mechanisms being used. Neither is tailored to the needs of either the website or the target users. This paper discusses problems related to identification and authentication of older web users, and reports on experiences with field tests of initial solutions.
Karen Renaud, Judith Ramsay
Behav. Inf. Technol.1
2006 "You've Got E-Mail!" ... Shall I Deal With It Now? Electronic Mail From the Recipient's Perspective
abstract
This article considers the nature of e-mail from the recipient's perspective-what the seemingly free and easy communication really costs the recipient. Information gathered by electronic monitoring software is shown to be at odds with the results of an online survey of e-mail users' perceptions of their e-mail experience-users drastically underestimate the disruptive effects of e-mail. The conclusion is that the constant monitoring of e-mail actually reduces productivity and that there is a need for increased power, control, and awareness on the part of the e-mail recipient to ensure that e-mail remains a tool rather than a tyrant. It is necesssary to alert the user of the true cost of e-mail alerts.
Karen Renaud, Judith Ramsay, Mario Hair
Int. J. Hum. Comput. Interact.1
2005 Is a picture really worth a thousand words? Exploring the feasibility of graphical authentication systems
Antonella De Angeli, Lynne M. Coventry, Graham Johnson, Karen Renaud
Int. J. Hum. Comput. Stud.4
2004 My password is here! An investigation into visuo-spatial authentication mechanisms
abstract
Passwords are the almost universal authentication mechanism, even though they are basically flawed and cause problems for users due to poor memorability. Graphical methods of authentication have recently excited some interest but little is known about their actual efficacy. There are basically two types of graphical authentication mechanisms: recognition-based and location-based—also called visuo-spatial mechanisms. Whereas some kinds of recognition-based graphical authentication mechanisms have been evaluated by various researchers, there is still a need to investigate location-based graphical authentication mechanisms in a more rigorous fashion to determine whether they could be a viable alternative to traditional passwords for web usage. This paper discusses graphical authentication mechanisms in general and reports on the evaluation of one particular visuo-spatial mechanism, aimed at augmenting the password paradigm by providing a way to record passwords securely. Results and findings are presented, and conclusions drawn, some of which can also be applied to other types of visuo-spatial mechanisms. We also propose a set of metrics which can be used to measure the quality of web authentication mechanisms and apply these to a range of existing authentication mechanisms.
Karen Renaud, Antonella De Angeli
Interact. Comput.1
2004 Quantification of Authentication Mechanisms: a Usability Perspective
Karen Renaud
J. Web Eng.1
2003 Zazu - Investigating the Difference between Interaction Approaches in Advisory Support Systems for Curriculum
Judy van Biljon, Karen Renaud
INTERACT2
2001 Tailoring E-Commerce Sites to Ease Recovery after Disruptions
abstract
Developers of e-commerce applications are often unrealistic about how their Web site is going to be used, and about possible outcomes during site usage. The most commonly considered outcomes of a user's visit to a site are firstly that the visit culminates in a sale, and secondly that the user leaves the site without buying anything - perhaps to return later. In the second case, sites often "remember" any accumulated items so that a shopper can return at a later stage to resume shopping. In this paper, we consider certain disruptions, such as breakdowns, problems caused by human errors and interruptions, which could affect the outcome of the e-commerce shopping experience. These events have definite and possibly long-lasting effects on users, and applications should therefore be developed to cater for these eventualities so as to enhance the usability of the site and encourage further usage. We develop a model for analysing e-commerce application usage and, using this model, propose an evaluation strategy for determining whether an e-commerce site is resistant to such factors. The proposed evaluation mechanism is applied to three sites to arrive at what we call a "disruption-resistance score".
Karen Renaud, Tobie van Dyk
COMPSAC1
2000 HERCULE : Non-invasively Tracking JavaTM Component-Based Application Activity
Karen Renaud
ECOOP1
1999 HERCULE: a framework for enhancing error reporting in component-based systems
abstract
The paper presents a novel approach to providing error feedback for distributed, component based applications. We describe HERCULE, a framework within which an existing application can execute, to enhance error feedback. HERCULE will collect data from user actions and server requests and provide context dependent feedback on errors. The strength of HERCULE is that the application will not have to be modified or transformed in any way to participate in the framework. Users of software systems often spend a great deal of time trying to work out how to use the system and, in particular, how to deal with errors. It is often difficult to find out what has caused an error, and how to recover from it. Sometimes users are even oblivious to the presence of errors. In component based applications, the constituent parts are developed independently, and consequently traditional methods for implementing global feedback mechanisms will not be feasible. We therefore propose the introduction of an error reporting framework which will provide the required level of feedback for component based systems.
Karen Renaud, Richard L. Cooper
EDOC1