Alessandro Acquisti

dblp:49/3744 · DBLP profile ↗
← Back
33ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0001-6582-6178ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 25 · 2 since 2021Security and privacy · 17 · 3 since 2021Computer networks · 2Artificial intelligence and machine learning · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2024 Encouraging Users to Change Breached Passwords Using the Protection Motivation Theory
abstract
We draw on the Protection Motivation Theory (PMT) to design interventions that encourage users to change breached passwords. Our online experiment ( \(n=1{,}386\) ) compared the effectiveness of a threat appeal (highlighting the negative consequences after passwords were breached) and a coping appeal (providing instructions on changing the breached password) in a 2 \(\times\) 2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords. Participants’ password change behaviors are further associated with other factors, such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based interventions are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT’s application in security research and provides concrete design implications for improving compromised credential notifications.
Yixin Zou, Khue Le, Peter Mayer 0001, Alessandro Acquisti, Adam J. Aviv, Florian Schaub
ACM Trans. Comput. Hum. Interact.4
2023 Is There a Reverse Privacy Paradox? An Exploratory Analysis of Gaps Between Privacy Perspectives and Privacy-Seeking Behaviors
abstract
Privacy scholars have long studied, and argued about, a so-called privacy paradox---the alleged gap between individuals' claims of caring about privacy and their actual behaviors. This manuscript explores whether a different type of mismatch occurs in an online sample of US participants: a mismatch between participants' dismissive perspectives on privacy and their privacy-protective behaviors. In a series of online studies with Prolific US participants we tackle two research questions: is there evidence of mismatches between (dismissive) privacy perspectives, and (protective) privacy behaviors? If so, what can explain those mismatches? In a Behavior Elicitation study, we collect a corpus of privacy-regulating and privacy-protective behaviors. Next, in Study 1, we find evidence that engagement in a broad array of privacy behaviors is, in fact, very common in our sample. We also find that mismatches between dismissive privacy perspectives and protective behaviors emerge in a large proportion of participants. Finally, in Study 2, we uncover several common but distinct reasons for those mismatches, including construing seemingly protective behaviors as motivated by reasons other than privacy, and nuanced stances on when to express privacy concern. Collectively, the results indicate that individuals who are seemingly dismissive of privacy concerns engage in behaviors that can be construed as privacy-seeking. The findings highlight the nuances of individual privacy decision-making and suggest that public policy related to privacy should account for the evidence for widespread privacy-seeking behaviors.
Jessica Colnago, Lorrie Faith Cranor, Alessandro Acquisti
Proc. Priv. Enhancing Technol.3
2022 Increasing Adoption of Tor Browser Using Informational and Planning Nudges
abstract
Abstract Browsing privacy tools can help people protect their digital privacy. However, tools which provide the strongest protections—such as Tor Browser—have struggled to achieve widespread adoption. This may be due to usability challenges, misconceptions, behavioral biases, or mere lack of awareness. In this study, we test the effectiveness of nudging interventions that encourage the adoption of Tor Browser. First, we test an informational nudge based on protection motivation theory (PMT), designed to raise awareness of Tor Browser and help participants form accurate perceptions of it. Next, we add an action planning implementation intention, designed to help participants identify opportunities for using Tor Browser. Finally, we add a coping planning implementation intention, designed to help participants overcome challenges to using Tor Browser, such as extreme website slowness. We test these nudges in a longitudinal field experiment with 537 participants. We find that our PMT-based intervention increased use of Tor Browser in both the short- and long-term. Our coping planning nudge also increased use of Tor Browser, but only in the week following our intervention. We did not find statistically significant evidence of our action planning nudge increasing use of Tor Browser. Our study contributes to a greater understanding of factors influencing the adoption of Tor Browser, and how nudges might be used to encourage the adoption of Tor Browser and similar privacy enhancing technologies.
Peter Story, Daniel Smullen, Rex Chen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
Proc. Priv. Enhancing Technol.5
2021 Toggles, Dollar Signs, and Triangles: How to (In)Effectively Convey Privacy Choices with Icons and Link Texts
abstract
Increasingly, icons are being proposed to concisely convey privacy-related information and choices to users. However, complex privacy concepts can be difficult to communicate. We investigate which icons effectively signal the presence of privacy choices. In a series of user studies, we designed and evaluated icons and accompanying textual descriptions (link texts) conveying choice, opting-out, and sale of personal information — the latter an opt-out mandated by the California Consumer Privacy Act (CCPA). We identified icon-link text pairings that conveyed the presence of privacy choices without creating misconceptions, with a blue stylized toggle icon paired with “Privacy Options” performing best. The two CCPA-mandated link texts (“Do Not Sell My Personal Information” and “Do Not Sell My Info”) accurately communicated the presence of do-not-sell opt-outs with most icons. Our results provide insights for the design of privacy choice indicators and highlight the necessity of incorporating user testing into policy making.
Hana Habib, Yixin Zou, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Joel R. Reidenberg, Norman M. Sadeh, Florian Schaub
CHI4
2021 Awareness, Adoption, and Misconceptions of Web Privacy Tools
abstract
Abstract Privacy and security tools can help users protect themselves online. Unfortunately, people are often unaware of such tools, and have potentially harmful misconceptions about the protections provided by the tools they know about. Effectively encouraging the adoption of privacy tools requires insights into people’s tool awareness and understanding. Towards that end, we conducted a demographically-stratified survey of 500 US participants to measure their use of and perceptions about five web browsing-related tools: private browsing, VPNs, Tor Browser, ad blockers, and antivirus software. We asked about participants’ perceptions of the protections provided by these tools across twelve realistic scenarios. Our thematic analysis of participants’ responses revealed diverse forms of misconceptions. Some types of misconceptions were common across tools and scenarios, while others were associated with particular combinations of tools and scenarios. For example, some participants suggested that the privacy protections offered by private browsing, VPNs, and Tor Browser would also protect them from security threats – a misconception that might expose them to preventable risks. We anticipate that our findings will help researchers, tool designers, and privacy advocates educate the public about privacy- and security-enhancing technologies.
Peter Story, Daniel Smullen, Yaxing Yao, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
Proc. Priv. Enhancing Technol.4
2020 Informing the Design of a Personalized Privacy Assistant for the Internet of Things
abstract
Internet of Things (IoT) devices create new ways through which personal data is collected and processed by service providers. Frequently, end users have little awareness of, and even less control over, these devices' data collection. IoT Personalized Privacy Assistants (PPAs) can help overcome this issue by helping users discover and, when available, control the data collection practices of nearby IoT resources. We use semi-structured interviews with 17 participants to explore user perceptions of three increasingly more autonomous potential implementations of PPAs, identifying benefits and issues associated with each implementation. We find that participants weigh the desire for control against the fear of cognitive overload. We recommend solutions that address users' differing automation preferences and reduce notification overload. We discuss open issues related to opting out from public data collections, automated consent, the phenomenon of user resignation, and designing PPAs with at-risk communities in mind.
Jessica Colnago, Yuanyuan Feng, Tharangini Palanivel, Sarah Pearman, Megan Ung, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh
CHI6
2020 "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion Choices
abstract
We conducted an in-lab user study with 24 participants to explore the usefulness and usability of privacy choices offered by websites. Participants were asked to find and use choices related to email marketing, targeted advertising, or data deletion on a set of nine websites that differed in terms of where and how these choices were presented. They struggled with several aspects of the interaction, such as selecting the correct page from a site's navigation menu and understanding what information to include in written opt-out requests. Participants found mechanisms located in account settings pages easier to use than options contained in privacy policies, but many still consulted help pages or sent email to request assistance. Our findings indicate that, despite their prevalence, privacy choices like those examined in this study are difficult for consumers to exercise in practice. We provide design and policy recommendations for making these website opt-out and deletion choices more useful and usable for consumers.
Hana Habib, Sarah Pearman, Yixin Zou, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh, Florian Schaub
CHI5
2020 The Impact of Ad-Blockers on Product Search and Purchase Behavior: A Lab Experiment
Alisa Frik, Amelia Haviland, Alessandro Acquisti
USENIX Security Symposium3
2018 Should Credit Card Issuers Reissue Cards in Response to a Data Breach?: Uncertainty and Transparency in Metrics for Data Security Policymaking
abstract
When card data is exposed in a data breach but has not yet been used to attempt fraud, the overall social costs of that breach depend on whether the financial institutions that issued those cards immediately cancel them and issue new cards or instead wait until fraud is attempted. This article empirically investigates the social costs and benefits of those options. We use a parameterized model and Monte Carlo simulation to compare the cost of reissuing cards to the total expected cost of fraud if cards are not reissued. The ranges and distributions in our model are informed by publicly available information, from which we extrapolate estimates of the number of credit card records historically exposed in data breaches, the probability that a card exposed in a breach will be used for fraud, and the associated expected cost of existing-account credit card fraud. We find that automatically reissuing cards may have lower social costs than the costs of waiting until fraud is attempted, although the range of results is considerably broad.
James T. Graves, Alessandro Acquisti, Nicolas Christin
ACM Trans. Internet Techn.2
2017 Format vs. Content: The Impact of Risk and Presentation on Disclosure Decisions
Sonam Samat, Alessandro Acquisti
SOUPS2
2017 Raise the Curtains: The Effect of Awareness About Targeting on Consumer Attitudes and Purchase Intentions
Sonam Samat, Alessandro Acquisti, Linda Babcock
SOUPS2
2016 Engineering Information Disclosure: Norm Shaping Designs
abstract
Nudging behaviors through user interface design is a practice that is well-studied in HCI research. Corporations often use this knowledge to modify online interfaces to influence user information disclosure. In this paper, we experimentally test the impact of a norm-shaping design patterns on information divulging behavior. We show that (1) a set of images, biased toward more revealing figures, change subjects' personal views of appropriate information to share; (2) that shifts in perceptions significantly increases the probability that a subject divulges personal information; and (3) that these shift also increases the probability that the subject advises others to do so. Our main contribution is empirically identifying a key mechanism by which norm-shaping designs can change beliefs and subsequent disclosure behaviors.
Daphne Chang, Erin L. Krupka, Eytan Adar, Alessandro Acquisti
CHI4
2016 Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions
Bin Liu 0017, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Zhang, Norman M. Sadeh, Yuvraj Agarwal, Alessandro Acquisti
SOUPS8
2016 Do or Do Not, There Is No Try: User Engagement May Not Improve Security Outcomes
Alain Forget, Sarah Pearman, Jeremy Thomas, Alessandro Acquisti, Nicolas Christin, Lorrie Faith Cranor, Serge Egelman, Marian Harbach, Rahul Telang
SOUPS4
2016 Expecting the Unexpected: Understanding Mismatched Privacy Expectations Online
Ashwini Rao, Florian Schaub, Norman M. Sadeh, Alessandro Acquisti, Ruogu Kang
SOUPS4
2015 Your Location has been Shared 5, 398 Times!: A Field Study on Mobile App Privacy Nudging
abstract
Smartphone users are often unaware of the data collected by apps running on their devices. We report on a study that evaluates the benefits of giving users an app permission manager and sending them nudges intended to raise their awareness of the data collected by their apps. Our study provides both qualitative and quantitative evidence that these approaches are complementary and can each play a significant role in empowering users to more effectively control their privacy. For instance, even after a week with access to the permission manager, participants benefited from nudges showing them how often some of their sensitive data was being accessed by apps, with 95% of participants reassessing their permissions, and 58% of them further restricting some of their permissions. We discuss how participants interacted both with the permission manager and the privacy nudges, analyze the effectiveness of both solutions, and derive some recommendations.
Hazim Almuhimedi, Florian Schaub, Norman M. Sadeh, Idris Adjerid, Alessandro Acquisti, Joshua Gluck, Lorrie Faith Cranor, Yuvraj Agarwal
CHI5
2015 I Would Like To..., I Shouldn't..., I Wish I...: Exploring Behavior-Change Goals for Social Networking Sites
abstract
Despite benefits and uses of social networking sites (SNSs) users are not always satisfied with their behaviors on the sites. These desires for behavior change both provide insight into users' perceptions of how SNSs impact their lives (positively or negatively) and can inform tools for helping users achieve desired behavior changes. We use a 604-participant online survey to explore SNS users' behavior-change goals for Facebook, Instagram, and Twitter. While some participants want to reduce site use, others want to improve their use or increase a range of behaviors. These desired changes differ by SNS, and, for Twitter, by participants' levels of site use. Participants also expect a range of benefits from these goals, including increased time, contact with others, intrinsic benefits, better security/privacy, and improved self presentation. Based on these results we provide insights both into how participants perceive different SNSs, as well as potential designs for behavior-change mechanisms to target SNS behaviors.
Manya Sleeper, Alessandro Acquisti, Lorrie Faith Cranor, Patrick Gage Kelley, Sean A. Munson, Norman M. Sadeh
CSCW2
2014 A field trial of privacy nudges for facebook
abstract
Anecdotal evidence and scholarly research have shown that Internet users may regret some of their online disclosures. To help individuals avoid such regrets, we designed two modifications to the Facebook web interface that nudge users to consider the content and audience of their online disclosures more carefully. We implemented and evaluated these two nudges in a 6-week field trial with 28 Facebook users. We analyzed participants' interactions with the nudges, the content of their posts, and opinions collected through surveys. We found that reminders about the audience of posts can prevent unintended disclosures without major burden; however, introducing a time delay before publishing users' posts can be perceived as both beneficial and annoying. On balance, some participants found the nudges helpful while others found them unnecessary or overly intrusive. We discuss implications and challenges for designing and evaluating systems to assist users with online disclosures.
Yang Wang 0005, Pedro Giovanni Leon, Alessandro Acquisti, Lorrie Faith Cranor, Alain Forget, Norman M. Sadeh
CHI3
2014 Would a Privacy Fundamentalist Sell Their DNA for $1000 ... If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences
Allison Woodruff, Vasyl Pihur, Sunny Consolvo, Lauren Schmidt, Laura Brandimarte, Alessandro Acquisti
SOUPS6
2013 "i read my Twitter the next morning and was astonished": a conversational perspective on Twitter regrets
abstract
We present the results of an online survey of 1,221 Twitter users, comparing messages individuals regretted either saying during in-person conversations or posting on Twitter. Participants generally reported similar types of regrets in person and on Twitter. In particular, they often regretted messages that were critical of others. However, regretted messages that were cathartic/expressive or revealed too much information were reported at a higher rate for Twitter. Regretted messages on Twitter also reached broader audiences. In addition, we found that participants who posted on Twitter became aware of, and tried to repair, regret more slowly than those reporting in-person regrets. From this comparison of Twitter and in-person regrets, we provide preliminary ideas for tools to help Twitter users avoid and cope with regret.
Manya Sleeper, Justin Cranshaw, Patrick Gage Kelley, Blase Ur, Alessandro Acquisti, Lorrie Faith Cranor, Norman M. Sadeh
CHI5
2013 Tweets are forever: a large-scale quantitative analysis of deleted tweets
abstract
This paper describes an empirical study of 1.6M deleted tweets collected over a continuous one-week period from a set of 292K Twitter users. We examine several aggregate properties of deleted tweets, including their connections to other tweets (e.g., whether they are replies or retweets), the clients used to produce them, temporal aspects of deletion, and the presence of geotagging information. Some significant differences were discovered between the two collections, namely in the clients used to post them, their conversational aspects, the sentiment vocabulary present in them, and the days of the week they were posted. However, in other dimensions for which analysis was possible, no substantial differences were found. Finally, we discuss some ramifications of this work for understanding Twitter usage and management of one's privacy.
Hazim Almuhimedi, Shomir Wilson, Bin Liu 0017, Norman M. Sadeh, Alessandro Acquisti
CSCW5
2013 Privacy manipulation and acclimation in a location sharing application
abstract
Location sharing is a popular feature of online social networks, but challenges remain in the effective presentation of privacy choices to users, whose location sharing preferences are complex and diverse. One proposed approach for capturing these nuances builds on the observation that key attributes of users' location sharing preferences can be represented by a small number of privacy profiles, which can provide a basis for configuring individual preferences. However, the impact of this approach on how users view their privacy is relatively unknown. We present a study evaluating the impact of this approach on users' location sharing preferences and their satisfaction with the decisions made by their resulting settings. The results suggest that this approach can influence users to share significantly more without a substantial difference in comfort. This further suggests that the provision of profiles for privacy settings must be carefully considered, as they can substantially alter sharing behavior.
Shomir Wilson, Justin Cranshaw, Norman M. Sadeh, Alessandro Acquisti, Lorrie Faith Cranor, Jay Springfield, Sae Young Jeong, Arun Balasubramanian
UbiComp4
2013 Sleights of privacy: framing, disclosures, and the limits of transparency
abstract
In an effort to address persistent consumer privacy concerns, policy makers and the data industry seem to have found common grounds in proposals that aim at making online privacy more "transparent." Such self-regulatory approaches rely on, among other things, providing more and better information to users of Internet services about how their data is used. However, we illustrate in a series of experiments that even simple privacy notices do not consistently impact disclosure behavior, and may in fact be used to nudge individuals to disclose variable amounts of personal information. In a first experiment, we demonstrate that the impact of privacy notices on disclosure is sensitive to relative judgments, even when the objective risks of disclosure actually stay constant. In a second experiment, we show that the impact of privacy notices on disclosure can be muted by introducing simple misdirections that do not alter the objective risk of disclosure. These findings cast doubts on the likelihood of initiatives predicated around notices and transparency to address, by themselves, online privacy concerns.
Idris Adjerid, Alessandro Acquisti, Laura Brandimarte, George Loewenstein
SOUPS2
2011 "I regretted the minute I pressed share": a qualitative study of regrets on Facebook
abstract
We investigate regrets associated with users' posts on a popular social networking site. Our findings are based on a series of interviews, user diaries, and online surveys involving 569 American Facebook users. Their regrets revolved around sensitive topics, content with strong sentiment, lies, and secrets. Our research reveals several possible causes of why users make posts that they later regret: (1) they want to be perceived in favorable ways, (2) they do not think about their reason for posting or the consequences of their posts, (3) they misjudge the culture and norms within their social circles, (4) they are in a "hot" state of high emotion when posting, or under the influence of drugs or alcohol, (5) their postings are seen by an unintended audience, (6) they do not foresee how their posts could be perceived by people within their intended audience, and (7) they misunderstand or misuse the Facebook platform. Some reported incidents had serious repercussions, such as breaking up relationships or job losses. We discuss methodological considerations in studying negative experiences associated with social networking posts, as well as ways of helping users of social networking sites avoid such regrets.
Yang Wang 0005, Gregory Norcie, Saranga Komanduri, Alessandro Acquisti, Pedro Giovanni Leon, Lorrie Faith Cranor
SOUPS4
2010 Teaching Johnny not to fall for phish
abstract
Phishing attacks, in which criminals lure Internet users to Web sites that spoof legitimate Web sites, are occurring with increasing frequency and are causing considerable harm to victims. While a great deal of effort has been devoted to solving the phishing problem by prevention and detection of phishing emails and phishing Web sites, little research has been done in the area of training users to recognize those attacks. Our research focuses on educating users about phishing and helping them make better trust decisions. We identified a number of challenges for end-user security education in general and anti-phishing education in particular: users are not motivated to learn about security; for most users, security is a secondary task; it is difficult to teach people to identify security threats without also increasing their tendency to misjudge nonthreats as threats. Keeping these challenges in mind, we developed an email-based anti-phishing education system called “PhishGuru” and an online game called “Anti-Phishing Phil” that teaches users how to use cues in URLs to avoid falling for phishing attacks. We applied learning science instructional principles in the design of PhishGuru and Anti-Phishing Phil. In this article we present the results of PhishGuru and Anti-Phishing Phil user studies that demonstrate the effectiveness of these tools. Our results suggest that, while automated detection systems should be used as the first line of defense against phishing attacks, user education offers a complementary approach to help people better recognize fraudulent emails and websites.
Ponnurangam Kumaraguru, Steve Sheng, Alessandro Acquisti, Lorrie Faith Cranor, Jason I. Hong
ACM Trans. Internet Techn.3
2009 Timing is everything?: the effects of timing and placement of online privacy indicators
abstract
Many commerce websites post privacy policies to address Internet shoppers' privacy concerns. However, few users read or understand them. Iconic privacy indicators may make privacy policies more accessible and easier for users to understand: in this paper, we examine whether the timing and placement of online privacy indicators impact Internet users' browsing and purchasing decisions. We conducted a laboratory study where we controlled the placement of privacy information, the timing of its appearance, the privacy level of each website, and the price and items being purchased. We found that the timing of privacy information had a significant impact on how much of a premium users were willing to pay for privacy. We also found that timing had less impact when users were willing to examine multiple websites. Finally, we found that users paid more attention to privacy indicators when purchasing privacy-sensitive items than when purchasing items that raised minimal privacy concerns.
Serge Egelman, Janice Y. Tsai, Lorrie Faith Cranor, Alessandro Acquisti
CHI4
2009 School of phish: a real-word evaluation of anti-phishing training
abstract
PhishGuru is an embedded training system that teaches users to avoid falling for phishing attacks by delivering a training message when the user clicks on the URL in a simulated phishing email. In previous lab and real-world experiments, we validated the effectiveness of this approach. Here, we extend our previous work with a 515-participant, real-world study in which we focus on long-term retention and the effect of two training messages. We also investigate demographic factors that influence training and general phishing susceptibility. Results of this study show that (1) users trained with PhishGuru retain knowledge even after 28 days; (2) adding a second training message to reinforce the original training decreases the likelihood of people giving information to phishing websites; and (3) training does not decrease users' willingness to click on links in legitimate messages. We found no significant difference between males and females in the tendency to fall for phishing emails both before and after the training. We found that participants in the 18--25 age group were consistently more vulnerable to phishing attacks on all days of the study than older participants. Finally, our exit survey results indicate that most participants enjoyed receiving training during their normal use of email.
Ponnurangam Kumaraguru, Justin Cranshaw, Alessandro Acquisti, Lorrie Faith Cranor, Jason I. Hong, Mary Ann Blair, Theodore Pham
SOUPS3
2009 The impact of privacy indicators on search engine browsing patterns
abstract
No abstract available.
Janice Y. Tsai, Serge Egelman, Lorrie Faith Cranor, Alessandro Acquisti
SOUPS4
2007 Protecting people from phishing: the design and evaluation of an embedded training email system
abstract
Phishing attacks, in which criminals lure Internet users to websites that impersonate legitimate sites, are occurring with increasing frequency and are causing considerable harm to victims. In this paper we describe the design and evaluation of an embedded training email system that teaches people about phishing during their normal use of email. We conducted lab experiments contrasting the effectiveness of standard security notices about phishing with two embedded training designs we developed. We found that embedded training works better than the current practice of sending security notices. We also derived sound design principles for embedded training systems.
Ponnurangam Kumaraguru, Yong Rhee, Alessandro Acquisti, Lorrie Faith Cranor, Jason I. Hong, Elizabeth Ferrall-Nunge
CHI3
2007 Anti-Phishing Phil: the design and evaluation of a game that teaches people not to fall for phish
abstract
In this paper we describe the design and evaluation of Anti-Phishing Phil, an online game that teaches users good habits to help them avoid phishing attacks. We used learning science principles to design and iteratively refine the game. We evaluated the game through a user study: participants were tested on their ability to identify fraudulent web sites before and after spending 15 minutes engaged in one of three anti-phishing training activities (playing the game, reading an anti-phishing tutorial we created based on the game, or reading existing online training materials). We found that the participants who played the game were better able to identify fraudulent web sites compared to the participants in other conditions. We attribute these effects to both the content of the training messages presented in the game as well as the presentation of these materials in an interactive game format. Our results confirm that games can be an effective way of educating people about phishing and other security attacks.
Steve Sheng, Bryant Magnien, Ponnurangam Kumaraguru, Alessandro Acquisti, Lorrie Faith Cranor, Jason I. Hong, Elizabeth Ferrall-Nunge
SOUPS4
2006 Trust modelling for online transactions: a phishing scenario
abstract
Trust is an important component of online transactions. The increasing amount and sophistication of spam, phishing, and other semantic attacks increase users' uncertainty about the consequences of their actions and their distrust towards other online parties. In this paper, we highlight some key characteristics of a model that we are developing to represent and compare the online trust decision processes of "expert" and "non-expert" computer users. We also report on preliminary data we are gathering to validate, refine, and apply our model. This research is part of a broader project that aims at developing tools and training modules to help online users make good trust decisions.
Ponnurangam Kumaraguru, Alessandro Acquisti, Lorrie Faith Cranor
PST2
2006 Power strips, prophylactics, and privacy, oh my!
abstract
While Internet users claim to be concerned about online privacy, their behavior rarely reflects those concerns. In this paper we investigate whether the availability of comparison information about the privacy practices of online merchants affects users’ behavior. We conducted our study using Privacy Finder, a “privacy-enhanced search engine” that displays search results annotated with the privacy policy information of each site. The privacy information is garnered from computer-readable privacy policies found at the respective sites. We asked users to purchase one nonprivacy- sensitive item and then one privacy-sensitive item using Privacy Finder, and observed whether the privacy information provided by our search engine impacted users’ purchasing decisions (participants’ costs were reimbursed, in order to separate the effect of privacy policies from that of price). A control group was asked to make the same purchases using a search engine that produced the same results as Privacy Finder, but did not display privacy information. We found that while Privacy Finder had some influence on non-privacy-sensitive purchase decisions, it had a more significant impact on privacy-sensitive purchases. The results suggest that when privacy policy comparison information is readily available, individuals may be willing to seek out more privacy friendly web sites and perhaps even pay a premium for privacy depending on the nature of the items to be purchased.
Julia Gideon, Lorrie Faith Cranor, Serge Egelman, Alessandro Acquisti
SOUPS4
2004 Privacy in electronic commerce and the economics of immediate gratification
abstract
Dichotomies between privacy attitudes and behavior have been noted in the literature but not yet fully explained. We apply lessons from the research on behavioral economics to understand the individual decision making process with respect to privacy in electronic commerce. We show that it is unrealistic to expectindividual rationality in this context. Models of self-control problems and immediate gratification offer more realistic descriptions of the decision process and are more consistent with currently available data. In particular, we show why individuals who may genuinely want to protect their privacy might not do so because of psychological distortions well documented in the behavioral literature; we show that these distortions may affect not only 'naive' individuals but also 'sophisticated' ones; and we prove that this may occur also when individuals perceive the risks from not protecting their privacy as significant.
Alessandro Acquisti
EC1