Showing posts with label CUPS. Show all posts
Showing posts with label CUPS. Show all posts

Sunday, July 13, 2014

A Decade Into Its Vital Work, Another Savory SOUPS, A Report from the 10th Annual Symposium On Usable Privacy and Security



CMU CyLab's Dr. Lorrie Cranor, Founder of CUPS and SOUPS preps
for welcoming remarks at SOUPS 2014


The CyLab Usable Privacy and Security Laboratory (CUPS) 10th Annual Symposium on Usable Privacy and Security (SOUPS) was hosted by Facebook at its headquarters in Menlo Park, California (7/9/14 - 7/11/14). CUPS Director Lorrie Cranor welcomed the attendees, with the record-breaking numbers in both attendance and papers submitted. For three full days of proceedings, hundreds of researchers from business, academia and government communed together amidst the proliferation of signage which has come to characterize the social media giant's corporate culture: e.g., "Ship Love," "Ruthless Prioritization," "Demand Success," Nelson Mandela, arms outstretched, with the caption, "Open the Doors," etc. (Not so subliminal messaging.)
 
Perhaps more poignantly than any previous SOUPS keynote, Christopher Soghoian of American Civil Liberties Union (ACLU) articulated the vital nature of research into usable privacy and security. Putting flesh and blood on these issues, Soghoian used examples from the shadow world of investigative reporters and whistle-blowers to highlight the need for privacy and security software that is not only robust but eminently usable. One great benefit of the revelations brought forth by Glenn Greenwald in the Edward Snowden affair, Soghoian opined, is that there has been increased crypto adoption by journalists.
But the heightened engagement has also brought long-standing problems into a harsh new light. For example, Soghoian told SOUPS attendees, many investigative journalists using PGP still do not realize subject lines are not encrypted. "The best our community has to offer sucks, the usability and the default values suck," Soghoian declared, "the software is not protecting journalists and human rights activists, and that's our fault as researchers"

As contributing markets factors for why we still don't have usable encryption, Soghoian cited: potential data loss ("telling your customer that they've just lost every photo of their children is a non starter"), current business models, and of course, government pressure.

Facebook HQ Signage, 1 Hacker Way, Menlo Park
In other parts of his very substantive keynote, Soghoian touched on consumer issues related to the efficacy of privacy and security. He elucidated the differences in privacy and security between the iPhone and the Android: "The privacy and security differences ... are not advertised." He also shed light on a new aspect of the growing gap between rich and poor, "security by default for the rich," and "insecurity by default for the poor." "Those who are more affluent get the privacy benefits without shopping around," he explained, because the discounted, and mass-marketed versions of software often do not have the same full-featured privacy and security as the more expensive business or professional versions.

[NOTE: Full-length video of Soghoian's keynote is available via the CyLab YouTube Channel.]

Several awards were also announced during the opening sessions, including:

The 2014 IAPP SOUPS Privacy Award for the paper with the most practical application in the field of privacy went to Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences authored by Allison Woodruff, Vasyl Pihur, Sunny Consolvo, and Lauren Schmidt of Google; and Laura Brandimarte and Alessandro Acquisti of Carnegie Mellon University.

The 2014 SOUPS Impact Award for a SOUPS paper "published between 2005 and 2009 that has had a significant impact on usable privacy and security research and practice" went to Usability of CAPTCHAs or Usability Issues in CAPTCHA Design authored in 2008 by Jeff Yan and Ahmad Salah El Ahmad of Newcastle University (UK).

Two Distinguished Papers awards were presented:

Understanding and Specifying Social Access Control Lists, authored by Mainack Monda of Max Planck Institute for Software Systems (MPI-SWS), Yabing Liu of Northeastern University, Bimal Viswanath and Krishna P. Gummadi of Max Planck Institute for Software Systems (MPI-SWS), and Alan Mislove of Northeastern University.

Crowdsourcing Attacks on Biometric Systems, authored by Saurabh Panjwani, an independent consultant and Achintya Prakash of University of Michigan.
Carnegie Mellon University (CMU), home to the CyLab Usable Privacy and Security (CUPS) Lab and the MSIT-Privacy Engineering Masters Program was well-represented in the proceeding.

In addition to the IAPP SOUPS Privacy Award winning "Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences," co-authored with Google researchers, several other CMU papers were presented:

Parents’ and Teens’ Perspectives on Privacy In a Technology-Filled World, authored by Lorrie Faith Cranor, Adam L. Durity, Abigail Marsh, and Blase Ur, Carnegie Mellon University

Privacy Attitudes of Mechanical Turk Workers and the U.S. Public, authored by Ruogu Kang, Carnegie Mellon University, Stephanie Brown, Carnegie Mellon University and American University, Laura Dabbish and Sara Kiesler, Carnegie Mellon University

CMU researcher Ruogu Kang presenting
Privacy Attitudes of Mechanical Turk Workers and the U.S. Public
Harder to Ignore? authored by Cristian Bravo-Lillo, Lorrie Cranor, and Saranga Komanduri, Carnegie Mellon University, Stuart Schechter, Microsoft Research, Manya Sleeper, Carnegie Mellon University

The Effect of Social Influence on Security Sensitivity, authored by Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, and Jason I. Hong, Carnegie Mellon University

Modeling Users’ Mobile App Privacy Preferences: Restoring Usability in a Sea of Permission Settings, authored by Jialiu Lin, Bin Liu, Norman Sadeh, and Jason I. Hong, Carnegie Mellon University

The full proceedings of SOUPS 2014 are available via USENIX.

-- Richard Power

Check out CyLab CyBlog's Archive of SOUPS Coverage

A Distinguish Paper Award for CUPS, and Other News from Ninth Annual SOUPS 2013

CyLab's SOUPS 2012 Continues Its Ongoing, Deepening Dialogue on What Works and What Doesn't

SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security  

 SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

Mike Farb of CyLab's SafeSlinger project presents during the 2014 EFF Crypto Usability Prize (EFF CUP)
Workshop on Day One of SOUPS 2014

Facebook HQ Signage, 1 Hacker Way, Menlo Park

Monday, July 29, 2013

A Distinguish Paper Award for CUPS, and Other News from Ninth Annual SOUPS 2013

CyLab graduate student Cristian Bravo Lillo presents at SOUPS 2013
The ninth annual Symposium on Usable Privacy and Security (SOUPS 2013) was held July 9th through July 11th at Northumbria University (Newcastle, U.K.).

Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS), chaired the conference, and CyLab Associate Research Professior Lujo Bauer served as technical papers co-chair.

CUPS researchers Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie Downs, Saranga Komanduri, and Robert W. Reeder (Carnegie Mellon University), Stuart Schechter (Microsoft Research), and Manya Sleeper (Carnegie Mellon University) won one of two Distinguished Paper Awards, for Your Attention Please: Designing Security-Decision UIs to Make Genuine Risks Harder to Ignore.

Here is a brief excerpt with a link to the full text:

We designed and tested attractors for computer security dialogs: user-interface modi cations used to draw users' attention to the most important information for making decisions. Some of these modi cations were purely visual, while others temporarily inhibited potentially-dangerous behaviors to redirect users' attention to salient information. We conducted three between-subjects experiments to test the effectiveness of the attractors. In the fi rst two experiments, we sent participants to perform a task on what appeared to be a third-party site that required installation of a browser plugin. We presented them with what appeared to be an installation dialog from their operating system. Participants who saw dialogs that employed inhibitive attractors were signifi cantly less likely than those in the control group to ignore clues that installing this software might be harmful. In the third experiment, we attempted to habituate participants to dialogs that they knew were part of the experiment. We used attractors to highlight a eld that was of no value during habituation trials and contained critical information after the habituation period. Participants exposed to inhibitive attractors were two to three times more likely to make an informed decision than those in the control condition. Your Attention Please: Designing Security-Decision UIs to Make Genuine Risks Harder to Ignore, Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie Downs, Saranga Komanduri, and Robert W. Reeder (Carnegie Mellon University), Stuart Schechter (Microsoft Research), and Manya Sleeper (Carnegie Mellon University)


The SOUPS proceedings will be archived in the ACM Digital Library in a few weeks. All papers are also available linked from the SOUPS 2013 program page on the SOUPS site.

CyLab graduate student Pedro Leon presents At SOUPS 2013


Tuesday, May 25, 2010

CyLab's Lorrie Cranor Participates in Capitol Hill Briefing on Nuts & Bolts of Online Privacy, Advertising, Notice & Choice



CyLab's Lorrie Cranor Participates in Capitol Hill Briefing on Nuts & Bolts of Online Privacy, Advertising, Notice & Choice

On 5/24/10, Dr. Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS) Laboratory participated in a Capital Hill briefing on "Nuts & Bolts of Online Privacy, Advertising, Notice & Choice."

Organized by the Progress and Freedom Foundation, the event featured a panel of experts; Ari Schwartz, Vice President & Chief Operating Officer at the Center for Democracy & Technology and Shane Wiley, Senior Director of Privacy & Data Governance for Yahoo! participated along with Dr. Cranor, and Berin Szoka, a Senior Fellow at the Progress & Freedom Foundation. Szoka moderated.

Here is a brief excerpt from Szoka's post to the Progress and Freedom Foundation blog:

Ari got us started with an intro to the Boucher bill and Shane offered an overview of the technical mechanics of online advertising and why it requires data about what users do online. Lorrie & Ari then talked about concerns about data collection, leading into a discussion of the challenges and opportunities for empowering privacy-sensitive consumers to manage their online privacy without breaking the advertising business model that sustains most Internet content and services. In particular, we had a lengthy discussion of the need for computer-readable privacy disclosures like P3P (pioneered by Lorrie & Ari) and the CLEAR standard developed by Yahoo! and others as a vital vehicle for self-regulation, but also an essential ingredient in any regulatory system that requires that notice be provided of the data collection practices of all tracking elements on the page.

For more on the event, including audio and video, see PFF Event Recap: Nuts & Bolts of Online Privacy, Advertising, Notice & Choice, 5-25-10

Some Related Posts:

CyLab Chronicles Q&A with Lorrie Cranor (2010)

CUPS wins Google Focused Research Award

SOUPS 2010: Sixth Annual Symposium On Usable Privacy and Security

CUPS Director Lorrie Cranor Receives NSF Funding For Interdisciplinary Doctoral Program in Privacy and Security

CyLab Usable Privacy and Security Researchers Release Study on SSL Warning Effectiveness

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (requires Partners Portal access)

CyLab Chronicles: Wombat - The Latest CyLab Success Story

CyLab Chronicles: Q&A with Lorrie Cranor (2008)

Wednesday, April 21, 2010

CyLab News Update: Recent Awards & Activities Highlight Strength & Scope of Program

Samuel Langhorne Clemens (a.k.a. Mark Twain) in the lab of Nikola Tesla, spring of 1894.

CyLab News Update: Recent Awards & Activities Highlight Strength & Scope of Program

By Richard Power


Here are brief excerpts on CyLab news stories about three awards and four activities from the first third of 2010 (with links to the full text of posts). These items highlight the strength and scope of CyLab's world-class research program.

Stay tuned, it is going to be an exciting year!

CyLab's Anupam Datta Named to SHARPS Multi-University Research Effort into Health IT Security & Privacy
Carnegie Mellon University’s Anupam Datta is part of a multi-institutional research team that received a $15 million grant from the U.S. Department of Health and Human Services to reduce security and privacy barriers to the meaningful use of health information technology. Datta, an Assistant Research Professor with Carnegie Mellon CyLab, is one of twenty senior investigators from twelve institutions involved in this collaborative project named Strategic Healthcare IT Advanced Research Projects on Security (SHARPS). Carnegie Mellon’s portion of the award is around $700,000 spread over 4 years. Full text.

Carnegie Mellon CyLab’s David Brumley Receives Prestigious Early Career Award from National Science Foundation
Carnegie Mellon University CyLab's David Brumley has received the National Science Foundation's Faculty Early Career Development (CAREER) Award, its most prestigious award for junior faculty.
Brumley, 35, who is a CyLab researcher as well as an assistant professor in the Department of Electrical and Computer Engineering and the School of Computer Science, received a five-year, $521,494 award to develop a system that will track and eliminate annoying software bugs.
Full text.

CyLab Researchers Win ACM WiSec Best Paper Award for Mobile User Location-specific Encryption (MULE)
CyLab's Technical Director Adrian Perrig and graduate student Ahren Studer have won Best Paper for the Association of Computing Machiner (ACM) Conference on Wireless Network Security (WiSec).
The award-winning paper is entitled: "Mobile User Location-specific Encryption (MULE): Using Your Office as Your Password."

Full text.

CUPS wins Google Focused Research Award
Dr. Lorrie Cranor, CUPS Director, has been named one of the recipients of a Google Focused Research Award ... According to Google, "These unrestricted grants are for two to three years, and the recipients will have the advantage of access to Google tools, technologies, and expertise."
Dr. Cranor is one of thirty-one professors at ten universities, working on twelve different projects.
Full text.

A Report from "Hacking Comes of Age: Climategate, Cyber-Espionage and iWar," a University Lecture Series Event
On March 18, 2010, six distinguished speakers participated in a Carnegie Mellon University Lecture Series (ULS) panel on "Hacking Comes of Age: Climategate, Cyber-Espionage and iWar." The panel explored these issues with uncommon depth and uncommon clarity. This event was a testimonial on just how uniquely situated Carnegie Mellon University really is, to serve as a vital national resource; the event also underscored the importance of CyLab's role within the University, cultivating, as it does, both the human factor and the technological edge. (Indeed, five of the six panel participants have some CyLab affiliation.) Full text.

A Report on the CyLab Silicon Valley Briefing
On 3-8-10, an impressive gathering was held at the Carnegie Mellon Silicon Valley Campus in NASA Research Park. The presenters were CyLab researchers. The other participants consisted of CEOs, VPs, CTOs, CSOs and leading technologists from a range of companies including Cisco and Microsoft to WhiteHat Security and iSEC, along with regional representatives from the Federal Bureau of Investigations and the U.S. Secret Service, as well as Board of Directors members from the local chapters of Information Systems Security Association (ISSA) and the American Society for Industrial Security (ASIS). Full text.

CyLab's Cranor Testifies on Privacy Issues to Joint Hearing of Two Congressional Subcommittee
On 2-24-10, the U.S. House of Representatives Committee on Energy and Commerce's Subcommittees on Commerce, Trade, and Consumer Protection and Communications, Technology, and the Internet held a joint hearing titled, "The Collection and Use of Location Information for Commercial Purposes."
Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS) testified on the privacy issues related to the use of location information for commercial purposes.

Full text.

For more about CyLab, visit http://www.cylab.cmu.edu/

Friday, November 20, 2009

Significant Contribution of Carnegie Mellon Privacy Research Cited in Congressional Hearing

U.S. Capital Building

I want to credit the work dozens of dedicated faculty and students working on consumers' data privacy at Carnegie Mellon University, located in the heart of my district, have done. [Carnegie Mellon University], the data privacy lab and CyLab have all greatly contributed to the academic literature, commercial consciousness, public awareness, and my understanding of this issue. Rep. Mike Doyle (D-PA)

Significant Contribution of Carnegie Mellon Privacy Research Cited in Congressional Hearing

The work of Carnegie Mellon CyLab faculty and students was cited today in remarks by Rep. Mike Doyle (D-PA.) during hearings on Exploring the Offline and Online Collection and Use of Consumer Information held by the Committee on Energy and Commerce's Subcommittee on Commerce, Trade and Consumer Protection. Doyle also quoted CyLab researcher Alessandro Acquisti directly.

Here is a transcript of Rep. Doyle's remarks (thanks to CUPS' Aleecia McDonald).

"Thank you, Mr. Chairman, for holding this hearing today. Trading and selling of personal information began as long ago as 1899. Two brothers created the retail credit company to track the credit worthiness of Atlanta grocery and retail customers. Some people know that company now as Equifax. Since then, the cost of storing and manipulating information has fallen sharply, and now organizations capture increasing amounts of data about individuals' behavior. Consumers hunger for personalization, product services, websites that cater to them. That causes them to reveal information about themselves. Ordering off a catalog reveals other information. Using a credit card yields more. And thinking you have to send in that warrantee card can reveal almost your entire life to other parties.
But that information probably delivers better products, more targeted services, and a more enjoyable Internet experience. As Alessandro Acquisti of Carnegie Mellon writes, 'Is there a combination of economic incentives and technological solutions to privacy issues that is acceptable for the individual and beneficial to society?' In other words is there a sweet spot that satisfies the interests of all parties? And then, what are the rules of the road that we need to put in place to make sure consumers' privacy is protected and that commerce flourishes. That's what I hope to learn more about in today's hearing. I want to credit the work dozens of dedicated faculty and students working on consumers' data privacy at Carnegie Mellon University, located in the heart of my district, have done. [Carnegie Mellon University], the data privacy lab and CyLab have all greatly contributed to the academic literature, commercial consciousness, public awareness, and my understanding of this issue. Thank you, Mr. Chairman, I yield back."


Details and video of the hearing are available from the Committee on Energy and Commerce Subcomittee Note: Video starts at 17:40 with audio starting at 18:26 -- nothing but a title screen before that. Representative Doyle begins speaking at 43:29.

Tuesday, August 25, 2009

CUPS Director Lorrie Cranor Receives NSF Funding For Interdisciplinary Doctoral Program in Privacy and Security



Patrick Kelly of Tonawanda, N.Y., also said the new program will dovetail nicely with his privacy research. "I'm looking at how to improve the often arcane privacy policies all shoppers experience when surfing the Internet," said Kelly, a Ph.D. student at the Institute for Software Research in the School of Computer Science. "We would ultimately like to create a standard format for privacy rules."



CUPS Director Lorrie Cranor Receives NSF Funding For Interdisciplinary Doctoral Program in Privacy and Security

Carnegie Mellon University’s Lorrie Cranor and her colleagues received a five-year, $3 million grant from the National Science Foundation (NSF) to establish a Ph.D. program in usable privacy and security.
“Carnegie Mellon’s CyLab Usable Privacy and Security (CUPS) Doctoral Training Program will offer Ph.D. students a new cross-disciplinary training experience that helps them produce solutions to ongoing tensions between security, privacy and usability,” said Cranor, associate professor in the Institute for Software Research, the Department of Engineering and Public Policy and Carnegie Mellon CyLab — one of the largest university-based cybersecurity education and research centers in the world.
Cranor said the CUPS doctoral training program is designed to give students both classroom learning as well as collaborative research training with teams of mentors from different disciplines, internships and summer seminars …
The new CUPS program funded through the NSF’s Integrative Graduate Education and Research Traineeship program is now available to Ph.D. students across the university, including the programs in Computation, Organizations and Society, Engineering and Public Policy, Human Computer Interaction, Computer Science, Electrical and Computer Engineering, and Public Policy and Management.
Core faculty in the program include Alessandro Acquisti, an assistant professor of information technology and policy in the H. John Heinz III College and CyLab researcher; Lujo Bauer, a research scientist with Carnegie Mellon CyLab and the Electrical and Computer Engineering Department; Nicolas Christian, associate director in the Information Networking Institute and CyLab researcher; Julie Downs, a research scientist in the Social and Decision Sciences Department; Jason Hong, an assistant professor in the Human Computer Interaction Institute; Norman Sadeh, a professor in the Institute for Software Research and CyLab researcher; and Marios Savvides, director of the Carnegie Mellon CyLab Biometrics Center and a research scientist in the Department of Electrical and Computer Engineering.

Full text of the press release

For more information

Some Related Posts

CyLab CUPS Researchers Release Study on SSL Warning Effectiveness

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

CyLab's Cranor Publishes in Scientific American --"How to Foil Phishing Scams"

CyLab Research on the Cost of Reading Privacy Policies Makes Waves

CyLab Chronicles: Q&A with Lorrie Cranor

Sunday, August 16, 2009

Android Security, Naked Keystrokes, Selling Viagra, Crying Wolf & More! -- A Report from the 18th USENIX Security Symposium (Montreal, 2009)

Montreal Harbor, 1889


The city proper covers most of the of the Island of Montreal at the confluence of the Saint Lawrence and Ottawa Rivers. The port of Montreal lies at one end of the Saint Lawrence Seaway, which is the river gateway that stretches from the Great Lakes into the Atlantic Ocean.[36] Montreal is defined by its location in between the St. Lawrence river on its south, and by the Rivière des Prairies on its north. The city is named after the most prominent geographical feature on the island, a three-head hill called Mount Royal, topped at 232 m above sea level. Wikipedia

Android Security, Naked Keystrokes, Selling Viagra, Crying Wolf & More! -- A Report from the 18th USENIX Security Symposium (Montreal, 2009)

By Richard Power


The 18th USENIX Security Symposium was held in Montreal, Quebec (August 10-14, 2009). This conference always provides an excellent opportunity to catch up on the thinking of some impressive minds and delivers the most technical content of all the major security-focused IT conferences.

USENIX distinguishes itself by being a non-profit organization, and acting like one. Seventy-nine students were given stipends to attend this year’s Security Symposium, at a cost of approximately $100,000. This is how USENIX spent the contributions of its sponsors, as well as a significant chunk of its own funds. None of the commercial conferences can lay claim to any such altruism.

I asked legendary login editor Rik Farrow (well, he is the Editor, and kept up the publication’s high standards for many years, enough to qualify as a legend in this field, and yes, he is my friend) how he would distinguish USENIX Security Symposium from the other major cyber security conferences?

“USENIX Sec is one of four top tier security research conferences, and certainly my favorite because accepted papers must include an implementation. So this goes well beyond theory.”

Rich Cannings, Android Security Leader at Google delivered the keynote, “Securing a Mobile Platform from the Ground Up.”

Here are my notes from the talk --

Cannings started off by breaking down the numbers:

-- 6.77 billion human beings on the planet.
-- 1.48 billion Internet-enabled PCs
-- 4.10 billion mobile phones, with a 12-18 month average replacement rate.
-- 1 billion mobile phone purchases per year

“And 13.5% of them are smart phones. This number will soon compare with the number of Internet enabled PCs, and they will become major security targets.”

Next, Cannings gave some background on Android:

Google’s Android is free, open source mobile program, intended to “empower both users and developers.”

It has a Linux kernel. It relies upon 90+ open source libraries (e.g., SQLite for structured data storage, OpenSSL, etc.). It supports common codes for sound, image, etc.

Android is also “designed to protect battery life.”

Developers don’t understand battery life
Users do.

In outlining Google’s security philosophy in regard to Android, Cannings articulated some of the premises with which they approach the issue:

-- Finite time and resources
-- Humans have difficulty understanding risk
-- Safer to assume that most developers do not understand security
-- Most users do not understand security

The cornerstones of the Android security philosophy, as formulated by Cannings, emphasize some basic needs:

-- Need to prevent security breaches from occurring
-- Need to detect them when they occur
-- Need to minimize their impact
-- Need to react to both to vulnerabilities and breaches swiftly

Cannings went on to explore each of these elements as they came into play in the development, roll-out and support of Android.

No one with serious experience in cyber security could argue with Cannings’ guiding principle: “Security is an ongoing process, not a checkbox.”

But of course, Android means “five millions lines of new code,” utilizing, as I mentioned earlier, one hundred open source libraries. And since Android is open source, Cannings remarked, it “can’t rely on obscurity.”

There are tremendous challenges ahead.

Farrow elaborates.

“I liked the keynote, as I am very concerned about the security of mobile devices. The obvious trend is for people to use their smart phones as their primary method for interacting with the Internet, and I would love to see the security of phone software fare MUCH better than Windows has in this area. Rich Canning did a good job of describing the Android security model, but I was left feeling that there are real weaknesses in the Android security model largely because the Android team is being rushed, and layering their security on top of ancient UNIX security features. The notion of relying on users to permit applications based on the number and importance of privileges required is flawed, as most people make poor security decisions (and there is lots of research to back this up).

“Android does present a chance to create a secure environment,” Farrow adds, “but it must also satisfy both developers and users if it is to be successful.”

The program committee received one hundred seventy submissions for this year’s Symposium, only twenty-six papers were accepted.

Martin Vuagnoux and Sylvain Pasini of LASEC/EPFL received an “Outstanding Paper” award for “Compromising Electromagnetic Emanations of Wired and Wireless Keyboards.” These students cobbled together a system capable of converting broad spectrum radio emissions of keyboards into actual keystrokes.

Roxana Geambasu, Tadayoshi Kohno, Amit A. Levy, and Henry M. Levy of University of Washington also received an “Outstanding Papers” awards for “Vanish: Increasing Data Privacy with Self-Destructing Data.”

Carnegie Mellon University was represented by Joshua Sunshine, who presented “Crying Wolf: An Empirical Study of SSL Warning Effectiveness,” headline-grabbing research conducted with Serge Egelman, Hazim Almuhimedi, and Neha Atri, under the guidance of Lorrie Cranor, Director of CyLab’s Usability of Privacy and Security Lab.

Of course, CyBlog covered this compelling research, recently, when the story broke. (See CyLab CUPS Researchers Release Study on SSL Warning Effectiveness)

CyLab corporate partners can read my full report on the 2009 USENIX Security Symposium, including my notes on Vern Paxson's “How the Pursuit of Truth Led Me to Selling Viagra” and interview with Metronics 4.0 chair, Jennifer Bayuk, in the Intelligence Briefing section of the CyLab partners-only portal.

Monday, August 3, 2009

CyLab CUPS Researchers Release Study on SSL Warning Effectiveness



"People get pop-ups in their browsers and they say something about security and they don't know what they are, so they swat them away," said Lorrie Cranor, associate professor of computer science and engineering at Carnegie Mellon. "Nothing bad happened before and they think nothing bad will happen again." ABC News, 7-30-09



CyLab CUPS Researchers Release Study on SSL Warning Effectiveness

Josh Sunshine will be presenting the paper Crying Wolf: An Empirical Study of SSL Warning Effectiveness at the USENIX 2009 Security Symposium.

Co-authored by with Serge Egelman, Hazim Almuhimedi, Neha Atri, and Lorrie Faith Cranor, Crying Wolf is another compelling example of how Carnegie Mellon University CyLab is helping to both frame the dialogue and deliver the goods on how best to raise awareness and deliver effective user education:

We conducted a survey of over 400 Internet users to examine their reactions to and understanding of current SSL warnings.
We then designed two new warnings using warnings science principles and lessons learned from the survey … Our results suggest that, while warnings can be improved, a better approach may be to minimize the use of SSL warnings altogether by blocking users from making unsafe connections and eliminating warnings in benign situations.
Crying Wolf: An Empirical Study of SSL Warning Effectiveness

Dr. Cranor, Director of the CyLab Center for Usable Privacy and Security (CUPS), was quoted in several news media stories breaking the study’s results.

Here is a sampling with links to the full texts:

After studying the behavior of more than 400 Internet users, Carnegie Mellon University computer researchers concluded that because users encounter so many pop-up warnings in benign situations, they have become immune to the messages … People get pop-ups in their browsers and they say something about security and they don't know what they are, so they swat them away," said Lorrie Cranor, associate professor of computer science and engineering at Carnegie Mellon. "Nothing bad happened before and they think nothing bad will happen again." ABC News, 7-30-09

“The big takeaway is that computer security warnings are not an effective way of addressing computer security,” study researcher and co-author Lorrie Faith Cranor, an associate professor of computer science, engineering and public policy at Carnegie Mellon University, told SCMagazineUS.com on Tuesday. “People don't read warnings and don't understand them when they do read them” … In addition, researchers also surveyed experts – those with an IT-related degree, computer security work experience or programming knowledge – to see if they would behave any differently when receiving a warning. Researchers found that even experts often ignored the warnings, indicating that the system of relying on warnings to communicate computer security risks is “fundamentally broken,” Cranor said. SC Magazine, 7-28-09

"Everyone knew that there was a problem with these warnings," said Joshua Sunshine, a Carnegie Mellon graduate student and one of the paper's co-authors. "Our study showed dramatically how big the problem was … hey found that people often had a mixed-up understanding of certificate warnings. For example, many thought they could ignore the messages when visiting a site they trust, but that they should be more wary at less-trustworthy sites. "That's sort of a backwards understanding of what these messages mean," Sunshine said. "The message is validating that you're visiting the site you think you're visiting, not that the site is trustworthy." Computerworld, 7-24-09

Friday, July 17, 2009

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness



"Any intelligent fool can make things bigger, more complex, and more violent. It takes a touch of genius -- and a lot of courage -- to move in the opposite direction." -- Albert Einstein

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

-- Richard Power


The success of the fifth annual Symposium on Usable Privacy and Security (SOUPS) -- more papers submitted than ever before, more papers accepted than ever before, more attendees registered than ever before -- is an affirmation of the usability concept and its vital role in the development of security and privacy strategies.

On the third and final day of SOUPS 2009, Lorrie Cranor, the driving force behind both SOUPS and the CUPS from whence it poured, was unable to attend the morning session, she was across town, keynoting on "Teaching Johnny Not to Fall for Phish" at the Sixth Conference for E-Mail and Anti-Spam.

The research of Cranor and her CUPS colleagues demonstrates that user education can indeed play a critical role in the fight against phishing, etc., IF the tools utilized are engaging, enlightening and designed to exploit the "teachable moment." It has also led to the formation of Wombat Security Technologies.

In the technical paper session on Passwords and Authentication, Alexander De Luca of the Media Informatics Group at University of Munich presented Look into my Eyes! Can you guess my Password?, co-authored with his University of Munich colleagues Martin Denzel and Heinrich Hussmann.

In the same session, Stuart Schechter of Microsoft presented 1 + 1 = You: Measuring the comprehensibility of metaphors for configuring backup authentication, co-authored with his Microsoft colleague, Robert Reeder.

The work of De Luca, Denzell and Hussman explored the potential of having users authenticate themselves, particularly at terminals in public places, by drawing shapes with their eyes.

The work of Schechter and Reeder explored the issues involved in user-chosen challenge questions (e.g., the kind you answering when you've lost your password or user ID in Hotmail or G-mail), and showed that somewhat better results were achieved if the user had to take an exam and get a passing grade.

These and other presentations I attended were fascinating.

Our problem is, however, that the challenge in cyber security and privacy is not one of cleverness, but one of consciousness.

We are still between worlds, really.

The Information Age that Alvin Toffler heralded as the "Third Wave" has already broken over our heads, it has already swept us away; but, in many ways, our minds are still on the shore, or reaching back toward the shore, wanting to somehow, impossibly, to take it with us.

In the 1990s, the news was that the periphery between the network and the Internet no longer existed. Here and now, at the end of the first decade of the 21st Century, the news is that the periphery between the mind and the World Wide Web is gone.

The implications are profound.

Some months ago, at dinner with a colleague from inside the US intelligence community's own attempt to comprehend this Brave New World, we discussed these issues at great depth, and both came to the same conclusion: most of the human race will not recognize the world in which they live and work even as soon as ten years from now.

Most of what we are trying to accomplish in cyber security and privacy is based on a paradigm that has been eclipsed; no, not an IT-related paradigm, an old paradigm of the human psyche and its relationships to both the natural world and the digital world, and the interpenetration of all three.

There is something profoundly new coming in the realm of cyber security and privacy.

You and I will recognize it when we see it because not only will we not have seen it before, it will change the way we perceive problems and approach solutions.

It may well come from such academic research. That's why participating in conference such as SOUPS is of great importance.

But it will not reflect superior cleverness, it will signal a shift in consciousness.

Of course, meanwhile, we must rely on superior cleverness, and that too is a reason to participate in SOUPS, etc.

For more commentary on SOUPS 2009, go to the CUPS Blog.

Speaking of which, I will be blogging from Blackhat later this month and from the USENIX Security Symposium in August. Stay tuned.

Summary of SOUPS 2009 Posts:

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CUPS Related Posts:

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

Thursday, July 16, 2009

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users



"The Windows Vista personal firewall provides its diverse users with a basic interface that hides many operational details. However, concealing the impact of network context on the security state of the firewall may result in users developing an incorrect mental model of the protection provided by the firewall." Fahimeh Raja, University of British Columbia

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users

Paul Van Oorschot of Carelton University in Ottawa chaired the Mental Models session.

Fahimeh Raja of University of British Columbia (Vancouver) presented Revealing Hidden Context: Improving Mental Models of Personal Firewall Users, co-authored with her colleagues, Kirstie Hawkey and Konstantin Beznosov.

The goal of the study was to investigate the impact of adding contextual information to the Vista Firewall Basic Interface. The researchers looked at the impact of Vista Firewall functionality on users' mental models, as well as the impact of Vista Firewall configuration on users' understanding.

"The Windows Vista personal firewall provides its diverse users with a basic interface that hides many operational details. However, concealing the impact of network context on the security state of the firewall may result in users developing an incorrect mental model of the protection provided by the firewall."

Raja and her colleagues determined that because the security technology makes changes in the users' security state, it is important to somehow communicate these changes to users; "otherwise, these users can be left in dangerous situations; for example, only protected in the current network context but believing themselves to be protected for future network contexts."

Users could think that their firewall was turned on when it was turned off, or conversely, that their firewall was turned off when it was turned on.

"Users need to understand the effect of the configuration on the system's security state. We argue as users become more mobile, it is increasingly important to understand the security state for both current and future contexts of use."

They concluded that the design of the Vista Firewall Basic Interface does not provide enough context for mobile users. If unaware that configuration changes only apply to current network location, users may be left with dangerous misconceptions. The researchers also concluded that users' mental models can be supported by revealing context.

The implications of this study are important, i.e., it may be possible to balance complexity and security.

Two other papers were presented in this session:

Andrew Besmer of University of North Carolina (Charlotte) presented Social Applications: Exploring A More Secure Framework, a paper co-authored with colleagues Heather Richter Lipford, Mohamed Shehab and Gorrell Cheek, also from the Department of Software and Information Systems.

Ponnurangam Kumaraguru of Carnegie Mellon University CyLab presented on School of Phish: A Real-Word Evaluation of Anti-Phishing Training, a paper co-authored with fellow Carnegie Mellon researchers Justin Cranshaw, Alessandro Acquisti, Lorrie Cranor, Jason Hong, Mary Ann Blair and Theodore Pham.

Some Related Posts:

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.

-- Richard Power

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"



Often, futuristic shopping scenarios highlight ways in which a network of computers are able to determine the items a consumer needs by intelligently surveying food stocks and other goods in the individuals home. However, as Friedewald and colleagues note, such scenarios tend to take an individualistic approach, ignoring the ways in which the various interests within a family may converge or conflict within a shopping expidition. In many families, shopping is considered a social activity where all family members might take part in the process. Younger members of a family (seldom seen in the ubicomp world) are typically active participants in the weekly shopping task, and are given their own responsibilities or activities. Linda Little, Elizabeth Sillence and Pam Briggs, Ubiquitous Systems and the Family: Thoughts about the Networked Home

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

Andrew Patrick and Simson Garfinkel, SOUPS Technical Papers Co-Chairs, announced SOUPS 2009 Best Paper Award has been bestowed on Ubiquitous Systems and the Family: Thoughts about the Networked Home by Linda Little, Elizabeth Sillence and Pam Briggs of the PaCT Lab, Northumbria University (U.K.).

Here are brief excerpts from the award-winning paper followed by a link to full text:

Developments in ubiquitous and pervasive computing herald a future in which computation is embedded into our daily lives. Such a vision raises important questions about how people, especially families, will be able to engage with and trust such systems whilst maintaining privacy and individual boundaries. To begin to address such issues, we have recently conducted a wide reaching study eliciting trust, privacy and identity concerns about pervasive computing. Over three hundred UK citizens participated in 38 focus groups. The groups were shown Videotaped Activity Scenarios [11] depicting pervasive or ubiquitous computing applications in a number of contexts including shopping. The data raises a number of important issues from a family perspective in terms of access, control, responsibility, benefit and complexity. Also findings highlight the conflict between increased functionality and the subtle social interactions that sustain family bonds. We present a Pre-Concept Evaluation Tool (PRECET) for use in design and implementation of ubicomp systems."

The design and implementation of ubiquitous systems cannot be solely based on traditional HCI issues of functionality, usability and accessibility. In a shopping context at least ubicomp systems need to incorporate a better understanding of family interactions and need to show some sensitivities to the natural information sharing boundaries that occur within the family. Such an approach will resonate with developments in other technologies, where the focus on ‘user-experience’ as opposed to ‘usability’ has seen a shift towards an understanding of the wider social impacts of HCI.


Ubiquitous Systems and the Family: Thoughts about the Networked Home, Linda Little, Elizabeth Sillence and Pam Briggs, PaCT Lab, Northumbria University, U.K.

Some Related Posts:

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.

-- Richard Power''

Wednesday, July 15, 2009

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology


"Once you have real people using the security in this design, what is the performance that you can expect? What is the performance you can expect at the security level in terms of the choices that the users will make? This is where we have a problem ... We don't have a clear set of criteria to assess a particular performance against ... If you don't have a criteria for what is actually an acceptable level of performance, then you just don't know if it is good enough or not." Angela Sasse, University College London

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

By Richard Power


As I drove across Google's sprawling Mountain View campus, the memory of a 2005 visit to Microsoft rose up in my mind. I had traveled there to participate in a CSO Council meeting. The Redmond campus is a city-state, of course, with its own police force and its own street. In 2005, Google was only ten years old. Fast forward another four years. Just this month, Google announced that it is going to challenge Microsoft on the OS front (See Now Google parks its tanks right outside Microsoft's gates, Guardian, 7-12-09).

This afternoon, sitting in a sun-drenched pavilion on Google's grounds during a lunch break, I looked up from my grilled salmon to notice a employee walking by, with her dog on a leash, then I saw another, and then I saw another. There were dogs everywhere. I asked if this happened to be a special "Bring Your Dog to Work Day," but was told, "No, we are allowed to bring our dogs to work everyday." Hmmm. Could this remarkable corporate culture innovation give Google an edge in the struggle ahead?

But, of course, I did not come here to handicap the coming clash of the titans; I came here to report to you on the fifth Symposium on Usable Privacy and Security (SOUPS), which Google is hosting and co-sponsoring along with CyLab. (Next year, SOUPS will be held in Redmond.)

SOUPS is an annual event organized by Carnegie Mellon CyLab's Usable Privacy & Security Lab (CUPS).

Several significant evolutionary trends have emerged in cyber security and privacy over the last decade, ranging from the somewhat ill-conceived search for Return on Investment (ROI) in cyber security deployments to the much more promising inquiry into the ways in which the sciences of economics and psychology might better inform cyber security development. The quest for "Usable Security and Privacy" is one of the most intriguing of these trends; and SOUPS provides an invaluable forum for the exploration of themes in this vital area of research.

The first day of SOUPS 2009 was built around an all-day tutorial on "Designing and Evaluating Usable Security and Privacy Technology" led by M. Angela Sasse, Professor of Human-Centred Technology in the Department of Computer Science at UCL, Clare-Marie Karat, Research Staff Member in the Policy Lifecycle Technologies department at the IBM TJ Watson Research Center, and CyLab researcher Roy Maxion, a faculty member in the Computer Science and Machine Learning Departments at Carnegie Mellon University.

Sasse spoke on "Evaluating for Usability & Security."

Karat delivered a "Case Study of Usable Privacy and Security Policy Research."

Maxton shared "Mechanics of Experiments, Forensics, and Security."

Here are some excerpts from my notes and transcription of Sasse's compelling talk:

Starting off by citing a "cumbersome" definition of "evaluation" as “an assessment of the conformity between a work system's performance and its desired performance.” (Whitefield et al., 1991); Sasse then explained, "What they really mean by 'work system' is if a user works together with a system, what is the performance that you are going to get out of the combination? That is what you are actually interested in. Once you have real people using the security in this design, what is the performance that you can expect? What is the performance you can expect at the security level in terms of the choices that the users will make? This is where we have a problem ... We don't have a clear set of criteria to assess a particular performance against ... If you don't have a criteria for what is actually an acceptable level of performance, then you just don't know if it is good enough or not."

In the course of outlining the essentials of a proper usability evaluation plan, Sasse went into some depth concerning evaluation goals, first emphasizing the difference between summative goals (e.g., "Mech 1 performs better than Mech 2" or "Mech 1 meets performance criteria X, Y, Z") and formative goals (e.g., "exploratory evaluation of feasibility and indicative performance, user feedback, pointers for improvement"), and then exploring the breakdown of an evaluation goal.

"When it comes to usability and security, we need to look at two things: not only how well does the user perform with the security mechanism (e.g., how long does it take the user to remember, read off and enter the one-time pin, how long does it take to figure out which finger to use, where to put, etc.) but also what is the primary task, or production task, within which this security task is performed. The kind of experiments we have seen so far is basically, 'Thank you for coming, try this security mechanism, and I will measure how well you do.' But if it is envisioned, for example, that they do this as part of their on-line banking session, or for governments purposes, to fill their taxes on-line, then we need to create a realistic approximation of what that whole procedure looks like. At what point, would a user normally in the real world approach the system with the goal of 'I'm filing my taxes, and goddamn I'm late, I've got about twenty hours or so to do it."

"There are some things you can do in the lab, but there are some things that you can never really reproduce in a lab. If people anticipate that they are going to have problems with a security mechanism, they are going to change altogether how they behave and how they do their work. You find that because people fear that they might fail to authenticate themselves to a service that they either completely re-organize how they do their work, which has an impact on their productivity, and an impact on the productivity of the organization overall, or they might find workarounds, for instance, they just find ways of leaving the system open in order to avoid entering their credentials time and time again. You are never going to see people do that in the lab experiment."

Along with evaluating "performance achieved on security tasks" as well as the "actual level of security achieved given user choices and behaviour," Sasse also stressed evaluating "at what cost" these were achieved -- "to the individual user, to the system owner and to society as a whole."

"I recognize some of the issues, and they are pretty obvious," Roy Maxton asked Sasse, "so my question is what do you think makes it not obvious to so many people?"

"The answer is that so far security has basically been treated as special," she responded. "A lot of organizations out there are not very good at assessing the ongoing cost of ownership of certain types of technology. And when it comes to security that problem is magnified, because the argument always made is 'Security is important, just think of what could happen if we didn't have it.' They tend to only look at the cost of purchasing it and putting it in place. How much time or productivity is it going to take out of a company is a question I have never seen anybody ask up front, until very recently. Or 'how much of our system administrator's time is it going to take ... it is generally not looked at and factored into the cost of operating. But I am sure this will change. These kinds of ideas have now gotten out there. Traditionally, the only argument for security was risk mitigation, it was very often not off-set by the cost of ownership and operation ..."

Sasse went on to articulate other key elements of the evaluation process:

Scope, both summative (e.g., "sample large enough for adequate statistical power; generally larger samples than for formative evaluations" and formative (e.g., "explanatory results" providing "reasons for user choices" and "reasons for failure');

Participants (e.g., "need to control for practice and interference effects")

Context of use (e.g., need to replicate demands of production task, equipment used, physical context and situational context)

Criteria, including user cost (e.g., physical and mental workload), owner cost (e.g., "needs to be proportionate to degree of security achieved"), user satisfaction (e.g., "user confidence in mechanism itself" and "their own ability to operate it correctly") and, of course, security.

Aye, but there's the rub. The internationally recognized framework, Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408), does not include in usability.

In her conclusion, Sasse emphasized the need to develop a framework for evaluating usability and security to ensure comparable and generalisable results, suggesting it that should be "linkable to assessment via Common Criteria" and might incorporate the NIST taxonomy as template for procedure.

These notes reflect the richness of the discussion in this day-long tutorial led by Karat, Maxton and Sasse.

Stay tuned for more from SOUPS 2009 over the next two days.

Some Related Posts:

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.

Sunday, May 17, 2009

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"


"As we all realize on a daily basis, application developers have great expect- ations about what we users are capable of doing. They expect us to be able to properly configure the firewall on our home computer and virus settings on our cell phone. As enterprises move towards more agile and decentralized business practices, developers also expect us to configure increasingly complex access control policies at work. Are these expectations realistic? If they are not, how much trouble are we in and what can we do about it?"

CyLab Seminar Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

[NOTE: CyLab's weekly seminar series provides a powerful platform for highlighting vital research. The physical audience in the auditorium is composed of Carnegie Mellon University faculty and graduate students, but CyLab's corporate partners also have access to both the live stream and the archived content via the World Wide Web. From time to time, CyBlog will wet your appetite by offering brief glimpses into these talks. Here are some of my notes from a talk delivered by Norman Sadeh on 3-16-09. Sadeh's team of collaborators in this important research includes faculty members Jason Hong, Lorrie Cranor, Lujo Bauer, Tuomas Sandholm, post docs Paul Hankes Drielsma, Eran Toch, Jinghai Rao, and PhD students Patrick Kelley, Jialiu Lin, Janice Tsai, Michael Benisch and Ram Ravichandran. -- Richard Power]

Can users be expected to effectively specify their policies? Do people even what policies they want or need? Even if they did, could they articulate these policies? What if policies evolve over time? Are we always willing to invest enough time to have perfect policies or are there important trade-offs between user burden and policy accuracy? Can we develop technologies that mitigate these potential problems and empower users to more accurately and efficiently specify security and privacy policies?

To shed some light on these compelling questions, Norman Sadeh shared some insights into data from lab and field research on mobile social networking applications.

An example is a location sharing application that uses GPS and WiFi triangulation on laptops and cell phones and allows people to share their locations with friends, families, colleagues, and ... Well, that is one of the big issues that arises in this space, who exactly are you sharing this information with? And to what extent can you control access to it?

According to Sadeh, although many such applications have been released over the past several years, adoption has been rather limited. Early on, Sadeh and his team noticed that users had great difficulty specifying location sharing privacy policies that accurately reflected their preferences.

“So what’s going on? Is it because these applications have bad user interfaces? Do people who define more privacy rules do better? Do the people who spend more time defining and refining their rules do better?” Sadeh continued. “Location sharing applications seemed to be a very good domain to study these and related issues. Because, at the end of the day, the problems are the same, whether you are trying to configure a firewall at home or at work, or you are trying to configure social networking policies. Ultimately, the question is whether we can empower users (both expert users and lay users) to specify combinations of rules that enact the behaviors they really want to enforce?”

From 2003 to 2005, Sadeh and his colleagues worked on early prototypes and did some lab studies. In 2006 and 2007, they launched the "People Finder" application, which involved a couple of hundred users in multiple pilots, with laptops and some cell phones.

In 2008, they developed their first Facebook application, Locyoution, which was piloted by over one hundred users on their laptops.

In February, 2009, Sadeh and his colleagues launched Locaccino, a new Facebook app, which could scale to hundreds of thousand of users if successful.

Data from the team’s research indicates that the problem is not bad interfaces, or the number of rules defined, or even the time spent defining and refining those rules.

But Sadeh’s work and the data he has collected through a number of pilots are providing a number of powerful insights into what it takes to better support users as they define and maintain security policies. One element of functionality that has been shown by Sadeh and his teamto have a major impact on the ability of users to specify policies they feel more comfortable with is auditing functionality:


Auditing (‘feedback’) functionality that enables users to review decisions made by the rules they have specified and ask questions such as “Which rule in my policy is responsible for this particular decision” can help users better understand the behaviors their policies give rise to

The chart on "Evaluating Usefulness of Feedback," provides a summarized view of the impact of auditing (or “feedback”) functionality on user’s comfort and, ultimately, their "willingness to share their locations with others." What you are looking at in these two charts are the total number of hours per week different users were willing to share their location with others, depending on whether they had access to feedback functionality or not.. People who had access to the auditing functionality (“Feedback” chart) started to feel more comfortable and gradually relaxed their rules, utlimately resulting in more sharing than what was observed among users who did not have access to this functionality (“No Feedback” chart).

"That makes perfect sense. You see what is going on, you gain more confidence that the system is, in fact, not leading to any sort of abuse, and is not leading to any bad scenarios, and you end up sharing your location on a more regular basis,” Sadeh explained. “This is, by the way, one of those very simply types of functionality that none of the commercial applications out there today supporting location-sharing offers. So it is not surprising that when these applications get launched, tens of thousands of people download them, but these people only end up using the application for a few days.” Current location-sharing applications are very restrictive in the types of controls they allow their users to define and provide no such feedback functionality. The end result is very little sharing. In other words, the applications are of little value.

In his remarks, Sadeh went on to explore another challenging question, "How expressive should security or privacy policies be?"

Security and privacy policies can be viewed in the light of research on mechanism design. Through recent work, Sadeh and his colleagues has looked at the benefits afforded by more expressive mechanisms or more expressive security and privacy policies, when it comes to more accurately capturing the preferences of a user or organization... ” What are the sorts of features, and the types of attributes, I will need to make available in my language to my users, so that they can end up with policies that accurately capture their intended policies?"

" You can think of a security or privacy mechanism as being some sort of function that associates different actions with different sets of conditions subject to a collection of preferences expressed by a user. Work in mechanism design typically assumes a fully rational user. In other words, given some level of expressiveness in a policy language, we would assume that our user will be able to fully take advantage of that expressiveness. ... This is what is stated in this complex formula with the arg max. The notion of efficiency is a traditional one in mechanism design. Ideally we would want our policy, or mechanism, to be as efficient as possible, namely to do the best possible job capturing our user’s ground truth preferences. If however the policy language the user is given imposes restrictions on what he or she can express, the efficiency of the resulting mechanism may be less than 100%. In other words, the user may have to make some sacrifices. For instance, you may have to decide that you will not disclose your location to a given individual at all because you don’t have the ability to accurately specify the fine conditions under which you would have been willing to do so. Instead, given the restrictions of the available policy language, you decide that you will “play it safe” and simply deny all requests for your location from that individual. In general, one can define the efficiency of a security or privacy mechanism by looking at all possible scenarios and looking at the percentage of the time when the best policy a user can define (subject to the expressiveness of the available policy language) accurately captures what the user would like to do (e.g. sharing your location versus not sharing it). However rather than doing this for a single user, we will try to do this for the entire population of users for whom the mechanism is being designed. In practice, one can approximate this by looking for a representative sample of the target user population, collect their ground truth preferences and see how we can optimally configure policies to capture their preferences subject to different restrictions in the available policy language.” –For instance, in the case of location sharing applications, we can collect people’s ground truth preferences about sharing their locations with others and examine the impact of different levels of expressiveness in the language made available to users to specify the conditions under which they are willing to disclose their location to others. This means estimating the benefits afforded by a privacy language where users can specify rules that include restrictions tied to groups of people (e.g. friends, colleagues), restrictions tied to the day or time of the request, or to where the user is at the time his or her location is requested (....or some combination of the above).

What Sadeh and his colleagues found was that such insight could be applied to the design of any security or privacy mechanism to help users take fuller advantage of the expressiveness of the language through the interface. But real users are not fully rational. There is a point where users will say, "Well, I don't care. Yes, in principle I could get a higher efficiency, i.e., policies that more closely reflect what I really want, but perhaps I am not willing to invest the time, or no matter how hard I try, beyond six or seven rules I get completely confused."

At this point, Sadeh remarked, the next natural question arises, "What about machine learning? Could machine learning help us?"

In some of the team's early experiments, using case-based reasoning, it was clear that yes, in principle, machine learning could make "a huge difference."

"You might say this is wonderful, problem solved, let's just use your game theory results, add machine learning, and we're done. So why is it that this is not the case?'

"There is a slight problem," Sadeh points out, "and that is that we are talking about privacy and security. Machine learning can be used for lots of different things, and be more accurate than we humans can be, but machine learning is not 100% accurate and there lies the potential problem. It could end up making a decision that we don't feel comfortable with at all. Even if machine-learning gives us 99% accuracy, in security or privacy the remaining 1% could be devastating: you could be giving away national security secrets, or sensitive corporate data ... “

The problem, Sadeh adds, is that machine learning is traditionally configured as a “black box” technology, i.e., users are unlikely to understand the policies they end up with.

"So we are developing different families of machine learning techniques that essentially reconcile the power of machine learning, which is unquestionable, with the principle that ultimately the user has to remain in control. If the user loses control, you have not accomplished anything. “

"Can we develop technology that incrementally suggests policy changes to users? This leads us to the concept of user-controllable policy learning. The idea is that users are willing to provide feedback. We have seen that they are actually keen to have the auditing interface; and we have also seen that they are willing to provide feedback, e.g. thumbs up or thumbs down on decisions made by their current policy. They are not necessarily going to review every decision that was made, but they are willing to go back occasionally and provide feedback. ... So what we do is take this feedback, but instead of taking over, we develop suggestions we are going to present to the user and let the user decide whether or not to accept these suggestions. You might say, 'that sounds very easy, anybody can do that.' Well, there is another problem, in order for these suggestions to be meaningful, they have to be understandable: we have to develop suggestions that a user can relate to. If your suggestion is a new decision tree with a number of different branches, the user will stare at it for a very long time and not know what to do. Instead, we tend to limit ourselves to incremental changes to user policies. We start from the policy that the user has already defined, and see if we can learn over time small, incremental variations to the policy that can be presented to the user in a way that he or she can still relate to them. When you do that, the user can make a meaningful decision, as to whether or not he likes policy changes you are suggesting and gradually improve the accurary of his or her policy. If conditions suddenly change, the user can also directly manipulate his or her policy, because he or she continues to understand it. There is no need to wait for machine learning to adapt to the new situation. So you have the best of both worlds, with users and machine learning working hand in hand.”

Yes, patents are pending.

Some References

User-Controllable Security and Privacy Project

N. Sadeh, J. Hong, L. Cranor, I. Fette, P. Kelley, M. Prabaker, and J. Rao,
"Understanding and Capturing People's Privacy Policies in a Mobile Social
Networking Application", Journal of Personal and Ubiquitous Computing
.

P.G.Kelley, P. Hankes Drielsma, N. Sadeh, and L.F. Cranor, "User-Controllable Learning of Security and Privacy Policies", First ACM Workshop on AISec (AISec'08), ACM CCS 2008 Conference. Oct. 2008.

J.Tsai, P. Kelley, P. Drielsma, L. Cranor, J. Hong, and N. Sadeh. Who’s Viewed You? The Impact of Feedback in a Mobile-location Application. To appear in CHI '09.

Michael Benisch, Patrick Gage Kelley, Norman Sadeh, Tuomas Sandholm, Lorrie
Faith Cranor, Paul Hankes Drielsma, and Janice Tsai. The Impact of Expressiveness on the Effectiveness of Privacy Mechanisms for Location Sharing. CMU Technical Report CMU-ISR-08-139, December 2008

Other Relevant Links

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Q&A w/ Norman Sadeh

Some Other CyLab Seminar Notes

CyLab Seminar Series: Of Frogs, Herds, Behavioral Economics, Malleable Privacy Valuations, and Context-Dependent Willingness to Divulge Personal Info

CyLab Seminar Series Notes: Why do people and corporations not invest more in security?

CyLab Research Update: Basic Instincts in the Virtual World?

For information on the benefits of partnering with CyLab, contact Gene Hambrick, CyLab Director of Corporate Relations: hambrick at andrew.cmu.edu