Showing posts with label SOUPS. Show all posts
Showing posts with label SOUPS. Show all posts

Sunday, July 13, 2014

A Decade Into Its Vital Work, Another Savory SOUPS, A Report from the 10th Annual Symposium On Usable Privacy and Security



CMU CyLab's Dr. Lorrie Cranor, Founder of CUPS and SOUPS preps
for welcoming remarks at SOUPS 2014


The CyLab Usable Privacy and Security Laboratory (CUPS) 10th Annual Symposium on Usable Privacy and Security (SOUPS) was hosted by Facebook at its headquarters in Menlo Park, California (7/9/14 - 7/11/14). CUPS Director Lorrie Cranor welcomed the attendees, with the record-breaking numbers in both attendance and papers submitted. For three full days of proceedings, hundreds of researchers from business, academia and government communed together amidst the proliferation of signage which has come to characterize the social media giant's corporate culture: e.g., "Ship Love," "Ruthless Prioritization," "Demand Success," Nelson Mandela, arms outstretched, with the caption, "Open the Doors," etc. (Not so subliminal messaging.)
 
Perhaps more poignantly than any previous SOUPS keynote, Christopher Soghoian of American Civil Liberties Union (ACLU) articulated the vital nature of research into usable privacy and security. Putting flesh and blood on these issues, Soghoian used examples from the shadow world of investigative reporters and whistle-blowers to highlight the need for privacy and security software that is not only robust but eminently usable. One great benefit of the revelations brought forth by Glenn Greenwald in the Edward Snowden affair, Soghoian opined, is that there has been increased crypto adoption by journalists.
But the heightened engagement has also brought long-standing problems into a harsh new light. For example, Soghoian told SOUPS attendees, many investigative journalists using PGP still do not realize subject lines are not encrypted. "The best our community has to offer sucks, the usability and the default values suck," Soghoian declared, "the software is not protecting journalists and human rights activists, and that's our fault as researchers"

As contributing markets factors for why we still don't have usable encryption, Soghoian cited: potential data loss ("telling your customer that they've just lost every photo of their children is a non starter"), current business models, and of course, government pressure.

Facebook HQ Signage, 1 Hacker Way, Menlo Park
In other parts of his very substantive keynote, Soghoian touched on consumer issues related to the efficacy of privacy and security. He elucidated the differences in privacy and security between the iPhone and the Android: "The privacy and security differences ... are not advertised." He also shed light on a new aspect of the growing gap between rich and poor, "security by default for the rich," and "insecurity by default for the poor." "Those who are more affluent get the privacy benefits without shopping around," he explained, because the discounted, and mass-marketed versions of software often do not have the same full-featured privacy and security as the more expensive business or professional versions.

[NOTE: Full-length video of Soghoian's keynote is available via the CyLab YouTube Channel.]

Several awards were also announced during the opening sessions, including:

The 2014 IAPP SOUPS Privacy Award for the paper with the most practical application in the field of privacy went to Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences authored by Allison Woodruff, Vasyl Pihur, Sunny Consolvo, and Lauren Schmidt of Google; and Laura Brandimarte and Alessandro Acquisti of Carnegie Mellon University.

The 2014 SOUPS Impact Award for a SOUPS paper "published between 2005 and 2009 that has had a significant impact on usable privacy and security research and practice" went to Usability of CAPTCHAs or Usability Issues in CAPTCHA Design authored in 2008 by Jeff Yan and Ahmad Salah El Ahmad of Newcastle University (UK).

Two Distinguished Papers awards were presented:

Understanding and Specifying Social Access Control Lists, authored by Mainack Monda of Max Planck Institute for Software Systems (MPI-SWS), Yabing Liu of Northeastern University, Bimal Viswanath and Krishna P. Gummadi of Max Planck Institute for Software Systems (MPI-SWS), and Alan Mislove of Northeastern University.

Crowdsourcing Attacks on Biometric Systems, authored by Saurabh Panjwani, an independent consultant and Achintya Prakash of University of Michigan.
Carnegie Mellon University (CMU), home to the CyLab Usable Privacy and Security (CUPS) Lab and the MSIT-Privacy Engineering Masters Program was well-represented in the proceeding.

In addition to the IAPP SOUPS Privacy Award winning "Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences," co-authored with Google researchers, several other CMU papers were presented:

Parents’ and Teens’ Perspectives on Privacy In a Technology-Filled World, authored by Lorrie Faith Cranor, Adam L. Durity, Abigail Marsh, and Blase Ur, Carnegie Mellon University

Privacy Attitudes of Mechanical Turk Workers and the U.S. Public, authored by Ruogu Kang, Carnegie Mellon University, Stephanie Brown, Carnegie Mellon University and American University, Laura Dabbish and Sara Kiesler, Carnegie Mellon University

CMU researcher Ruogu Kang presenting
Privacy Attitudes of Mechanical Turk Workers and the U.S. Public
Harder to Ignore? authored by Cristian Bravo-Lillo, Lorrie Cranor, and Saranga Komanduri, Carnegie Mellon University, Stuart Schechter, Microsoft Research, Manya Sleeper, Carnegie Mellon University

The Effect of Social Influence on Security Sensitivity, authored by Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, and Jason I. Hong, Carnegie Mellon University

Modeling Users’ Mobile App Privacy Preferences: Restoring Usability in a Sea of Permission Settings, authored by Jialiu Lin, Bin Liu, Norman Sadeh, and Jason I. Hong, Carnegie Mellon University

The full proceedings of SOUPS 2014 are available via USENIX.

-- Richard Power

Check out CyLab CyBlog's Archive of SOUPS Coverage

A Distinguish Paper Award for CUPS, and Other News from Ninth Annual SOUPS 2013

CyLab's SOUPS 2012 Continues Its Ongoing, Deepening Dialogue on What Works and What Doesn't

SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security  

 SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

Mike Farb of CyLab's SafeSlinger project presents during the 2014 EFF Crypto Usability Prize (EFF CUP)
Workshop on Day One of SOUPS 2014

Facebook HQ Signage, 1 Hacker Way, Menlo Park

Monday, July 29, 2013

A Distinguish Paper Award for CUPS, and Other News from Ninth Annual SOUPS 2013

CyLab graduate student Cristian Bravo Lillo presents at SOUPS 2013
The ninth annual Symposium on Usable Privacy and Security (SOUPS 2013) was held July 9th through July 11th at Northumbria University (Newcastle, U.K.).

Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS), chaired the conference, and CyLab Associate Research Professior Lujo Bauer served as technical papers co-chair.

CUPS researchers Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie Downs, Saranga Komanduri, and Robert W. Reeder (Carnegie Mellon University), Stuart Schechter (Microsoft Research), and Manya Sleeper (Carnegie Mellon University) won one of two Distinguished Paper Awards, for Your Attention Please: Designing Security-Decision UIs to Make Genuine Risks Harder to Ignore.

Here is a brief excerpt with a link to the full text:

We designed and tested attractors for computer security dialogs: user-interface modi cations used to draw users' attention to the most important information for making decisions. Some of these modi cations were purely visual, while others temporarily inhibited potentially-dangerous behaviors to redirect users' attention to salient information. We conducted three between-subjects experiments to test the effectiveness of the attractors. In the fi rst two experiments, we sent participants to perform a task on what appeared to be a third-party site that required installation of a browser plugin. We presented them with what appeared to be an installation dialog from their operating system. Participants who saw dialogs that employed inhibitive attractors were signifi cantly less likely than those in the control group to ignore clues that installing this software might be harmful. In the third experiment, we attempted to habituate participants to dialogs that they knew were part of the experiment. We used attractors to highlight a eld that was of no value during habituation trials and contained critical information after the habituation period. Participants exposed to inhibitive attractors were two to three times more likely to make an informed decision than those in the control condition. Your Attention Please: Designing Security-Decision UIs to Make Genuine Risks Harder to Ignore, Cristian Bravo-Lillo, Lorrie Faith Cranor, Julie Downs, Saranga Komanduri, and Robert W. Reeder (Carnegie Mellon University), Stuart Schechter (Microsoft Research), and Manya Sleeper (Carnegie Mellon University)


The SOUPS proceedings will be archived in the ACM Digital Library in a few weeks. All papers are also available linked from the SOUPS 2013 program page on the SOUPS site.

CyLab graduate student Pedro Leon presents At SOUPS 2013


Monday, July 16, 2012

CyLab's SOUPS Continues Its Ongoing, Deepening Dialogue on What Works and What Doesn't



CyLab's SOUPS Continues Its Ongoing, Deepening Dialogue on What Works and What Doesn't

Last week in Washington, D.C., the important work of the Symposium on Usable Privacy and Security (SOUPS), now in its eighth year, continued to deepen and expand. The annual event, shaped and led by Dr. Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS) Lab, generates rich content with which to better inform the development of programs, policies and applications.

SOUPS' technical paper sessions were organized into five categories:

Mobile Privacy and Security

User Perceptions

Authentication

Online Social Networks

Access Control

Here are excerpts from select papers in each of these categories, along with links to the full texts:

Mobile Privacy and Security

Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, David Wagner, Android Permissions: User Attention, Comprehension, and Behavior, UC Berkeley:

We performed two usability studies to address the attention, comprehension, and behavior questions ... Our primary findings are: Attention. In both the Internet survey and laboratory study, 17% of participants paid attention to permissions during a given installation. At the same time, 42% of laboratory participants were unaware of the existence of permissions. Comprehension. Overall, participants demonstrated very low rates of comprehension. Only 3% of Internet survey respondents could correctly answer three comprehension questions. However, 24% of laboratory study participants demonstrated competent—albeit imperfect—comprehension. Behavior. A majority of Internet survey respondents claimed to have decided not to install an application because of its permissions at least once. Twenty percent of our laboratory study participants were able to provide concrete details about times that permissions caused them to cancel installation. Our findings indicate that the Android permission system is neither a total success nor a complete failure.

User Perceptions

Blase Ur, Pedro Giovanni Leon, Lorrie Faith Cranor, Richard Shay, Yang Wang, Smart, Useful, Scary, Creepy: Perceptions of Online Behavioral Advertising, Carnegie Mellon University:

Participants found behavioral advertising both useful and privacyinvasive. The majority of participants were either fully or partially opposed to OBA, finding the idea smart but creepy. However, this attitude seemed to be influenced in part by beliefs that more data is collected than actually is. Participants understood neither the roles of different companies involved in OBA, nor the technologies used to profile users, contributing to their misunderstandings. Given effective notice about the practice of tailoring ads based on users’ browsing activities, participants wouldn’t need to understand the underlying technologies and business models. However, current notice and choice mechanisms are ineffective. Furthermore, current mechanisms focus on opting out of targeting by particular companies, yet participants displayed faulty reasoning in evaluating companies. In contrast, participants displayed complex preferences about the situations in which their browsing data could be collected, yet they currently cannot exercise these preferences.

Authentication

Richard Shay, Patrick Gage Kelley, Saranga Komanduri, Michelle L. Mazurek, Blase Ur, Timothy Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Correct horse battery staple: Exploring the usability of system-assigned passphrases, Carnegie Mellon University:

Our findings suggest that system-assigned passphrases are far from a panacea for user authentication. Rather than committing them to memory, users tend to write down or otherwise store both passwords and passphrases when they are system assigned. When compared to our password conditions, no passphrase condition significantly outperformed passwords in any of our usability metrics, indicating that the system assigned passphrase types we tested fail to offer substantial usability benefits over system-assigned passwords of equivalent strength. We even find that system-assigned passphrases might actually be less usable than system-assigned passwords. For instance, users were able to enter their passwords more quickly and with fewer errors than passphrases of similar strength. While our results in general do not strongly favor system-assigned passwords over system-assigned passphrases or vice versa, we identify several areas for further investigation. For example, larger dictionary sizes do not appear to have a substantial impact on usability for passphrases. This could be leveraged to make stronger passphrases without much usability cost. We also find that lowercase, pronounceable passwords are an unexpectedly promising strategy for generating system-assigned passwords.

Online Social Networks

Thomas Muders, Matthew Smith and Uwe Sander, Helping Johnny 2.0 to Encrypt His Facebook Conversations, Leibniz Universitaet and University of Applied Sciences and Arts, Hannover, Germany:

While there are some solutions available to cryptographically protect Facebook conversations, to the best of the authors' knowledge, there is no widespread use of them. Thus, the aim of our work was to nd out why this might be the case and what could be done to help OSN users to encrypt their Facebook conversations. While mechanisms to protect email messaging could in principle be adapted to Facebook conversations in a straightforward manner, previous usability studies show signi cant problems with the existing email encryption mechanisms. One of our goals was therefore to see if the changes brought about by the OSN paradigm might open up new possibilities for a usable security mechanism protecting private OSN messages. To answer these questions, we conducted multiple studies to evaluate needs surrounding the protection of users' conversations on Facebook and then compared different existing solutions for conversation encryption. Based on these intermediate results, we developed an approach to encrypt Facebook conversations which we tested in two user studies to ascertain whether the solution provided good usability characteristics while at the same time protecting user privacy. The results of the final study show that the OSN paradigm does indeed o er new ways of simplifying security and fi nding security/usability trade-o s which are acceptable to users.

Access Control

Jason Watson, Andrew Besmer, Heather Richter Lipford, +Your Circles - Sharing Behavior on Google+, University of North Carolina (Charlotte):

This study o ers insight into the behavior of Google+ users and how they use group based sharing. We found participants had strong positive attitudes towards using circles and generally understood the intended purpose of them. However, much of the use of circles was not to protect disclosures from certain people, but to increase the relevance of posting to people. Thus, users are still treating information they post as relatively public. While this may decrease the liklihood of accidentally oversharing, this also means that users will continue to experience the issues from self-censoring, such as the inability to more deeply connect to close friends. Also, despite user understanding, we still saw a disconnect in users' stated desires and behavior. While Google+ lowered the level of eff ort required to interact in contextually appropriate ways, many continued using strategies for privacy management they had formed by using Facebook and simply posted to all circles. In addition, some participants found that circle use increased the mental demand required for social network interaction. Similar to previous studies, the increased e ort lead some of our participants to bypass the privacy mechanisms. In the case of this study, this meant collapsing friends into a single circle. Thus, Google+ users are not yet taking full advantage of the capabilities provided by circles for greater control over information flow. However, these results are also heavily influenced by the overall lack of people and activity on the site, which may have reduced the need for the use of circles. Yet, if site usage grows and users add more connections, the burden of managing circles is also likely to grow.

For the full agenda and links to all the papers presented, visit SOUPS 2012.

For more information on CyLab's ongoing research into Usable Privacy and Security, visit CUPS.

See Also

SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security

SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

For information on other aspects of CyLab's vital work, visit
http://www.cylab.cmu.edu/

Thursday, July 28, 2011

SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security



SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security

The seventh annual Symposium On Usable Privacy and Security (SOUPS) was held in Pittsburgh, PA., July 20th thru July 23rd, 2011. SOUPS is an annual event that has evolved out of the work of the CyLab Usable Privacy and Security (CUPS) Lab. This year's SOUPS sessions included Security Warnings and Authentication to Privacy on Social Networks and Perceptions of Privacy and Security. It also included a day of tutorials and workshops, such as Usable Security Indicator Conventions and Experiment Design and Quantitative Methods for Usable Security Research.

The papers presented ranged from Using Data Type Based Security Alert Dialogs to Raise Online Security Awareness, presented by University of Munich, and Breaking Undercover: Exploiting Design Flaws and Nonuniform Human Behavior, presented by researchers from the National University of Science and Technology (Pakistan) and University of Split, (Croatia) to "I regretted the minute I pressed share": A Qualitative Study of Regrets on Facebook, presented by Carnegie Mellon University researchers, and Indirect Content Privacy Surveys: Measuring Privacy Without Asking About It, presented by Google researchers.

The embeded video of a panel on The Battle Over Behavioral Advertising
Choice Mechanisms. (For more videos of CyLab seminars and conferences, visit our You Tube Channel.)

Dr. Lorrie Cranor, Director of CUPS, is the panel moderator. Panel participants included Alan Chapel (BlueKal), Manoj Hastak (American University), Aleecia McDonald (Carnegie Mellon CyLab) Brendan Riordan-Buttenworth, Harlan Yu (Princeton University).

The Battle Over Behavioral Advertising Choice Mechanisms (SOUPS 2011 panel)


For the full agenda and links to all the papers presented, visit SOUPS 2011.

For more information on CyLab's ongoing research into Usable Privacy and Security, visit CUPS.

See Also

SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

For information on other aspects of CyLab's vital work, visit
http://www.cylab.cmu.edu/

Friday, July 16, 2010

SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Carnegie Mellon students Richard Shay and Saranga Komanduri present on "Encountering Stronger Password Requirements: User Attitudes and Behaviors" at SOUPS 2010 (Photo credit: Lujo Bauer)


SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

By Richard Power


SOUPS 2010 is the sixth annual event, and the third one it has been my pleasure to cover. It is also the second year in a row that the event was held at one of the centers of true power in cyberspace; last year it was held at the Google campus in Silicon Valley, this year it was held at Microsoft campus in Redmond, Washington.

Adam Shostack, a program manager for Microsoft's Trustworthy Computing Initiative, gave the Invited Talk. Shostack's presentation was titled, "Engineers Are People, Too."

Cormac Herley and Dinei Florencio of Microsoft Research won the Best Paper Award for their "Where Do Security Policies Come From?

To give you a feeling and a sense for the nature of the research explored at SOUPS 2010, here are some brief excerpts from the papers presented on just one day:

Do Windows Users Follow the Principle of Least Privilege? Investigating User Account Control Practices by Sara Motiee, Kirstie Hawkey and Konstantin Beznosov, University of British Columbia (Vancouver, B.C.):

All our participants used an admin account on their laptop. Although 71% had a partial understanding of the limitations and rights of each user account type, 91% of participants were not aware of the security risks of high-privilege accounts or the security benefi ts of low-privilege ones. Also, while 62% had experienced a low-privilege user account, they were not motivated to use it on their own laptops be- cause of the limitations they had faced using these accounts.

"Encountering Stronger Password Requirements: User Attitudes and Behaviors" by Richard Shay, Saranga Komanduri, Patrick Gage Kelley, Pedro Giovanni Leon, Michelle L. Mazurek, Lujo Bauer, Nicolas Christin and Lorrie Faith Cranor, Carnegie Mellon University (Pittsburgh, PA.):

Our results reveal flaws in NIST's assumptions. NIST bases its per-password entropy estimates on several assumptions that are inconsistent with our findings [2]. They assume users will create passwords of the minimum required length, but our results show an average length more than two characters above the minimum. NIST also assumes users will have the minimum number of special characters, but our participants frequently indicated using more. Over two-thirds of users who responded said they used more than the one required number. It would be useful to examine larger sets of passwords created under a variety of password policies to provide empirical data to improve the NIST guidelines.

"A Closer Look at Recognition-based Graphical Passwords on Mobile Devices" by
Paul Dunphy of Newcastle University (Newcastle upon Tyne, U.K.), Andreas Heiner and N. Asokan of Nokia Research (Helsinki, Finland):

Despite the increasing presence of biometrics for user authentication on consumer electronics e.g. laptops, knowledge-based authentication systems are likely to remain attractive due to being purely software-based solutions. Graphical password systems based on recognition potentially have a role to play in this area, due to accurate user performance in previous studies, including this one. One key limitation however, is that login durations recorded for our systems – and others – are still too long. User acceptance is often driven by convenience and login durations of approximately 20 seconds are unattractive to many users.

"Usably Secure, Low-Cost Authentication for Mobile Banking" by Saurabh Panjwani and Ed Cutrell of Microsoft India:

While the design of secure and usable authentication for banking applications is a well-studied problem in the developed world, applying the same solutions to developing-world mobile banking is a challenge, primarily due to the limited capacity of the phones available in these regions. Amongst all mobile banking providers in the world, EKO is unique ... In this paper, we have demonstrated a security weakness in EKO’s solution which causes the privacy of user PINs to be easily compromised. On the positive side, we have also shown an alternative solution which not only fixes this problem with EKO’s scheme but also improves its usability and user-friendliness. This is an absolute win-win situation for user-centric security design – better security with better usability. Our research has potential implications for banking in the developed world also. While ATM-based banking is claimed to offer secure 2-factor authentication, such claims have considerably weakened with the increasing incidence of skimming attacks in the recent past ...

"Two Heads are Better Than One: Security and Usability of Device Associations in Group Scenarios" by Ronald Kainda, Ivan Flechais and Andrew William Roscoe of Oxford University (Oxford, U.K.):

We have analysed, evaluated and compared methods for transferring ngerprints among devices for the purpose of bootstrapping security in group scenarios. While it has been believed that group settings may be more subject to failures during the association process compared to single user pair-wise associations, our findings show the converse to be true ...
Based on participants' feedback and video analysis, we concluded that in group settings security of device association is a function of a sum of efforts rather than weakest link. Data further revealed that users rarely read instructions before using a new system but learn as they 'get on with it.' Users also believe that a secure system must be complex and difficult to use. In addition we realised how contextualising laboratory studies can lead to richer data and responses from participants.


"Influence of User Perception, Security Needs, and Social Factors on Device Pairing Method Choices" by Iulia Ion and Srdjan Capkun of ETH Zurich (Zurich, Switzerland), Marc Langheinrich of University of Lugano (Lugano, Switzerland) and Ponnurangam Kumaraguru of IIIT Delhi (New Delhi, India):

Creating a technically secure and highly usable method is not always sufficient to meet users' needs. The method should also comply with users' security perception and be appropriate for the specific social situation.
1. Map perceived security to method guarantees: Designers should create methods whose actual security guarantees are consistent with users' perceived security. To achieve this, it might be necessary to introduce redundant steps, controls, cancel buttons, and double confirmations.
2. Include security by default: We detected several mismatches between users' mental models and system designs, which prove the need to include security by default when dealing with sensitive data, such as a customer entrusting a confidential financial report or a bank issuing a credit card. Also, our results show users' willingness to have security enabled by default.
3. Support several methods: Some users liked Take a picture very much and disliked Listen up, and others felt exactly the opposite. To account for diverse personal preferences, mobile devices should support a set of different pairing methods.
4. Account for social factors: No single method is adequate for all situations. Users are likely to bypass security before breaking social norms. Designers should provide appropriate methods for professional environments, public and private places, and interaction with friends or strangers. The user could, for instance, choose between several variants: meeting mode, quiet room mode, professional mode, play/fun mode, etc.


The full text of these papers, as well as the others presented at SOUPS 2010, are available from the event's official site; along with information on two workshops held: Usable Security Experiment Reports (USER) and Security & Privacy Usability Technology Transfer: Emerging Research (SPUTTER).

See Also

NSF Awards Grant for Privacy Study to CyLab Researchers Acquisti, Cranor and Sadeh

CyLab Chronicles: Q and A with Lorrie Cranor (2010)

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

Friday, July 17, 2009

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness



"Any intelligent fool can make things bigger, more complex, and more violent. It takes a touch of genius -- and a lot of courage -- to move in the opposite direction." -- Albert Einstein

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

-- Richard Power


The success of the fifth annual Symposium on Usable Privacy and Security (SOUPS) -- more papers submitted than ever before, more papers accepted than ever before, more attendees registered than ever before -- is an affirmation of the usability concept and its vital role in the development of security and privacy strategies.

On the third and final day of SOUPS 2009, Lorrie Cranor, the driving force behind both SOUPS and the CUPS from whence it poured, was unable to attend the morning session, she was across town, keynoting on "Teaching Johnny Not to Fall for Phish" at the Sixth Conference for E-Mail and Anti-Spam.

The research of Cranor and her CUPS colleagues demonstrates that user education can indeed play a critical role in the fight against phishing, etc., IF the tools utilized are engaging, enlightening and designed to exploit the "teachable moment." It has also led to the formation of Wombat Security Technologies.

In the technical paper session on Passwords and Authentication, Alexander De Luca of the Media Informatics Group at University of Munich presented Look into my Eyes! Can you guess my Password?, co-authored with his University of Munich colleagues Martin Denzel and Heinrich Hussmann.

In the same session, Stuart Schechter of Microsoft presented 1 + 1 = You: Measuring the comprehensibility of metaphors for configuring backup authentication, co-authored with his Microsoft colleague, Robert Reeder.

The work of De Luca, Denzell and Hussman explored the potential of having users authenticate themselves, particularly at terminals in public places, by drawing shapes with their eyes.

The work of Schechter and Reeder explored the issues involved in user-chosen challenge questions (e.g., the kind you answering when you've lost your password or user ID in Hotmail or G-mail), and showed that somewhat better results were achieved if the user had to take an exam and get a passing grade.

These and other presentations I attended were fascinating.

Our problem is, however, that the challenge in cyber security and privacy is not one of cleverness, but one of consciousness.

We are still between worlds, really.

The Information Age that Alvin Toffler heralded as the "Third Wave" has already broken over our heads, it has already swept us away; but, in many ways, our minds are still on the shore, or reaching back toward the shore, wanting to somehow, impossibly, to take it with us.

In the 1990s, the news was that the periphery between the network and the Internet no longer existed. Here and now, at the end of the first decade of the 21st Century, the news is that the periphery between the mind and the World Wide Web is gone.

The implications are profound.

Some months ago, at dinner with a colleague from inside the US intelligence community's own attempt to comprehend this Brave New World, we discussed these issues at great depth, and both came to the same conclusion: most of the human race will not recognize the world in which they live and work even as soon as ten years from now.

Most of what we are trying to accomplish in cyber security and privacy is based on a paradigm that has been eclipsed; no, not an IT-related paradigm, an old paradigm of the human psyche and its relationships to both the natural world and the digital world, and the interpenetration of all three.

There is something profoundly new coming in the realm of cyber security and privacy.

You and I will recognize it when we see it because not only will we not have seen it before, it will change the way we perceive problems and approach solutions.

It may well come from such academic research. That's why participating in conference such as SOUPS is of great importance.

But it will not reflect superior cleverness, it will signal a shift in consciousness.

Of course, meanwhile, we must rely on superior cleverness, and that too is a reason to participate in SOUPS, etc.

For more commentary on SOUPS 2009, go to the CUPS Blog.

Speaking of which, I will be blogging from Blackhat later this month and from the USENIX Security Symposium in August. Stay tuned.

Summary of SOUPS 2009 Posts:

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CUPS Related Posts:

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

Thursday, July 16, 2009

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users



"The Windows Vista personal firewall provides its diverse users with a basic interface that hides many operational details. However, concealing the impact of network context on the security state of the firewall may result in users developing an incorrect mental model of the protection provided by the firewall." Fahimeh Raja, University of British Columbia

SOUPS 2009 Mental Modes Session: Study Demonstrates that Pursuit of Seamless Security can Lead to New Dangers, Particularly for Mobile Users

Paul Van Oorschot of Carelton University in Ottawa chaired the Mental Models session.

Fahimeh Raja of University of British Columbia (Vancouver) presented Revealing Hidden Context: Improving Mental Models of Personal Firewall Users, co-authored with her colleagues, Kirstie Hawkey and Konstantin Beznosov.

The goal of the study was to investigate the impact of adding contextual information to the Vista Firewall Basic Interface. The researchers looked at the impact of Vista Firewall functionality on users' mental models, as well as the impact of Vista Firewall configuration on users' understanding.

"The Windows Vista personal firewall provides its diverse users with a basic interface that hides many operational details. However, concealing the impact of network context on the security state of the firewall may result in users developing an incorrect mental model of the protection provided by the firewall."

Raja and her colleagues determined that because the security technology makes changes in the users' security state, it is important to somehow communicate these changes to users; "otherwise, these users can be left in dangerous situations; for example, only protected in the current network context but believing themselves to be protected for future network contexts."

Users could think that their firewall was turned on when it was turned off, or conversely, that their firewall was turned off when it was turned on.

"Users need to understand the effect of the configuration on the system's security state. We argue as users become more mobile, it is increasingly important to understand the security state for both current and future contexts of use."

They concluded that the design of the Vista Firewall Basic Interface does not provide enough context for mobile users. If unaware that configuration changes only apply to current network location, users may be left with dangerous misconceptions. The researchers also concluded that users' mental models can be supported by revealing context.

The implications of this study are important, i.e., it may be possible to balance complexity and security.

Two other papers were presented in this session:

Andrew Besmer of University of North Carolina (Charlotte) presented Social Applications: Exploring A More Secure Framework, a paper co-authored with colleagues Heather Richter Lipford, Mohamed Shehab and Gorrell Cheek, also from the Department of Software and Information Systems.

Ponnurangam Kumaraguru of Carnegie Mellon University CyLab presented on School of Phish: A Real-Word Evaluation of Anti-Phishing Training, a paper co-authored with fellow Carnegie Mellon researchers Justin Cranshaw, Alessandro Acquisti, Lorrie Cranor, Jason Hong, Mary Ann Blair and Theodore Pham.

Some Related Posts:

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.

-- Richard Power

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"



Often, futuristic shopping scenarios highlight ways in which a network of computers are able to determine the items a consumer needs by intelligently surveying food stocks and other goods in the individuals home. However, as Friedewald and colleagues note, such scenarios tend to take an individualistic approach, ignoring the ways in which the various interests within a family may converge or conflict within a shopping expidition. In many families, shopping is considered a social activity where all family members might take part in the process. Younger members of a family (seldom seen in the ubicomp world) are typically active participants in the weekly shopping task, and are given their own responsibilities or activities. Linda Little, Elizabeth Sillence and Pam Briggs, Ubiquitous Systems and the Family: Thoughts about the Networked Home

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

Andrew Patrick and Simson Garfinkel, SOUPS Technical Papers Co-Chairs, announced SOUPS 2009 Best Paper Award has been bestowed on Ubiquitous Systems and the Family: Thoughts about the Networked Home by Linda Little, Elizabeth Sillence and Pam Briggs of the PaCT Lab, Northumbria University (U.K.).

Here are brief excerpts from the award-winning paper followed by a link to full text:

Developments in ubiquitous and pervasive computing herald a future in which computation is embedded into our daily lives. Such a vision raises important questions about how people, especially families, will be able to engage with and trust such systems whilst maintaining privacy and individual boundaries. To begin to address such issues, we have recently conducted a wide reaching study eliciting trust, privacy and identity concerns about pervasive computing. Over three hundred UK citizens participated in 38 focus groups. The groups were shown Videotaped Activity Scenarios [11] depicting pervasive or ubiquitous computing applications in a number of contexts including shopping. The data raises a number of important issues from a family perspective in terms of access, control, responsibility, benefit and complexity. Also findings highlight the conflict between increased functionality and the subtle social interactions that sustain family bonds. We present a Pre-Concept Evaluation Tool (PRECET) for use in design and implementation of ubicomp systems."

The design and implementation of ubiquitous systems cannot be solely based on traditional HCI issues of functionality, usability and accessibility. In a shopping context at least ubicomp systems need to incorporate a better understanding of family interactions and need to show some sensitivities to the natural information sharing boundaries that occur within the family. Such an approach will resonate with developments in other technologies, where the focus on ‘user-experience’ as opposed to ‘usability’ has seen a shift towards an understanding of the wider social impacts of HCI.


Ubiquitous Systems and the Family: Thoughts about the Networked Home, Linda Little, Elizabeth Sillence and Pam Briggs, PaCT Lab, Northumbria University, U.K.

Some Related Posts:

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.

-- Richard Power''

Wednesday, July 15, 2009

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology


"Once you have real people using the security in this design, what is the performance that you can expect? What is the performance you can expect at the security level in terms of the choices that the users will make? This is where we have a problem ... We don't have a clear set of criteria to assess a particular performance against ... If you don't have a criteria for what is actually an acceptable level of performance, then you just don't know if it is good enough or not." Angela Sasse, University College London

SOUPS 2009 Tutorial Explores Challenges of Evaluating Usable Security and Privacy Technology

By Richard Power


As I drove across Google's sprawling Mountain View campus, the memory of a 2005 visit to Microsoft rose up in my mind. I had traveled there to participate in a CSO Council meeting. The Redmond campus is a city-state, of course, with its own police force and its own street. In 2005, Google was only ten years old. Fast forward another four years. Just this month, Google announced that it is going to challenge Microsoft on the OS front (See Now Google parks its tanks right outside Microsoft's gates, Guardian, 7-12-09).

This afternoon, sitting in a sun-drenched pavilion on Google's grounds during a lunch break, I looked up from my grilled salmon to notice a employee walking by, with her dog on a leash, then I saw another, and then I saw another. There were dogs everywhere. I asked if this happened to be a special "Bring Your Dog to Work Day," but was told, "No, we are allowed to bring our dogs to work everyday." Hmmm. Could this remarkable corporate culture innovation give Google an edge in the struggle ahead?

But, of course, I did not come here to handicap the coming clash of the titans; I came here to report to you on the fifth Symposium on Usable Privacy and Security (SOUPS), which Google is hosting and co-sponsoring along with CyLab. (Next year, SOUPS will be held in Redmond.)

SOUPS is an annual event organized by Carnegie Mellon CyLab's Usable Privacy & Security Lab (CUPS).

Several significant evolutionary trends have emerged in cyber security and privacy over the last decade, ranging from the somewhat ill-conceived search for Return on Investment (ROI) in cyber security deployments to the much more promising inquiry into the ways in which the sciences of economics and psychology might better inform cyber security development. The quest for "Usable Security and Privacy" is one of the most intriguing of these trends; and SOUPS provides an invaluable forum for the exploration of themes in this vital area of research.

The first day of SOUPS 2009 was built around an all-day tutorial on "Designing and Evaluating Usable Security and Privacy Technology" led by M. Angela Sasse, Professor of Human-Centred Technology in the Department of Computer Science at UCL, Clare-Marie Karat, Research Staff Member in the Policy Lifecycle Technologies department at the IBM TJ Watson Research Center, and CyLab researcher Roy Maxion, a faculty member in the Computer Science and Machine Learning Departments at Carnegie Mellon University.

Sasse spoke on "Evaluating for Usability & Security."

Karat delivered a "Case Study of Usable Privacy and Security Policy Research."

Maxton shared "Mechanics of Experiments, Forensics, and Security."

Here are some excerpts from my notes and transcription of Sasse's compelling talk:

Starting off by citing a "cumbersome" definition of "evaluation" as “an assessment of the conformity between a work system's performance and its desired performance.” (Whitefield et al., 1991); Sasse then explained, "What they really mean by 'work system' is if a user works together with a system, what is the performance that you are going to get out of the combination? That is what you are actually interested in. Once you have real people using the security in this design, what is the performance that you can expect? What is the performance you can expect at the security level in terms of the choices that the users will make? This is where we have a problem ... We don't have a clear set of criteria to assess a particular performance against ... If you don't have a criteria for what is actually an acceptable level of performance, then you just don't know if it is good enough or not."

In the course of outlining the essentials of a proper usability evaluation plan, Sasse went into some depth concerning evaluation goals, first emphasizing the difference between summative goals (e.g., "Mech 1 performs better than Mech 2" or "Mech 1 meets performance criteria X, Y, Z") and formative goals (e.g., "exploratory evaluation of feasibility and indicative performance, user feedback, pointers for improvement"), and then exploring the breakdown of an evaluation goal.

"When it comes to usability and security, we need to look at two things: not only how well does the user perform with the security mechanism (e.g., how long does it take the user to remember, read off and enter the one-time pin, how long does it take to figure out which finger to use, where to put, etc.) but also what is the primary task, or production task, within which this security task is performed. The kind of experiments we have seen so far is basically, 'Thank you for coming, try this security mechanism, and I will measure how well you do.' But if it is envisioned, for example, that they do this as part of their on-line banking session, or for governments purposes, to fill their taxes on-line, then we need to create a realistic approximation of what that whole procedure looks like. At what point, would a user normally in the real world approach the system with the goal of 'I'm filing my taxes, and goddamn I'm late, I've got about twenty hours or so to do it."

"There are some things you can do in the lab, but there are some things that you can never really reproduce in a lab. If people anticipate that they are going to have problems with a security mechanism, they are going to change altogether how they behave and how they do their work. You find that because people fear that they might fail to authenticate themselves to a service that they either completely re-organize how they do their work, which has an impact on their productivity, and an impact on the productivity of the organization overall, or they might find workarounds, for instance, they just find ways of leaving the system open in order to avoid entering their credentials time and time again. You are never going to see people do that in the lab experiment."

Along with evaluating "performance achieved on security tasks" as well as the "actual level of security achieved given user choices and behaviour," Sasse also stressed evaluating "at what cost" these were achieved -- "to the individual user, to the system owner and to society as a whole."

"I recognize some of the issues, and they are pretty obvious," Roy Maxton asked Sasse, "so my question is what do you think makes it not obvious to so many people?"

"The answer is that so far security has basically been treated as special," she responded. "A lot of organizations out there are not very good at assessing the ongoing cost of ownership of certain types of technology. And when it comes to security that problem is magnified, because the argument always made is 'Security is important, just think of what could happen if we didn't have it.' They tend to only look at the cost of purchasing it and putting it in place. How much time or productivity is it going to take out of a company is a question I have never seen anybody ask up front, until very recently. Or 'how much of our system administrator's time is it going to take ... it is generally not looked at and factored into the cost of operating. But I am sure this will change. These kinds of ideas have now gotten out there. Traditionally, the only argument for security was risk mitigation, it was very often not off-set by the cost of ownership and operation ..."

Sasse went on to articulate other key elements of the evaluation process:

Scope, both summative (e.g., "sample large enough for adequate statistical power; generally larger samples than for formative evaluations" and formative (e.g., "explanatory results" providing "reasons for user choices" and "reasons for failure');

Participants (e.g., "need to control for practice and interference effects")

Context of use (e.g., need to replicate demands of production task, equipment used, physical context and situational context)

Criteria, including user cost (e.g., physical and mental workload), owner cost (e.g., "needs to be proportionate to degree of security achieved"), user satisfaction (e.g., "user confidence in mechanism itself" and "their own ability to operate it correctly") and, of course, security.

Aye, but there's the rub. The internationally recognized framework, Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408), does not include in usability.

In her conclusion, Sasse emphasized the need to develop a framework for evaluating usability and security to ensure comparable and generalisable results, suggesting it that should be "linkable to assessment via Common Criteria" and might incorporate the NIST taxonomy as template for procedure.

These notes reflect the richness of the discussion in this day-long tutorial led by Karat, Maxton and Sasse.

Stay tuned for more from SOUPS 2009 over the next two days.

Some Related Posts:

SOUPS 2009 Best Paper Award Goes to "Ubiquitous Systems and the Family: Thoughts about the Networked Home"

CyLab Seminar Series Notes: User-Controllable Security and Privacy -- Norman Sadeh asks, "Are Expectations Realistic?"

CyLab Research Update: Locaccino Enables the Watched to Watch the Watchers

CyLab Chronicles: Wombat, the Latest CyLab Success Story

CyLab Chronicles: Q&A w/ Norman Sadeh

CyLab Chronicles: Q&A w/ Lorrie Cranor

Culture of Security: CUPS Research Takes on Both Widespread Attack Method & Dangerous Meme (Available to Cylab Partners Only)

For further commentary on SOUPS 2009, go to the CUPS Blog.