Nudging users towards better security decisions in password creation using whitebox-based multidimensional visualisations

被引:19
作者
Hartwig, Katrin [1 ]
Reuter, Christian [1 ]
机构
[1] Tech Univ Darmstadt, Sci & Technol Peace & Secur PEASEC, Pankratiusstr 2, D-64289 Darmstadt, Germany
关键词
Nudging; whitebox; usable security; personalisation; passwords;
D O I
10.1080/0144929X.2021.1876167
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Nudging users to keep them secure online has become a growing research field in cybersecurity. While existing approaches are mainly blackbox based, showing aggregated visualisations as one-size-fits-all nudges, personalisation turned out promising to enhance the efficacy of nudges within the high variance of users and contexts. This article presents a disaggregated whitebox-based visualisation of critical information as a novel nudge. By segmenting users according to their decision-making and information processing styles, we investigate if the novel nudge is more effective for specific users than a common black-box nudge. Based on existing literature about critical factors in password security, we designed a dynamic radar chart and parallel coordinates as disaggregated visualisations. We evaluated the short-term effectiveness and users' perception of the nudges in a think-aloud prestudy and a representative online evaluation (N=1.012). Our findings suggest that dynamic radar charts present a moderately effective nudge towards stronger passwords regarding short-term efficacy and are appreciated particularly by players of role-playing games.
引用
收藏
页码:1357 / 1380
页数:24
相关论文
共 81 条
[11]  
Brooke J., 1996, Usability Eval. Ind., V189, P4, DOI DOI 10.1201/9781498710411-35
[12]  
CHEN J, 2016, P ACM C COMPUTER SUP, V27
[13]   Explaining Decision-Making Algorithms through UI: Strategies to Help Non-Expert Stakeholders [J].
Cheng, Hao-Fei ;
Wang, Ruotong ;
Zhang, Zheng ;
O'Connell, Fiona ;
Gray, Terrance ;
Harper, F. Maxwell ;
Zhu, Haiyi .
CHI 2019: PROCEEDINGS OF THE 2019 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2019,
[14]   A COEFFICIENT OF AGREEMENT FOR NOMINAL SCALES [J].
COHEN, J .
EDUCATIONAL AND PSYCHOLOGICAL MEASUREMENT, 1960, 20 (01) :37-46
[15]   Privacy Personas: Clustering Users via Attitudes and Behaviors toward Security Practices [J].
Dupree, Janna Lynn ;
DeVries, Richard ;
Berry, Daniel M. ;
Lank, Edward .
34TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2016, 2016, :5228-5239
[16]  
Egelman S., 2015, P 2015 NEW SECURITY, P16, DOI DOI 10.1145/2841113.2841115
[17]   Behavior Ever Follows Intention? A Validation of the Security Behavior Intentions Scale (SeBIS) [J].
Egelman, Serge ;
Harbach, Marian ;
Peer, Eyal .
34TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2016, 2016, :5257-5261
[18]  
Egelman Serge, 2013, CHI 13, P2379
[19]  
Fahl S., 2013, PROC SOUPS 2013, P13
[20]  
Fonteyn ME, 1993, Qual Health Res, V3, P430, DOI [10.1177/104973239300300403, DOI 10.1177/104973239300300403]