Clickbait, masked behind interesting headlines and thumbnails, is often used to spread misinformation and trick users into clicking on social media posts or links that direct them to malicious websites. To help users protect against clickbait, we examined interventions based on persuasion theories including designs that used social consequence, personal consequence, and badges. To this end, we first conducted a preliminary study to translate the participants' feedback into improving our initial designs, followed by a lab study with 20 participants (60% Male, 40% Female; 18-44 years old) aimed at understanding their perceptions of the improved interventions; we further updated our designs based on their feedback. We then conducted an online study with 773 participants (56% Male, 42% Female; 18 to above 65 years old) over MTurk to evaluate the impact of persuasion techniques leveraged in our designs. Our findings suggest that persuasion can be an effective strategy to warn users against clickbait, specifically ones that use incentives such as revealing mystery of clickbait. Overall, our studies provide valuable insights into understanding users' needs and expectations around interventions against clickbait, and offer guidelines for future research in these directions.
Purpose - A huge amount of personal and sensitive data are shared on Facebook, which makes it a prime target for attackers. Adversaries can exploit third-party applications connected to a user's Facebook profiles (i.e. Facebook apps) to gain access to this personal information. Users lack of knowledge and the varying privacy policies of these apps make them further vulnerable to information leakage However, little has been done to identify mismatches between users perceptions and the privacy policies of Facebook apps. This paper aims to address this challenge in the work. Design/methodology/approach - The authors conducted a lab study with 31 participants, where the authors received data on how they share information on Facebook, their Facebook-related security and privacy practices and their perceptions on the privacy aspects of 65 frequently-used Facebook apps in terms of data collection. sharing and deletion. The authors then compared participants perceptions with the privacy policy of each reported app. Participants also reported their expectations about the types of information that should not be collected or shared by any Facebook app. Findings - The analysis reveals significant mismatches between users' privacy perceptions and reality (i.e. privacy policies of Facebook apps). where the authors identified over-optimism not only in users' perceptions of information collection but also in their self-efficacy in protecting their information in Facebook despite experiencing negative incidents in the past. Originality/value - To the best of the knowledge, this is the first study on the gap between users privacy perceptions around Facebook apps and reality. The findings from this study offer direction for future research to address that gap through designing usable, effective and personalized privacy notices to help users to make informed decisions about using Facebook apps.
Facial recognition (FR) technology is being adopted in both private and public spheres for a wide range of reasons, from ensuring physical safety to providing personalized shopping experiences. It is not clear yet, though, how users perceive this emerging technology in terms of usefulness, risks, and comfort. We begin to address these questions in this paper. In particular, we conducted a vignette-based study with 314 participants on Amazon Mechanical Turk to investigate their perceptions of facial recognition in the physical world, based on thirty-five scenarios across eight different contexts of FR use. We found that users do not have a binary answer towards FR adoption. Rather, their perceptions are grounded in the specific contexts in which FR will be applied. The participants considered a broad range of factors, including control over facial data, the utility of FR, the trustworthiness of organizations using FR, and the location and surroundings of FR use to place the corresponding privacy risks in context. They weighed the privacy risks with the usability, security, and economic gain of FR use as they reported their perceptions. Participants also noted the reasons and rationals behind their perceptions of facial recognition, which let us conduct an in-depth analysis of their perceived benefits, concerns, and comfort with using this technology in various scenarios. Through this first systematic look into users’ perceptions of facial recognition in the physical world, we shed light on the tension between FR adoption and users’ concerns. Taken together, our findings have broad implications that advance the Privacy and Security community’s understanding of FR through the lens of users, where we presented guidelines for future research in these directions.
There is heightened concern over deliberately inaccurate news. Recently, so-called deepfake videos and images that are modified by or generated by artificial intelligence techniques have become more realistic and easier to create. These techniques could be used to create fake announcements from public figures or videos of events that did not happen, misleading mass audiences in dangerous ways. Although some recent research has examined accurate detection of deepfakes, those methodologies do not generalize well to real-world scenarios and are not available to the public in a usable form. In this project, we propose a system that will robustly and efficiently enable users to determine whether or not a video posted online is a deepfake. We approach the problem from the journalists' perspective and work towards developing a tool to fit seamlessly into their workflow. Results demonstrate accurate detection on both within and mismatched datasets.
Facebook remains the largest social media platform on the Internet with over one billion active monthly users. A variety of personal and sensitive data is shared on the platform, which makes it a prime target for attackers. Increasingly, we see phishing attacks that take advantage of users' lack of security knowledge, deceiving victims by using fake or compromised accounts to share malicious posts. These attacks may slip undetected by the Facebook defense system, exposing users to potentially be phished or have their devices infected with drive-by downloads and malware. Only a few studies have been conducted to date to understand how users interact with attacks like this in Facebook. In our prior work, we conducted a study to address this challenge using a simulated interface and think-aloud protocol. In this study, we aim to make further progress in understanding the impact of different factors on users' clicking decision in social media through a vignette study that encourages participants to think about realistic scenarios that they might face.
Facebook, the largest social networking site (SNS) with over one billion active monthly users, has been woven into the everyday life of many people. While this platform has drastically improved how we interact with one another, it has also opened up a multitude of security and privacy issues. For example, online attackers are increasingly employing phishing attacks on Facebook, seeking to fool their victims by posing as friends using fake or compromised accounts. These attacks are hard to recognize by the Facebook defense system and users alike, and few studies give any insight into how users interact with such attacks. In this study, we take the first step to understand how users react and decide whether to click when they encounter SNS posts with links, including possibly suspicious links. We found that users decide to interact with shared contents based on their relationship with the post author (from whose account the post is shared; perhaps compromised). At the same time, they mostly ignore the location of the shared post (e.g., post author’s wall or target user’s wall), and any context pointing to a post possibly being suspicious. We also explored the potential of showing a visual warning for suspicious posts. Although our simple warning system failed to prevent users from clicking on suspicious posts altogether, it did reduce the likelihood of users clicking on such posts. Based on our findings, we identified the scope of future work to protect users against phishing attacks in SNSes.
Facebook, the largest social networking site (SNS) with over one billion users, has been woven into the everyday life of many people. Online attackers are increasingly employing phishing attacks on Facebook due to its wealth of personal information and users’ lack of security knowledge, seeking to fool their victims by using fake or compromised accounts. These attacks are hard to recognize by the Facebook defensive system and users alike, and few studies have been done on how users interact with such attacks. This study aims to take the initial step in understanding the thought process of users and influences of different variables when they interact with their Facebook newsfeed.
Older users (aged 55 and over) are generally thought to have limited knowledge in online security; additionally, their declining cognitive and perceptive abilities can further expose them to digital attacks. Despite these risks and the growing older population, little has been studied about older users’ security performance, perception, and behavior. We begin to address this gap with this preliminary study. First, we studied older users’ ability to memorize passwords through a multisession user study with seven participants at a local retirement community. For this study, we leveraged a recently-proposed graphical authentication scheme that offers multiple cues (visual, verbal, spatial) to memorize system-assigned random passwords. To tailor this password scheme to an older population, we build on prior work in cognitive psychology that has been done to understand older users’ needs. Second, we conducted a survey to further learn about their security perceptions and practices. Based on what we have learned and the challenges that we have faced during our study, we offer guidelines for other researchers interested in designing new systems and conducting usability study with older population, and we also outline the future work for our ongoing research.
Introduction. Given the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. Addressing this usability-security tension in user authentication remains the key research issue in password studies for decades. In our research, we aim to understand how humans’ cognitive abilities could be leveraged to design more secure and memorable authentication schemes. To achieve this goal, we draw upon multiple theories from cognitive psychology and implement them in the context of improving memorability for systemassigned random passwords. In this workshop, we would provide a clear picture on our findings about the impact of memory cues and user interaction on the memorability of system-assigned passwords. We have conducted several studies in last three years including both lab and field studies on different populations that accommodate young and senior users. The findings from our studies are promising and the experiences are worth sharing . Below, we provide an overview of our major contributions in improving the memorability of system-assigned random passwords: