"Should I Worry?" A Cross-Cultural Examination of Account Security Incident Response

08/24/2018
by   Elissa M. Redmiles, et al.
0

Digital security technology is able to identify and prevent many threats to users accounts. However, some threats remain that, to provide reliable security, require human intervention: e.g., through users paying attention to warning messages or completing secondary authentication procedures. While prior work has broadly explored people's mental models of digital security threats, we know little about users precise, in-the-moment response process to in-the-wild threats. In this work, we conduct a series of qualitative interviews (n=67) with users who had recently experienced suspicious login incidents on their real Facebook accounts in order to explore this process of account security incident response. We find a common process across participants from five countries -- with differing online and offline cultures -- allowing us to identify areas for future technical development to best support user security. We provide additional insights on the unique nature of incident-response information seeking, known attacker threat models, and lessons learned from a large, cross-cultural qualitative study of digital security.

READ FULL TEXT

page 6

page 7

page 9

research
06/01/2021

"Why wouldn't someone think of democracy as a target?": Security practices challenges of people involved with U.S. political campaigns

People who are involved with political campaigns face increased digital ...
research
11/21/2019

Insider threats in Cyber Security: The enemy within the gates

Insider threats have become reality for civilian firms such as Tesla, wh...
research
05/20/2022

Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web

The ubiquity of user accounts in websites and online services makes acco...
research
01/04/2022

Prospects for Improving Password Selection

User-chosen passwords remain essential to online security, and yet peopl...
research
02/16/2023

"There's so much responsibility on users right now:" Expert Advice for Staying Safer From Hate and Harassment

Online hate and harassment poses a threat to the digital safety of peopl...
research
08/01/2023

Assessment of POS Owners Awareness of Cybersecurity and Insider Threats in POS Kiosks Related Financial Crimes

The introduction of point of sales POS technologies as a payment system ...
research
06/23/2018

A Recursive PLS (Partial Least Squares) based Approach for Enterprise Threat Management

Most of the existing solutions to enterprise threat management are preve...

Please sign up or login with your details

Forgot password? Click here to reset