“Protect Me Tomorrow”: Commitment Nudges to Remedy Compromised Passwords

Author:

Peer Eyal1ORCID,Frik Alisa2ORCID,Gilsenan Conor3ORCID,Egelman Serge4ORCID

Affiliation:

1. Hebrew University of Jerusalem, Israel

2. International Computer Science Institute, USA

3. University of California, Berkeley, USA

4. International Computer Science Institute / University of California, Berkeley, USA

Abstract

Internet users often neglect important security actions (e.g., installing security updates or changing passwords) because they interrupt users’ main task at inopportune times. Commitment devices, such as reminders and promises, have been found to be effective at reducing procrastination in other domains. In a series of online experiments ( \(n\,{\gt}\,3,000\) ), we explored the effects of reminders and promises on users’ willingness to change a compromised password. We find that adding an option to delay the task increases the share of people willing to eventually change their password considerably. Critically, the option to delay yields this overall increase without reducing the share of people choosing to change their password immediately. Additionally, most participants who promised to change their password later, or asked to be reminded to do so, indeed followed through on their commitment, leading to a net positive effect. Reminding participants of their previous commitment further increased this effect.

Publisher

Association for Computing Machinery (ACM)

Reference90 articles.

1. Alessandro Acquisti. 2004. Privacy in Electronic Commerce and the Economics of Immediate Gratification. In Proceedings of the ACM Electronic Commerce Conference (EC ’04). ACM Press, New York, NY, 21–29. http://www.heinz.cmu.edu/∼acquisti/papers/privacy-gratification.pdf.

2. Nudges for Privacy and Security

3. Dan Ariely and Klaus Wertenbroch. 2002. Procrastination, deadlines, and performance: Self-control by precommitment. Psychological science 13, 3 (2002), 219–224.

4. Gabriel Bassett C. David Hylender Philippe Langlois Alexandre Pinto and Suzanne Widup. 2021. 2021 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/2021/2021-data-breach-investigations-report.pdf. Verizon.

5. Can honesty oaths, peer interaction, or monitoring mitigate lying;Beck Tobias;Journal of Business Ethics,2020

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3