Did You Ever Have To Make Up Your Mind? What Notes Users Do When Faced With A Security Decision

  • Authors:
  • Mary Ellen Zurko;Charlie Kaufman;Katherine Spanbauer;Chuck Bassett

  • Affiliations:
  • -;-;-;-

  • Venue:
  • ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Designers are often faced with difficult tradeoffsbetween easing the user's burden by making securitydecisions for them and offering features that ensure thatusers can make the security decisions that are right forthem and their environment. Users often do not understandenough about the impact of a security decision to make aninformed choice. We report on the experience in a 500-person organization on the security of each user's LotusNotes client against unsigned active content. We found thatthe default configuration of the majority of users did notallow unsigned active content to run. However, we foundthat when presented with a choice during their work flow,many of those otherwise secured users would allowunsigned active content to run. We discuss the featuresthat are in Lotus Notes that provide security for activecontent and that respond to the usability issues from thisstudy.