Replication: No One Can Hack My Mind Revisiting a Study on Expert and Non-Expert Security Practices and Advice

Replication: No One Can Hack My Mind Revisiting a Study on Expert and Non-Expert Security Practices and Advice
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Karoline Busse;J. Schäfer;Matthew Smith
Karoline Busse;J. Schäfer;Matthew Smith
中科院分区:
其他
文献类型:
--
作者:
Karoline Busse;J. Schäfer;Matthew Smith

文献摘要

被引文献

相似文献

2015年,Iulia Ion、Rob Reeder和Sunny Con-Solvo进行了一项研究,调查了安全专家和非专家自我报告的安全行为。他们还分析了专家向非专家提供的安全建议的类型,以及他们认为典型建议的现实性和有效性。现在,大约四年后,我们的目标是用一组相似的非专家和一组不同的专家来复制和扩展这项研究。对于非专家,我们招募了288名MTurk参与者,就像Ion等人一样。做。我们还招募了75名安全专家,其中大部分是欧洲人,而Ion等人的样本大多是美国人。我们的fi编码显示,尽管样本不同,而且已经过去了四年,但最常见的专家建议大多没有变化,有一个值得注意的例外。此外,我们确实在建议的长尾中看到了相当数量的fl功能。然而,非专家的自我报告行为没有变化,这意味着在Ion等人中看到的专家和非专家之间的差距。S的工作在我们的研究中仍然同样突出。为了扩展这项工作,我们还进行了A/B研究,以更好地了解与专家建议有关的关键问题之一,并确定了哪些类型的建议最需要可用的安全社区进行研究。
A 2015 study by Iulia Ion, Rob Reeder, and Sunny Con-solvo examined the self-reported security behavior of security experts and non-experts. They also analyzed what kind of security advice experts gave to non-experts and how realistic and effective they think typical advice is. Now, roughly four years later, we aimed to replicate and extend this study with a similar set of non-experts and a different set of experts. For the non-experts, we recruited 288 MTurk participants, just as Ion et al. did. We also recruited 75 mostly European security experts, in contrast to the mostly US sample from Ion et al. Our findings show that despite the different samples and the four years that have passed, the most common pieces of expert advice are mostly unchanged, with one notable exception. In addition, we did see a fair amount of fluctuation in the long tail of advice. Non-expert self-reported behavior, however, is unchanged, meaning that the gap be-tween experts and non-experts seen in Ion et al.’s work is still just as prominent in our study. To extend the work, we also conducted an A/B study to get a better understanding of one of the key questions concerning experts’ recommendations, and we identified types of advice where research by the usable security community is most sorely needed.