A quarter century of usable security and privacy research: transparency, tailorability, and the road ahead
Christian Reuter,
Luigi Lo Iacono and
Alexander Benlian
Publications of Darmstadt Technical University, Institute for Business Studies (BWL) from Darmstadt Technical University, Department of Business Administration, Economics and Law, Institute for Business Studies (BWL)
Abstract:
In the last decades, research has shown that both technical solutions and user perceptions are important to improve security and privacy in the digital realm. The field of ‘usable security’ already started to emerge in the mid-90s, primarily focussed on password and email security. Later on, the research field of ”usable security and privacy” evolved and broadened the aim to design concepts and tools to assist users in enhancing their behaviour with regard to both privacy and security. Nevertheless, many user interventions are not as effective as desired. Because of highly diverse usage contexts, leading to different privacy and security requirements and not always to one-size-fits-all approaches, tailorability is necessary to address this issue. Furthermore, transparency is a crucial requirement, as providing comprehensible information may counter reactance towards security interventions. This article first provides a brief history of the research field in its first quarter-century and then highlights research on the transparency and tailorability of user interventions. Based on this, this article then presents six contributions with regard to (1) privacy concerns in times of COVID-19, (2) authentication on mobile devices, (3) GDPR-compliant data management, (4) privacy notices on websites, (5) data disclosure scenarios in agriculture, as well as (6) rights under data protection law and the concrete process should data subjects want to claim those rights. This article concludes with several research directions on user-centred transparency and tailorability.
Date: 2022
Note: for complete metadata visit http://tubiblio.ulb.tu-darmstadt.de/132897/
References: Add references at CitEc
Citations:
Published in Behaviour & Information Technology 10 (2022) : pp. 2035-2048
Downloads: (external link)
https://www.tandfonline.com/doi/full/10.1080/0144929X.2022.2080908
Our link check indicates that this URL is bad, the error code is: 403 Forbidden
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:dar:wpaper:132897
Access Statistics for this paper
More papers in Publications of Darmstadt Technical University, Institute for Business Studies (BWL) from Darmstadt Technical University, Department of Business Administration, Economics and Law, Institute for Business Studies (BWL) Contact information at EDIRC.
Bibliographic data for series maintained by Dekanatssekretariat ().