Nudging Users to Change Breached Passwords Using the Protection Motivation Theory
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2024
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866929357434388480 |
|---|---|
| author | Zou, Yixin Le, Khue Mayer, Peter Acquisti, Alessandro Aviv, Adam J. Schaub, Florian |
| author_facet | Zou, Yixin Le, Khue Mayer, Peter Acquisti, Alessandro Aviv, Adam J. Schaub, Florian |
| contents | We draw on the Protection Motivation Theory (PMT) to design nudges that encourage users to change breached passwords. Our online experiment ($n$=$1,386$) compared the effectiveness of a threat appeal (highlighting negative consequences of breached passwords) and a coping appeal (providing instructions on how to change the breached password) in a 2x2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords; both comparisons have a small effect size. Participants' password change behaviors are further associated with other factors such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based nudges are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT's application in security research and provides concrete design implications for improving compromised credential notifications. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2405_15308 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Nudging Users to Change Breached Passwords Using the Protection Motivation Theory Zou, Yixin Le, Khue Mayer, Peter Acquisti, Alessandro Aviv, Adam J. Schaub, Florian Cryptography and Security Human-Computer Interaction We draw on the Protection Motivation Theory (PMT) to design nudges that encourage users to change breached passwords. Our online experiment ($n$=$1,386$) compared the effectiveness of a threat appeal (highlighting negative consequences of breached passwords) and a coping appeal (providing instructions on how to change the breached password) in a 2x2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords; both comparisons have a small effect size. Participants' password change behaviors are further associated with other factors such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based nudges are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT's application in security research and provides concrete design implications for improving compromised credential notifications. |
| title | Nudging Users to Change Breached Passwords Using the Protection Motivation Theory |
| topic | Cryptography and Security Human-Computer Interaction |
| url | https://arxiv.org/abs/2405.15308 |