Nudging Users to Change Breached Passwords Using the Protection Motivation Theory

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zou, Yixin, Le, Khue, Mayer, Peter, Acquisti, Alessandro, Aviv, Adam J., Schaub, Florian
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866929357434388480
author Zou, Yixin
Le, Khue
Mayer, Peter
Acquisti, Alessandro
Aviv, Adam J.
Schaub, Florian
author_facet Zou, Yixin
Le, Khue
Mayer, Peter
Acquisti, Alessandro
Aviv, Adam J.
Schaub, Florian
contents We draw on the Protection Motivation Theory (PMT) to design nudges that encourage users to change breached passwords. Our online experiment ($n$=$1,386$) compared the effectiveness of a threat appeal (highlighting negative consequences of breached passwords) and a coping appeal (providing instructions on how to change the breached password) in a 2x2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords; both comparisons have a small effect size. Participants' password change behaviors are further associated with other factors such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based nudges are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT's application in security research and provides concrete design implications for improving compromised credential notifications.
format Preprint
id arxiv_https___arxiv_org_abs_2405_15308
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Nudging Users to Change Breached Passwords Using the Protection Motivation Theory
Zou, Yixin
Le, Khue
Mayer, Peter
Acquisti, Alessandro
Aviv, Adam J.
Schaub, Florian
Cryptography and Security
Human-Computer Interaction
We draw on the Protection Motivation Theory (PMT) to design nudges that encourage users to change breached passwords. Our online experiment ($n$=$1,386$) compared the effectiveness of a threat appeal (highlighting negative consequences of breached passwords) and a coping appeal (providing instructions on how to change the breached password) in a 2x2 factorial design. Compared to the control condition, participants receiving the threat appeal were more likely to intend to change their passwords, and participants receiving both appeals were more likely to end up changing their passwords; both comparisons have a small effect size. Participants' password change behaviors are further associated with other factors such as their security attitudes (SA-6) and time passed since the breach, suggesting that PMT-based nudges are useful but insufficient to fully motivate users to change their passwords. Our study contributes to PMT's application in security research and provides concrete design implications for improving compromised credential notifications.
title Nudging Users to Change Breached Passwords Using the Protection Motivation Theory
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2405.15308