Awareness about security and privacy risks is important for developing good security habits. Learning about real-world security incidents and data breaches can alert people to the ways in which their information is vulnerable online, thus playing a significant role in encouraging safe security behavior. This paper examines 1) how often people read about security incidents online, 2) of those people, whether and to what extent they follow up with an action, e.g., by trying to read more about the incident, and 3) what influences the likelihood that they will read about an incident and take some action. We study this by quantitatively examining real-world internet-browsing data from 303 participants. Our findings present a bleak view of awareness of security incidents. Only 16% of participants visited any web pages related to six widely publicized large-scale security incidents; few read about one even when an incident was likely to have affected them (e.g., the Equifax breach almost universally affected people with Equifax credit reports). We further found that more severe incidents as well as articles that constructively spoke about the incident inspired more action. We conclude with recommendations for specific future research and for enabling useful security incident information to reach more people.
翻译:对安全和隐私风险的认识对于形成良好的安全习惯十分重要。了解真实世界安全事件和数据破坏情况可以使人们警惕其信息在网上的脆弱性,从而在鼓励安全行为方面发挥重大作用。本文审查:(1) 这些人在网上阅读安全事件的次数多多,(2) 这些人在网上阅读安全事件的次数多,是否以及在多大程度上采取了一项行动,例如试图更多地阅读事件,以及(3) 影响他们阅读事件和采取某种行动的可能性。我们通过定量审查实际世界互联网浏览303名参与者的数据来研究这一问题。我们的调查结果对安全事件的认识呈现暗淡的看法。只有16%的参与者访问过与六起广为宣传的大规模安全事件有关的任何网页;即使事件可能影响到他们,也很少读过一个网页(例如Equifax几乎普遍受到影响的人,Equifax信用报告)。我们进一步发现,更严重的事件以及建设性地谈论事件的文章激发了更多的行动。我们最后建议进行具体的未来研究,并使得有用的安全事件信息能够接触到更多的人。