Behavior change ideas from health psychology can also help boost end user compliance with security recommendations, such as adopting two-factor authentication (2FA). Our research adapts the Transtheoretical Model Stages of Change from health and wellness research to a cybersecurity context. We first create and validate an assessment to identify workers on Amazon Mechanical Turk who have not enabled 2FA for their accounts as being in Stage 1 (no intention to adopt 2FA) or Stages 2-3 (some intention to adopt 2FA). We randomly assigned participants to receive an informational intervention with varied content (highlighting process, norms, or both) or not. After three days, we again surveyed workers for Stage of Amazon 2FA adoption. We found that those in the intervention group showed more progress toward action/maintenance (Stages 4-5) than those in the control group, and those who received content highlighting the process of enabling 2FA were significantly more likely to progress toward 2FA adoption. Our work contributes support for applying a Stages of Change Model in usable security.
翻译:健康心理学的改变观念也可以帮助提高终端用户对安全建议的遵守,例如采用两个因素的认证(2FA)等。我们的研究将改变的跨理论模型阶段从健康和健康研究转变为网络安全环境。我们首先创建和验证一项评估,以查明亚马逊机械土耳其公司的工人,他们未能在第一阶段(无意采用2FA)或第2-3阶段(有意采用2FA)或第2-3阶段(有意采用2FA)账户。我们随机指派参与者接受内容不同的信息干预(高亮进程、规范或两者兼有)。三天后,我们再次调查亚马逊2FA阶段的采用情况。我们发现,干预小组中的工人在行动/维护方面比控制小组的工人(4-5)取得了更多进展,而那些得到强调使2FA进程的内容的人在采用2FA程序方面更有可能取得进展。我们的工作有助于支持在可用安全方面应用变革模式的阶段。