Users Really Don’t Learn – What Does That Mean For Security?
I’ve written about this subject a few times in the past – your average user does not care about security and getting them to care is virtually impossible. A recent survey by getsafeonline.org of over 3000 adults shows that 56% of the UK has been targeted in online attacks and of those a full 65% haven’t changed their online behavior accordingly.
Basically most users just can’t get themselves to care. And (this is outside of the scope of this study) I think that of the ones that do care there is a minority that has the knowledge or patience necessary to really keep themselves safe. There are these campaigns to get people aware of the security issues out there and to help them learn to protect themselves but in my opinion they are largely ineffective.
This is not their fault. I don’t care about loads of things and you probably care very little about a fair number of subjects as well. The issue here is what we make of this situation – we are trying to protect a group of people who do not care to protect themselves.
Don’t get me wrong, user education can help prevent attacks. If your user is suspicious of a link they might not click it and the attack won’t proceed. But the types of people who can be educated are typically the same type of people who already would be educated. The truth is that campaigns to educate users are generally going to fail because you can’t keep them interested long enough to teach them all that much and you’re only going to convince a few to use safe practices in the real world.
Security models need to take this into account. Programs designed to keep a user safe need to stop relying on that same user who downloaded malware.exe to decide whether it should run or not.
This latest survey is just more proof that security needs to move away from users, not continue to maintain an interactive relationship with them.
blog comments powered by Disqus