How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and Behavior
Elissa M. Redmiles, Sean Kross, Michelle L. Mazurek
Abstract
Few users have a single, authoritative, source from whom they can request digital-security advice. Rather, digital-security skills are often learned haphazardly, as users filter through an overwhelming quantity of security advice. By understanding the factors that contribute to users' advice sources, beliefs, and security behaviors, we can help to pare down the quantity and improve the quality of advice provided to users, streamlining the process of learning key behaviors. This paper rigorously investigates how users' security beliefs, knowledge, and demographics correlate with their sources of security advice, and how all these factors influence security behaviors. Using a carefully pre-tested, U.S.-census-representative survey of 526 users, we present an overview of the prevalence of respondents' advice sources, reasons for accepting and rejecting advice from those sources, and the impact of these sources and demographic factors on security behavior. We find evidence of a "digital divide" in security: the advice sources of users with higher skill levels and socioeconomic status differ from those with fewer resources. This digital security divide may add to the vulnerability of already disadvantaged users. Additionally, we confirm and extend results from prior small-sample studies about why users accept certain digital-security advice (e.g., because they trust the source rather than the content) and reject other advice (e.g., because it is inconvenient and because it contains too much marketing material). We conclude with recommendations for combating the digital divide and improving the efficacy of digital-security advice.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8d4c6099-a8a2-49f6-a863-45f3c5505bd2Cited by top-tier papers45
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 222 citations
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog et al.CCS 2017 · 146 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
- Computer Security and Privacy for Refugees in the United StatesLucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner et al.S&P 2018 · 77 citations
- Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection PracticesYixin Zou, Kevin A. Roundy, Acar Tamersoy, Saurabh Shintre et al.CHI 2020 · 73 citations
Related papers
- I Think They're Trying to Tell Me Something: Advice Sources and Selection for Digital SecurityElissa M. Redmiles, Amelia R. Malone, Michelle L. MazurekS&P 2016 · 151 citations
- A Comprehensive Quality Evaluation of Security and Privacy Advice on the WebElissa M. Redmiles, Noel Warford, Amritha Jayanti, Aravind Koneru et al.USENIX Security 2020
- Who Is At Risk? Examining the Prevalence of Digital-Safety Attacks and Contextual Risk Factors in the United StatesSharon Heung, Claire Florence Weizenegger, Mo Houtti, Sunny Consolvo et al.CHI 2026 · 2 citations
- "Un-Equal Online Safety?" A Gender Analysis of Security and Privacy Protection Advice and Behaviour PatternsKovila P. L. Coopamootoo, Magdalene NgUSENIX Security 2023
- "It's Time. Time for Digital Security.": An End User Study on Actionable Security and Privacy AdviceAnna Lena Rotthaler, Harshini Sri Ramulu, Lucy Simko, Sascha Fahl et al.S&P 2025
