Supports · 2009
So long, and no thanks for the externalities: the rational rejection of security advice by users
Cormac Herley
Key finding
Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.
Why it mattersReframes non-compliance as a reasonable response to burdensome advice, shifting responsibility to how security asks are designed and prioritized.
Informs CiteHerley, C. (2009). So long, and no thanks for the externalities: the rational rejection of security advice by users. Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09). https://doi.org/10.1145/1719030.1719050