← Studies

Supports · 2009

So long, and no thanks for the externalities: the rational rejection of security advice by users

Cormac Herley

Key finding

Argues that users ignoring security advice is economically rational: advice imposes large, constant effort costs while its benefits are often speculative. For example, the time cost of everyone checking URLs would dwarf all phishing losses.

Why it matters

Reframes non-compliance as a reasonable response to burdensome advice, shifting responsibility to how security asks are designed and prioritized.

Informs Cite
Herley, C. (2009). So long, and no thanks for the externalities: the rational rejection of security advice by users. Proceedings of the 2009 New Security Paradigms Workshop (NSPW '09). https://doi.org/10.1145/1719030.1719050