Psychology and Usability
Ross Anderson · 2020
Many real attacks exploit psychology at least as much as technology. In this chapter, the author first surveys relevant research in psychology, then works through how we apply the principles to make password authentication mechanisms more robust against attack, to security usability more generally, and beyond that to good design. Deception, of various kinds, is now the principal mechanism used to defeat online security. The management of passwords gives an instructive context in which usability, applied psychology and security meet. Security-economics research in underground markets has shown that by 2011 the action had moved to using humans; people in countries with incomes of a few dollars a day will solve Completely Automated Public Turing Test to Tell Computers and Humans Aparts (CAPTCHAs) for about 50c per 1000. The implementation of CAPTCHAs is often thoughtless, with accessibility issues for users who are visually impaired.