CyLab Usable Privacy and Security Laboratory 1 CyLab Usable Privacy and Security Laboratory Design for.

Slides:



Advertisements
Similar presentations
RP Designs Semi-Custom e-Commerce Package. Overview RP Designs semi- custom e-commerce package is a complete website solution. Visitors can browse a catalog.
Advertisements

Ethics Ethics are the rules of personal behavior and conduct established by a social group for those existing within the established framework of the social.
Back to Table of Contents
MXIE overview 5/4/ Update1. MXIE Media Exchange Interface for End Users 5/4/ Update2.
Identity Management Based on P3P Authors: Oliver Berthold and Marit Kohntopp P3P = Platform for Privacy Preferences Project.
Configuring Windows Vista Security Lesson 8. Skills Matrix Technology SkillObjective DomainObjective # Setting Up Users Configure and troubleshoot parental.
Marketing for Hospitality and Tourism, 3e©2003 Pearson Education, Inc. Philip Kotler, John Bowen, James MakensUpper Saddle River, NJ Chapter 16.
Secure File Interchange 2 Whitenoise Laboratories Inc. Quick User Guide.
Business Aids for Success Business: BambooHR Management: Glip E-Commerce: Shopify
Recommender Systems Aalap Kohojkar Yang Liu Zhan Shi March 31, 2008.
 Guarantee that EK is safe  Yes because it is stored in and used by hw only  No because it can be obtained if someone has physical access but this can.
Usable Privacy and Security Carnegie Mellon University Spring 2006 Cranor/Hong/Reiter 1 Design for Privacy 1 February.
C MU U sable P rivacy and S ecurity Laboratory 1 Privacy Policy, Law and Technology Engineering Privacy November 6, 2008.
Requirements Specification
Usable Privacy and Security Carnegie Mellon University Spring 2007 Cranor/Hong 1 Design for Privacy February 20,
1 of 5 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Data Privacy.
User studies. Why user studies? How do we know security and privacy solutions are really usable? Have to observe users! –you may be surprised by what.
Institute of Information Systems, Humboldt University, 2006· Privacy Engineering Sarah Spiekermann & Lorrie Faith Cranor DIMACS Workshop, Rutgers University.
Usable Privacy and Security Carnegie Mellon University Spring 2008 Lorrie Cranor 1 Design for Privacy February.
CyLab Usable Privacy and Security Laboratory 1 CyLab Usable Privacy and Security Laboratory Introduction.
Chapter 9 e-Commerce Systems.
Information Architecture Creating well structured, usable sites.
Customer Service and Web Site Personalization Back to Table of Contents.
The Privacy Tug of War: Advertisers vs. Consumers Presented by Group F.
“If you build it, they will come.”. Virtual Business  There is much more that goes into a virtual business than just building the web site.  You will.
July 25, 2005 PEP Workshop, UM A Single Sign-On Identity Management System Without a Trusted Third Party Brian Richardson and Jim Greer ARIES Lab.
Jared Cinque Section 6.  Internet tracking is the process of following internet activity backwards from recipient to user through a special type of software.
Upay User Guide
Upay User Guide WELCOME TO UPAY This guide aims to help you use the upay website. You will receive a welcome from Wolfson College.
CHC DI Group. What We Will Cover Securing your devices and computers. Passwords. s. Safe browsing for shopping and online banks. Social media.
CMU Usable Privacy and Security Laboratory Hey, That’s Personal! Lorrie Faith Cranor 28 July 2005
1 Shopping on the Internet INFO 654 – Spring 2007.
Chapter 10 Developing a Web-Based Online Shopping Application (I)
AL-MAAREFA COLLEGE FOR SCIENCE AND TECHNOLOGY INFO 232: DATABASE SYSTEMS CHAPTER 1 DATABASE SYSTEMS (Cont’d) Instructor Ms. Arwa Binsaleh.
©2006, CSA Creating and Managing Your COS Expertise Profile Managing Your CV and Promoting Your Work ® Resources for Research, Worldwide.
POSITIONING STATEMENT For people who operate shared computers with Genuine Windows XP, the Shared Computer Toolkit is an affordable, integrated, and easy-to-use.
Virtual Business CREATING A WEB PRESENCE Copyright © Texas Education Agency, All rights reserved.
OHT 11.1 © Marketing Insights Limited 2004 Chapter 9 Analysis and Design EC Security.
Business Software What is database software? p. 145 Allows you to create, access, and manage data Add, change, delete, sort, and retrieve data Next.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
Event Management & ITIL V3
1 OPOL Training (OrderPro Online) Prepared by Christina Van Metre Independent Educational Consultant CTO, Business Development Team © Training Version.
SPAM Settings. The ExchangeDefender Admin Site is a powerful tool that gives you access to all of the benefits ExchangeDefender has to offer, from the.
Client/User Analysis Website Design. 2 Questions to be answered: What is the purpose of the site? What is the purpose of the site? Who is the site for?
12 Developing a Web Site Section 12.1 Discuss the functions of a Web site Compare and contrast style sheets Apply cascading style sheets (CSS) to a Web.
Section 12.1 Discuss the functions of a Web site Create a feedback form Compare and contrast option buttons and check boxes Section 12.2 Explain the use.
D1 - 25/10/2015 The present document contains information that remains the property of France Telecom. The recipient’s acceptance of this document implies.
Customer Interface for wuw.com 1.Context. Customer Interface for wuw.com 2. Content Our web-site can be classified as an service-dominant website. 3.
ITGS Databases.
Order the featured book of the day Estimated effort: 2.
Table of Contents TopicSlide Administrator Login 2 Administrator Navigations 3 Managing AlternativeDr.com Blogs 4 Managing Dr. Lloyd May Blogs 5 Managing.
Requirements specification Why is this the first major stage of software development? –Need to understand what customer wants first Goal of requirements.
Organisations and Data Management 1 Data Collection: Why organisations & individuals acquire data & supply data via websites 2Techniques used by organisations.
Copyright © 2007 Pearson Education Canada 23-1 Chapter 23: Using Advanced Skills.
Privacy & Confidentiality in Internet Research Jeffrey M. Cohen, Ph.D. Associate Dean, Responsible Conduct of Research Weill Medical College of Cornell.
McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, All Rights Reserved Chapter 7 Storing Organizational Information - Databases.
Upay User Guide WELCOME TO UPAY This guide is aimed to help you to use the Upay website. To launch Upay you will need to navigate to
Introduction Web analysis includes the study of users’ behavior on the web Traffic analysis – Usage analysis Behavior at particular website or across.
On-Line BankCard Center Presentation Cardholder Role During the Presentation click the mouse on this button to move back a slide During the Presentation.
“Candidates were not advantaged by defining every type of operating system provided as examples in the explanatory notes of the standard. Candidates who.
Protecting your search privacy A lesson plan created & presented by Maria Bernhey (MLS) Adjunct Information Literacy Instructor
Top Ten Ways to Protect Privacy Online -Abdul M. Look for privacy policies on Web Sites  Web sites can collect a lot of information about your visit.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Unlinking Private Data
"Our vision is to be earth's most customer-centric company; to build a place where people can come to find and discover anything they might want to buy.
About SharePoint Server 2007 My Sites
Vocabulary Big Data - “Big data is a broad term for datasets so large or complex that traditional data processing applications are inadequate.” Moore’s.
Chapter 12: Automated data collection methods
Preparing for GDPR Sharing experiences of the process and using the British Canoeing Toolkit bit.ly/BCGDPRToolkit
Presentation transcript:

CyLab Usable Privacy and Security Laboratory 1 CyLab Usable Privacy and Security Laboratory Design for Privacy September

CyLab Usable Privacy and Security Laboratory 2 Outline  Engineering privacy  Design of privacy tools  Design for privacy in everyday software  Obtaining informed consent

CyLab Usable Privacy and Security Laboratory 3 Engineering privacy

CyLab Usable Privacy and Security Laboratory 4 How Privacy Rights are Protected  By policy – Protection through laws and organizational privacy policies – Must be enforced – Often requires mechanisms to obtain and record consent – Transparency facilitates choice and accountability – Technology facilitates compliance and reduces the need to rely solely on trust and external enforcement – Technology reduces or eliminates any form of manual processing or intervention by humans – Violations still possible due to bad actors, mistakes, government mandates  By architecture – Protection through technology – Reduces the need to rely on trust and external enforcement – Violations only possible if technology fails or the availability of new data or technology defeats protections – Often viewed as too expensive or restrictive Limits the amount of data available for data mining, R&D, targeting, other business purposes May require more complicated system architecture, expensive cryptographic operations Pay now or pay later

CyLab Usable Privacy and Security Laboratory 5 Privacy stages identifiability Approach to privacy protection Linkability of data to personal identifiers System Characteristics 0identified privacy by policy (notice and choice) linked unique identifiers across databases contact information stored with profile information 1 pseudonymous linkable with reasonable & automatable effort no unique identifies across databases common attributes across databases contact information stored separately from profile or transaction information 2 privacy by architecture not linkable with reasonable effort no unique identifiers across databases no common attributes across databases random identifiers contact information stored separately from profile or transaction information collection of long term person characteristics on a low level of granularity technically enforced deletion of profile details at regular intervals 3anonymousunlinkable no collection of contact information no collection of long term person characteristics k-anonymity with large value of k Sarah Spiekermann and Lorrie Faith Cranor. Engineering Privacy. IEEE Transactions on Software Engineering. Vo. 35, No. 1, January/February, 2009, pp Degrees of Identifiability

CyLab Usable Privacy and Security Laboratory 6 Design of Privacy Tools

CyLab Usable Privacy and Security Laboratory 7 Privacy tool examples  Cookie managers  Anonymizers  Encryption tools  Disk wiping utilities  P3P user agents

CyLab Usable Privacy and Security Laboratory 8 Laptop Compubody Sock for privacy, warmth, and concentration in public spaces Created by Becky Stern Laptop Compubody Sock for privacy, warmth, and concentration in public spaces Created by Becky Stern CIPP/IT Section Three | Privacy Protection Mechanisms

CyLab Usable Privacy and Security Laboratory 9 Issues to consider  Privacy is a secondary task – Users of privacy tools often seek out these tools due to their awareness of or concern about privacy – Even so, users still want to focus on their primary tasks  Users have differing privacy concerns and needs – One-size-fits-all interface may not work  Most users are not privacy experts – Difficult to explain current privacy state or future privacy implications – Difficult to explain privacy options to them – Difficult to capture privacy needs/preferences  Many privacy tools reduce application performance, functionality, or convenience

CyLab Usable Privacy and Security Laboratory 10 Case study: Tor  Internet anonymity system  Allows users to send messages that cannot be traced back to them (web browsing, chat, p2p, etc.)  UI was mostly command line interface until recently  2005 Tor GUI competition – CUPS team won phase 1 with design for Foxtor!

CyLab Usable Privacy and Security Laboratory 11 One-size-doesn’t-fit-all problem  Tor is configurable and different users will want to configure it in different ways – But most users won’t understand configuration options – Give users choices, not dilemmas  We began by trying to understand our users – No budget, little time, limited access to users – So we brainstormed about their needs, tried to imagine them, and develop personas for them  This process led to realization that our users had 3 categories of privacy needs – Basic, selective, critical  Instead of asking users to figure out complicated settings, most of our configuration involves figuring out which types of privacy needs they have

CyLab Usable Privacy and Security Laboratory 12

CyLab Usable Privacy and Security Laboratory 13 Understand primary task  Anonymity is not a primary task  What are the primary tasks our users are engaged in when they want anonymity?  Lots of them …. Web browsing, chatting, file sharing, etc., but we speculate that browsing will be most frequent for most users  So, instead of building anonymity tool that you can use to anonymize web browsing…  … build a web browser with built in anonymity functions

CyLab Usable Privacy and Security Laboratory 14 Metaphors  Because of performance issues and problems accessing some web sites through Tor, some users will want to turn the anonymity function on and off  Important to make it easy for users to determine current state  Communicate through visual symbol and readily understandable metaphor  Brainstormed possibilities: torized/untorized, private/exposed, cloaked/uncloaked, masked/unmasked

CyLab Usable Privacy and Security Laboratory 15

CyLab Usable Privacy and Security Laboratory 16 Design for privacy in every day software

CyLab Usable Privacy and Security Laboratory 17 Examples  Ecommerce personalization systems – Concerns about use of user profiles  Software that “phones home” to fetch software updates or refresh content, report bugs, relay usage data, verify authorization keys, etc. – Concerns that software will track and profile users  Communications software ( , IM, chat) – Concerns about traffic monitoring, eavesdroppers  Presence systems (buddy lists, shared spaces, friend finders) – Concerns about limiting when info is shared and with whom

CyLab Usable Privacy and Security Laboratory 18 Issues to consider  Similar to issues to consider for privacy tools PLUS  Users may not be aware of privacy issues up front – When they find out about privacy issues they may be angry or confused, especially if they view notice as inadequate or defaults as unreasonable  Users may have to give up functionality or convenience, or spend more time configuring system for better privacy  Failure to address privacy issues adequately may lead to bad press and legal action

CyLab Usable Privacy and Security Laboratory 19 The Prada NYC dressing room   What aspects seem privacy invasive?  How could the design be changed to reduce privacy concerns?

CyLab Usable Privacy and Security Laboratory 20 Amazon.com privacy makeover

Streamline menu navigation for customization

CyLab Usable Privacy and Security Laboratory 22 Provide way to set up default rules  Every time a user makes a new purchase that they want to rate or exclude they have to edit profile info – There should be a way to set up default rules Exclude all purchases Exclude all purchases shipped to my work address Exclude all movie purchases Exclude all purchases I had gift wrapped

CyLab Usable Privacy and Security Laboratory 23 Remove excluded purchases from profile  Users should be able to remove items from profile  If purchase records are needed for legal reasons, users should be able to request that they not be accessible online

CyLab Usable Privacy and Security Laboratory 24 Better: options for controlling recent history

CyLab Usable Privacy and Security Laboratory 25 Use personae  Amazon already allows users to store multiple credit cards and addresses  Why not allow users to create personae linked to each with option of keeping recommendations and history separate (would allow easy way to separate work/home/gift personae)?

CyLab Usable Privacy and Security Laboratory 26 Allow users to access all privacy-related options in one place  Currently privacy-related options are found with relevant features  Users have to be aware of features to find the options  Put them all in one place  But also leave them with relevant features

CyLab Usable Privacy and Security Laboratory 27 I didn’t buy it for myself How about an “I didn’t buy it for myself” check-off box (perhaps automatically checked if gift wrapping is requested) I didn’t buy it for myself

CyLab Usable Privacy and Security Laboratory 28 Other ideas for improving Amazon privacy interface?

CyLab Usable Privacy and Security Laboratory 29 Obtaining informed consent  Many software products contain phone home features, for example, for performing software updates or monitoring usage patterns. In some cases software phones homes quite frequently, for example, to update phishing black lists or check for fresh image files. Users may be concerned that the software company is using these features to track or profile them. Thus it is important that the software is up front about the fact that it is phoning home. Furthermore, some users may wish to disable such features or be prompted every time before they phone home (due to privacy or other concerns), whereas other users are happy to have them operate automatically.  Discuss the various approaches you have seen different software manufacturers take to addressing this problem. What do you like/dislike about them?  How should phone home features be designed so that they facilitate informed consent? Describe an example user interface design and general principles that might be applied to specific cases.  What sort of user studies should be performed to test this user interface design?