Research: Slight Changes to Appearance of Privacy Warnings Significantly Improves Attention

attention message bubble in smartphone

New research from a team at Brigham Young University finds that people tend to tune out security warnings as they see them more often. Conducted by information systems professors Anthony Vance, Bonnie Anderson and Jeff Jenkins, the study was funded by the National Science Foundation and follows on previous work the researchers have conducted with Brock Kirwan, a neuroscience professor at BYU.

"The problem — and something everyone has experienced — is that warnings just fade away and disappear over time in our consciousness because we're exposed to them so often," said Vance, lead author on the study, in a prepared statement.

Previously, the team had looked at snapshots of user attention and neural response. This time, the researchers combined a five-day lab experiment that tracked neural and visual responses to security warnings with a three-week field experiment that observed users interacting with their devices naturally and tracked their responses to privacy permissions warnings.

The field study required participants to install and evaluate three apps from the Android Play store each day for 15 days. Warnings popped up for each app listing any permissions the app requested related to accessing or modifying data, with some, such as "Sell your web-browsing data" or "Record microphone audio any time," representing significant risk. Some participants received warnings that looked the same every time, while others received warnings that changed in appearance each time.

Users who received the same warnings each time adhered to the warnings 55 percent of the time at the end of the study, while those who received the shifting warnings adhered to them 76 percent of the time.

"Even using a few variations can have a substantial effect over time," said Anderson, chair of the BYU Department of information Systems, in a prepared statement. "The trick is to get the variations to the point where people pay attention without being annoyed."

The lab component of the study seems to back up those findings, as it showed reduced neural activity and eye movement with repeated static-appearance warnings and a significant increase in sustained attention for the polymorphic warnings.

"System designers need to understand this is how the brain works, and they need to be as judicious as possible with the number of warnings they present," Vance said. "Secondly, if they can add some visual novelty to the warning, that really helps the brain recapture attention."

The study, "Tuning out Security Warnings: A Longitudinal Examination of Habituation through fMRI, Eye Tracking and Field Experiments," is published in the June issue of MIS Quarterly.

About the Author

Joshua Bolkan is contributing editor for Campus Technology, THE Journal and STEAM Universe. He can be reached at [email protected].

Featured

  • abstract pattern of shapes, arrows and circuit lines

    Internet2 Announces a New President and CEO to Step Up in October

    Internet2, the member-driven nonprofit offering advanced network technology services and cyberinfrastructure to the research and education community has completed its search, which began this past May, for a new president and CEO to take the helm.

  • shield with an AI microchip emblem hovering above stacks of gold coins

    AI Security Spend Surges While Traditional Security Budgets Shrink

    A new Thales report reveals that while enterprises are pouring resources into AI-specific protections, only 8% are encrypting the majority of their sensitive cloud data — leaving critical assets exposed even as AI-driven threats escalate and traditional security budgets shrink.

  • stack of gold coins disintegrates into digital particles against a dark circuit-board background with glowing AI imagery

    MIT Report: Most Organizations See No Business Return on Gen AI Investments

    A recent report out of the MIT Media Lab found that despite $30-40 billion in enterprise spending on generative AI, 95% of organizations are seeing no business return.

  • young man in a denim jacket scans his phone at a card reader outside a modern glass building

    Colleges Roll Out Mobile Credential Technology

    Allegion US has announced a partnership with Florida Institute of Technology (FIT) and Denison College, in conjunction with Transact + CBORD, to install mobile credential technologies campuswide. Implementing Mobile Student ID into Apple Wallet and Google Wallet will allow students access to campus facilities, amenities, and residence halls using just their phones.