Study Shows Average User Is Pretty Stupid When It Comes to Popups
September 24, 2008 8:15 AM
comment(s) - last by
The new study from the North Carolina State University's Psych department shows just how dumb the average user is when it comes to computer security. The study shows users are willing to do anything, including throwing security caution to the wind, to get rid of minor annoyances.
A new study is giving computer savvy users a look at the "other" users' behavior
You often wonder how users fall for seemingly obvious ploys -- you know, the letter from Makib in Ethiopia seeking for donations for an orphanage, or perhaps the most recent
fake ticket emails that claim to have your ticket in a ZIP file
. To the computer savvy, these silly attempts might make for a good morning laugh, but security experts say there's nothing to laugh about when millions of naïve users fall for the scheme and their computers become part of a botnet, used to
launch devastating DoS attacks
A new study from the Psychology Department of North Carolina State University gives some insight into just how
easily tricked many users are
. On compromised websites one form of malware distribution is through popup windows. If users click to dismiss them, they often download malware onto their computers. So just how many users would be tricked into clicking?
The researchers crafted 4 dialog boxes and exposed 42 college students to them in a normal browsing atmosphere. Each box contained the cryptic message "The instruction at '0x77f41d24 referenced memory at '0x595c2a4c." The first one bore the markings of a standard Windows dialog, but the remainder had noticeable differences that should have warned users that it was malware.
In each of the dialogs putting the mouse over the "OK" button turned the cursor into a hand, a sign that it was a browser control, not a Windows dialog. The dialogs also all had minimize and maximize buttons. Starting with the second one, a browser status bar was added to the bottom. Finally the last one was made blatantly obvious by text that flashed from black on a white background to white on a black background.
To properly lure the college students into the ruse, they created a series of fake medical websites in Flash. The students were told they were going to be quizzed on the information on the sites after the test. The popups were then activated as the students were browsing the sites.
Of the 42 college students, 26 clicked the "OK" button on the most normal looking dialog, 25 clicked on each of the more obvious fakes, and 23 clicked on the most obvious fake, the one with the flashing text. This study should be welcome news to malware crafters -- college educated users will click obviously dangerous dialogs over 50 percent of the time.
In all only 9 users closed the dialogs. The rest minimized them, or dragged them out of the way, risky behaviors, as the next user at the computer could be exposed to the dialog. The time between the dialog appearing and the user clicking remained approximately constant for all the dialogs. This seems to indicate that the users did not even think much before clicking the foreign message.
In follow up questions, over half of students said the dialog boxes were a distraction from the task at hand and they would do anything to get rid of them. The study seems to indicate that computer exposure, with lack of understanding has bred an atmosphere where users are unsurprised by dialogs and GUIs, and care little for their contents.
While the study's authors suggested education of students to warn them of these kind of dangers, the apathy of the students towards the dialogs seems to bring the fruits of such education into question.
The study is appearing soon in the journal
Proceedings of the Human Factors and Ergonomics Society.
This article is over a month old, voting and posting comments is disabled
RE: Not surprised
9/24/2008 10:38:48 AM
Who would be surprised? We are all people who use the computer a lot. Most people use computers for just web browsing and instant message. You can tell how much people know about computers when they buy one. People now a day spend 2000 dollars on a laptop sometimes when all they do is web browse. Then there are others who buy an XPS because they THINK it's a gaming laptop (when dell hasn't even upgraded to Centrino 2 yet).
Computers are confusing to most people and I don't think any amount of training will help them. They have to be generally interested in computers and most just want to keep in touch with their friends. This is why the IT industry is flourishing and also why people in the IT industry usually don't have much trouble with their jobs. All they have to do is remind people to turn on their computers or to plug it in(the most frequent problems according to my IT friend in the Navy). Ya it's a problem that they become part of a bot network but there isn't much we can do to stop people from not caring.
RE: Not surprised
9/24/2008 12:23:16 PM
when dell hasn't even upgraded to Centrino 2 yet
Centrino 2 is a platform. You don't need to comply to Centrino 2 standards to make a gaming laptop.
An XPS M1730 with a C2D Extreme and 8800M GTX SLI is a extremely capable gaming laptop. Many gamer's desktops couldn't even match it in performance. It's not Centrino 2, cause it uses an Nvidia chipset.
If I wanted a gaming laptop, I'd probably go with a Dell over HP/Compaq, Gateway, or the other high priced alternatives.
"What would I do? I'd shut it down and give the money back to the shareholders." -- Michael Dell, after being asked what to do with Apple Computer in 1997
Hackers Inject Trojans Into Computers with Airline Ticket Scam
September 22, 2008, 10:11 AM
CNN.com Repels Hacker Attack After Coverage On Tibet
April 21, 2008, 9:55 AM
Man Finds He Is On "Most Wanted" List in California from Google Search
March 17, 2014, 9:50 AM
Facebook CEO Called President Barack Obama to Complain About NSA Spying
March 14, 2014, 1:40 PM
Quick Note: Google Drive 100GB, 1TB Plans See Major Price Cuts
March 13, 2014, 2:45 PM
Target Missed Early Warning Signs of Holiday Data Breach
March 13, 2014, 1:45 PM
Amazon Increases Prime Subscription to $99/year Starting March 19
March 13, 2014, 8:23 AM
Bitcoin King's American Accounts Get Frozen
March 13, 2014, 3:00 AM
Most Popular Articles
Malaysian Airlines Flight 370 Made Wild Altitude Changes
March 14, 2014, 9:21 PM
Tesla Motors Calls New Jersey Out on New Rule Against Its Direct Sales Model
March 11, 2014, 12:01 PM
Hack Reveals Fallen Bitcoin CEO's Posh Tokyo Penthouse
March 10, 2014, 4:28 PM
Apple Authorized to Seek $40 Per Device Against Samsung
March 13, 2014, 4:31 PM
Man Who Shot Father for Texting During Movie Previews Was Also Texting
March 14, 2014, 2:25 PM
Latest Blog Posts
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
Is The Period Becoming an Expression of Anger?
Nov 26, 2013, 2:02 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information