Do I feel lucky markets in everything?

Here is a new paper by Christin, Egelman, Vidas, and Grossklags, entitled “It’s All About the Benjamins”:


We examine the cost for an attacker to pay users to execute arbitrary code—potentially malware. We asked users at home to download and run an executable we wrote without being told what it did and without any way of knowing it was harmless. Each week, we increased the payment amount. Our goal was to examine whether users would ignore common security advice—not to run untrusted executables—if there was a direct incentive, and how much this incentive would need to be. We observed that for payments as low as $0.01, 22% of the people who viewed the task ultimately ran our executable. Once increased to $1.00, this proportion increased to 43%. We show that as the price increased, more and more users who understood the risks ultimately ran the code. We conclude that users are generally unopposed to running programs of unknown provenance, so long as their incentives exceed their inconvenience.


The article is here (pdf), for the pointer I thank Bruce Schnier.


 •  0 comments  •  flag
Share on Twitter
Published on June 19, 2014 23:06
No comments have been added yet.


Tyler Cowen's Blog

Tyler Cowen
Tyler Cowen isn't a Goodreads Author (yet), but they do have a blog, so here are some recent posts imported from their feed.
Follow Tyler Cowen's blog with rss.