The Neurosecurity Lab at 11,752 Feet

As an end-of-summer activity, members of the Neurosecurity Lab hiked Utah Valley’s Mount Timpanogos, a 11,752-foot (3,582 m) peak in the Wasatch Mountain range.

It was a beautiful day, despite some smoke from forest fires in Idaho that had been blown to the south.

Below are photos from our trip.

A mountain goat:

Presentation at Google

Yesterday Bonnie and Tony visited Google in Mountain View to present our research to Adrienne Porter Felt and members of the Android and Chrome security teams. We had very productive discussions with all about potential applications of our neurosecurity work.

Our lunch table was reserved with this sign, which itself seems like a warning:

Presentation at SOUPS 2015

Tony presented at the Symposium on Usable Privacy and Security (SOUPS) 2015 held July 22–24 in Ottawa, Canada. His presentation was entitled, “How to Conduct an fMRI Study to Examine Usable Privacy and Security.” You can watch a video of the presentation here:

Presentation Video

The presentation was well-received, and the attendees liked the 3D printout of Tony’s brain:

Presentation at Apple

Last week Bonnie and Tony gave an invited presentation to a group of information security professionals at Apple, Inc. in Silicon Valley. With increased emphasis in usable privacy and security in the field of information security, there is growing interest in using neuroscience to explain users’ security behaviors. We presented an overview of the research at the BYU Neurosecurity Lab, and received good feedback and questions from the attendees.

The building we met at had rooms named for characters from the Pixar movie, “The Incredibles,” as the above image from the entrance lobby shows.

Presentations at the Workshop on Security and Human Behavior (SHB) and Gmuden Retreat on NeuroIS 2015

Bonnie and Tony presented research at the Workshop on Security and Human Behavior (SHB) held at Georgetown University, June 8–9, 2015. Bruce Schneier calls the workshop “the most intellectually stimulating two days of my year”:

This is a small invitational gathering of people studying various aspects of the human side of security. The fifty people in the room include psychologists, computer security researchers, sociologists, behavioral economists, philosophers, political scientists, lawyers, biologists, anthropologists, business school professors, neuroscientists, and a smattering of others. It’s not just an interdisciplinary event; most of the people here are individually interdisciplinary.

Tony presented research on how warnings that interrupt us weaken our ability to respond to security messages through a cognitive phenomenon called “dual-task interference.” Ross Anderson summarized his presentation as follows:

Tony Vance is using fMRI to explore dual-task interference with security behaviour, and in particular security message disregard. People often have to complete two tasks at once, such as clearing email when interrupted by a security warnings, and pay less attention to the secondary task. How can performance change if tasks are tackled in a more rational order, for example? They tested volunteers in an fMRI machine and found they could use brain data to predict performance on a warning task. He concludes that security tasks which interrupt users make us less secure, as the interruption makes them harder to deal with; wherever possible, warnings should be dealt with later.

Bonnie presented on how technostress (stress experienced as a result of using technology) influences our ability to respond to warnings. Ross Anderson summarized her presentation this way:

Bonnie Anderson works in neurosecurity, including how technostress affects the response to security warnings. Subjects think they’re evaluating weather extensions in Chrome; in the treatment conditions, various security warnings are given, and the app asks for access to all your data. Saliva samples measure cortisol levels and subjects were also asked about stress. Curiously, the reports and measurements turned out to be in conflict for most subjects.

Gmunden Retreat on NeuroIS 2015

From June 1–3, Brock and Tony presented research on dual-task interference at the Gmunden Retreat on NeuroIS 2015, held every year in Gmuden, Austria. This is a gathering of researchers in the field of information systems (IS) who use theory and methods from neuroscience to study IS phenomenon. We received encouraging feedback from the participants, who you can see in a group photo here: