Too many security warnings desensitize people to real ones
Aliases: warning fatigue · alert habituation · security interstitial
What it is
If every step on the pay path pops “confirm it is you,” “beware fraud,” “scanning a secure environment,” people encode them as interstitial. Desensitization means that when a real risk warning appears (amount changed, domain wrong, a second transfer), the tap habit is already “Next.” This is dose and grading of copy, not how lock icons are drawn, and not whether large amounts step up—step-up is an action; this is speech.
Why it happens
Attention habituates to repeated, low-consequence alarms—the same family as alarm fatigue: noise floor rises, signal must be stronger to pass. Boilerplate on the pay path satisfies a legal checklist and trains people to skip every sentence with a shield. A real warning in the same visual template is skipped with them. Grading also fails when small amounts get a full-screen interrupt and large amounts get a grey footnote—the intensity runs opposite the loss.
Studying it
Vary boilerplate frequency on one pay path, then insert a true amount-changed or domain warning. Watch whether people tap through the real one.
Independent variables: notices per payment, whether the real warning shares the template, whether intensity scales with amount. Dependent variables: dwell and read-aloud on the real warning, tap-through rate, later restating the warning.
Labs that say “please read carefully” inflate reading. Closer: bury the warning in a task they think is ordinary pay. “We warned them, so we are covered” is not a measure.
Where it stops holding
Mandated risk copy cannot be deleted, but it can merge into one confirm instead of repeating every screen. New-device first use can be denser; familiar devices should drop to quiet fast. Assistive speech will read every notice; excess blocks input, so dose is harsher for screen readers.
Applying it
- Collapse boilerplate into one expandable “security notes”; keep on the default path only warnings about this capture.
- Amount changed, payee changed, domain or app-signature anomaly use a different template and a blocking confirm.
- The same boilerplate appears at most once per session.
- Verify by running three ordinary small pays, then a confirm whose amount was altered: do they read the new amount. If every step of the three was “Got it” and the fourth is too, the dose is too high.
Related
- Within the group: H7.11.1 Payment pages need recognizable security cues · H7.11.2 Sensitive payment entry needs anti-shoulder-surf and anti-screenshot · H7.11.3 Large or anomalous payments need step-up identity checks
- Adjacent: H5.08 Alarm fatigue · O4.01 Trust signals · H7.03 Price transparency
- Search terms:
warning fatigue·alert habituation·security interstitial