Websites Need Your Permission Too -- User Sentiment and Decision-Making on Web Permission Prompts in Desktop Chrome
Authors
Privacy by Design & User ControlPrivacy Perception & Decision-MakingDark Patterns RecognitionCybersecurity EngineersPrivacy Policy Makers
Title of the Paper
Websites Need Your Permission Too – User Sentiment and Decision-Making on Web Permission Prompts in Desktop Chrome
Paper Information
- Domain: User privacy, interaction design for permission systems
- Keywords: Web permission prompts, desktop browsers, user behavior, user perception, Chrome, interaction design, security, privacy, usability, experimental research
Research Background and Issues
- Identified Problems and Challenges:
- User behavior and decision-making regarding web permission prompts have not been sufficiently studied, particularly in desktop browsers where permission prompts differ significantly from mobile systems.
- Standardizing the user experience for permission requests is challenging: web developers can display permission prompts freely without mandatory review mechanisms.
- Permission prompts can easily cause user annoyance, especially when users lack a clear intention to use the requested functionality.
- There is a lack of analysis on user motivations for ignoring or dismissing permission prompts.
- Importance:
- Permission management directly impacts user privacy and security decisions, forming an essential part of the digital experience.
- User satisfaction and trust in permission prompts are linked to whether users can safely and smoothly utilize web functionalities, ultimately influencing the overall browsing experience.
- Exploring ways to improve the usability of permission prompts and reduce user frustration contributes to designing safer and more practical permission management systems.
- Research Motivation and Related Work:
- Extending existing research on mobile permission systems (e.g., Android permissions) to web-based permission prompts.
- Incorporating quantitative analysis of user behavior data (e.g., ignoring, denying, or approving permissions) to complement existing qualitative research findings.
- Investigating the relationship between user decision-making, contextual information, and the usability of prompts.
Solution
- Proposed Research Methods:
- Quantitative Data Analysis: Collecting 28 days of telemetry data from 102M desktop Chrome installations to understand user interactions and behaviors regarding permission prompts.
- Experience Sampling Surveys: Gathering real-time survey responses from 25,706 Chrome users to evaluate user perceptions, motivations, and decision-making factors regarding permission prompts.
- Problem Breakdown and Research Objectives:
- Do web permission prompts disturb users?
- Do users find permission prompts easy to decide on?
- What are the reasons behind user decisions?
- How much contextual information do users perceive before encountering permission prompts?
- Does user perception influence behavior and their perceived utility of permissions?
- How do user interactions prior to encountering permission prompts affect decision-making?
- Innovative Aspects:
- Combining large-scale telemetry data with experience sampling surveys for the first time to systematically analyze user behavior and perception of web permission prompts on desktop platforms.
- Emphasizing detailed analysis of user behaviors (allow, deny, ignore, dismiss) and comparing different types of permissions (notifications, geolocation, microphone, camera).
- Linking the richness of contextual information to user decision outcomes and perceptions, exploring ways to optimize permission prompt UI design.
Research Findings
- Specific Results:
- Ignoring and dismissing are the most common ways users handle permission prompts, accounting for 42.7% and 33.9% of the telemetry data, respectively.
- Survey responses indicate that permission prompts, particularly for notifications and geolocation, are prone to causing user annoyance.
- Users are more likely to approve permission requests when they clearly perceive the functionality or developer as trustworthy (73.1% of approvers cited reasonable reasons).
- Lack of contextual information significantly impacts user decisions; prompts that do not align with user expectations are more likely to be denied (approval rate before interaction was only 9%).
- Lightweight design of permission prompts (non-modal prompts) encourages users to ignore rather than outright deny, but 30.4% of users reported not noticing the prompt.
- User interactions prior to encountering permission prompts significantly influence approval rates, especially for geolocation requests, which saw a threefold increase in approval rate (9% vs. 27%).
- Advantages Compared to Existing Solutions:
- Provides the first comprehensive quantitative study of desktop browser permission systems, complementing prior research focused primarily on mobile platforms.
- Introduces analysis of user motivations after ignoring or dismissing prompts, highlighting the positive impact of non-direct denial options on user experience.
- Experimental and Evaluation Results:
- Analysis shows that users require more contextual information before making approval decisions; effective contextual design significantly enhances user perception and reduces annoyance.
- Developer practices regarding permission prompts have a notable impact on user behavior (e.g., triggering prompts before interaction significantly affects approval rates).
- Limitations and Future Directions:
- Limitations:
- Sample data is limited to Chrome users and may not be directly applicable to other desktop browsers.
- Data is sourced from users who did not opt out of telemetry data collection, potentially limiting representativeness.
- Survey content was constrained and did not fully cover all possible user motivations.
- Future Directions:
- Extend research to mobile platforms and other browsers to compare permission prompt designs across different environments.
- Further explore the impact of contextual information design on user decision-making in permission requests.
- Propose improvements to the visual prominence of ignored permission prompts while avoiding increased user disturbance.
- Limitations:
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- Do permission prompts on web pages disrupt users?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- Do users find permission prompts easy to decide on?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- What reasons drive users' decisions about permission prompts?Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
lightbulb
Practical Problems
1- Users often ignore or resent permission prompts on web pages, degrading browsing experience.Category: Cookie, Permission, and Consent ControlsSimilar questionsarrow_forward
- 80%
A Field Study of Computer-Security Perceptions Using Anti-Virus Customer-Support Chats
CHI '19· Privacy by Design & User Control +1
- 80%
Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?
CHI '25· Privacy by Design & User Control +1
- 80%
A Visual Exploration of Cybersecurity Concepts
C&C '22· Privacy by Design & User Control +1
- 67%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 67%
What is this URL's Destination? Empirical Evaluation of Users' URL Reading
CHI '20· Privacy by Design & User Control +2
- 67%
The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
CHI '25· Privacy by Design & User Control +2
- 60%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 60%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 60%
It's So Difficult to Sever that Connection: The Role of FoMO in Users' Reluctant Privacy Behaviours
CHI '21· Privacy by Design & User Control +2
- 60%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642252
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
1 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Dark Patterns Recognition
work
Professions
Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers