To Self-persuade or Be Persuaded: Examining Interventions for Users' Privacy Setting Selection
Authors
Title of the Paper
To Self-Persuade or be Persuaded: Examining Interventions for Users’ Privacy Setting Selection
Paper Information
- Subject Area: User privacy setting selection, social influence, and self-persuasion
- Keywords: Social network security, social influence, authority, reflective writing, privacy behavior, decision-making, individual differences, quantitative methods, qualitative methods
Research Background and Questions
- Research Question: Despite the continuous promotion of security and privacy (S&P) best practices, user adoption remains low. Existing studies suggest that social influence is an effective method for behavior modification, but prior research has mainly focused on social influence among acquaintances, neglecting broader non-personal social influence options.
- Significance: The increasing number of data breaches and the strong demand for online privacy protection make it crucial to study effective privacy intervention methods.
- Motivation and Related Work: This research is grounded in theories of bounded rationality and cognitive biases from behavioral economics, analyzing why users struggle to adhere to privacy best practices. Previous studies have focused on the effects of individual differences, social connections, and device interface design on privacy behavior. This study explores two novel intervention methods—non-personal social influence (e.g., recommendations from the public or experts) and reflective writing—and examines their effectiveness and interactive effects.
Proposed Solution
- Proposed Methods:
- Non-Personal Social Influence: Providing privacy setting recommendations through public or expert endorsements.
- Reflective Writing: Encouraging users to engage in reflective writing before configuring privacy settings, helping them make more autonomous decisions.
- Innovations:
- Combining non-personal social influence with reflective writing for privacy setting selection.
- Expanding social influence research by shifting the target group from acquaintances to the public and experts.
- Leveraging writing activities to stimulate user self-reflection, reducing mechanical compliance with external recommendations.
- Implementation Steps:
- Selecting Facebook as the experimental platform (widely used and featuring complex privacy settings).
- Conducting a questionnaire-based experiment to investigate user choices for 14 S&P settings, using a 2 (reflective writing) × 4 (social influence recommendation sources) mixed experimental design.
- Comparing the effects of four influence sources (expert recommendations, public recommendations, Facebook default settings, no recommendations) and reflective writing on users’ privacy configuration decisions.
Research Findings
- Specific Findings:
- In the experiment, non-personal social influence recommendations from experts and the public significantly increased the likelihood of users adopting privacy best practices.
- Reflective writing weakened the effect of social influence recommendations but encouraged users to choose safer privacy configurations (e.g., safer than Facebook’s default recommendations).
- Advantages and Contributions:
- Practical Feasibility: Non-personal social influence recommendations represent a scalable and cost-effective intervention method, providing users with safer configuration suggestions.
- Potential of Reflective Writing: Reflective writing not only improved privacy behavior but also showed potential to resist manipulative designs (e.g., dark patterns) influencing users’ privacy choices.
- Analysis of Individual Differences: The study identified the influence of users’ collective identity and Facebook usage habits on their acceptance of recommendations, offering insights for future personalized privacy intervention designs.
- Experimental Results:
- Users were more likely to accept public and expert recommendations (non-personal social influence) over Facebook default settings.
- Privacy settings chosen after reflective writing demonstrated higher levels of privacy protection, even when inconsistent with social recommendations.
- Under experimental conditions involving reflective writing, users were more likely to select settings aligned with expert recommendations.
- Limitations and Future Directions:
- Limitations: Sample bias (skewed toward younger and male users), lack of testing for intervention effects in real-life scenarios, and insufficient comparison between personal and non-personal social influence.
- Future Directions:
- Explore more effective combinations of reflective writing and other intervention methods.
- Test the methods across different platforms and international user groups.
- Investigate the potential of reflective writing to resist negative designs (e.g., dark patterns).
Summary and Recommendations
This study demonstrates that non-personal social recommendations from experts and the public, as well as reflective writing, are effective methods for improving users’ privacy setting choices. Future research could further explore how to optimize the application of these two intervention methods and validate their applicability across broader user groups.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- Why do users struggle to adopt security and privacy best-practice settings?Category: Security and Privacy Risk Factors and Impact AssessmentSimilar questionsarrow_forward
- Can impersonal social influence (e.g., expert advice or public recommendations) effectively change users' privacy behaviors?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- How does reflective writing affect users' choices in privacy settings?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
Practical Problems
1- Users struggle to correctly configure complex online privacy settings and face data breach risks.Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- 100%
Machine Heuristic: When We Trust Computers More than Humans with Our Personal Information
CHI '19· Privacy by Design & User Control +1
- 80%
“We Are the Product”: Public Reactions to Online Data Sharing and Privacy Controversies in the Media
CHI '18· AI Ethics, Fairness & Accountability +2
- 80%
Visual Interactive Privacy Policy: The Better Choice?
CHI '21· Uncertainty Visualization +2
- 75%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 75%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 75%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
- 75%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 75%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 75%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 75%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)