<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Nudging Users Towards Privacy on Mobile Devices</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Rebecca Balebako</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pedro G. Leon</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hazim Almuhimedi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Patrick Gage Kelley</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jonathan Mugan</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alessandro Acquisti</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Lorrie Faith Cranor</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Norman Sadeh</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Author Keywords Nudge</institution>
          ,
          <addr-line>Privacy, Security, Location Sharing, Mobile Devices, Soft Paternalism</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Carnegie Mellon University 5000</institution>
          <addr-line>Forbes Ave. Pittsburgh, PA 15213</addr-line>
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>By allowing individuals to be permanently connected to the Internet, mobile devices ease the way information can be accessed and shared online, but also raise novel privacy challenges for end users. Recent behavioral research on “soft” or “asymmetric” paternalism has begun exploring ways of helping people make better decisions in different aspects of their lives. We apply that research to privacy decision making, investigating how soft paternalistic solutions (also known as nudges) may be used to counter cognitive biases and ameliorate privacy-sensitive behavior. We present the theoretical background of our research, and highlight current industry solutions and research endeavors that could be classified as nudging interventions. We then describe our ongoing work on embedding soft paternalistic mechanisms in location sharing technologies and Twitter privacy agents.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION
As mobile devices and applications become pervasive,
privacy risks to their users also grow. The accessibility and
ease of use of these devices make it easy to casually
broadcast personal information at any time, from anywhere, to
friends and strangers. Without a doubt, users benefit from
and enjoy such streams of information sharing. However,
they also expose themselves to tangible and intangible risks:
from tracking by commercial entities interested in
exploiting personal information for profit, to surveillance or even
stalking by malicious parties. However, it is difficult for
individuals to determine the optimal balance between
revealing and hiding personal data. Sometimes we are not even
aware that information about us is being broadcast, shared,
Copyright ⃝c 2011 for the individual papers by the papers’ authors.
Copying permitted only for private and academic purposes. This volume is
published and copyrighted by the editors of PINC2011.
or monitored; other times, while aware of ongoing
information flows, we do not understand their consequences, or
properly assess their risks. Such challenges are magnified
in mobile scenarios. Therefore, a mobile device user may
end up sharing information in a manner that goes against her
own long-term self interests.</p>
      <p>
        In recent years, there has been growing interest in using
lessons from behavioral economics to influence and
ameliorate decision making in situations where cognitive and
behavioral biases may adversely affect the individual [
        <xref ref-type="bibr" rid="ref11 ref16">11,
16</xref>
        ]. This approach is often referred to as soft or asymmetric
paternalism, or with the more popular term “nudges.” Soft
paternalism aims at countering and overcoming those biases,
so as to assist individual decision making. Our research aims
at applying and extending lessons from the nascent field of
soft paternalism to the field of privacy decision making. This
paper presents an overview of our research agenda in this
area. First, we introduce the research exploring cognitive
and behavioral biases in privacy decision making. Then, we
examine current academic studies and industry products that
focus on influencing privacy (and security) decision making,
and that therefore may be compared to nudging
interventions. Finally, we discuss how we are integrating soft
paternalistic mechanisms in our research on privacy in location
sharing applications and social networks.
      </p>
      <p>
        FROM HURDLES IN PRIVACY DECISION MAKING
TO SOFT PATERNALISM
Findings from behavioral economics and behavioral
decision research have highlighted hurdles in human decision
making that lead, sometimes, to undesirable outcomes. The
hurdles are often due to lack of information or insight,
cognitive limitations and biases, or lack of self-control [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
Because of those hurdles, individuals may end up making
decisions that they later regret. Those decisions may include
(not) saving for retirement, (not) eating well, or smoking
cigarettes [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. They may also include decisions about
protecting too much, or not enough, personal information [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
Privacy decisions are complex and often taken in conditions
of information asymmetry (that is, individuals may not have
full knowledge of how much of their personal information is
being gathered, and how it is being used). Furthermore,
privacy decision making may be overwhelming: the cognitive
costs associated with considering all the ramifications of a
disclosure may hamper decision making [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Finally,
cognitive biases may affect one’s propensity to reveal personal
information: for instance, heightened control of one’s
personal information may, paradoxically, make the user
overconfident about sharing information [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        Paternalistic policies try to solve decision-making hurdles
by mandating decisions for individuals. Such policies are
often heavy-handed and generate externalities [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Soft
paternalism, on the other hand, avoids coercion; it seeks to steer
users in a direction (believed to be more desirable based on
the user’s own prior judgement, or on external empirical
validation), without impinging on her autonomy. A soft
paternalistic solution, for instance, would consist of making an
individual aware of the biases, lack of information, or
cognitive overload that may affect her decision.
      </p>
      <p>
        Nudges are tools of soft-paternalism, and may be used to
ameliorate privacy (as well as security) decision making [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
Their application to scenarios involving mobile devices is
particularly appealing. In the case of insecure
communication channels, or covert data collection through a mobile
device, a nudge may take the form of an alert that informs the
user of the risk. In the case of mobile devices that store
sensitive information (which could be accessed by strangers if
the phone was misplaced), a nudge might discourage users
from storing private data on mobile phones. When
information is being disclosed through a smart-phone, nudges may
provide alerts about the recipients, contexts, or type of data
being shared.
      </p>
      <p>
        Many different types of nudging interventions are possible.
Some simply consist of informing the user — in which case
they relate to privacy research on informed consent. Some
focus on making systems simpler to use — in which case,
privacy nudges fall into the realm of research on privacy
usability. However, other nudges aim at countering
specific cognitive and behavioral biases, such as neutralizing
the detrimental effects of immediate gratification biases in
privacy decision making [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] by altering the individual’s
perception of the sequence of costs and benefits associated with
revealing sensitive information.
      </p>
      <p>The literature on soft paternalism applied to privacy
decision making is in its infancy, and therefore extremely scarce.
However, a number of recent studies and products focus on
mechanisms that may be categorized as nudges. We present
a brief overview of them in the following sections.
PRIVACY NUDGES IN THE LITERATURE
Previous research on the drivers of privacy concerns has
demonstrated that users’ attitudes towards security and privacy are
influenced by numerous factors, including information
available, personal beliefs, economic valuations, moral
reasoning, social values, cognitive biases, and so on. Therefore,
providing adequate information, making privacy tools more
evident, or rewarding and punishing users as they make safer
or riskier decisions are all ways of nudging or influencing
privacy behavior. The privacy literature offers some
examples of these approaches.</p>
      <p>
        For example, recent experimental research has shown that
users are interested in protecting their privacy and may even
pay for it, if appropriate tools and salient, simple, and
compact privacy information are offered. Specifically, one series
of studies explored the impact of making information about
privacy practices on web sites more accessible to buyers.
The results showed that online customers are more likely to
shop online from websites that exhibit more protective
privacy policies. Additionally, those customers are willing to
pay a premium for privacy. Furthermore, privacy indicators
displayed at the moment an individual is shopping online
may have an impact on consumer decisions. In particular,
they increase the willingness to pay for privacy; however,
if the indicator is provided only after the shopper has
already chosen the website from which to buy, the user will
not change their already-made decisions. The authors find
that timing is essential when trying to help people to protect
their privacy [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Similarly, another study found that
merely priming Facebook users with questions about their
online disclosure behavior and the visibility of their
Facebook profiles was sufficient to trigger changes in their
disclosure behavior [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Application interface design is also
important, and should help users notice when changes in
context generate changes in information flows and then help
them to maintain their privacy [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        In the context of location sharing applications, providing
feedback to users whose location has been requested by
others has been shown to have both positive and negative
implications [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. It can prevent excessive requests and hence
protect people’s privacy. However, unless appropriate
notifications are used, feedback receivers could also be annoyed.
In addition, notifications may inhibit users from requesting
others locations and hence affect system usage.
      </p>
      <p>PRIVACY NUDGES IN INDUSTRY
Examples of industry products or solutions that influence
decision making in regards to privacy (either to better protect
the user, or instead to influence her to reveal more
information) take various forms, and some have been applied to
mobile devices. Some of these solutions may be interpreted as
soft paternalistic for privacy protection, in the sense that they
nudge towards privacy. They include privacy/security
usability solutions, simplifications of privacy settings, or tests
and delays before one can post information. More frequent,
however, are the examples of products and solutions that
nudge individuals to give up even more of their privacy,
surrendering sensitive information. These include privacy
defaults that are open, lack of usability in privacy settings
interfaces, poorly designed warnings, and other rewards for
sharing data or encouraging friends to share data.</p>
      <p>Connections in social applications
Some applications provide information about who can see
your data, who has seen your data, or how many people can
see your data. For instance, Flickr.com, a video and image
sharing website, provides information on each user-owned
picture stating who can see it, followed by a link to edit the
privacy settings for that picture. This may be a nudge
towards privacy, as users may decide to share certain photos
with friends, and share other photos with everyone.
Social networking sites often show the number of
connections a user has. These connections may be called
followers, friends, or ties. In some cases, connections can have
access to all the user’s information that is on the
application. Twitter and Google Buzz are examples of sites that
prominently show the number of connections. In the case of
LinkedIn.com, a job searching social network, the user may
prefer to add additional connections, even with people they
don’t know well, in order to grow their job-searching
network. However, by opening their information to more
connections, they may be compromising their privacy. These
applications may nudge users towards increasing their
connections and revealing more information. Indeed, several online
social networks such as Facebook.com and LinkedIn.com
periodically encourage users to add new connections by
searching the user’s email accounts for email contacts.</p>
      <p>Connections such as friends in Facebook and followers in
Twitter do not set the boundaries for information flow. One’s
connections may be able to share information with other
unintended recipients, or even make it available to the
public. In Twitter, for example, re-tweets allow connections to
pass on information without the original sender’s control. In
Facebook, default privacy settings usually allow sharing of
individual’s information with friends of friends. Therefore,
the information provided about the number of connections
may mislead the user about the privacy of their data and
decrease the likelihood that the user will take an
informationprotective stance.</p>
      <p>
        Privacy Settings
The privacy settings allowed in an application impact the
user’s ability to control how their information is shared. Both
the default settings and the usability of the settings user
interface create nudges towards and away from privacy [
        <xref ref-type="bibr" rid="ref10 ref12 ref13">10,
12, 13</xref>
        ].
      </p>
      <p>Some websites make privacy options very simple. For
example, Pandora.com, an online music station, explicitly gives
users two options regarding their profile page: make
private or keep public. These clear options allow a user to
choose without understanding complex details or settings.
Conversely, the lack of granularity may encourage users to
make everything public.</p>
      <p>Several tools provide simple ratings of privacy settings.
PrivacyCheck,1 and ProfileWatch,2 give Facebook settings a
privacy score. Other services provide a user-friendly layer
on the Facebook privacy settings, allowing the user to change
the settings. For example, Privacy Defender3 provides a
sliding color scale that allows the user to set their Facebook
options as more or less private. These software services
actively encourage stricter privacy settings.</p>
      <p>Reduction of Information Disclosure
If an individual expects she may be likely to post information
she may later regret, software exists to discourage her from
1 http://rabidgremlin.com/fbprivacy
2 http://atherionsecurity.com/idpro.html
3 http://privacydefender.net
doing so. Sophisticated users may choose to employ
software tools to prevent excess disclosure. For example, the
Social Media Sobriety Test, socialmediasobrietytest.
com, and Mail Goggles on Gmail googlelabs.com both
allow the user to set certain hours of the week when they may
typically embarrass themselves, such as weekend evenings
after trips to the bar. During these hours, social network
sites or Gmail may be blocked until the user can complete a
dexterity or cognitive test. The user has the option to bypass
the test. Alternatively, a user may set up a warning system
if a message is likely to be poorly interpreted. ToneCheck
tonecheck.com scans emails written in Outlook to
discover whether the tone is off-putting, and will ask the user to
confirm before sending it. This may help discourage users
from sending or posting regrettable information.</p>
      <p>Other tools may discourage users from posting information
by reminding the user who can see it. NetNanny is a tool
that parents can user to protect their children online. It will
show a message every time a child posts on a social network.
This message reminds the child that her parents will see the
post as well netnanny.com.</p>
      <p>
        ONGOING WORK WITH MOBILE APPLICATIONS
By studying and understanding the specific biases and user
actions in regards to mobile applications, we hope to
suggest and test nudges that will help users make decisions that
improve their satisfaction and well being. We are moving
towards that goal by first understanding users’ needs,
preferences, biases, and limitations about privacy, and second by
using that information to evaluate the efficacy of techniques
that exploit biases to improve decision making. As an
example, we are currently pursuing foundational studies with two
applications developed at Carnegie Mellon: a location
sharing application called Locaccino [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] and a privacy agent for
Twitter.
      </p>
      <p>
        Locaccino is a unique location sharing application that
allows users to control the conditions under which they make
their location visible to others. This includes controlling the
times and days of the week when different groups of people
can see the user’s location as well as the specific locations
where the user is willing to be visible. For instance, a user
can specify rules such as “I’m willing to let my colleagues
see my location but only when I am on company premises
and only 9am-5pm on weekdays.” Research conducted by
our group has shown that this level of expressiveness is
critical to capturing the location sharing preferences many
people have when it comes to disclosing their locations to
others across a broad range of scenarios [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]—in contrast to the
much narrower set of scenarios supported by location
sharing applications such as Foursquare.
      </p>
      <p>
        As part of our ongoing research, we are interested in
better understanding how different elements of Locaccino
functionality effectively nudge people in different directions. This
includes experimenting with new interface designs as well
as new ways of leveraging some of the machine learning
techniques we have been developing, from exposing
different sets of default privacy personas to users [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] to helping
them refine their privacy preferences [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. We are looking at
the preferences of like-minded users who have been using
the system for a while and trying to use their preferences to
guide new users. This would have the potential of reducing
regret by giving new users the benefit of the experience
acquired over time by others. We plan to explore to what extent
such an approach can be made to work and to what extent it
seems beneficial.
      </p>
      <p>The Twitter privacy agent is an application we are building
to help Twitter users behave in a more privacy protective
way. We plan to build tools that will provide nudges that
guide users to restrict their tweets to smaller groups of
followers or discourage them from sending tweets from mobile
devices that they may later regret. We plan to empirically
test the impact of these nudges on user behavior. We will
also examine whether fine-grained privacy controls result in
more or less data sharing.</p>
      <p>We expect our work on nudges in behavioral advertising,
social networks, and location sharing to be effective for
improving privacy decisions on mobile devices. We further
hope our soft-paternalistic approach to have a broader
impact, guiding the development of tools and methods that
assist users in privacy and security decision making.</p>
      <p>ACKNOWLEDGMENTS
This material is based upon work supported by the National
Science Foundation under Grant CNS-1012763 (Nudging
Users Towards Privacy), and by Google under a Focused
Research Award on Privacy Nudges. This work has also been
supported by NSF grants CNS-0627513, CNS-0905562, and
by CyLab at Carnegie Mellon under grants
DAAD19-02-10389 and W911NF-09-1-0273 from the Army Research
Office. Additional support has been provided by the IWT SBO
project on Security and Privacy in Online Social Networks
(SPION), Nokia, France Telecom, and the CMU/Portugal
Information and Communication Technologies Institute.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          .
          <article-title>Privacy in electronic commerce and the economics of immediate gratification</article-title>
          .
          <source>In Proceedings of the ACM Conference on Electronic Commerce (EC '04)</source>
          , pages
          <fpage>21</fpage>
          -
          <lpage>29</lpage>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          .
          <article-title>Nudging privacy: The behavioral economics of personal information</article-title>
          .
          <source>Security &amp; Privacy</source>
          , IEEE,
          <volume>7</volume>
          (
          <issue>6</issue>
          ):
          <fpage>82</fpage>
          -
          <lpage>85</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Grossklags</surname>
          </string-name>
          .
          <article-title>Privacy and rationality in individual decision making</article-title>
          .
          <source>Security &amp; Privacy</source>
          , IEEE,
          <volume>3</volume>
          (
          <issue>1</issue>
          ):
          <fpage>26</fpage>
          -
          <lpage>33</lpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>M.</given-names>
            <surname>Benisch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Sadeh</surname>
          </string-name>
          , and
          <string-name>
            <given-names>L.</given-names>
            <surname>Cranor</surname>
          </string-name>
          . Capturing
          <string-name>
            <surname>Location-Privacy</surname>
            <given-names>Preferences</given-names>
          </string-name>
          :
          <article-title>Quantifying Accuracy and User-Burden Tradeoffs</article-title>
          .
          <source>Journal of Personal and Ubiquitous Computing</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>L.</given-names>
            <surname>Brandimarte</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Loewenstein. Misplaced Confidences</surname>
          </string-name>
          :
          <article-title>Privacy and the Control Paradox</article-title>
          .
          <source>Technical report, Mimeo</source>
          , Carnegie Mellon University,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>S.</given-names>
            <surname>Egelman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Tsai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          .
          <article-title>Timing is everything?: the effects of timing and placement of online privacy indicators</article-title>
          .
          <source>In Proceedings of the 27th international conference on Human factors in computing systems, CHI '09</source>
          , pages
          <fpage>319</fpage>
          -
          <lpage>328</lpage>
          , New York, NY, USA,
          <year>2009</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>G.</given-names>
            <surname>Hull</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. R.</given-names>
            <surname>Lipford</surname>
          </string-name>
          , and
          <string-name>
            <given-names>C.</given-names>
            <surname>Latulipe</surname>
          </string-name>
          .
          <article-title>Contextual gaps: Privacy issues on facebook</article-title>
          .
          <source>Ethics and Information Technology</source>
          , pages
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>L.</given-names>
            <surname>Jedrzejczyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B. A.</given-names>
            <surname>Price</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. K.</given-names>
            <surname>Bandara</surname>
          </string-name>
          , and
          <string-name>
            <given-names>B.</given-names>
            <surname>Nuseibeh</surname>
          </string-name>
          .
          <article-title>On the impact of real-time feedback on users' behaviour in mobile location-sharing applications</article-title>
          .
          <source>In Proceedings of the Sixth Symposium on Usable Privacy and Security</source>
          ,
          <source>SOUPS '10</source>
          , pages
          <fpage>14</fpage>
          :
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          , New York, NY, USA,
          <year>2010</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>P.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Hankes Drielsma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Sadeh</surname>
          </string-name>
          , and
          <string-name>
            <surname>L. Cranor.</surname>
          </string-name>
          <article-title>User-controllable learning of security and privacy policies</article-title>
          .
          <source>In Proceedings of the 1st ACM workshop on Workshop on AISec</source>
          , pages
          <fpage>11</fpage>
          -
          <lpage>18</lpage>
          . ACM,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Y.-L. Lai</surname>
            and
            <given-names>K. L.</given-names>
          </string-name>
          <string-name>
            <surname>Hui</surname>
          </string-name>
          .
          <article-title>Internet opt-in and opt-out: investigating the roles of frames, defaults and privacy concerns</article-title>
          .
          <source>In Proceedings of the 2006 ACM SIGMIS CPR conference on computer personnel research</source>
          , pages
          <fpage>253</fpage>
          -
          <lpage>263</lpage>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <given-names>G. F.</given-names>
            <surname>Loewenstein</surname>
          </string-name>
          and
          <string-name>
            <given-names>E. C.</given-names>
            <surname>Haisley</surname>
          </string-name>
          .
          <article-title>The Foundations of Positive and Normative Economics, chapter 9: The Economist as Therapist: Methodological Ramifications of 'Light' Paternalism</article-title>
          . Oxford University Press,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <given-names>W.</given-names>
            <surname>Mackay</surname>
          </string-name>
          .
          <article-title>Triggers and barriers to customizing software</article-title>
          .
          <source>In Proceedings of the SIGCHI conference on Human factors in computing systems: Reaching through technology</source>
          , pages
          <fpage>153</fpage>
          -
          <lpage>160</lpage>
          . ACM,
          <year>1991</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <given-names>Ralph</given-names>
            <surname>Gross</surname>
          </string-name>
          and
          <string-name>
            <given-names>Alessandro</given-names>
            <surname>Acquisti</surname>
          </string-name>
          .
          <article-title>Information Revelation and Privacy in Online Social Networks</article-title>
          .
          <source>In Workshop on Privacy in the Electronic Society (WPES)</source>
          , pages
          <fpage>71</fpage>
          -
          <lpage>80</lpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <given-names>R.</given-names>
            <surname>Ravichandran</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Benisch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kelley</surname>
          </string-name>
          , and
          <string-name>
            <given-names>N.</given-names>
            <surname>Sadeh</surname>
          </string-name>
          .
          <article-title>Capturing social networking privacy preferences: can default policies help alleviate tradeoffs between expressiveness and user burden</article-title>
          ?
          <source>In Proceedings of the 5th Symposium on Usable Privacy and Security, page 1. ACM</source>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>N.</given-names>
            <surname>Sadeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Hong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Fette</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Prabaker</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Rao</surname>
          </string-name>
          .
          <article-title>Understanding and capturing peoples privacy policies in a mobile social networking application</article-title>
          .
          <source>Personal and Ubiquitous Computing</source>
          ,
          <volume>13</volume>
          (
          <issue>6</issue>
          ):
          <fpage>401</fpage>
          -
          <lpage>412</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <given-names>R.</given-names>
            <surname>Thaler</surname>
          </string-name>
          and
          <string-name>
            <given-names>C.</given-names>
            <surname>Sunstein</surname>
          </string-name>
          . Nudge:
          <article-title>Improving decisions about health, wealth, and happiness</article-title>
          .
          <source>Yale Univ Pr</source>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <given-names>J. Y.</given-names>
            <surname>Tsai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Egelman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Acquisti</surname>
          </string-name>
          .
          <article-title>The effect of online privacy information on purchasing behavior: An experimental study</article-title>
          .
          <source>Information Systems Research</source>
          , In press,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>