Different domains of computing systems require higher level of focus towards specific quality factors like privacy, integrity, flexibility, usability etc. Moreover, certain quality factors help in each other’s existence while others oppose each other significantly. Usability of software applications is one factor that reduces security and privacy up to a substantial level. This paper examines the differences between usability factors and aspects related to security and privacy. A clear understanding of gaps between these two opposing factors has been presented in this paper. In addition, an account of efforts carried out to bridge these gaps has also been presented. We have divided these efforts into the categories of guidelines, frameworks and use of technology. The fields of e-banking and social networks have been considered specifically for identification of gaps in these particular fields.
KeywordsUsabilitySoftware Quality FactorsSecurityPrivacyOnline Social Networks (OSN)
McCall, J.A., Richards, P.K. and Walters, G.F. (1977) Factors in software quality. Volume I. Concepts and Definitions of Software Quality. General Electric Co., Sunnyvale, CA.
Fléchais, I. (2005) Designing Secure and Usable Systems. Dissertation, University College London.
Madejski, M., Johnson, M.L. and Bellovin, S.M. (2011) The Failure of Online Social Network Privacy Settings. https://mice.cs.columbia.edu/getTechreport.php?techreportID=1459
Zhang, C., et al. (2010) Privacy and Security for Online Social Networks: Challenges and Opportunities. IEEE Network, 24, 13-18. http://dx.doi.org/10.1109/MNET.2010.5510913
Abran, A., et al. (2003) Usability Meanings and Interpretations in ISO Standards. Software Quality Journal, 11, 325-338. http://dx.doi.org/10.1023/A:1025869312943
Quesenbery, W. (2001) What Does Usability Mean: Looking beyond Ease of Use. Proceeding of 48th Annual Conference-Society for Technical Communication, Chicago, 13-16 May 2001.
ISO 9241-11:1998 (1998) Ergonomic Requirements for Office Work with Visual Display Terminals (VDTs). The International Organization for Standardization, Geneva.
Geraci, A., et al. (1991) IEEE Standard Computer Dictionary: A Compilation of IEEE Standard Computer Glossaries.
Nielsen, J. (2003) Usability 101: Introduction to Usability. https://www.nngroup.com/articles/top-10-mistakes-web-design/
Febretti, A. and Garzotto, F. (2009) Usability, Playability, and Long-Term Engagement in Computer Games. CHI’09 Extended Abstracts on Human Factors in Computing Systems, 4063-4068. http://dx.doi.org/10.1145/1520340.1520618
Iwarsson, S. and Stahl, A. (2003) Accessibility, Usability and Universal Design—Positioning and Definition of Concepts Describing Person-Environment Relationships. Disability and Rehabilitation, 25, 57-66.
Tilson, R., et al. (1998) Factors and Principles Affecting the Usability of Four E-Commerce Sites. Proceedings of the 4th Conference on Human Factors & the Web, Basking Ridge, New Jersey.
Just, M. (2010) Security and Usability. School of Informatics, University of Edinburgh, Edinburgh.
Ivanovic, M., et al. (2013) Usability and Privacy Aspects of Moodle: Students’ and Teachers’ perspective. Informatica, 37, 221-230.
Montazemi, A.R. and Hamed, Q. (2015) Factors Affecting Adoption of Online Banking: A Meta-Analytic Structural Equation Modeling Study. Information & Management, 52, 210- 226. http://dx.doi.org/10.1016/j.im.2014.11.002
Majid, R.A.L., Mardziah, H. and Nurul A’syida Abdul, J. (2014) An Evaluation on the Usability of E-Commerce Website Using Think Aloud Method. New Perspectives in Information Systems and Technologies, 2, 289-296. http://dx.doi.org/10.1007/978-3-319-05948-8_28
Whitten, A. and Tygar, J. (1999) Why Johnny Can’t Encrypt: A Usability Evaluation of PGP 5.0. Proceedings of the 8th USENIX Security Symposium, 8, 14.
Hof, H.-J. (2015) User-Centric IT Security—How To Design Usable Security Mechanisms. arXiv preprint arXiv:1506.07167
Pimenta, P.C. and De Freitas, C.M. (2010) Security and Privacy Analysis in Social Network Services. 5th Iberian Conference on Information Systems and Technologies (CISTI), Santiago de Compostela, 16-19 June 2010, 1-6.
Parveen, N., Rizwan, B. and Khan, M. (2014) Integrating Security and Usability at Requirement Specification Process. International Journal of Computer Trends and Technology, 10, 236-240. http://dx.doi.org/10.14445/22312803/IJCTT-V10P142
Holzinger, A. (2005) Usability Engineering Methods for Software Developers. Communications of the ACM, 48, 71-74. http://dx.doi.org/10.1145/1039539.1039541
Devanbu, P.T. and Stuart, S. (2000) Software Engineering for Security: A Roadmap. Proceedings of the Conference on the Future of Software Engineering, Davis, 4-11 June 2000, 227-239. http://dx.doi.org/10.1145/336512.336559
Balfanz, D., et al. (2004) In Search of usable Security: Five Lessons from the Field. IEEE Security & Privacy, 5, 19-24. http://dx.doi.org/10.1109/MSP.2004.71
Garfinkel, S. and Heather, R.L. (2014) Usable Security: History, Themes, and Challenges. Synthesis Lectures on Information Security, Privacy, and Trust. Morgan & Claypool Publishers, San Rafael, 1-124. http://dx.doi.org/10.2200/S00594ED1V01Y201408SPT011
Cranor, L.F. and Norbou, B. (2014) Better Together: Usability and Security Go Hand in Hand. IEEE Security & Privacy, 6, 89-93. http://dx.doi.org/10.1109/MSP.2014.109
Prettyman, S.S., et al. (2015) Privacy and Security in the Brave New World: The Use of Multiple Mental Models. In: Tryfonas, T. and Askoxylakis, I., Eds., Human Aspects of Information Security, Privacy, and Trust, Springer, Berlin, 260-270. http://dx.doi.org/10.1007/978-3-319-20376-8_24
Swaak, M., De Jong, M. and De Vries, P. (2009) Effects of Information Usefulness, Visual Attractiveness, and Usability on Web Visitors’ Trust and Behavioral Intentions. IEEE International Professional Communication Conference, Waikiki, 19-22 July 2009, 1-5. http://dx.doi.org/10.1109/ipcc.2009.5208719
Susanto, A., Lee, H. and Zo, H. (2011) Factors Influencing Initial Trust Formation in Adopting Internet Banking in Indonesia. 2011 International Conference on Advanced Computer Science and Information System (ICACSIS), Jakarta, 17-18 December 2011, 305- 310.
Zou, X. and Jin, B. (2010) Identity Management with Trust Relationship and Privacy Preservation. 2010 IEEE International Conference on Information Theory and Information Security (ICITIS), Beijing, 17-19 December 2010, 366-370.
Farrukh, S. (2013) Tradeoffs between Usability and Security. IACSIT International Journal of Engineering and Technology, 5, 536-540.
Mihajlov, M., Blazic, B.J. and Josimovski, S. (2011) Quantifying Usability and Security in Authentication. 2011 IEEE 35th Annual Computer Software and Applications Conference (COMPSAC), Munich, 18-22 July 2011, 626-629. http://dx.doi.org/10.1109/COMPSAC.2011.87
Mairiza, D. and Zowghi, D. (2010) An Ontological Framework to Manage the Relative Conflicts between Security and Usability Requirements. 2010 3rd International Workshop on Managing Requirements Knowledge (MARK), Sydney, 27 September 2010, 1-6. http://dx.doi.org/10.1109/MARK.2010.5623814
Ko, H.-G., Kim, S.-H. and Jin, S.-H. (2007) Usability Enhanced Privacy Protection System Based on Users’ Responses. IEEE International Symposium on Consumer Electronics, Las Vegas, 10-14 January 2007, 1-6. http://dx.doi.org/10.1109/isce.2007.4382188
Fang, S.-W., Rajamanthri, D. and Husain, M. (2015) Facebook Privacy Management Simplified. 2015 12th International Conference on Information Technology-New Generations (ITNG), Las Vegas, 13-15 April 2015, 719-720. http://dx.doi.org/10.1109/ITNG.2015.121
Fahl, S., et al. (2012) Confidentiality as a Service—Usable Security for the Cloud. 2012 IEEE 11th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Liverpool, 25-27 June 2012, 153-162. http://dx.doi.org/10.1109/TrustCom.2012.112
Kainda, R., Flechais, I. and Roscoe, A.W. (2010) Security and Usability: Analysis and Evaluation. International Conference on Availability, Reliability, and Security, Krakow, 15-18 February 2010, 275-282. http://dx.doi.org/10.1109/ARES.2010.77
Hausawi, Y.M. and Allen, W.H. (2014) An Assessment Framework for Usable-Security Based on Decision Science. International Conference on Human Aspects of Information Security, Privacy, and Trust, Heraklion, 22-27 June 2014, 33-44. http://dx.doi.org/10.1007/978-3-319-07620-1_4
Hackett, M. and Kirstie, H. (2012) Security, Privacy and Usability Requirements for Federated Identity. Web 2.0 Security & Privacy Workshop, 2.
Van Heerde, H., Maarten, F. and Nicolas, A. (2009) A Framework to Balance Privacy and Data Usability Using Data Degradation. International Conference on Computational Science and Engineering, 3, 146-153. http://dx.doi.org/10.1109/cse.2009.174
Madejski, Mi., Maritza Lupe, J. and Bellovin, S.M. (2011) The Failure of Online Social Network Privacy Settings.
Liu, Y., et al. (2011) Analyzing Facebook Privacy Settings: User Expectations vs. Reality. Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, Berlin, 2-4 November 2011, 61-70. http://dx.doi.org/10.1145/2068816.2068823
Paul, T., Puscher, D. and Strufe, T. (2011) Improving the Usability of Privacy Settings in Facebook. arXiv:1109.6046
Bilge, L., et al. (2009) All Your Contacts Are Belong to Us: Automated Identity Theft Attacks on Social Networks. Proceedings of the 18th International Conference on World Wide Web, Madrid, 20-24 April 2009, 551-560. http://dx.doi.org/10.1145/1526709.1526784
Catanese, S.A., et al. (2011) Crawling Facebook for Social Network Analysis Purposes. Proceedings of the International Conference on Web Intelligence, Mining and Semantics, Sogndal, 25-27 May 2011, Article No. 52. http://dx.doi.org/10.1145/1988688.1988749
Strufe, T. (2010) Profile Popularity in a Business-Oriented Online Social Network. Proceedings of the 3rd Workshop on Social Network Systems, Paris, 13-16 April 2010, Article No. 2. http://dx.doi.org/10.1145/1852658.1852660
Zhang, C., et al. (2010) Privacy and Security for Online Social Networks: Challenges and Opportunities. IEEE Network, 24, 13-18. http://dx.doi.org/10.1109/MNET.2010.5510913
Cooharojananone, N., Chofa, S. and Phimoltares, S. (2011) A Study on Intention to Use Factor in the Internet Banking Websites in Thailand. 11th International Symposium on Applications and the Internet (SAINT), Munich, 18-21 July 2011, 556-561. http://dx.doi.org/10.1109/saint.2011.103
Costante, E., Den Hartog, J. and Petkovic, M. (2011) On-Line Trust Perception: What Really Matters. 1st Workshop on Socio-Technical Aspects in Security and Trust (STAST), Milan, 8 September 2011, 52-59. http://dx.doi.org/10.1109/STAST.2011.6059256