Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and Behavior
Abstract
1 Introduction
2 Background and Related Work
3 Methods
3.1 Pilot Studies
3.2 Participant Recruitment
3.3 Label Design
3.4 Survey Design
3.5 Data Analysis
3.6 Limitations
4 Results
4.1 Participants
Low | Medium | High | Total | ||
Age | 18-35 | 68(13.1%) | 51(9.8%) | 60(11.6%) | 179(34.6%) |
36-53 | 56(10.8%) | 64(12.4%) | 57(11.0%) | 177(34.2%) | |
54+ | 52(10.0%) | 57(11.0%) | 53(10.2%) | 162(31.3%) | |
Gender | Male | 85(16.4%) | 86(16.6%) | 92(17.8%) | 263(50.8%) |
Female | 87(16.8%) | 86(16.6%) | 72(13.9%) | 245(47.3%) | |
Non-binary | 4(0.8%) | 0(0.0%) | 5(1.0%) | 9(1.7%) | |
Prefer to self describe | 0(0.0%) | 0(0.0%) | 1(0.2%) | 1(0.2%) | |
Back-ground | Technical | 54(10.4%) | 53(10.2%) | 53(10.2%) | 160(30.9%) |
Non-technical | 122(23.6%) | 119(23.0%) | 117(22.6%) | 358(69.1%) | |
Total | 176(34.0%) | 172(33.2%) | 170(32.8%) | 518(100.0%) |
4.2 Understanding the Labels (RQ1)
4.3 Consumer Behavior and Intentions (RQ2)
4.4 Consumer Preferences (RQ3 and RQ4)
4.5 U.S. Cyber Trust Mark Education (RQ5a)
4.6 Effects of Demographic Factors (RQ5b, RQ5c, and RQ5d)
5 Discussion
6 Conclusion
Acknowledgments
A Survey Questions
A.1 Consent form and screening questions
A.1.1 Summary and Purpose.
A.1.2 Procedures.
A.1.3 Participant Requirements.
A.1.4 Risks.
A.1.5 Benefits.
A.1.6 Compensation & Costs.
A.1.7 Future Use of Information.
A.1.8 Confidentiality.
A.1.9 Right to Ask Questions & Contact Information.
A.1.10 Voluntary Participation.
A.2 Pre-screen survey
A.3 Main Survey
B Educational Interventions
C List of Qualifying Devices
D Kupper-Hafner Agreement for Qualitative Coding
Low-complexity | Medium-complexity | High-complexity | ||||
Scanned | Did not scan | Scanned | Did not scan | Scanned | Did not scan | |
q27 - What additional information about security or privacy, if any, would be useful for you to see on the label (you viewed after scanning/on the product packaging)? | 0.690 | 0.704 | 0.760 | 0.688 | 0.585 | 0.668 |
q33 - Suppose the label you were shown throughout the survey is used for other IoT devices in the market. How would you improve the label itself? | 0.590 | 0.757 | 0.653 | |||
q29 - Why did you choose the option you selected for the previous question? | 0.669 |
E High-complexity Label Accessed Via QR Code
F Complete Statistical Results
Question Text | Label Complexity (Overall) | Label Complexity (Low vs. Mid) | Label Complexity (Low vs. High) | Label Complexity (Mid vs. High) |
Q1 - If you saw these three labels on their product packaging, would you consider them as you shop? Which of the following actions would you take? | ||||
A. I would thoroughly examine the labels | < 0.001 | < 0.001 | 0.006 | 0.469 |
B. I would carefully compare the labels | < 0.001 | < 0.001 | < 0.002 | 0.040 |
C. I would look for anything that looks particularly bad/concerning. | < 0.001 | < 0.001 | < 0.001 | 0.897 |
D. I would glance at them | 0.004 | 0.017 | 0.004 | 0.810 |
E. I would look for anything that looks particularly good | 0.055 | 0.169 | 0.019 | 0.568 |
F. I would not use them at all | 0.865 | - | - | - |
G. I would look for anything that looks particularly good | <0.001 | 0.002 | 0.001 | 0.915 |
Q2 - Which of the three devices are you most likely to purchase given the information on the labels? | <0.001 | <0.001 | <0.001 | 0.010 |
Q3(a)(i) - You chose the Sustios Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing Sustios over All4Home? | ||||
A. Sustios has better privacy than All4Home | 0.568 | - | - | - |
B. Sustios has better security than All4Home | 0.019 | 0.700 | 0.004 | 0.019 |
C. Sustios has better functionality than All4Home | 0.091 | 0.991 | 0.366 | 0.038 |
Q3(b)(i) - You chose the Sustios Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing Sustios over EcoHouse? | ||||
A. Sustios has better privacy than EcoHouse | 0.900 | - | - | - |
B. Sustios has better security than EcoHouse | 0.004 | 0.220 | 0.987 | 0.002 |
C. Sustios has better functionality than EcoHouse | 0.163 | - | - | - |
Q3(a)(ii) - You chose the All4Home Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing All4Home over EcoHouse? | ||||
A. All4Home has better privacy than EcoHouse | 0.925 | - | - | - |
B. All4Home has better security than EcoHouse | 0.545 | - | - | - |
C. All4Home has better functionality than EcoHouse | 0.163 | - | - | - |
Q3(b)(ii) - You chose the All4Home Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing All4Home over Sustios? | ||||
A. All4Home has better privacy than Sustios | 0.565 | - | - | - |
B. All4Home has better security than Sustios | 0.761 | - | - | - |
C. All4Home has better functionality than Sustios | 0.166 | - | - | - |
Q3(a)(iii) - You chose the EcoHouse Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing EcoHouse over All4Home? | ||||
A. EcoHouse has better privacy than All4Home | 0.287 | - | - | - |
B. EcoHouse has better security than All4Home | 0.469 | - | - | - |
C. EcoHouse has better functionality than All4Home | 0.802 | - | - | - |
Q3(b)(iii) - You chose the EcoHouse Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing EcoHouse over Sustios? | ||||
A. EcoHouse has better privacy than Sustios | 0.925 | - | - | - |
B. EcoHouse has better security than Sustios | 0.991 | - | - | - |
C. EcoHouse has better functionality than Sustios | 0.750 | - | - | - |
Q3(d) - How helpful would additional information about each of the following factors be to you when making a purchasing decision? | ||||
A. Data selling practices | 0.761 | - | - | - |
B. Data sharing practices | 0.234 | - | - | - |
C. Data retention practices | 0.987 | - | - | - |
D. Data storage practices | 0.925 | - | - | - |
E. Access control | 0.366 | - | - | - |
F. Security updates | 0.198 | - | - | - |
G. Sensors used | 0.925 | - | - | - |
Q4 - Which of the following do you think best describes what the presence of the Cyber Trust Mark on the label represents? | 0.377 | - | - | - |
Q5 - Which device uses a camera or other visual sensor? | 0.002 | 0.002 | 0.002 | 1.000 |
Q6 - Which device shares data with ONLY the manufacturer and service providers? | 0.002 | 0.002 | 0.002 | 0.002 |
Q7 - Which device sells data to third parties? | 0.002 | 0.002 | 0.002 | 0.002 |
Q8 - Which device provides consent-based security updates? | 0.002 | 0.002 | 0.002 | 0.002 |
Q9 - Did you attempt to scan the QR code on any of the labels? If so, how many labels did you scan? | 0.002 | 0.002 | 0.002 | 0.188 |
Q10 - If you saw a label like this when actually shopping for an IoT device, how likely would you be to scan the QR code for more information? | 0.218 | - | - | - |
Q11 - If you were looking at a box containing an IoT device in a store and saw a label with a QR code, what would you be most likely to do if you wanted to see more information? | 0.915 | - | - | - |
Q12 - Which of the following best describes what you would expect to find after scanning the QR code? | 0.319 | - | - | - |
Q13 - Which of the following best describes what you would expect to find after scanning the QR code? | 0.399 | - | - | - |
Q14 - How easy was it for you to scan the QR code(s)? | 0.496 | - | - | - |
Q15 - How easy was it for you to use the label(s) accessed by scanning the QR code to make your purchase decision? | 0.666 | - | - | - |
Q22 - Overall, how helpful did you find the information on the packaging label (before scanning the QR code) in making your purchasing decision? | < 0.001 | < 0.001 | < 0.001 | < 0.001 |
Q23 - Overall, how helpful did you find the information accessed by scanning the QR code in making a purchasing decision? | 0.295 | - | - | - |
Q24 - What do you think about the amount of information on the labels (before scanning the QR code) shown above? | 0.002 | 0.002 | 0.002 | 0.002 |
Q25 - What do you think about the amount of information on the labels you saw by scanning the QR codes? | 0.631 | - | - | - |
Q26 - How convenient did you find retrieving information using the QR code? | 0.582 | - | - | - |
Q28 - When you are shopping for an IoT device, which of the four label designs above would you be most interested in seeing on the product packaging? (Note: These are all labels for the same device.) | 0.002 | 0.002 | 0.332 | 0.030 |
Q30 - When you are shopping for an IoT device, which of these label designs (if any) would you like to see after you scan the QR Code on the label on product packaging? (Note: you must select a different label design from what you selected above.) | 0.991 | - | - | - |
Q31 - When you are purchasing an IoT device, how important are the following to you? | ||||
A. Strong privacy | 0.925 | - | - | - |
B. Strong security | 0.786 | - | - | - |
C. Device functionality | 0.545 | - | - | - |
D. Brand reputation | 0.817 | - | - | - |
E. Ease of use | 0.917 | - | - | - |
F. Price | 0.666 | - | - | - |
Q32 - How well do you agree with each of the following statements? | ||||
A. I typically read privacy policies | 0.250 | - | - | - |
B. I am extremely motivated to take all the steps needed to keep my online data and accounts safe | 0.255 | - | - | - |
C. I have adjusted my browser settings to block some or all cookies or have installed a browser extension to do so | 0.666 | - | - | - |
D. I typically enable two-factor authentication when it is available | 0.689 | - | - | - |
Question Text | Education vs. No Education |
---|---|
Q4 - Which of the following do you think best describes what the presence of the Cyber Trust Mark on the label represents? | 0.003 |
Q13 - Which of the following best describes what you would expect to find after scanning the QR code? | 0.003 |
Q18 - How well do you feel you understand what each of the following label elements conveys? | |
A. QR code | 0.358 |
B. Cyber Trust Mark | <0.001 |
C. Data collected | 0.921 |
D. Data shared | 0.689 |
E. Security updates | 0.806 |
F. Access control | 0.600 |
G. Sensor data | 0.535 |
H. Data Stored | 0.900 |
I. Data Sold | 0.667 |
Q20 - How much does each of the following label elements influence your decision about which product to purchase? | |
A. QR code | 0.553 |
B. Cyber Trust Mark | 0.003 |
C. Data collected | 0.461 |
D. Data shared | 0.900 |
E. Security updates | 0.701 |
F. Access control | 0.916 |
G. Sensor data | 0.522 |
H. Data Stored | 0.689 |
I. Data Sold | 0.791 |
Participant Groups | p-value |
Education vs. No Education (Overall, Number of Labels Scanned) | 0.001 |
Education vs. No Education (Low-complexity group, Number of Labels Scanned) | 0.002 |
Education vs. No Education (Medium-complexity group, Number of Labels Scanned) | 0.282 |
Education vs. No Education (High-complexity group, Number of Labels Scanned) | 0.667 |
Education vs. No Education (Overall, Scanning vs. No Scanning) | 0.012 |
Question Text | Age (Overall) | Age (18-35 vs. 36-53) | Age (18-35 vs. 54+) | Age (36-53 vs. 54+) | Technical Background (Y vs. N) | Gender (Male vs. Non-male) |
Q2 - Which of the three devices are you most likely to purchase given the information on the labels? | 0.487 | - | - | - | 0.566 | 0.925 |
Q3(a)(i) - You chose the Sustios Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing Sustios over All4Home? | ||||||
A. Sustios has better privacy than All4Home | 0.616 | - | - | - | 0.926 | 0.926 |
B. Sustios has better security than All4Home | 0.843 | - | - | - | 0.926 | 0.569 |
C. Sustios has better functionality than All4Home | 0.900 | - | - | - | 0.807 | 0.727 |
Q3(b)(i) - You chose the Sustios Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing Sustios over EcoHouse? | ||||||
A. Sustios has better privacy than EcoHouse | 0.988 | - | - | - | 0.462 | 0.989 |
B. Sustios has better security than EcoHouse | 0.667 | - | - | - | 0.725 | 0.926 |
C. Sustios has better functionality than EcoHouse | 0.859 | - | - | - | 0.767 | 0.926 |
Q3(a)(ii) - You chose the All4Home Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing All4Home over EcoHouse? | ||||||
A. All4Home has better privacy than EcoHouse | 0.719 | - | - | - | 0.727 | 0.991 |
B. All4Home has better security than EcoHouse | 0.900 | - | - | - | 0.569 | 0.922 |
C. All4Home has better functionality than EcoHouse | 0.926 | - | - | - | 0.264 | 0.922 |
Q3(b)(ii) - You chose the All4Home Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing All4Home over Sustios? | ||||||
A. All4Home has better privacy than Sustios | 0.121 | <0.001 | <0.001 | 0.701 | 0.991 | 0.220 |
B. All4Home has better security than Sustios | 0.499 | - | - | - | 0.991 | 0.515 |
C. All4Home has better functionality than Sustios | 0.806 | - | - | - | 0.232 | 0.926 |
Q3(a)(iii) - You chose the EcoHouse Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing EcoHouse over All4Home? | ||||||
A. EcoHouse has better privacy than All4Home | 0.150 | - | - | - | 0.107 | 0.922 |
B. EcoHouse has better security than All4Home | 0.582 | - | - | - | 0.545 | 0.543 |
C. EcoHouse has better functionality than All4Home | 0.569 | - | - | - | 0.398 | 0.226 |
Q3(b)(iii) - You chose the EcoHouse Voice-Activated Thermostat. To what extent do you agree with the following reasons for choosing EcoHouse over Sustios? | ||||||
A. EcoHouse has better privacy than Sustios | 0.802 | - | - | - | 0.076 | 0.235 |
B. EcoHouse has better security than Sustios | 0.701 | - | - | - | 0.739 | 0.986 |
C. EcoHouse has better functionality than Sustios | 0.864 | - | - | - | 0.0855 | 0.170 |
Q3(d) - How helpful would additional information about each of the following factors be to you when making a purchasing decision? | ||||||
A. Data selling practices | 0.926 | - | - | - | 0.701 | 0.991 |
B. Data sharing practices | 0.991 | - | - | - | 0.254 | 0.569 |
C. Data retention practices | 0.956 | - | - | - | 0.787 | 0.751 |
D. Data storage practices | 0.922 | - | - | - | 0.653 | 0.900 |
E. Access control | 0.926 | - | - | - | 0.054 | 0.438 |
F. Security updates | 0.667 | - | - | - | 0.060 | 0.145 |
G. Sensors used | 0.783 | - | - | - | 0.030 | 0.904 |
Q4 - Which of the following do you think best describes what the presence of the Cyber Trust Mark on the label represents? | 0.034 | 0.412 | 0.0235 | 0.021 | 0.0710 | 0.003 |
Q5 - Which device uses a camera or other visual sensor? | 0.600 | - | - | - | 0.921 | 0.797 |
Q6 - Which device shares data with ONLY the manufacturer and service providers? | 0.689 | - | - | - | 0.515 | 0.806 |
Q7 - Which device sells data to third parties? | 0.610 | - | - | - | 0.900 | 0.434 |
Q8 - Which device provides consent-based security updates? | 0.988 | - | - | - | 0.070 | 0.595 |
Q10 - If you saw a label like this when actually shopping for an IoT device, how likely would you be to scan the QR code for more information? | <0.001 | <0.001 | <0.001 | 0.526 | 0.884 | 0.269 |
Q11 - If you were looking at a box containing an IoT device in a store and saw a label with a QR code, what would you be most likely to do if you wanted to see more information? | 0.020 | 0.049 | 0.020 | 0.367 | 0.582 | 0.717 |
Q12 - Which of the following best describes what you would expect to find after scanning the QR code? | 0.043 | 0.926 | 0.020 | 0.118 | 0.367 | 0.667 |
Q13 - Which of the following best describes what you would expect to find after scanning the QR code? | 0.591 | - | - | - | 0.946 | 0.725 |
Q14 - How easy was it for you to scan the QR code(s)? | 0.499 | - | - | - | 0.921 | 0.925 |
Q15 - How easy was it for you to use the label(s) accessed by scanning the QR code to make your purchase decision? | 0.767 | - | - | - | 0.806 | 0.204 |
Q22 - Overall, how helpful did you find the information on the packaging label (before scanning the QR code) in making your purchasing decision? | 0.034 | 0.011 | 0.249 | 0.314 | 0.945 | 0.849 |
Q23 - Overall, how helpful did you find the information accessed by scanning the QR code in making a purchasing decision? | 0.665 | - | - | - | 0.806 | 0.987 |
Q24 - What do you think about the amount of information on the labels (before scanning the QR code) shown above? | 0.689 | - | - | - | 0.900 | 0.921 |
Q25 - What do you think about the amount of information on the labels you saw by scanning the QR codes? | 0.667 | - | - | - | 0.242 | 0.667 |
Q26 - How convenient did you find retrieving information using the QR code? | 0.124 | 0.578 | 0.0502 | 0.198 | 0.807 | 0.545 |
Q28 - When you are shopping for an IoT device, which of the four label designs above would you be most interested in seeing on the product packaging? (Note: These are all labels for the same device.) | <0.001 | 0.105 | 0.003 | 0.219 | 0.194 | 0.930 |
Q30 - When you are shopping for an IoT device, which of these label designs (if any) would you like to see after you scan the QR Code on the label on product packaging? (Note: you must select a different label design from what you selected above.) | 0.496 | - | - | - | 0.725 | 0.922 |
Q31 - When you are purchasing an IoT device, how important are the following to you? | ||||||
A. Strong privacy | 0.105 | 0.203 | 0.0455 | 0.667 | 0.880 | 0.203 |
B. Strong security | 0.121 | 0.265 | 0.048 | 0.578 | 0.954 | 0.925 |
C. Device functionality | 0.219 | - | - | - | 0.667 | 0.548 |
D. Brand reputation | 0.216 | - | - | - | 0.751 | 0.667 |
E. Ease of use | 0.026 | 0.843 | 0.0115 | 0.049 | 0.068 | 0.154 |
F. Price | 0.249 | - | - | - | 0.198 | 0.767 |
Q32 - How well do you agree with each of the following statements? | ||||||
A. I typically read privacy policies | <0.001 | <0.001 | 0.032 | 0.096 | 0.235 | 0.595 |
B. I am extremely motivated to take all the steps needed to keep my online data and accounts safe | <0.001 | <0.001 | 0.034 | 0.220 | 0.012 | 0.701 |
C. I have adjusted my browser settings to block some or all cookies or have installed a browser extension to do so | 0.085 | 0.261 | 0.500 | 0.030 | 0.050 | 0.011 |
D. I typically enable two-factor authentication when it is available | 0.667 | - | - | - | 0.921 | 0.070 |
Footnotes
Supplemental Material
- Download
- 2.96 MB
- Transcript
- Download
- 45.86 MB
- Transcript
References
Index Terms
- Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and Behavior
Recommendations
Exploring How Privacy and Security Factor into IoT Device Purchase Behavior
CHI '19: Proceedings of the 2019 CHI Conference on Human Factors in Computing SystemsDespite growing concerns about security and privacy of Internet of Things (IoT) devices, consumers generally do not have access to security and privacy information when purchasing these devices. We interviewed 24 participants about IoT devices they ...
Investigating the effect of security and privacy on IoT device purchase behaviour
AbstractGiven the significant privacy and security risks of Internet-of-Things (IoT) devices, it seems desirable to nudge consumers towards buying more secure devices and taking privacy into account in the purchase decision. In order to ...
Systematically Evaluating Security and Privacy for Consumer IoT Devices
IoTS&P '17: Proceedings of the 2017 Workshop on Internet of Things Security and PrivacyInternet-of-Things (IoT) devices such as smart bulbs, cameras, and health monitors are being enthusiastically adopted by consumers, with numbers projected to rise to the billions. However, such devices are also easily attacked, or used for launching ...
Comments
Please enable JavaScript to view thecomments powered by Disqus.Information & Contributors
Information
Published In
Sponsors
Publisher
Association for Computing Machinery
New York, NY, United States
Publication History
Check for updates
Author Tags
Qualifiers
- Research-article
- Research
- Refereed limited
Funding Sources
Conference
Acceptance Rates
Upcoming Conference
- Sponsor:
- sigchi
Contributors
Other Metrics
Bibliometrics & Citations
Bibliometrics
Article Metrics
- View Citations1Total Citations
- 1,415Total Downloads
- Downloads (Last 12 months)1,415
- Downloads (Last 6 weeks)563
Other Metrics
Citations
View Options
View options
View or Download as a PDF file.
PDFeReader
View online with eReader.
eReaderHTML Format
View this article in HTML Format.
HTML FormatGet Access
Login options
Check if you have access through your login credentials or your institution to get full access on this article.
Sign in