"This is the way 'I' create my passwords ..." : does the endowment effect deter people from changing the way they create their passwords?

Renaud, Karen and Otondo, Robert and Warkentin, Merrill (2019) "This is the way 'I' create my passwords ..." : does the endowment effect deter people from changing the way they create their passwords? Computers and Security, 82. pp. 241-260. ISSN 0167-4048 (https://doi.org/10.1016/j.cose.2018.12.018)

[thumbnail of Renaud-etal-CS2019-This-is-the-way-I-create-my-passwords-endowment-effect]
Preview
Text. Filename: Renaud_etal_CS2019_This_is_the_way_I_create_my_passwords_endowment_effect.pdf
Accepted Author Manuscript
License: Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 logo

Download (725kB)| Preview

Abstract

The endowment effect is the term used to describe a phenomenon that manifests as a reluctance to relinquish owned artifacts, even when a viable or better substitute is offered. It has been confirmed by multiple studies when it comes to ownership of physical artifacts. If computer users also "own", and are attached to, their personal security routines, such feelings could conceivably activate the same endowment effect. This would, in turn, lead to their over-estimating the "value" of their existing routines, in terms of the protection they afford, and the risks they mitigate. They might well, as a consequence, not countenance any efforts to persuade them to adopt a more secure routine, because their comparison of pre-existing and proposed new routine is skewed by the activation of the endowment effect. In this paper, we report on an investigation into the possibility that the endowment effect activates when people adopt personal password creation routines. We did indeed find evidence that the endowment effect is likely to be triggered in this context. This constitutes one explanation for the failure of many security awareness drives to improve password strength. We conclude by suggesting directions for future research to confirm our findings, and to investigate the activation of the effect for other security routines.