24
I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security and Usability in Mobile Tap-and-Pay Jun Ho Huh, Saurabh Verma, Swathi Sri V Rayala, Rakesh B. Bobba, Konstantin Beznosov, and Hyoungshick Kim

I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

IDon’tUseApplePayBecauseIt’sLessSecure...:PerceptionofSecurityandUsabilityinMobileTap-and-Pay

JunHoHuh,SaurabhVerma,Swathi SriVRayala,RakeshB.Bobba,KonstantinBeznosov,andHyoungshick Kim

Page 2: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

ApplePay

• InOctober2014,ApplelaunchediPhone6andApplePay

• Marketingpitchwas:tap-and-paywithiPhonesinstoresisfaster andmoresecure

• ApplePayquicklybecamethebiggesttap-and-paymobilepaymentsystemintheUS

• Accountingfor$2outofevery$3processedthroughcontactlesspayment

2

Page 3: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

3

Page 4: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

AndroidPay

• GooglelaunchedtheirownmobilepaymentsolutioncalledAndroidPayaroundSeptember2015

• AlsoclaimingthatAndroidPayismoreconvenientandsecurethanswipe-and-paywithtraditionalcreditcards

4

Page 5: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Researchquestions

• Howpopulararethetwotechnologies?

• Whydopeopleuseornotusethem?Howimportantaresecurityandusabilityfactorsinaffectingpeople’sdecisions?

• Whatarespecificusabilityandsecurityconcerns?

• Arethereanysecurityorusabilitymisconceptions?

5

Page 6: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Firststudy:in-personinterviews

• Conductedsemi-structuredinterviewstoidentifyhypotheses

• ConductedontwodifferentparticipantpoolswithintheUS:• 21participantsfromauniversity• 15participantsthroughonlineadvertisements(e.g.,Craiglist)

• Conductedbytworesearcherstogethertoensureallquestionswereaskedconsistently

• Averagetimetakenwas35minutes• Separatelyperformedthematicanalysisofeachinterview,independentlycreatinglistofthemes(“codes”)

6

Page 7: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Interviewquestions

• Usage: weaskedabouttheirfamiliaritywithApple(Android)Pay,andwhethertheyuseittopayinstores

• Whyuseornotuse• Askedwhytheyuse,notuse,orstoppedusingApple(Android)Pay

• Askedhowtheyfeelaboutsecurityandusability

• Familiaritywithsecurity: askedwhethertheyunderstand• HowApple(Android)Payprotecttheirtap-and-paytransactionprivacyandsecurity

• Howitprotectscarddetails• Howitensuresonlytheycanpaywiththeirphone

7

Page 8: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

ApplePayresults

• Aftermergingthecodesfrombothgroups,thethreedominantfactorsforusing ApplePaywere

• More secure (12)• Faster (11)• More convenient (12)

Hypothesis1:usabilityisamoreimportantfactorthansecurityforusingApplePay

8

Page 9: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

“It’smoreconvenient..ratherthantakingmywallet,findingmycard,andswipingit..”(P7)

“..youhaveto..authorize[itsuse]withthethumbprint.Sothatmakes[ApplePay]very

secure.”(P13)

9

Page 10: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

ApplePayresults

• Fornotusing ApplePaythedominantfactorswere• Not many stores support it (6)• Less secure (6)

Hypothesis2:securityisamoreimportantfactorthanusabilityfornotusingApplePay

10

Page 11: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

“ItisnotobviouswhereyoucanandcannotuseApplePay”(P1)

“IfmyPINiscompromised,IcanresetittoanotherPIN.Butmybiometricinformationcannotbe

reset..”(P14)

11

Page 12: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

AndroidPayresults• Forusing AndroidPaythedominantfactorswere

• More convenient (4)

• More private (4)

• For not using Android Pay,• Not many stores support it (6)• Less secure (5)• Less convenient (5)

Hypothesis3:thereisnostatisticallysignificantdifferencebetweentheimportanceofusabilityandsecurityfactorswhenitcomesto

usingornotusingAndroidPay

12

Page 13: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Secondstudy:onlinesurvey• Alarge-scaleonlinesurveywasconductedtoaddresslimitationsofthefirststudy,andtesthypotheses

• Designedbasedonthecodesidentifiedinthefirststudy,followingthesamestructure

• RecruitedparticipantthroughAmazonMechanicalTurkbetweenMarchandApril2016

• LimitedtoUSparticipants• ParticipateonlyiftheyhavesomefamiliaritywithApple(Android)Pay,andownsaphonethatsupportsit

13

Page 14: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Validatingresponses• Participantswereaskedtosubmittwophotos

14

• Excluded responses from those who- Didn’t provide photos- Didn’t follow instructions- Provided photos that do not match their claimed model- Provided photos of devices that do not support Apple (Android) Pay

Page 15: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Adoptionrates

15

Option ApplePay AndroidPayNo,Ihaveneverusedit 189(54%) 330(64%)Yes,Iuseit 124(36%) 100(21%)Iwasusingitinthepastbutstoppedusingit

36(10%) 81(15%)

Page 16: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Reasonsfornotusing ApplePay

16

Page 17: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Reasonsfornotusing AndroidPay

17

Page 18: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Reasonsforusing ApplePay

18

Page 19: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Reasonsforusing AndroidPay

19

Page 20: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

SecurityknowledgeandApplePayadoptionrate

20

UsingPearson’scorrelation,wefoundapositivecorrelation(ρ =0.19,p<0.0001)

Page 21: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

SecurityknowledgeandAndroidPayadoptionrate

21

Wefoundapositivecorrelation(ρ =0.20,p<0.0001)

Page 22: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Perceptionofsecurity• Tothenonuserswhochoseless secure asthetopconcern,weasked

• Whydoyoufeelit’slesssecure?• IfyoulearnthatusingApple(Android)Payismoresecure,wouldyouthenuseittopayinstores?

• ForApplePay,10outof12 saidyestothesecondquestion.ForAndroidPay,8outof14 saidyes.

• Tothefirstquestion,• Insecure storage of card information wasmostfrequentlymentioned(13outof26)

• Butonly2outofthat13correctlyansweredthequestionaboutcardprotectionmechanisms

• Stealing phone and making purchases wasalsopopular(7outof26)

22

Page 23: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Overcomingsecuritymisconceptions• Insecure storage of card information

• Educatingnonusersaboutthecardinformationprotectiontechnologiescouldhelpthemovercomethissecuritymisconception

• Stealing phone and making purchases

• Learning about authentication mechanisms and lost/stolen phone features (that allows one to quickly disable mobile tap-and-pay remotely)

• Help nonusers realize that using stolen phones to make purchases is harder than physically using stolen cards

23

Page 24: I Don’t Use Apple Pay Because It’s Less Secure : Perception of …verma/usec2017_02_1_Huh_slides.pdf · I Don’t Use Apple Pay Because It’s Less Secure ...: Perception of Security

Conclusions• Mobiletap-and-payadoptionrateisactuallyquitelow!!

• Securitywasthetopconcernformanynonusers• Commonsecuritymisconceptionwasthatthecardinformationarenot

securelystored,andstealingphoneandmakingpurchasesiseasy

• Wefoundapositivecorrelationbetweenthesecurityknowledgelevelsandthelikelihoodofusingmobiletap-and-pay

• Furtherinvestigationisneededtostudythecausalrelations• Manynonusersmentionedthatiftheylearnmobiletap-and-payismore

secure,theywoulduseit

• AppleandGooglecouldpotentiallyimproveadoptionratesbyeducatingpeopleaboutthesecurityprotections,andaddressingtheirsecuritymisconceptions

24