Abstract :
Progress in user security has been slow for several reasons. First, the Web´s scale and diversity make one-size-fits-all approaches hard. Second, the competition for user attention is fierce: there are no pools of unexploited user effort to be had. Third, persuasion is the only tool we have, mandates being often impossible or undesirable. We need to find new techniques to improve user security.