Skip to main content

Security should be there by default: Investigating how journalists perceive and respond to risks from the Internet of Things

Shere, Anjuli R. K., Nurse, Jason R. C., Flechais, Ivan (2020) Security should be there by default: Investigating how journalists perceive and respond to risks from the Internet of Things. In: 5th European Workshop on Usable Security (EuroUSEC 2020). . IEEE ISBN 978-1-72818-598-9. E-ISBN 978-1-72818-597-2. (doi:10.1109/EuroSPW51379.2020.00039) (KAR id:80999)

PDF Author's Accepted Manuscript
Language: English
Download (371kB) Preview
[thumbnail of EuroUSEC-2020-Journalists-IoT-Risks.pdf]
Preview
This file may not be suitable for users of assistive technology.
Request an accessible format
Official URL:
http://dx.doi.org/10.1109/EuroSPW51379.2020.00039

Abstract

Journalists have long been the targets of both physical and cyber-attacks from well-resourced adversaries. Internet of Things (IoT) devices are arguably a new avenue of threat towards journalists through both targeted and generalised cyber-physical exploitation. This study comprises three parts: First, we interviewed 11 journalists and surveyed 5 further journalists, to determine the extent to which journalists perceive threats through the IoT, particularly via consumer IoT devices. Second, we surveyed 34 cyber security experts to establish if and how lay-people can combat IoT threats. Third, we compared these findings to assess journalists' knowledge of threats, and whether their protective mechanisms would be effective against experts' depictions and predictions of IoT threats. Our results indicate that journalists generally are unaware of IoT-related risks and are not adequately protecting themselves; this considers cases where they possess IoT devices, or where they enter IoT-enabled environments (e.g., at work or home). Expert recommendations spanned both immediate and long-term mitigation methods, including practical actions that are technical and socio-political in nature. However, all proposed individual mitigation methods are likely to be short-term solutions, with 26 of 34 (76.5%) of cyber security experts responding that within the next five years it will not be possible for the public to opt-out of interaction with the IoT.

Item Type: Conference or workshop item (Paper)
DOI/Identification number: 10.1109/EuroSPW51379.2020.00039
Uncontrolled keywords: journalism, internet of things, smart devices, anticipatory threat models, security, privacy, data protection
Subjects: H Social Sciences > H Social Sciences (General)
Q Science > QA Mathematics (inc Computing science)
T Technology
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Divisions > Division for the Study of Law, Society and Social Justice > Centre for Journalism
Divisions > Division for the Study of Law, Society and Social Justice > School of Social Policy, Sociology and Social Research
Depositing User: Jason Nurse
Date Deposited: 26 Apr 2020 15:07 UTC
Last Modified: 22 Nov 2022 00:03 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/80999 (The current URI for this page, for reference purposes)
Nurse, Jason R. C.: https://orcid.org/0000-0003-4118-1680
  • Depositors only (login required):

Downloads

Downloads per month over past year