CyLab has played a leading role in advancing usable privacy and security education, research, and practice. Through interdisciplinary, human-centered research, CyLab has helped make security tools, privacy disclosures, and digital systems more understandable and effective for everyday users. Our work has influenced industry practices, technology design, and public policy, ensuring that privacy and security innovations are not only technically robust but also accessible and practical at scale.
On this page:
In 2005, Professor Lorrie Cranor co-edited the first book on usable privacy and security.
Shaping the Field of Usable Privacy and Security
In 1999, one of the first widely read usable security papers, “Why Johnny Can’t Encrypt: A Usability Evaluation of PGP 5.0,” was written by a Carnegie Mellon University computer science Ph.D. student, Alma Whitten. The paper argued that effective security requires ease in usability, and that most security failures were caused by user errors stemming from clumsy and confusing user interfaces.
In the early 2000s, Lorrie Cranor, who became CyLab Director in 2019, grew concerned about usability issues related to a privacy standard she was working on. She looked for research on usable privacy tools that could inform the standards work, and came up empty-handed.
“I realized that not a lot was known about how to make privacy or security tools usable,” says Cranor. “So, I decided to make that the focus of my research.”
Cranor joined CMU’s faculty in 2003 and was a key player in building momentum around the field of usable privacy and security. She formed the CyLab Usable Privacy and Security (CUPS) Laboratory in 2004 and started working with students interested in this area.
In 2005, Cranor co-edited the first book on usable privacy and security, and in 2006, she and two other CyLab faculty introduced the first usable privacy and security course at CMU, which is still taught today. The course features an open-sourced curriculum and has been adopted by universities worldwide.
Anti-Phishing
In 2005, CyLab began seminal work on anti-phishing techniques. Professors Lorrie Cranor, Jason Hong, and Norman Sadeh would later turn their work into Wombat Security Technologies, a startup focused on security awareness training to prevent phishing attacks, with Sadeh serving as founding CEO and, until the company's acquisition, as its chairman.
The company's products grew directly out of research conducted at Carnegie Mellon, where the team, building on learning science principles, had developed groundbreaking phishing education methods, including Anti-Phishing Phil, a cybersecurity game to teach players strategies for staying safe from phishing, and PhishGuru, a testing and training system enabling organizations to send simulated phishing emails internally and immediately train employees who fall for them. Wombat commercialized and extended these technologies, turning them into a comprehensive suite of about 40 cybersecurity training modules covering topics ranging from social engineering, mobile device security, safe browsing, and password security all the way to simulated USB attacks, with the modules available in more than 35 languages.
Wombat also commercialized machine learning technology for automatically detecting phishing emails first developed at Carnegie Mellon. Originally known as PILFER and described in one of the earliest and most cited papers, the technology was successively refined and rebranded by Wombat as PhishPatrol and later PhishAlarm Analyzer, a machine learning-based system that automatically prioritizes and categorizes user-reported emails to help security teams spot phishing threats faster. PhishAlarm Analyzer is now a key component of Proofpoint's CLEAR email security platform, which protects tens of millions of inboxes.
Wombat grew to an organization of over 200 employees serving well over 2,000 corporate customers, and helped define the multi-billion dollar user-oriented cybersecurity market. In February 2018, Wombat was acquired by Proofpoint for $225 million.
Project links: See the CyLab Usable Privacy and Security Laboratory “Supporting Trust Decisions” page for more information.
The Symposium on Usable Privacy and Security (SOUPS)
In 2005, Professor Lorrie Cranor founded the Symposium on Usable Privacy and Security (SOUPS). Originally held at Carnegie Mellon University's Collaborative Innovation Center, the inaugural event brought together interdisciplinary groups of researchers focused on solving challenges in areas of security, privacy, and human-computer interaction.
Now managed by USENIX, SOUPS has grown significantly, and has celebrated more than 20 installments across the world.
Project links: See full historic SOUPS proceedings under the stewardship of USENIX and the CyLab Usable Privacy and Security Laboratory.
Creating Interfaces for More Trustworthy Online Interactions
In 2009, Google acquired reCAPTCHA, a start-up that grew out of Carnegie Mellon researchers Luis von Ahn and Manuel Blum’s pioneering work. Websites still use the technology today to prevent automated programs, or bots, from perpetrating large-scale abuse.
Project links: Learn more about reCAPTCHA.
Making Passwords More Secure and Usable
In 2010, when Carnegie Mellon University changed its own password policy, CyLab researchers learned that the policy was based on National Institute of Standards and Technology (NIST) guidelines that were not heavily based on data, because little to no data on passwords existed.
A team of CyLab researchers changed that. The group, co-led by Lorrie Cranor, Lujo Bauer, and Nicolas Christin, went on to establish new, empirically-proven methods for evaluating both password usability for human users and also password strength against practical attacks. In 2016, the revised NIST password guidelines were directly influenced by the group’s work.
“I'm excited not just by our results on what makes a good password, but even more by what we learned about how to do research on passwords,” says Bauer. “We established a methodology for measuring password strength, which has by now been used by dozens of research groups. We also showed how to evaluate new password schemes through user studies and obtain results that generalize. Both of these were critical enablers for research on passwords.”
The research team has collaborated on more than 20 papers on password policies, and its body of work has led to tools like a password guessability service and a state-of-the-art password meter that gives users feedback on the strength of their passwords in real time and offers specific suggestions on how to make them stronger.
In 2020, the Carnegie Mellon School of Computer Science awarded the Allen Newell Award for Research Excellence to the team for pioneering contribution to the science of evaluating password strength, and for embodying this science in online tools that enable individuals and groups to more easily secure their systems.
Project links: See full details on CyLab's Passwords and Authentication Research.
Usable Security and Privacy Labels for Smart Devices
Since 2018, CyLab faculty and students have advocated for IoT labels to empower consumers by providing the knowledge necessary to make informed purchasing decisions.
CyLab's IoT label research builds on more than a decade of pioneering CyLab work on privacy labels. In 2009, CyLab researchers introduced a “privacy nutrition label” for websites, designed to present privacy policies in a standardized, easily digestible format. A 2013 study by Patrick Gage Kelley, Lorrie Cranor, and Norman Sadeh further demonstrated that displaying privacy information alongside apps in an app store influences which apps users choose to install. This line of work foreshadowed the privacy labels later adopted by major app stores, with Apple introducing privacy labels in its App Store in 2020 and Google following with Play Store data safety labels in 2022.
Led by Cranor and Yuvraj Agarwal, the CyLab IoT label team has explored how privacy and security factors into IoT device purchase behaviors, finding a willingness among consumers to pay significant premiums for products featuring a consistent label that highlights positive security and privacy features.On July 18, 2023, The Federal Communications Commission officially introduced the U.S. Cyber Trust Mark, a voluntary cybersecurity labeling program for wireless consumer IoT products. Building on Cranor and Agarwal's research, the program will designate qualifying consumer smart products that meet robust cybersecurity standards with a label to help consumers make informed decisions about the products they bring into their homes, differentiate trustworthy products in the marketplace, and create incentives for manufactures to meet higher cybersecurity standards.
Agarwal represented Carnegie Mellon University at The White House event to announce the launch of U.S. Cyber Trust Mark, meeting with government officials and technology industry leaders to share key findings from CyLab’s five-plus years of IoT security and privacy label research.
In 2025, the Foresight Institute awarded the Norm Hardy Prize to Cranor, Agarwal, and CyLab Ph.D. alumna Pardis Emami-Naeini for their contributions to advancing usable security through the development of a layered cybersecurity label for smart home devices.
Project links: See full details on CyLab's IoT Security and Privacy Label research.
Social Cybersecurity
In 2014, CyLab researchers helped establish the field of social cybersecurity by demonstrating that online security is shaped not only by technology, but also by human relationships and social behavior.
In their paper “Increasing Security Sensitivity with Social Proof: A Large-Scale Experimental Confirmation,” Carnegie Mellon researchers Sauvik Das, Laura Dabbish, and Jason Hong, along with Facebook researcher Adam D.I Kramer, explored the efficacy of “social proof,” a practice of showing an individual that their friends use security features with the goal of motivating that individual to adopt similar behaviors.
In recognition of their groundbreaking research, Das, Dabbish, Hong, and Kramer received an honorable mention in the National Security Agency's third annual Best Scientific Cybersecurity Paper Competition.
Their research challenged the long-standing assumption that cybersecurity decisions are made by individuals in isolation, instead showing that friends, family members, coworkers, and broader social networks strongly influence whether people adopt secure practices. Drawing on theories from social psychology and human-computer interaction, the team investigated how social influence affects behaviors such as enabling multi-factor authentication, creating strong passwords, updating software, and managing shared accounts.
The researchers translated these insights into practical tools and interventions designed to make secure behavior easier and more engaging. Their work included browser extensions that help users understand privacy settings, educational games that build cybersecurity confidence, validated frameworks for measuring security attitudes and behaviors, and behavior-change strategies that encourage people to adopt recommended security practices.
They also explored how cybersecurity unfolds in everyday life, examining password and account sharing among romantic partners, families, workplaces, and university communities to better understand how security decisions are negotiated in real-world social contexts.
By placing people and their social environments at the center of cybersecurity, Das, Dabbish, and Hong helped redefine how researchers and practitioners think about digital safety. Their work laid the foundation for evidence-based approaches that move beyond simply telling people what to do, instead designing technologies and interventions that account for how people actually make decisions, learn from one another, and balance security with the realities of everyday life. This research continues to influence the design of more usable, effective, and human-centered cybersecurity systems.
Project links: