Lorrie Cranor profile photo

Lorrie Cranor

Professor Carnegie Mellon University

  • Pittsburgh PA

Lorrie Cranor's research focusses on usability and policy issues related to security and privacy.

Contact
Carnegie Mellon University logo

Carnegie Mellon University

View more experts managed by Carnegie Mellon University

Biography

Lorrie Faith Cranor is Director and Bosch Distinguished Professor in Security and Privacy Technologies of CyLab and FORE Systems University Professor of Computer Science and of Engineering and Public Policy at Carnegie Mellon University. She directs the CyLab Usable Privacy and Security Laboratory (CUPS) and co-directs the Privacy Engineering program. In 2016 she served as Chief Technologist at the US Federal Trade Commission. She co-founded Wombat Security, a security awareness training company acquired by Proofpoint. She founded the Symposium On Usable Privacy and Security (SOUPS) and co-founded the Conference on Privacy Engineering Practice and Respect (PEPR). She serves on the Center for Democracy and Technology (CDT) Board of Directors, the Aspen Institute Cybersecurity Group, and the advisory boards of the Future of Privacy Forum (FPF) and the Electronic Privacy Information Center (EPIC). She was elected to the ACM CHI Academy and named a fellow of ACM, IEEE, and AAAS. She received the ACM CHI Social Impact Award and Lifetime Research Award, the International Association of Privacy Professionals Privacy Leadership Award, and (with colleagues) the IEEE Cybersecurity Award for Practice. She was previously a researcher at AT&T-Labs Research. She holds a doctorate in Engineering and Policy from Washington University in St. Louis. She has authored or edited several books, including a privacy book for kids. She plays soccer, walks to work, sews her own clothing with pockets, and tries not to embarrass her three young adult children.

Areas of Expertise

Engineering and Policy
Privacy
Cybersecurity and Privacy
Computer Science
Usable Security

Media Appearances

Logging In Was Never Supposed to Be This Complicated

The Atlantic  online

2026-08-24

Cybersecurity experts will tell you that passkeys—which typically entail logging in to apps or websites with a face or fingerprint scan instead of a password—are the future. When they work properly, they’re both painless and secure. “It may get to a point where we’re all using passkeys and we don’t even know we’re using passkeys,” Lorrie Cranor, a computer-science professor at Carnegie Mellon University who researches privacy and cybersecurity, told me. “I just say ‘Log in’ and I smile at it, and it gets my passkey, and I’m logged in.”

View More

McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There

WIRED  online

2026-08-12

“The 500 pages is kind of a wake-up call,” says Lorrie Cranor, a professor at Carnegie Mellon University and director of the CyLab Security and Privacy Institute. “But it's not in a format that people will readily understand.” She says a more beneficial approach for consumers would be highly detailed disclosures during the sign-up process that lay out what’s going to be stored in your “permanent record” and how that data will be used to make specific inferences about you.

View More

Inconsistent Privacy Labels Don't Tell Users What They Are Getting

Dark Reading  online

2026-04-03

That may sound great, but just as food nutrition labels haven't solved America's obesity crisis, data privacy labels aren't enough by themselves, according to Lorrie Cranor, director and Bosch distinguished professor at Carnegie Mellon University's CyLab Security & Privacy Institute.

View More

Media

Social

Industry Expertise

Writing and Editing
Education/Learning
Security
Research

Accomplishments

Andrew Carnegie Fellow

2019

Allen Newell Award for Research Excellence

2019

Carnegie Mellon University School of Computer Science

AAAS Fellow

2020

Education

Washington University in St. Louis

M.S.

Computer Science

1996

Washington University in St. Louis

M.S.

Technology and Human Affairs

1993

Washington University in St. Louis

D.Sc.

Engineering and Policy

1996

Affiliations

  • The Future of Privacy Forum Advisory Board
  • Deep Lab : Founding member
  • Wombat Security Technologies : Co-founder

Patents

User-controllable learning of policies

US8423483B2

2010-02-11

Various embodiments are directed to a computer implemented method for updating a policy that is enforced by a computer program. In one embodiment, a computer communicates, to a user, data regarding one or more decisions made by the program over a period of time according to a policy. Each decision is made on the particular policy in force at the time the decision is made. Policy data for the policy is stored in a machine readable format.

View more

Articles

Privacy Solution or Menace? Investigating Perceptions of Radio-Frequency Sensing

USENIX Security 2025

2025

Radio-frequency sensors are often introduced as privacy-preserving alternatives to cameras, as they enable similar use cases without relying on visual data. However, researchers argue that radio-frequency sensors cause privacy risks similar to cameras and even introduce additional risks. We conducted in-depth interviews (N=14) and a large-scale vignette survey (N=510) to understand people's perceptions and privacy concerns around radio-frequency sensing.

View more

Interface Design to Support Informed Choices When Users Face Numerous Privacy Decisions

IEEE Transactions on Privacy

2025

Applications that collect personal information from users often offer numerous privacy choices. However, providing user interfaces that support multiple informed privacy choices without fatiguing users is challenging. We developed interface variations for the onboarding process of a fictional social media app that included 17 privacy choices. These interfaces varied in several ways, including the number of screens, the way the settings were bundled on each screen, and whether there were “presets” that would pre-load choices.

View more

Exploring Expandable-Grid Designs to Make iOS App Privacy Labels More Usable

Twentieth Symposium on Usable Privacy and Security (SOUPS 2024)

2024

People value their privacy but often lack the time to read privacy policies. This issue is exacerbated in the context of mobile apps, given the variety of data they collect and limited screen space for disclosures. Privacy nutrition labels have been proposed to convey data practices to users succinctly, obviating the need for them to read a full privacy policy. In fall 2020, Apple introduced privacy labels for mobile apps, but research has shown that these labels are ineffective, partly due to their complexity, confusing terminology, and suboptimal information structure. We propose a new design for mobile app privacy labels that addresses information layout challenges by representing data collection and use in a color-coded, expandable grid format.

View more