Lorrie Cranor profile photo

Lorrie Cranor

Professor Carnegie Mellon University

  • Pittsburgh PA

Lorrie Cranor's research focusses on usability and policy issues related to security and privacy.

Contact
Carnegie Mellon University logo

Carnegie Mellon University

View more experts managed by Carnegie Mellon University

Biography

Lorrie Faith Cranor is Director and Bosch Distinguished Professor in Security and Privacy Technologies of CyLab and FORE Systems University Professor of Computer Science and of Engineering and Public Policy at Carnegie Mellon University. She directs the CyLab Usable Privacy and Security Laboratory (CUPS) and co-directs the Privacy Engineering program. In 2016 she served as Chief Technologist at the US Federal Trade Commission. She co-founded Wombat Security, a security awareness training company acquired by Proofpoint. She founded the Symposium On Usable Privacy and Security (SOUPS) and co-founded the Conference on Privacy Engineering Practice and Respect (PEPR). She serves on the Center for Democracy and Technology (CDT) Board of Directors, the Aspen Institute Cybersecurity Group, and the advisory boards of the Future of Privacy Forum (FPF) and the Electronic Privacy Information Center (EPIC). She was elected to the ACM CHI Academy and named a fellow of ACM, IEEE, and AAAS. She received the ACM CHI Social Impact Award and Lifetime Research Award, the International Association of Privacy Professionals Privacy Leadership Award, and (with colleagues) the IEEE Cybersecurity Award for Practice. She was previously a researcher at AT&T-Labs Research. She holds a doctorate in Engineering and Policy from Washington University in St. Louis. She has authored or edited several books, including a privacy book for kids. She plays soccer, walks to work, sews her own clothing with pockets, and tries not to embarrass her three young adult children.

Areas of Expertise

Engineering and Policy
Privacy
Cybersecurity and Privacy
Computer Science
Usable Security

Media Appearances

Logging In Was Never Supposed to Be This Complicated

The Atlantic  online

2026-08-24

Cybersecurity experts will tell you that passkeys—which typically entail logging in to apps or websites with a face or fingerprint scan instead of a password—are the future. When they work properly, they’re both painless and secure. “It may get to a point where we’re all using passkeys and we don’t even know we’re using passkeys,” Lorrie Cranor, a computer-science professor at Carnegie Mellon University who researches privacy and cybersecurity, told me. “I just say ‘Log in’ and I smile at it, and it gets my passkey, and I’m logged in.”

View More

McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There

WIRED  online

2026-08-12

“The 500 pages is kind of a wake-up call,” says Lorrie Cranor, a professor at Carnegie Mellon University and director of the CyLab Security and Privacy Institute. “But it's not in a format that people will readily understand.” She says a more beneficial approach for consumers would be highly detailed disclosures during the sign-up process that lay out what’s going to be stored in your “permanent record” and how that data will be used to make specific inferences about you.

View More

Inconsistent Privacy Labels Don't Tell Users What They Are Getting

Dark Reading  online

2026-04-03

That may sound great, but just as food nutrition labels haven't solved America's obesity crisis, data privacy labels aren't enough by themselves, according to Lorrie Cranor, director and Bosch distinguished professor at Carnegie Mellon University's CyLab Security & Privacy Institute.

View More

Media

Social

Industry Expertise

Writing and Editing
Education/Learning
Security
Research

Accomplishments

Andrew Carnegie Fellow

2019

Allen Newell Award for Research Excellence

2019

Carnegie Mellon University School of Computer Science

AAAS Fellow

2020

Education

Washington University in St. Louis

M.S.

Computer Science

1996

Washington University in St. Louis

M.S.

Technology and Human Affairs

1993

Washington University in St. Louis

D.Sc.

Engineering and Policy

1996

Affiliations

  • The Future of Privacy Forum Advisory Board
  • Deep Lab : Founding member
  • Wombat Security Technologies : Co-founder

Patents

User-controllable learning of policies

US8423483B2

2010-02-11

Various embodiments are directed to a computer implemented method for updating a policy that is enforced by a computer program. In one embodiment, a computer communicates, to a user, data regarding one or more decisions made by the program over a period of time according to a policy. Each decision is made on the particular policy in force at the time the decision is made. Policy data for the policy is stored in a machine readable format.

View more

Articles

Quantifying Risk Perception and Scam Response Among International and Domestic US University Students

Twenty Second Symposium On Usable Privacy and Security (SOUPS 2026)

2026

We conducted an online survey of 1,074 students from five U.S. universities to examine and quantify the differences between domestic and international students’ scam encounters, engagement behaviors, reporting tendencies, and exposure to anti-scam training. International students were significantly more likely than domestic students to say they would engage with scammers when presented with suspicious phone-call and text-message scenarios, but also more likely to disengage in our suspicious-rental email scenario.

View more

From "Be Careful" to "Here's Why": Investigating User Reasoning with Context-Specific SMS Scam Warnings

2026 IEEE Symposium on Security and Privacy

2026

SMS-based scams continue to pose a persistent security threat, yet today's mobile warning interfaces often provide generic alerts that users may overlook. In other domains, context-specific explanations have improved users' ability to evaluate malicious content, and advances in generative AI (GAI) make it feasible to generate such explanations at scale. While service providers are now exploring similar approaches for SMS, it remains unclear how to best present contextual information so that users can act on it appropriately. We conducted a task-based interview study (n=20) with US-based Android users in which participants assessed SMS messages using an inbox-style interface.

View more

What Adults Will (and Won't) Do to Prove Their Age: Empirical Evidence from a Deceptive Web Experiment

USENIX Security 2026

2026

As age verification laws proliferate across the United States and internationally, limited empirical evidence exists on how adults actually respond to these systems in practice. We conducted an IRB-approved, deceptive web experiment (n = 1,635) to examine how different age verification methods affect adults' decisions to access age-restricted content. Participants, recruited to evaluate R-rated movie clips, were randomly assigned to one of seven verification conditions: checkbox self-attestation, government-issued ID upload (with varying privacy reassurances), government-issued ID with liveness check, AI facial age estimation, or email age estimation. Completion rates varied substantially by method.

View more