Lorrie Cranor
Professor
- Pittsburgh PA UNITED STATES
Lorrie Cranor's research focusses on usability and policy issues related to security and privacy.
Biography
Areas of Expertise
Media Appearances
Logging In Was Never Supposed to Be This Complicated
The Atlantic online
2026-08-24
Cybersecurity experts will tell you that passkeys—which typically entail logging in to apps or websites with a face or fingerprint scan instead of a password—are the future. When they work properly, they’re both painless and secure. “It may get to a point where we’re all using passkeys and we don’t even know we’re using passkeys,” Lorrie Cranor, a computer-science professor at Carnegie Mellon University who researches privacy and cybersecurity, told me. “I just say ‘Log in’ and I smile at it, and it gets my passkey, and I’m logged in.”
McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There
WIRED online
2026-08-12
“The 500 pages is kind of a wake-up call,” says Lorrie Cranor, a professor at Carnegie Mellon University and director of the CyLab Security and Privacy Institute. “But it's not in a format that people will readily understand.” She says a more beneficial approach for consumers would be highly detailed disclosures during the sign-up process that lay out what’s going to be stored in your “permanent record” and how that data will be used to make specific inferences about you.
Inconsistent Privacy Labels Don't Tell Users What They Are Getting
Dark Reading online
2026-04-03
That may sound great, but just as food nutrition labels haven't solved America's obesity crisis, data privacy labels aren't enough by themselves, according to Lorrie Cranor, director and Bosch distinguished professor at Carnegie Mellon University's CyLab Security & Privacy Institute.
The book that could change how kids learn about digital privacy
Fast Company online
2026-01-04
Lorrie Faith Cranor’s latest effort to educate people about privacy is a short, colorfully illustrated book written for an audience who probably can’t read it yet.
This new children’s book is a bedtime story for the AI age
The Washington Post online
2025-12-05
Lorrie Cranor influenced what you know about digital privacy. Now she’s aiming for preschoolers.
You'll No Longer Need to Set a Password With New Microsoft Accounts
CNET online
2025-05-02
Lorrie Cranor (CyLab) supports the security benefits of passkeys over passwords but cautions that "usability" remains a concern—especially when users lose or upgrade devices or share accounts. She emphasized that companies must "support users who run into problems" by offering reliable fallback options.
Visit this store for a free iris scan to ‘prove’ you’re human, not AI
The Washington Post online
2025-05-02
On launch day for World ID, a digital identity system backed by iris scans, people enrolled by having their eyes scanned to prove they’re human amid growing concerns over AI impersonation and privacy. “Now I have features from the scan of my iris encrypted and stored on my phone, but if somebody else gets access to my phone or if a robot takes over my phone, does that mean that they can demonstrate that they’re human or maybe even me?" said Lorrie Cranor (CyLab) who is skeptical of the product.
Thieves took their iPhones. Apple won’t give their digital lives back.
Washington Post online
2025-04-20
Iphone theft victims are taking Apple to court to reclaim their personal data. “I find it odd that Apple is fighting this without explaining their rationale," said Lorrie Cranor (CyLab).
New password guidelines: What to know
WBUR online
2024-12-03
“Some people are concerned about them because they say, ‘What if my password manager gets hacked?’ Or every now and then you'll read a news report that a big password manager has had a security problem.
“The reality is that that doesn't happen very often. And when it does happen, usually you're informed right away. And so, as a result of these occasional breaches, there hasn't been a lot of damage, relatively speaking."
Annoying Password Rules Actually Make Us Less Secure
The Wall Street Journal online
2023-03-11
Does your company network or a frequently visited website force you to come up with a new password because it has declared your old one is past its expiration date?
How to tell if a gadget is secure? Look for this new government seal.
The Washington Post online
2023-07-19
Professor Lorrie Cranor of Carnegie Mellon University, whose research includes ways to make better security and privacy disclosures to users, said she hopes the final standard doesn’t gloss over privacy.
Mandatory password updates are passe
The Washington Post online
2022-08-18
“Most people, if they know they're going to have to change their password on a regular basis, they will pick a relatively weaker password and use a pattern for how they change it,” Lorrie Cranor, director of CyLab Security and Privacy Institute at Carnegie Mellon University, told me. And weaker passwords that are easy to predict are catnip for malicious hackers.
Google Settings Still Confusing After $85 Million Lawsuit Over How Confusing They Were
Gizmodo online
2022-10-05
“There’s a lot of fine print when you pause location history. Most people aren’t going to read it, and even if you do, it is confusing,” says Lorrie Cranor, a professor at Carnegie Mellon University whose research includes privacy settings and interfaces. “I’m a privacy expert and I still find it difficult to understand exactly what is getting turned off.”
Personalities of Pittsburgh: Lorrie Cranor is securing privacy in the digital age
Pittsburgh Business Times online
2022-09-30
Lorrie Cranor has dedicated her career to cybersecurity and protecting personal information.
Media
Social
Industry Expertise
Accomplishments
Andrew Carnegie Fellow
2019
Allen Newell Award for Research Excellence
2019
Carnegie Mellon University School of Computer Science
AAAS Fellow
2020
Alumni Achievement Award
2019
McKelvey School of Engineering, Washington University in St. Louis
Distinguished Professor of Engineering Award
2022
Carnegie Mellon University College of Engineering
Education
Washington University in St. Louis
M.S.
Computer Science
1996
Washington University in St. Louis
M.S.
Technology and Human Affairs
1993
Washington University in St. Louis
D.Sc.
Engineering and Policy
1996
Washington University in St. Louis
B.S.
Engineering and Public Policy
1992
Affiliations
- The Future of Privacy Forum Advisory Board
- Deep Lab : Founding member
- Wombat Security Technologies : Co-founder
Links
Patents
User-controllable learning of policies
US8423483B2
2010-02-11
Various embodiments are directed to a computer implemented method for updating a policy that is enforced by a computer program. In one embodiment, a computer communicates, to a user, data regarding one or more decisions made by the program over a period of time according to a policy. Each decision is made on the particular policy in force at the time the decision is made. Policy data for the policy is stored in a machine readable format.
Articles
Quantifying Risk Perception and Scam Response Among International and Domestic US University Students
Twenty Second Symposium On Usable Privacy and Security (SOUPS 2026)2026
We conducted an online survey of 1,074 students from five U.S. universities to examine and quantify the differences between domestic and international students’ scam encounters, engagement behaviors, reporting tendencies, and exposure to anti-scam training. International students were significantly more likely than domestic students to say they would engage with scammers when presented with suspicious phone-call and text-message scenarios, but also more likely to disengage in our suspicious-rental email scenario.
From "Be Careful" to "Here's Why": Investigating User Reasoning with Context-Specific SMS Scam Warnings
2026 IEEE Symposium on Security and Privacy2026
SMS-based scams continue to pose a persistent security threat, yet today's mobile warning interfaces often provide generic alerts that users may overlook. In other domains, context-specific explanations have improved users' ability to evaluate malicious content, and advances in generative AI (GAI) make it feasible to generate such explanations at scale. While service providers are now exploring similar approaches for SMS, it remains unclear how to best present contextual information so that users can act on it appropriately. We conducted a task-based interview study (n=20) with US-based Android users in which participants assessed SMS messages using an inbox-style interface.
What Adults Will (and Won't) Do to Prove Their Age: Empirical Evidence from a Deceptive Web Experiment
USENIX Security 20262026
As age verification laws proliferate across the United States and internationally, limited empirical evidence exists on how adults actually respond to these systems in practice. We conducted an IRB-approved, deceptive web experiment (n = 1,635) to examine how different age verification methods affect adults' decisions to access age-restricted content. Participants, recruited to evaluate R-rated movie clips, were randomly assigned to one of seven verification conditions: checkbox self-attestation, government-issued ID upload (with varying privacy reassurances), government-issued ID with liveness check, AI facial age estimation, or email age estimation. Completion rates varied substantially by method.
Passing Down Passwords: How Older Adults Approach Postmortem Account Access and Digital Estate Planning
CHI 20262026
Traditional estate planning practices enable people to provide their heirs access to the assets left behind but are often insufficient for the transfer and management of online accounts. To understand how estate planning practices could be improved, we conducted 21 semi-structured interviews with older adults in the United States that explored their practices, concerns, and needs regarding postmortem online account access and management. We encountered few formalized digital estate planning practices; many participants use their credential management practices—primarily pen-and-paper—to provide postmortem account access.
Privacy Solution or Menace? Investigating Perceptions of Radio-Frequency Sensing
USENIX Security 20252025
Radio-frequency sensors are often introduced as privacy-preserving alternatives to cameras, as they enable similar use cases without relying on visual data. However, researchers argue that radio-frequency sensors cause privacy risks similar to cameras and even introduce additional risks. We conducted in-depth interviews (N=14) and a large-scale vignette survey (N=510) to understand people's perceptions and privacy concerns around radio-frequency sensing.
Interface Design to Support Informed Choices When Users Face Numerous Privacy Decisions
IEEE Transactions on Privacy2025
Applications that collect personal information from users often offer numerous privacy choices. However, providing user interfaces that support multiple informed privacy choices without fatiguing users is challenging. We developed interface variations for the onboarding process of a fictional social media app that included 17 privacy choices. These interfaces varied in several ways, including the number of screens, the way the settings were bundled on each screen, and whether there were “presets” that would pre-load choices.
Design and Evaluation of Privacy-Preserving Protocols for Agent-Facilitated Mobile Money Services in Kenya
SOUPS 20252025
Mobile Money (MoMo), a technology that allows users to complete financial transactions using a mobile phone without requiring a bank account, is a common method for processing financial transactions in Africa and other developing regions. Users can deposit and withdraw money with the help of human agents. During deposit and withdraw operations, know-your-customer (KYC) processes require agents to access and verify customer information such as name and ID number, which can introduce privacy and security risks.
Exploring Expandable-Grid Designs to Make iOS App Privacy Labels More Usable
Twentieth Symposium on Usable Privacy and Security (SOUPS 2024)2024
People value their privacy but often lack the time to read privacy policies. This issue is exacerbated in the context of mobile apps, given the variety of data they collect and limited screen space for disclosures. Privacy nutrition labels have been proposed to convey data practices to users succinctly, obviating the need for them to read a full privacy policy. In fall 2020, Apple introduced privacy labels for mobile apps, but research has shown that these labels are ineffective, partly due to their complexity, confusing terminology, and suboptimal information structure. We propose a new design for mobile app privacy labels that addresses information layout challenges by representing data collection and use in a color-coded, expandable grid format.
What do Privacy Advertisements Communicate to Consumers?
Proceedings on Privacy Enhancing Technologies2024
When companies release marketing materials aimed at promoting their privacy practices or highlighting specific privacy features, what do they actually communicate to consumers? In this paper, we explore the impact of privacy marketing on: (1) consumers’ attitudes toward the organizations providing the campaigns, (2) overall privacy awareness, and (3) the actionability of suggested privacy advice. To this end, we investigated the impact of four privacy advertising videos and one privacy game published by five different technology companies.
Crumbling Cookie Categories: Deconstructing Common Cookie Categories to Create Categories that People Understand
Proceedings on Privacy Enhancing Technologies2024
Users of online services often encounter cookie banners that ask them to consent to different categories of cookies. Frequently, these categories are labelled using the four categories defined by the 2012 Cookie Guide from the UK's International Chamber of Commerce (ICC). However, prior research suggests that users have difficulty understanding what these category labels actually mean. We conducted a four-part study to identify labels that more intuitively convey the four cookie categories. First, we crowd sourced new category labels. We then evaluated users' comprehension and sentiment towards the labels in a series of surveys focused on definitions and hypothetical scenarios.
Data Safety vs. App Privacy: Comparing the Usability of Android and iOS Privacy Labels
Proceedings on Privacy Enhancing Technologies2024
Privacy labels---standardized, compact representations of data collection and data use practices---are often presented as a solution to the shortcomings of privacy policies. Apple introduced mandatory privacy labels for apps in its App Store in December 2020; Google introduced mandatory labels for Android apps in July 2022. iOS app privacy labels have been evaluated and critiqued in prior work. In this work, we evaluated Android Data Safety Labels and explored how differences between the two label designs impact user comprehension and label utility.
Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and Behavior
Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI '24)2024
The U.S. Government is developing a package label to help consumers access reliable security and privacy information about Internet of Things (IoT) devices when making purchase decisions. The label will include the U.S. Cyber Trust Mark, a QR code to scan for more details, and potentially additional information. To examine how label information complexity and educational interventions affect comprehension of security and privacy attributes and label QR code use, we conducted an online survey with 518 IoT purchasers.
"It was honestly just gambling": Investigating the Experiences of Teenage Cryptocurrency Users on Reddit
Twentieth Symposium on Usable Privacy and Security (SOUPS 2024)2024
Despite fears that minors may use unregulated cryptocurrency exchanges to gain access to risky investments, little is known about the experience of underage cryptocurrency users. To learn how teenagers access digital assets and the risks they encounter while using them, we conducted a multi-stage, inductive content analysis of 1,676 posts made to teenage communities on Reddit containing keywords related to cryptocurrency.
Are consumers willing to pay for security and privacy of IoT devices?
Proceedings of the 32nd USENIX Conference on Security Symposium (SEC '232023
Internet of Things (IoT) device manufacturers provide little information to consumers about their security and data handling practices. Therefore, IoT consumers cannot make informed purchase choices around security and privacy. While prior research has found that consumers would likely consider security and privacy when purchasing IoT devices, past work lacks empirical evidence as to whether they would actually pay more to purchase devices with enhanced security and privacy. To fill this gap, we conducted a two-phase incentive-compatible online study with 180 Prolific participants.
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels
CHI '22: Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems2022
Apple announced the introduction of app privacy details to their App Store in December 2020, marking the first ever real-world, large-scale deployment of the privacy nutrition label concept, which had been introduced by researchers over a decade earlier. The Apple labels are created by app developers, who self-report their app’s data practices. In this paper, we present the first study examining the usability and understandability of Apple’s privacy nutrition label creation process from the developer’s perspective.
Identifying User Needs for Advertising Controls on Facebook
Proceedings of the ACM on Human-Computer Interaction2022
We conducted an online survey and remote usability study to explore user needs related to advertising controls on Facebook and determine how well existing controls align with these needs. Our survey results highlight a range of user objectives related to controlling Facebook ads, including being able to select what ad topics are shown or what personal information is used in ad targeting.
“Okay, whatever”: An Evaluation of Cookie Consent Interfaces
CHI '22: Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems2022
Many websites have added cookie consent interfaces to meet regulatory consent requirements. While prior work has demonstrated that they often use dark patterns — design techniques that lead users to less privacy-protective options — other usability aspects of these interfaces have been less explored. This study contributes a comprehensive, two-stage usability assessment of cookie consent interfaces. We first inspected 191 consent interfaces against five dark pattern heuristics and identified design choices that may impact usability. We then conducted a 1,109-participant online between-subjects experiment exploring the usability impact of seven design parameters.
Understanding iOS Privacy Nutrition Labels: An Exploratory Large-Scale Analysis of App Store Data
CHI EA '22: Extended Abstracts of the 2022 CHI Conference on Human Factors in Computing Systems2022
Since December 2020, the Apple App Store has required all developers to create a privacy label when submitting new apps or app updates. However, there has not been a comprehensive study on how developers responded to this requirement. We present the first measurement study of Apple privacy nutrition labels to understand how apps on the U.S. App Store create and update privacy labels.
Less is Not More: Improving Findability and Actionability of Privacy Controls for Online Behavioral Advertising
CHI '23: Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems2023
Tech companies that rely on ads for business argue that users have control over their data via ad privacy settings. However, these ad settings are often hidden. This work aims to inform the design of findable ad controls and study their impact on users’ behavior and sentiment. We iteratively designed ad control interfaces that varied in the setting’s (1) entry point (within ads, at the feed’s top) and (2) level of actionability, with high actionability directly surfacing links to specific advertisement settings, and low actionability pointing to general settings pages (which is reminiscent of companies’ current approach to ad controls).
Practical Recommendations for Stronger, More Usable Passwords Combining Minimum-strength, Minimum-length, and Blocklist Requirements
CCS 20202020
Multiple mechanisms exist to encourage users to create stronger passwords, including minimum-length and character-class requirements, prohibiting blocklisted passwords, and giving feedback on the strength of candidate passwords. Despite much research, there is little definitive, scientific guidance on how these mechanisms should be combined and configured to best effect. Through two online experiments, we evaluated combinations of minimum-length and character-class requirements, blocklists, and a minimum-strength requirement that requires passwords to exceed a strength threshold according to neural-network-driven password-strength estimates.