5. OSI Layer 8: The user is responsible and bears all risks

While decision-makers are reluctant to assume responsibility – and even feel they have been absolved of responsibility in many areas – the question remains how to involve stakeholders and establish a system that actually allocates responsibility for Internet security. Despite the general tendency to want to delegate this responsibility, there is a basic consensus on one point: ultimately it is the user himself who is responsible.

“I am very much in favor of personal responsibility, because the moment I ask a third party to take responsibility for me – if I say to the state, for example, ‘please, please, protect me from the Internet’ – then I give the state too much control over my private computer, I give up too much freedom in exchange for what may or may not be considered improved security. So I lose in the end.”

Ultimately it is the user’s behavior and decision-making that determines, more than anything else, whether or not he is safe on the Internet. The user himself is thus the biggest risk to his own security. Not surprisingly, decision-makers consider users to be quite naïve in this regard.

“The most common is ERROR-40. You don’t know that one? […] Error 40 means the error is sitting 40 cm from the monitor.”

“As long as we’re on the topic of data privacy, I have to say that many users really are extremely naïve when it comes to the commercial mechanism driving the whole process. A lot of people just don’t bother to ask the question, ‘why am I not paying any money here?’”

“The negligence is amazing, really. Yes, paying for virus protection can be annoying, and it’s a pain to deal with, and so on. People are gullible, etc., etc., and they’re curious and want to try things out. As a user there’s this tendency to always make these kinds of hapless moves. In IT there’s this layer model, the seven-layer ISO/OSI model, it’s actually very technical – it goes from the hard- ware through to whatever kind of application software being used, which is the 7th layer. And then everyone always says the biggest problem is the 8th layer – that’s the user.”

Opinion leaders agree that the Internet user needs to carry a large share of the responsibility for himself. It is less clear, however, where this domain of personal responsibility begins and ends. On the one hand, the user should assume responsibility for that which he alone can control. But at the same time, the average user is said to know basically nothing; he knows neither what he can control nor how to control it.

Recommendation to users: Invest in security and act smart!

For starters, the user should be considered responsible for everything that can be considered “reasonable”. The comparison is most often made to driving a car and observing basic traffic laws. In this sphere too, one is expected to possess a minimum amount of basic knowledge and obey certain rules, but can also expect from the manufacturer a minimum level of basic security (a car free from technical defects, in good working order, etc.)

“Just like when people cross the street. They need to look left and then right to make sure they don’t get run over. It’s the same here. It’s their job to inform themselves before they start doing business on the Internet.”

“If you drive drunk into a lamppost, then you are responsible. You can’t then say ‘Hey, sorry, I’m just the end user of this Opel here.”

Thus, there are certain basic civic responsibilities that apply to the Internet as well. An individual’s basic sense of right and wrong is considered a given – or at least some sort of sense.

“Risks basically originate in a lack of awareness. As soon as the awareness is there, then people behave accordingly. The risk is actually always related to usage. If you open an email, for example, and there’s an attachment and you’ve told your computer to always open and execute attachments immediately because it’s just more convenient that way, well then you’ll have the virus on your hard drive right away. You simply need to be aware – you need to know how to use the Internet. And if you’ve got that, then there actually is no security problem on the Internet.”

Often the assignment of responsibility is done in terms of platitudes. Especially things like social network privacy settings and an individual’s own online profile are considered matters that a user should be able to manage by applying basic common sense (“you’ve got to know which photos of yourself to post on Facebook”). This also applies to the use of security software and the treatment of sensitive personal data (such as TAN lists). Decision-makers often draw the comparison to the requirements for operating a motor vehicle: you don’t need to know how a car actually works, but you do have to know to fill it up with gas and to head to the service station when an unfamiliar red warning light goes on. They also see it as the user’s responsibility to proactively search for information and answers if the situation seems unfamiliar or insecure.

“Ultimately everyone is responsible themselves for what they do. If I decide to use social networks, then I am the one responsible. Sure I can always try to assign the blame and say that their rules lack transparency and so on, but at the end of the day I’m the one responsible for going to the site and finding the terms and conditions, scrutinizing them, and asking questions. And if I feel I can’t be bothered with reading all that, then it’s my job to get the information somewhere else.”

“The limits of the user’s responsibility are actually pretty clear. A responsible user needs to make sure that his TANs are secure and that he doesn’t just enter them anywhere. He needs to make sure his anti-virus protection is working, which of course does not rule out the possibility of getting infected somehow, [thinks for several seconds] and he needs to be careful and make sure that he
a) doesn’t stumble onto something on the Internet that he does not want to see and
b) that nothing happens to him on the Internet that he doesn’t want to happen. And that’s about all.”

In the view of opinion leaders, security is, first and foremost, something that users are obligated to provide themselves. Personal responsibility is not directly coupled with external responsibility, for example, in the form of a mutual agreement that stipulates which party is actually liable for which aspects of security and where the border lies between personal and external responsibility.

Trust begins where personal responsibility ends

Opinion-leaders nevertheless acknowledge that the user cannot be expected to know everything and that the user’s control over the situation is limited. Especially representatives of civil society – and policy-makers to an extent as well – tend to want to protect the user. In their view, it is not possible for a user to gage the actual consequences of a provider using his data, or the possible influence of third parties. This is partly due to the fact that personal data first needs to be combined and contextualized (i.e. via profiling) before its actual value can be assessed. But it seems that opinion-leaders have not yet agreed on where exactly the border between individual and external responsibility lies.

“Yes, personal responsibility … the question is, of course, where do I draw the line. And in my view the line is not at all clear at the moment. Surely it has been defined in some court ruling – but in practice that doesn’t help much.”

One way out of the responsibility dilemma is trust as an organizing principle that is both overriding yet relativizing. Nearly all decision-makers regard trust as a possible key to diffusing the tension between security and responsibility. Trust also provides a guideline for understanding user-provider interactions for their own purposes and activities.

“Actually I think everyone would say ‘Of course the individual carries the responsibility.’ But I believe that is demanding too much of the individual. Sure, as a proclamation I think everyone would sign it. I, too, am responsible for my own security on the Internet, but I simply cannot know everything. To an extent, I need to be able to trust the other guy.”

“The whole Internet can only function if there’s a basic level of trust, or a basic level of naiveté – take your pick. […] But there’s no way that I can control it.”

But where does a healthy level of trust end, and where does naiveté begin? On the one hand, a minimum level of experience, knowledge and Internet literacy is considered a prerequisite (see above) before a user should be allowed on to the web. On the other hand, the user should rely on his instincts and do whatever he likes until he has a bad experience and learns from it.

“You should trust the other guy so long as the other guy doesn’t take advantage of you.”

“In early childhood people’s default setting is still to basically trust other people. You’ve had little bad experience, so, in the beginning, the question is: Why should I not trust him? And then that changes. In kindergarten, as soon as that other kid hits me in the face with the shovel two or three times, I’ll start to think about whether I really trust him and whether I get close to him when he has a shovel in his hand. So everyone needs to find their own way through – and it’s the same on the Internet.”

Trust is considered a variable – and the user should apply neither too much nor too little to any given situation. This is the only way to ensure competent and secure use of the Internet.

“It’s both. You [the user] have both too much and too little trust. Sometimes there is too little trust and the result is too little e-commerce taking place. But then in other situations the users are too trusting and get taken advantage of by dishonest vendors.”

The above statement demonstrates how much the decision-makers rely on user trust. The user has to trust the vendor, otherwise one’s own business model, and even the Internet itself, will cease to function. So trust is both the solution and the problem.

Trust as the key currency on the Internet

Opinion leaders regard trust as the Internet’s key currency. It paves the way for transactions and acts as a form of capital paid in advance to the vendor, which the vendor accumulates, and which the vendor can lose again if users decide that he is out of line and no longer worthy of their trust. No business can survive on the market without earning and retaining the trust of customers. But government, too, is dependent on the people’s trust. Without trust, it loses its ability to act – for example in the area of online government services or management of citizens’ personal data.

Lack of trust triggers activity, such as efforts to improve security standards, user boycotts of certain products and services, or political activity that puts certain Internet issues on the legislative agenda
possible bans on websites with child pornography or involvement in the debate over copyright law).

Even if trust remains a matter of subjective assessment and intuition, most opinion leaders nevertheless propose rational measures to build trust and confidence. These include (a) technical security standards, (b) transparency of commercial transactions and (c) promoting education for improved media literacy.

a) Decision-makers often consider improved security to be the most important trust- building measure. This includes the development of security concepts to contain potential infrastructural risk (such as compromised IT systems, data loss, hacker attacks).

“Of course we need to make sure, just as we do with banks and other such channels, that the connections are secure and that nobody else can gain access to these PINs and customer data. For us it would be disastrous if our customer data, which might even include things like account numbers, ever turned up somewhere. That would totally destroy people’s trust in us and basically threaten our existence as a company. So this is a fundamental issue for us.”

“Trust is also extremely important when it comes to the behind-the-scenes processes, because sensitive customer data also needs to be saved and processed. And every customer – whether it’s one of Google’s business customers or an end user – every customer expects that this data is being properly secured and not being shared or distributed inappropriately.”

b) Transparency with regard to data and data-handling is considered another important trust- building measure. Decision-makers maintain that users gain trust in an online transaction if a vendor takes the time to explain certain functionalities and even outline possible breakdown scenarios (i.e., does not guarantee 100 percent security).

“Taking the time to explain something always creates trust. That’s very important in my view. Vendors should always make the effort of explaining things, for example, ‘We are managing your data in such and such a way, and we have taken the following technical precautionary measures to make sure nothing happens. And if something does happen, then the following will be done about it’ etc.”

“Trust in institutions, regulations, compliance certifications and the like – these are basic requirements before Internet users can feel secure.”

According to opinion-leaders, an investment in trust-building measures is a clear win for the reputation of a company or organization over the long term.

“The whole concept and system of security on the Internet depends on having enough trust anchors. A big company with a well-known brand is considered trustworthy, for example, but also has a lot to lose, so it will go to great lengths to preserve and continue to earn that trust.”

Especially representatives of civil society and media professionals believe that vendors do not go far enough with these assurances of transparency. While they do not want to see a „transparency bubble“, they do demand that specific user-vendor interactions be clarified and made explicit (“companies need to make clear to users how they earn their money“). Transparency with regard to vendor intentions and processes, a clearly defined commitment on their part, as well as binding enforcement mechanisms are necessary before the user can act independently and responsibly.

“I think that would be a very nice development, if we could somehow make sure that providers or vendors are simply required to provide information on the actual monetary value and whether one just wants to pay that price.”

c) Finally, educating people about the risks on the Internet and promoting media literacy, especially among children and youth, is also considered an important means for developing and establishing trust. Trust in one’s own ability is the basis for trust placed in others, and the key to correctly gauging other trust indicators. While decision-makers are in agreement on this point, it remains unclear who should be responsible for instilling this trust. While policymakers consider it their responsibility to define parameters (such as school curricula), decision-makers from other sectors suggest that government is not doing enough on this front.

“But I think it is also a social/political responsibility to point out the risk potential – in the educational system, in kindergartens, elementary schools, secondary schools up through university. I don’t think there is a single occupational field today that doesn’t require basic knowledge and competence with regard to technology and security.”

“I think schools should take on some of the responsibility in the future. I don’t mean to suggest that we should introduce a new school subject ‘Internet’, but it should be included somewhere in the curriculum. And I think there should be organized events designed to educate and raise awareness. Media also has a role to play in educating people, especially the publicly-funded media.”

Interestingly, decision-makers give little indication as to whether these trust-building measures are actually effective in the context of Internet usage. No one raises the question, whether their own concept of trust even coincides with that of the user.

Trust without security?
The alleged legal framework as fallback strategy

Do the efforts of companies and government officials to inform, clarify and improve transparency actually increase user trust and confidence? Do individual security measures really add up to create an overall feeling of confidence and willingness on the part of the user to trust a given vendor/ provider? And how much does the user even want to (have to) know?

Based on everyday experience – and results of the DIVSI Milieu Study1 – it seems that actual user behavior on the Internet cannot necessarily be explained based on an overall sense of personal security. People do not always behave rationally or sensibly. And by no means do they behave consistently. This is, on the one hand, a function of the basic attitude characteristic of an individual’s milieu (such as the “Carefree Hedonists” or the “Responsibility-driven Individuals” as identified in the DIVSI Milieu Study). On the other hand, individuals will tend to rely on their intuition or instincts if a given situation becomes too complex and can no longer be analyzed or understood. This is often the case with users in the context of Internet security. It seems, therefore, that factors such as social feedback (“over 900 million users can’t be wrong”) are more relevant to explaining individual Internet behavior than statements from vendors/providers (“your data is secure with us”).

“Trust is a very important factor on the Internet, because one doesn’t really know most of the people with whom one interacts. This can be seen especially with the social networks. You may have 600 friends, but of course they aren’t really all friends. Many of them you probably don’t know at all. Maybe you connected somehow through someone else. So it’s always a question of: ‘if I share this bit of personal information, do I trust them not to take advantage of me?’ So trust turns out to be a very important thing on the Internet, even if it’s a kind of blind trust that we don’t really bother to verify.”

For users, trust indicators seem to be largely intuitive and quantitative, as reflected in today’s popular web parlance (“250 people like this product” or “customers who bought this item also bought these items”). If I buy a product or make use of a service, it is not necessarily a conscious decision on behalf of that product or service, but simple pragmatism: It is less about making a selection and much more about joining in and taking part.

“It’s the herd instinct – really pretty mundane actually. The thinking is: ‘if a lot of people are doing it and not having any problems, then it can’t be too bad, it must be OK.’”

Trust in one’s own instincts or „feel“ for the situation is more important for users – and more expedient – than a rational analysis of opportunity vs. risk. Interestingly, while decision-makers emphasize the importance of trust-building measures, they seem to contradict this when talking about their own personal Internet behavior. Their own behavior more likely reflects the intuitive, common sense approach, and less likely involves careful analysis and a weighing of the options.

“If one looks at one’s own online behavior – and my behavior surely cannot be considered representative, because I’m definitely online more than most people and am active in very wide range of contexts – personal responsibility plays a very important role, if not the most important role. It’s about personal responsibility, common sense, reliance on your intuition and feel for the situation. It’s just the same, really, as everywhere else.”

Finally, the question remains whether a user’s intuitive feeling of trust is truly independent of other factors. Is it based solely on the sense that nothing bad will happen, because so many other users seem to be OK? The DIVSI Milieu Study revealed that 74 percent of Germans believe government and business are ultimately responsible for ensuring security on the Internet. And they place a significant amount of trust in the notion that the government will intervene as needed or that a company will assume liability in the case of fraud.

In this way, users secretly assume that “justice” will prevail in the end and that government will ultimately fulfill its obligation to protect. And users are often astonished to learn that they are actually vulnerable.

“When I give a talk at a school and tell people about all the stuff that can be found about them on the Internet, they always say to me: ‘But that should be illegal.’”

The current debate surrounding the Facebook mass party phenomenon reveals that some users feel so secure on the web, that they trust the state to absorb the costs for police deployment and damage control – which it usually then does.

“Consumers do very little fact checking. […] That basically means blind trust. But the only way I can have this kind of blind trust is because I believe that there is some kind of legal framework that will protect me in the end.”

Thus, trust in online products and services is not necessarily born out of a propensity for risk- taking or willingness to remedy damages incurred; instead it is based on faith in an implicit fallback strategy and the assumption that, ultimately, someone else will bear the responsibility. It remains to be seen who that someone will be.

  1. See the DIVSI Milieu Study, www.www.divsi.de/publikationen/ []