The Carnegie Mellon University Usable Privacy and Security Laboratory (CUPS) was established in the Spring of 2004 to bring together
Carnegie Mellon University
Carnegie Mellon University (CMU) is a private research university in Pittsburgh, Pennsylvania, United States. The institution was established in 1900 by Andrew Carnegie as the Carnegie Technical Schools. In 1912, it became the Carnegie Institu ...
researchers working on a diverse set of projects related to understanding and improving the usability of
privacy
Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively.
The domain of privacy partially overlaps with security, which can include the concepts of a ...
and
security software
Computer security software or cybersecurity software is any computer program designed to influence information security. This is often taken in the context of defending computer systems or data, yet can incorporate programs designed specifically ...
and systems. The privacy and security research community has become increasingly aware that
usability
Usability can be described as the capacity of a system to provide a condition for its users to perform the tasks safely, effectively, and efficiently while enjoying the experience. In software engineering, usability is the degree to which a softw ...
problems severely impact the effectiveness of mechanisms designed to provide security and privacy in software systems. Indeed, one of the four grand research challenges in
information security
Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
and assurance identified by the
Computing Research Association in 2003 is: "Give end-users security controls they can understand and privacy they can control for the dynamic, pervasive computing environments of the future." This is the challenge that CUPS strives to address. CUPS is affiliated with Carnegie Mellon
CyLab and has members from the
Engineering and Public Policy Department, the School of Computer Science, the Electrical and Computer Engineering Department, the
Heinz College, and the
Department of Social and Decision Sciences. It is directed by
Lorrie Cranor
Lorrie Faith Cranor is an American academic who is the FORE Systems Professor of Computer Science and Engineering and Public Policy at Carnegie Mellon University, Director and Bosch Distinguished Professor in Security and Privacy Technologies of ...
.
Projects
*
P3P and computer-readable privacy policies
** Two members of the CUPS Lab are members of the
W3C
The World Wide Web Consortium (W3C) is the main international standards organization for the World Wide Web. Founded in 1994 by Tim Berners-Lee, the consortium is made up of member organizations that maintain full-time staff working together in ...
P3P Working Group, working on developing the
P3P 1.1 specification.
** In the fall of 2005,
AT&T
AT&T Inc., an abbreviation for its predecessor's former name, the American Telephone and Telegraph Company, is an American multinational telecommunications holding company headquartered at Whitacre Tower in Downtown Dallas, Texas. It is the w ...
gave the rights to the source code and trademarks surroundin
Privacy Bird their
P3P user-agent. Privacy Bird is currently maintained and distributed by the lab.
** In the summer of 2005, the lab made available to the public a "P3P-enabled search engine", known as Privacy Finder. It allowed a user to reorder search results based on whether each site complied with his or her privacy preferences. This information was gleaned from
P3P policies found on the web sites. Since 2012, Privacy Finder has been "temporarily out of service", with no indication of when service would be restored.
** Additionally, the lab archives web sites privacy policies and has been creating a toolkit to aid in the automated analysis of both
P3P policies as well as natural language privacy policies.
* Supporting trust decisions
** More recently, the lab is examining trends in phishing attacks as well as users' perceptions of these attacks to develop better methods of detecting and reporting phishing messages.
External links
The official CUPS Lab web sitePrivacy BirdPrivacy Finder
{{Carnegie Mellon University
2004 establishments in Pennsylvania
Privacy software
Schools and departments of Carnegie Mellon