M. Angela Sasse
- Co-authored Users Are Not the Enemy (1999) with Anne Adams
- Founded human-centred security as a research field
- Long-running work on the hidden organizational cost of security controls
Bio
M. Angela Sasse co-authored "Users Are Not the Enemy" with Anne Adams in 1999, at University College London, and built human-centred security into a research field. The paper showed that password workarounds, reuse, writing credentials down, sharing them, are produced by the policy rather than by careless people.
Profile built from public academic and publication records.
Where their work shows up
Every argument for passkeys, for dropping forced rotation, and for treating a help-desk reset queue as a security signal rather than an operational cost traces to this line of work. It also reframed what a control costs: if a policy generates ten thousand workarounds, the workarounds are the real system. See help desk social engineering, password spraying, and what is passwordless.
Related on Start with Identity
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev