Cormac Herley
- Wrote So Long, And No Thanks for the Externalities (2009) on the rational rejection of security advice
- Long-running work on the economics of passwords, phishing, and attacker incentives
Bio
Cormac Herley is a principal researcher at Microsoft Research. His 2009 paper argued that users reject security advice because the arithmetic favours rejection: the advice imposes certain, measurable effort now against a small and uncertain expected loss, and the people giving the advice never account for the aggregate cost of following it.
Profile built from public research and publication records.
Where their work shows up
This is the argument that made "blame the user" untenable as a security posture. If a control only works when millions of people absorb a cost nobody measured, the control is the problem. It is the intellectual basis for judging authentication by friction as well as strength, and for the conclusion that passwordless methods succeed where policy exhortation failed. See credential stuffing, MFA fatigue, and help desk social engineering.
Related on Start with Identity
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev