← Latest papers
💻 computer science

"You do understand that people don't trust technology?": Explaining Trusted Execution Environments to Non-Experts

This study finds that while non-technical explanations highlighting specific threats effectively improve non-experts' understanding of Trusted Execution Environments (TEEs), such explanations alone are insufficient to increase users' willingness to adopt the technology.

Original authors: McKenna McCall, Carolina Carreira, Miguel Flores, Lorrie Faith Cranor

Published 2026-05-27
📖 5 min read🧠 Deep dive

Original authors: McKenna McCall, Carolina Carreira, Miguel Flores, Lorrie Faith Cranor

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Idea: "You Do Understand That People Don't Trust Technology?"

Imagine you are trying to convince a nervous friend to let a stranger into their house to fix a leaky pipe. The stranger says, "Don't worry, I have a Trusted Execution Environment (TEE)."

To most people, that sounds like a fancy, confusing term. This paper asks: How do we explain what a TEE actually is to regular people without using confusing jargon, and does explaining it actually make them feel safer?

What is a TEE? (The "Secure Room" Analogy)

Think of your computer or phone as a busy, noisy office building.

  • The Main Office: This is where your regular apps run (like your browser or social media). It's open, and sometimes "bad guys" (viruses or hackers) can sneak in and steal papers from your desk.
  • The TEE: This is a secret, soundproof, bulletproof room built inside that office. Once you put your sensitive data (like your medical records or credit card number) inside this room, the door locks.
    • Even if the main office is on fire or filled with thieves, they cannot see what's happening inside the secret room.
    • Even the person who owns the building (the computer owner) cannot peek inside while the work is being done.

The goal of this study was to figure out the best way to tell a regular person about this "secret room" so they feel comfortable sharing their data.

The Experiment: Testing Different "Sales Pitches"

The researchers gathered 966 people (like you and me) and put them in two scenarios:

  1. Medical Research: Imagine sharing your health data for a study.
  2. Smart Home: Imagine buying a smart device that listens to your voice.

In both cases, the researchers told the participants: "Your data will be protected by a TEE."

Then, they gave them 12 different versions of an explanation to see which one worked best. They tested things like:

  • Technical vs. Simple: Did they use words like "integrity" and "attestation," or did they say "only authorized people can see this"?
  • Threats vs. Features: Did they explain what the TEE stops (e.g., "It stops hackers on your computer"), or just what it does?
  • Trust vs. Hardware: Did they say "It's built on trusted hardware" or "You can trust this"?

The Surprising Results

The researchers found two very different things:

1. The Best Way to Explain It (The "What It Stops" Strategy)
The explanations that helped people understand the technology the most were the ones that were:

  • Simple: No confusing tech words.
  • Specific about threats: They explicitly said, "This stops bad software on your computer from stealing your data."

Analogy: It's like telling a child, "This seatbelt stops you from flying out of the car if we crash," rather than saying, "This utilizes kinetic energy retention mechanisms." The child understands the danger being prevented, not the physics.

2. The "So What?" Problem (Understanding \neq Trust)
This was the biggest surprise. Even when the researchers gave the perfect explanation that made people understand exactly how the TEE worked, it did not make them more willing to use the technology.

  • People still felt just as nervous about sharing their data.
  • People still didn't feel their data was "completely safe."

Why?
The paper suggests that people's fears go deeper than just the technology.

  • The "Bad Apple" Fear: People worried that even if the "secret room" is secure, the people running the study or the company might still be dishonest.
  • The "Future Use" Fear: People worried that even if the data is safe now, the company might use it for something else later (like selling it).
  • The "Trust" Issue: Some people explicitly said, "I don't trust technology," or "I don't trust the word 'Trusted' in the name."

The FAQ Twist

In a second part of the study, the researchers added a "Frequently Asked Questions" (FAQ) sheet to answer people's specific doubts.

  • Did it help? Yes, people understood the technical details better.
  • Did it make them trust it? No. They still weren't willing to share their data. In fact, giving them more technical details sometimes made them realize there were more ways things could go wrong (like bugs in the code).

The Bottom Line

The paper concludes with a tough truth for tech companies:

You cannot "explain" your way out of a trust problem.

Explaining a TEE is like explaining how a vault works. You can tell someone exactly how the lock is made, how the steel is reinforced, and how the alarms work. But if they don't trust the bank manager, or if they think the bank might sell their gold to a third party, they still won't put their gold in the vault.

The study shows that while we can teach people what a TEE is, explaining the technology alone isn't enough to fix the deep-seated privacy concerns people have about who is holding the keys and what they might do with the data.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →