"I'm trying not to get hacked:" How Adults with Intellectual and Developmental Disabilities Navigate Security and Privacy Notifications
This paper investigates how adults with intellectual and developmental disabilities perceive and respond to security and privacy notifications through a user study, revealing that their decision-making is shaped by context, unfamiliar terminology, and outcome uncertainty, and proposing design strategies to enhance cognitive accessibility and support safe user actions.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Every day, digital life asks us to make small, critical choices. A website asks if we want to share our location. A bank sends an alert that someone might be trying to log in. A phone asks permission to send a notification. These are security and privacy notifications, the digital equivalent of a guard at a gate or a sign on a door. For most people, these prompts are a routine part of using technology, even if they are often ignored or clicked away without much thought. But for adults with intellectual and developmental disabilities, these same moments can be confusing, intimidating, or impossible to navigate. Intellectual and developmental disabilities describe a wide range of conditions where a person may have challenges with reasoning, learning, or handling daily tasks. These challenges do not mean a person cannot use technology; many adults with these conditions use smartphones, computers, and the internet to work, socialize, and manage their lives. However, the standard way computers ask for permission or warn of danger is often built for a mind that processes information differently than theirs. When a system fails to communicate clearly, it does not just create frustration; it can leave a person vulnerable to scams, identity theft, or the loss of their personal data.
Researchers at the University of Wisconsin–Madison set out to understand exactly how adults with intellectual and developmental disabilities experience these digital warnings. They did not simply ask people what they thought; they watched them interact with real-world scenarios. The team recruited seven adults, aged 19 to 42, who had various diagnoses including Down syndrome and autism spectrum disorder. Some participants worked with a support person, such as a parent or caregiver, while others worked alone. The researchers created a safe, controlled environment where participants used a computer and a smartphone to perform everyday tasks, like checking email or looking up the weather. Hidden within these tasks were realistic security prompts: a warning that a website was dangerous, a request to allow cookies, a two-step verification code, and a fake email from a hacker. The goal was to see how these individuals interpreted the messages, what confused them, and how they decided what to do.
The study revealed that the biggest hurdles were not always the technical words themselves, but how the messages fit into the flow of what the person was already doing. When a notification appeared, participants often tried to understand it based on the task at hand rather than the message's actual content. For example, when a cookie consent banner appeared while someone was trying to log in, they often assumed they had to click "Allow" just to proceed, treating it like a gate they had to open rather than a choice about their data. Similarly, when a warning about a dangerous download appeared, some participants thought the warning itself was the thing blocking them, rather than the file they had tried to download. The context of the screen and the task they were trying to finish shaped their understanding more than the words on the screen did.
Participants also relied heavily on their everyday experiences to make sense of unfamiliar terms. When they saw the word "cookies" in a privacy banner, many thought of the sweet food they could eat, not the small pieces of data websites use to track them. When they saw a red warning sign, they understood it as "dangerous" because red is the color of stop signs and danger in the real world. This strategy of using familiar anchors helped them navigate the unknown, but it sometimes led to mistakes. A participant might think a permission request was about sharing a location with a friend, rather than a company tracking their movements, because the language reminded them of a social interaction they knew. The researchers found that simply simplifying the language was not enough; the meaning of a word changed depending on where it appeared and what the person was doing at that moment.
Uncertainty was a powerful force in how these participants reacted. When they did not know what would happen if they clicked a button, they often hesitated, avoided the screen, or looked to someone else for help. One participant paused for seven seconds before nervously asking if they were allowed to proceed with a security check. Another let a dangerous download warning disappear without clicking it because they were afraid that clicking the warning itself might be dangerous. This hesitation was not just a lack of confidence; it was a rational response to a system that did not clearly explain the consequences of an action. When the outcome was unclear, the safest choice for many was to do nothing or to ask a trusted person. This behavior highlighted a key finding: these adults often make security decisions interdependently, relying on family members or caregivers to confirm their choices. They do not always seek to be independent in the traditional sense; they seek to be supported.
Based on these observations, the researchers proposed three ways to make security notifications better for everyone, but especially for those with cognitive differences. First, designers need to go beyond just using simple words. They must ensure that the meaning of a message stays clear regardless of the task the user is performing. If a notification asks for permission, it should clearly state what is being shared and with whom, without relying on the user to guess based on the surrounding screen. Second, the connection between an action and its result must be transparent. Instead of just saying "Secure your account," a notification could briefly show what will happen next, such as "Clicking this will send a code to your phone." This helps the user know what to expect before they commit to a choice. Finally, systems should be designed to allow for interdependent decision-making. This means creating interfaces that make it easy and safe for a user to pause, ask for help, or bring in a trusted person without feeling like they have failed. A notification could explicitly state that it is okay to step away and ask someone for advice, reducing the pressure to decide instantly.
The study involved a small group of seven people, so the findings suggest patterns rather than proving rules for every single person with a disability. However, the depth of the interaction provided a clear picture of where current systems fail. The researchers found that when security prompts are designed without considering how people actually think and act in the moment, they create barriers that can be dangerous. By making these digital gates clearer, more transparent, and more open to support, technology can become safer and more inclusive for the millions of adults with intellectual and developmental disabilities who rely on it every day. The goal is not to remove the need for security, but to make sure that the people who need protection the most are not left behind by the very systems meant to protect them.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.