Having decided to focus attention on the "weak link" of human fallibility, a growing number of security researchers are discovering the US Government's regulations that govern human subject research. This paper discusses those regulations, their application to research on security and usability, and presents strategies for negotiating the Institutional Review Board (IRB) approval process. It argues that a strict interpretation of regulations has the potential to stymie security research.
Simson L. Garfinkel