Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans.
As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based brute force techniques by, what, 10 seconds?
An article on Wired gets read and forgotten. An article about passwords in the NYT gets dismissed as "newfangled kids". Ten million credit cards stolen - one of which is yours - gets remembered. Having your FB account manually and maliciously defaced changes your life. That's visibility that no article or book can sell.
Consumers are supposed to start using tools like KeePass or LastPass. Adding symbols to a simple 6-character password doesn't help. Adding symbols to a high-entropy 20-character password and never using a password twice makes you basically immune to this kind of thing.
On the consumer end - what needs to be done is a massive education campaign, kept reasonably simple. It was done in 2000-2003 for anti-virus and it (roughly) worked for the 80% or so of the Windows world that did what they were told (by the mainstream press).
The mainstream press has (so far) done a terrible job on password education. You see long lists of rules that nobody but a security professional or hacker would follow. It needs to be boiled down to something simple, like:
Use a password manager to assign unique, random 15 character passwords for all accounts, protecting them with a strong master password.
I put together a guide based on this concept here:
Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans.
As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based brute force techniques by, what, 10 seconds?