So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users. In this 2009 work from the New Security Paradigms Workshop, Cormac Herley evaluates passwords, URL inspection and certificate warnings. He finds that rejecting security advice can be rational when compliance costs exceed the loss the advice is expected to prevent. This gives defenders a way to assess guidance, although calculations using victimisation, cleanup-time and wage inputs depend on those inputs. An externality here is a compliance cost shifted from the advice-giver to the user population. The person or organization issuing guidance can recommend work without bearing that population-wide burden. Herley therefore uses a break-even rule: added cost should be smaller than the reduction in incident probability multiplied by the harm avoided. In plain terms, advice is worthwhile only when the expected loss it prevents outweighs what compliance costs. That reframes the question from “Is this safer?” to “Is the extra safety worth what users must do?” Herley considers password guidance, inspecting URLs for phishing, and certificate warnings. He asks whether each burden is justified by the probability and size of the loss it can avoid. The practical value is testability: defenders can compare costs with harm reduction, focus guidance on people at risk, and stop repeating advice that fails that comparison. Herley works through passwords, URL inspection and certificate warnings as economic comparisons. For URL inspection, his calculation depends on then-current victimisation, cleanup-time and wage inputs. For passwords, he considers whether strength advice addresses phishing and keylogging, and how reuse assumptions affect the burden of unique passwords. He also evaluates observed certificate warnings. His test compares the cost of compliance with the reduction in the probability of harm multiplied by the harm itself. For passwords, stronger-password advice can be irrelevant to phishing and keylogging attacks. Unique-password advice also increases burden under the analysis's reuse assumptions. Using a reported average reuse factor of 3.9 sites, Herley estimates that eliminating reuse multiplies the work users must do. The finding is conditional: password guidance should be matched to the attacks it can affect and assessed against its compliance cost. Herley's URL calculation illustrates population-scale burden. Using victimisation, cleanup-time and wage inputs, the analysis valued a minute per day of URL inspection at $15.9 billion annually. That was roughly 164 times the phishing-harm input used in the same calculation. This comparison supports the economic argument under those assumptions. Because the result depends on its inputs, it should not be transferred unchanged to another setting. The estimates do not automatically carry into other environments. The URL result depends on the victimisation rate, cleanup time and wage inputs used, so different conditions can change the balance. The certificate-warning conclusion is also narrower than a universal rule: Herley characterized the warnings he observed as effectively all false positives, but that observation alone cannot establish the same result for every deployment. Finally, the argument analyzes why rejection can be rational; it does not advise users to disregard policies or security guidance. For security teams, the framework suggests treating advice as a control that must justify its total cost. Measure the harm at stake, estimate how much the guidance reduces incident probability, and count the compliance burden. Then target people at higher risk, prioritize guidance that clears the break-even test, and retire advice that does not. Identity teams, phishing-awareness teams and security architects can apply that process to the kinds of controls examined here, while still enforcing required policy. Herley's evidence supports a disciplined, case-by-case question: does expected harm reduction outweigh the burden shifted to users? Security leaders and teams designing password, phishing and warning controls should use measurements rather than assume every recommended action is worth its cost. They should not conclude that all rejected advice is bad, that all rejection is wise, or that users have permission to ignore policy. The useful takeaway is to measure, target, prioritize and retire guidance when it fails the cost-benefit test.