Why can’t users get security right?
This PDF slideshow is quite a refreshing, common-sense look at usability issues relating to internet security:
http://www.cs.auckland.ac.nz/~pgut001/pubs/phishing.pdf
It points out alot of the loopholes that phishing criminals can use to fool joe-user.
Unfortunately, it does not offer many good solutions or alternatives to the floors (that it highlights) in existing security techniques.
Definately worth a read though.