Alice in warningland: a {Large-Scale} field study of browser security warning effectiveness
We empirically assess whether browser security warnings are as ineffective as suggested by
popular opinion and previous literature. We used Mozilla Firefox and Google Chrome's in …
popular opinion and previous literature. We used Mozilla Firefox and Google Chrome's in …
Why phishing still works: User strategies for combating phishing attacks
We have conducted a user study to assess whether improved browser security indicators
and increased awareness of phishing have led to users׳ improved ability to protect …
and increased awareness of phishing have led to users׳ improved ability to protect …
Do security toolbars actually prevent phishing attacks?
Security toolbars in a web browser show security-related information about a website to help
users detect phishing attacks. Because the toolbars are designed for humans to use, they …
users detect phishing attacks. Because the toolbars are designed for humans to use, they …
SoK: SSL and HTTPS: Revisiting past challenges and evaluating certificate trust model enhancements
Internet users today depend daily on HTTPS for secure communication with sites they intend
to visit. Over the years, many attacks on HTTPS and the certificate trust model it uses have …
to visit. Over the years, many attacks on HTTPS and the certificate trust model it uses have …
Eyes wide open: The role of situational information security awareness for security‐related behaviour
Most contemporary studies on information security focus on largely static phenomena in
examining security‐related behaviours. We take a more dynamic, situational and …
examining security‐related behaviours. We take a more dynamic, situational and …
[PDF][PDF] Crying wolf: An empirical study of ssl warning effectiveness.
Web users are shown an invalid certificate warning when their browser cannot validate the
identity of the websites they are visiting. While these warnings often appear in benign …
identity of the websites they are visiting. While these warnings often appear in benign …
The emperor's new security indicators
SE Schechter, R Dhamija, A Ozment… - 2007 IEEE Symposium …, 2007 - ieeexplore.ieee.org
We evaluate Website authentication measures that are designed to protect users from man-
in-the-middle,'phishing', and other site forgery attacks. We asked 67 bank customers to …
in-the-middle,'phishing', and other site forgery attacks. We asked 67 bank customers to …
[PDF][PDF] A framework for reasoning about the human in the loop
LF Cranor - 2008 - usenix.org
Many secure systems rely on a “human in the loop” to perform security-critical functions.
However, humans often fail in their security roles. Whenever possible, secure system …
However, humans often fail in their security roles. Whenever possible, secure system …
Rethinking connection security indicators
We propose a new set of browser security indicators, based on user research and an
understanding of the design challenges faced by browsers. To motivate the need for new …
understanding of the design challenges faced by browsers. To motivate the need for new …
End-user privacy in human–computer interaction
G Iachello, J Hong - Foundations and Trends® in Human …, 2007 - nowpublishers.com
The purpose of this article is twofold. First, we summarize research on the topic of privacy in
Human–Computer Interaction (HCI), outlining current approaches, results, and trends …
Human–Computer Interaction (HCI), outlining current approaches, results, and trends …