Alice in warningland: a {Large-Scale} field study of browser security warning effectiveness

D Akhawe, AP Felt - … USENIX Security Symposium (USENIX Security 13), 2013 - usenix.org
We empirically assess whether browser security warnings are as ineffective as suggested by
popular opinion and previous literature. We used Mozilla Firefox and Google Chrome's in …

Why phishing still works: User strategies for combating phishing attacks

M Alsharnouby, F Alaca, S Chiasson - International Journal of Human …, 2015 - Elsevier
We have conducted a user study to assess whether improved browser security indicators
and increased awareness of phishing have led to users׳ improved ability to protect …

Do security toolbars actually prevent phishing attacks?

M Wu, RC Miller, SL Garfinkel - … of the SIGCHI conference on Human …, 2006 - dl.acm.org
Security toolbars in a web browser show security-related information about a website to help
users detect phishing attacks. Because the toolbars are designed for humans to use, they …

SoK: SSL and HTTPS: Revisiting past challenges and evaluating certificate trust model enhancements

J Clark, PC Van Oorschot - 2013 IEEE Symposium on Security …, 2013 - ieeexplore.ieee.org
Internet users today depend daily on HTTPS for secure communication with sites they intend
to visit. Over the years, many attacks on HTTPS and the certificate trust model it uses have …

Eyes wide open: The role of situational information security awareness for security‐related behaviour

L Jaeger, A Eckhardt - Information Systems Journal, 2021 - Wiley Online Library
Most contemporary studies on information security focus on largely static phenomena in
examining security‐related behaviours. We take a more dynamic, situational and …

[PDF][PDF] Crying wolf: An empirical study of ssl warning effectiveness.

J Sunshine, S Egelman, H Almuhimedi, N Atri… - USENIX security …, 2009 - usenix.org
Web users are shown an invalid certificate warning when their browser cannot validate the
identity of the websites they are visiting. While these warnings often appear in benign …

The emperor's new security indicators

SE Schechter, R Dhamija, A Ozment… - 2007 IEEE Symposium …, 2007 - ieeexplore.ieee.org
We evaluate Website authentication measures that are designed to protect users from man-
in-the-middle,'phishing', and other site forgery attacks. We asked 67 bank customers to …

[PDF][PDF] A framework for reasoning about the human in the loop

LF Cranor - 2008 - usenix.org
Many secure systems rely on a “human in the loop” to perform security-critical functions.
However, humans often fail in their security roles. Whenever possible, secure system …

Rethinking connection security indicators

AP Felt, RW Reeder, A Ainslie, H Harris… - Twelfth Symposium on …, 2016 - usenix.org
We propose a new set of browser security indicators, based on user research and an
understanding of the design challenges faced by browsers. To motivate the need for new …

End-user privacy in human–computer interaction

G Iachello, J Hong - Foundations and Trends® in Human …, 2007 - nowpublishers.com
The purpose of this article is twofold. First, we summarize research on the topic of privacy in
Human–Computer Interaction (HCI), outlining current approaches, results, and trends …