首页> 外文会议>IEEE Symposium on Security and Privacy >'If HTTPS Were Secure, I Wouldn't Need 2FA' - End User and Administrator Mental Models of HTTPS
【24h】

'If HTTPS Were Secure, I Wouldn't Need 2FA' - End User and Administrator Mental Models of HTTPS

机译:“如果HTTPS是安全的,则不需要2FA”-HTTPS的最终用户和管理员心理模型

获取原文

摘要

HTTPS is one of the most important protocols used to secure communication and is, fortunately, becoming more pervasive. However, especially the long tail of websites is still not sufficiently secured. HTTPS involves different types of users, e.g., end users who are forced to make critical security decisions when faced with warnings or administrators who are required to deal with cryptographic fundamentals and complex decisions concerning compatibility. In this work, we present the first qualitative study of both end user and administrator mental models of HTTPS. We interviewed 18 end users and 12 administrators; our findings reveal misconceptions about security benefits and threat models from both groups. We identify protocol components that interfere with secure configurations and usage behavior and reveal differences between administrator and end user mental models. Our results suggest that end user mental models are more conceptual while administrator models are more protocol-based. We also found that end users often confuse encryption with authentication, significantly underestimate the security benefits of HTTPS, and ignore and distrust security indicators while administrators often do not understand the interplay of functional protocol components. Based on the different mental models, we discuss implications and provide actionable recommendations for future designs of user interfaces and protocols.
机译:HTTPS是用于确保通信安全的最重要的协议之一,幸运的是,它变得越来越普遍。但是,尤其是网站的长尾仍然没有足够的安全性。 HTTPS涉及不同类型的用户,例如,最终用户在面临警告时被迫做出关键的安全决策,或者管理员需要处理加密基础知识和涉及兼容性的复杂决策。在这项工作中,我们将对HTTPS的最终用户和管理员心理模型进行首次定性研究。我们采访了18位最终用户和12位管理员。我们的发现揭示了两个群体对安全利益和威胁模型的误解。我们确定会干扰安全配置和使用行为的协议组件,并揭示管理员和最终用户心理模型之间的差异。我们的结果表明,最终用户心理模型更具概念性,而管理员模型则更加基于协议。我们还发现,最终用户经常将加密与身份验证相混淆,大大低估了HTTPS的安全优势,并且忽略和不信任安全指标,而管理员通常不了解功能协议组件之间的相互作用。基于不同的思维模型,我们讨论了含义并为用户界面和协议的未来设计提供了可行的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号