rethinking connection security indicators
play

Rethinking Connection Security Indicators Adrienne Porter Felt, - PowerPoint PPT Presentation

Rethinking Connection Security Indicators Adrienne Porter Felt, Robert W. Reeder, Alex Ainslie, Helen Harris, Max Walker, Christopher Thompson, Mustafa Emre Acer, Elisabeth Morant, Sunny Consolvo Connection Security Indicators Connection


  1. Rethinking Connection Security Indicators Adrienne Porter Felt, Robert W. Reeder, Alex Ainslie, Helen Harris, Max Walker, Christopher Thompson, Mustafa Emre Acer, Elisabeth Morant, Sunny Consolvo

  2. Connection Security Indicators

  3. Connection Security Indicators CHROME: FIREFOX: EDGE:

  4. TLS and HTTPS What guarantees do you get?

  5. TLS and HTTPS What guarantees do you get? What assumptions do you make?

  6. TLS and HTTPS What guarantees do you get? What assumptions do you make? What guarantees do you not get?

  7. Summarize all that in 100x100 pixels... CHROME: FIREFOX: EDGE:

  8. Miscommunication CHROME: FIREFOX: EDGE: https://www.freepik.com/free-ve https://www.indiamart.com/proddetail ctor/empty-shopping-bag-mocku /non-woven-shopping-bag-14414682 https://www.charmingcharlie.com/handbag p_1177172.htm 991.html s

  9. How To Convey the Guarantees of TLS in UI Grab paper and pen Draw a full-page connection security indicator

  10. What was missing in our design process? Measurement of current state Actual user input to identify helpful changes Measurement of success after change is made

  11. Research Question How can we improve connection security indicators?

  12. Research Question What were their goals? How do we know when connection security indicators are ‘improved’?

  13. Research Question Was it the right question?

  14. Problems to Be Solved How to measure current security indicator effectiveness How to improve connection security indicators Measure effectiveness after deployment

  15. Historical Indicators

  16. Measuring Current Indicators Most people understand at least partially the green lock More people are confused what the HTTP indicators are telling them

  17. Icon/Color Selection

  18. Icon/Color Selection

  19. Text Selection “secure” “https” “not secure”

  20. Why Does Chrome Not Use These Indicators Today? What changed?

  21. Why Does Chrome Not Use These Indicators? https://blog.chromium .org/2018/05/evolving -chromes-security-ind icators.html

  22. What Will Future Work Look Like?

Recommend


More recommend