USENIX Security2021Top-tier venue
Evaluating In-Workflow Messages for Improving Mental Models of End-to-End Encryption
Omer Akgul, Wei Bai, Shruti Das, Michelle L. Mazurek
Abstract
As large messaging providers increasingly adopt end-to-end encryption, private communication is readily available to more users than ever before. However, misunderstandings of end-to-end encryption's benefits and shortcomings limit people's ability to make informed choices about how and when to use these services. This paper explores the potential of using short educational messages, built into messaging workflows, to improve users' functional mental models of secure communication. A preliminary survey study (n=461) finds that such messages, when used in isolation, can effectively improve understanding of several key concepts. We then conduct a longitudinal study (n=61) to test these messages in a more realistic environment: embedded into a secure messaging app. In this second study, we do not find statistically significant evidence of improvement in mental models; however, qualitative evidence from participant interviews suggests that if made more salient, such messages could have potential to improve users' understanding.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 948fb8f1-79e8-4453-ac0f-a2a291f021dbCited by top-tier papers7
- 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire UniversityChristian Stransky, Oliver Wiese, Volker Roth, Yasemin Acar et al.S&P 2022 · 27 citations
- Investigating Influencer VPN Ads on YouTubeOmer Akgul, Richard Roberts, Moses Namara, Dave Levin et al.S&P 2022 · 27 citations
- A Decade of Privacy-Relevant Android App Reviews: Large Scale TrendsOmer Akgul, Sai Teja Peddinti, Nina Taft, Michelle L. Mazurek et al.USENIX Security 2024 · 14 citations
- "Did They F***ing Consent to That?": Safer Digital Intimacy via Proactive Protection Against Image-Based Sexual AbuseLucy Qin, Vaughn Hamilton, Sharon Wang, Yigit Aydinalp et al.USENIX Security 2024 · 14 citations
- Comprehension from Chaos: Towards Informed Consent for Private ComputationBailey Kacsmar, Vasisht Duddu, Kyle Tilbury, Blase Ur et al.CCS 2023 · 2 citations
Builds on2
- Obstacles to the Adoption of Secure Communication ToolsRuba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova et al.S&P 2017 · 170 citations
- Exploring Nudge Designs to Help Adolescent SNS Users Avoid Privacy and Safety ThreatsHiroaki Masaki, Kengo Shibata, Shui Hoshino, Takahiro Ishihama et al.CHI 2020 · 62 citations
Related papers
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
- The Impact of Risk Appeal Approaches on Users' Sharing Confidential InformationElham Al Qahtani, Peter Story, Mohamed ShehabCHI 2024
- Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate ContextVeroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters et al.USENIX Security 2022
- Cryptographic Deniability: A Multi-perspective Study of User Perceptions and ExpectationsTarun Kumar Yadav, Devashish Gosain, Kent E. SeamonsUSENIX Security 2023
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providersReethika Ramesh, Anjali Vyas, Roya EnsafiUSENIX Security 2023
