Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the Masses
Mauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert, Igor Bilogrevic, Kévin Huguenin
摘要
Internet users can download software for their computers from app stores (e.g., Mac App Store and Windows Store) or from other sources, such as the developers' websites. Most Internet users in the US rely on the latter, according to our representative study, which makes them directly responsible for the content they download. To enable users to detect if the downloaded files have been corrupted, developers can publish a checksum together with the link to the program file; users can then manually verify that the checksum matches the one they obtain from the downloaded file. In this paper, we assess the prevalence of such behavior among the general Internet population in the US (N = 2,000), and we develop easyto-use tools for users and developers to automate both the process of checksum verification and generation. Specifically, we propose an extension to the recent W3C specification for sub-resource integrity in order to provide integrity protection for download links. Also, we develop an extension for the popular Chrome browser that computes and verifies checksums of downloaded files automatically, and an extension for the WordPress CMS that developers can use to easily attach checksums to their remote content. Our in situ experiments with 40 participants demonstrate the usability and effectiveness issues of checksums verification, and shows user desirability for our extension.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- An Empirical Study of the Use of Integrity Verification Mechanisms for Web SubresourcesBertil Chapuis, Olamide Omolola, Mauro Cherubini, Mathias Humbert 等WWW 2020 · 被引用 13 次
- An Empirical Study of the Usage of Checksums for Web DownloadsGaël Bernard, Rémi Coudert, Bertil Chapuis, Kévin HugueninWWW 2023 · 被引用 1 次
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
它引用的顶会 Paper3
- How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and BehaviorElissa M. Redmiles, Sean Kross, Michelle L. MazurekCCS 2016 · 被引用 192 次
- Obstacles to the Adoption of Secure Communication ToolsRuba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova 等S&P 2017 · 被引用 170 次
- An Empirical Study of Textual Key-Fingerprint RepresentationsSergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar 等USENIX Security 2016 · 被引用 65 次
相关 Paper
- Accountable Javascript Code DeliveryIlkan Esiyok, Pascal Berrang, Katriel Cohn-Gordon, Robert KünnemannNDSS 2023
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 被引用 7 次
- An Empirical Study of Web Resource Manipulation in Real-world Mobile ApplicationsXiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia 等USENIX Security 2018 · 被引用 15 次
- Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsAsmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem FawazWWW 2024 · 被引用 12 次
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
