An Empirical Study of Textual Key-Fingerprint Representations
Sergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar, Sascha Fahl, Matthew Smith
摘要
Many security protocols still rely on manual fingerprint comparisons for authentication. The most well-known and widely used key-fingerprint representation are hexadecimal strings as used in various security tools. With the introduction of end-to-end security in WhatsApp and other messengers, the discussion on how to best represent key-fingerprints for users is receiving a lot of interest. We conduct a 1047 participant study evaluating six different textual key-fingerprint representations with regards to their performance and usability. We focus on textual fingerprints as the most robust and deployable representation. Our findings show that the currently used hexadecimal representation is more prone to partial preimage attacks in comparison to others. Based on our findings, we make the recommendation that two alternative representations should be adopted. The highest attack detection rate and best usability perception is achieved with a sentence-based encoding. If language-based representations are not acceptable, a simple numeric approach still outperforms the hexadecimal representation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- How Well Do My Results Generalize? Comparing Security and Privacy Survey Results from MTurk, Web, and Telephone SamplesElissa M. Redmiles, Sean Kross, Michelle L. MazurekS&P 2019 · 被引用 222 次
- Obstacles to the Adoption of Secure Communication ToolsRuba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova 等S&P 2017 · 被引用 170 次
- On the Usability of Authenticity Checks for Hardware Security TokensKatharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer 等USENIX Security 2021 · 被引用 12 次
- Towards Usable Checksums: Automating the Integrity Verification of Web Downloads for the MassesMauro Cherubini, Alexandre Meylan, Bertil Chapuis, Mathias Humbert 等CCS 2018 · 被引用 11 次
- Sounds Good? Fast and Secure Contact Exchange in GroupsFlorentin Putz, Steffen Haesler, Matthias HollickCSCW 2024 · 被引用 4 次
相关 Paper
- Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanningShubham Jain, Ana-Maria Cretu, Yves-Alexandre de MontjoyeUSENIX Security 2022
- Exploring User-Centered Security Design for Usable Authentication CeremoniesMatthias Fassl, Lea Theresa Gröber, Katharina KrombholzCHI 2021 · 被引用 20 次
- All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile MessengersChristoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko 等NDSS 2021
- Human Distinguishable Visual Key FingerprintsMozhgan Azimpourkivi, Umut Topkara, Bogdan CarbunarUSENIX Security 2020
- Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with AutoethnographyMatthias Fassl, Katharina KrombholzCHI 2023 · 被引用 18 次
