"If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPS
Katharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith, Emanuel von Zezschwitz
摘要
HTTPS is one of the most important protocols used to secure communication and is, fortunately, becoming more pervasive. However, especially the long tail of websites is still not sufficiently secured. HTTPS involves different types of users, e.g., end users who are forced to make critical security decisions when faced with warnings or administrators who are required to deal with cryptographic fundamentals and complex decisions concerning compatibility. In this work, we present the first qualitative study of both end user and administrator mental models of HTTPS. We interviewed 18 end users and 12 administrators; our findings reveal misconceptions about security benefits and threat models from both groups. We identify protocol components that interfere with secure configurations and usage behavior and reveal differences between administrator and end user mental models. Our results suggest that end user mental models are more conceptual while administrator models are more protocol-based. We also found that end users often confuse encryption with authentication, significantly underestimate the security benefits of HTTPS, and ignore and distrust security indicators while administrators often do not understand the interplay of functional protocol components. Based on the different mental models, we discuss implications and provide actionable recommendations for future designs of user interfaces and protocols.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar 等S&P 2022 · 被引用 51 次
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 被引用 48 次
- The Web's Identity Crisis: Understanding the Effectiveness of Website Identity IndicatorsChristopher Thompson, Martin Shelton, Emily Stark, Max Walker 等USENIX Security 2019 · 被引用 48 次
- Unsafe Diffusion: On the Generation of Unsafe Images and Hateful Memes From Text-To-Image ModelsYiting Qu, Xinyue Shen, Xinlei He, Michael Backes 等CCS 2023 · 被引用 48 次
- "I need a better description": An Investigation Into User Expectations For Differential PrivacyRachel Cummings, Gabriel Kaptchuk, Elissa M. RedmilesCCS 2021 · 被引用 45 次
它引用的顶会 Paper7
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- Obstacles to the Adoption of Secure Communication ToolsRuba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova 等S&P 2017 · 被引用 170 次
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog 等CCS 2017 · 被引用 146 次
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 被引用 114 次
相关 Paper
- Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate ContextVeroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters 等USENIX Security 2022
- Evaluating In-Workflow Messages for Improving Mental Models of End-to-End EncryptionOmer Akgul, Wei Bai, Shruti Das, Michelle L. MazurekUSENIX Security 2021 · 被引用 21 次
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providersReethika Ramesh, Anjali Vyas, Roya EnsafiUSENIX Security 2023
- Security Knight in Shining Armor: What and Who VPN Providers Claim to Shield Consumers AgainstFelix Reichmann, Jens Christian Opdenbusch, Karola Marky, Marco GutfleischCHI 2025 · 被引用 2 次
- Investigating the Password Policy Practices of Website AdministratorsSena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank LiS&P 2023
