'Setting Up TLS Authentication Was Hell': A Usability Study of Client Certificate Authentication
Abubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott Ruoti
摘要
Cryptography turns a security problem into a key management problem" [1]. Despite decades of research effort towards usable key management, it remains unclear whether key management issues are inherent to every cryptographic system or merely artifacts of specific designs. To investigate, this paper presents a user study of mutual TLS (mTLS) usability, tracking 46 senior and graduate computer science students-highly technical users who configured client certificates, used them for routine authentication over a semester-long course, and managed credentials across multiple devices. Our results show that initial setup and setting up credentials on a second device are difficult, while routine authentication is easy once configured. Nevertheless, perceived usability remained low, and alarmingly, only 9% of participants fully understood mTLS security implications and key management. Our findings demonstrate that usability challenges shift across the credential lifecycle depending on system architecture. We conclude by offering design recommendations for future key management systems to better support users across the complete credential lifecycle.
• Security and privacy → Usability in security and privacy; Key management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes 等S&P 2020 · 被引用 124 次
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 被引用 114 次
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 等S&P 2019 · 被引用 105 次
- A Tale of Two Studies: The Best and Worst of YubiKey UsabilityJoshua Reynolds, Trevor Smith, Ken Reese, Luke Dickinson 等S&P 2018 · 被引用 95 次
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 被引用 48 次
相关 Paper
- "I Can't Believe It's Not Custodial!": Usable Trustless Decentralized Key ManagementTanusree Sharma, Vivek C. Nair, Henry Wang, Yang Wang 等CHI 2024 · 被引用 6 次
- "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsJuliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha FahlS&P 2025
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas SchreckS&P 2026
- Exploring User-Centered Security Design for Usable Authentication CeremoniesMatthias Fassl, Lea Theresa Gröber, Katharina KrombholzCHI 2021 · 被引用 20 次
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres 等CCS 2019 · 被引用 46 次
