Rethinking Connection Security Indicators Adrienne Porter Felt, - - PowerPoint PPT Presentation

rethinking connection security indicators
SMART_READER_LITE
LIVE PREVIEW

Rethinking Connection Security Indicators Adrienne Porter Felt, - - PowerPoint PPT Presentation

Rethinking Connection Security Indicators Adrienne Porter Felt, Robert W. Reeder, Alex Ainslie, Helen Harris, Max Walker, Christopher Thompson, Mustafa Emre Acer, Elisabeth Morant, Sunny Consolvo Connection Security Indicators Connection


slide-1
SLIDE 1

Rethinking Connection Security Indicators

Adrienne Porter Felt, Robert W. Reeder, Alex Ainslie, Helen Harris, Max Walker, Christopher Thompson, Mustafa Emre Acer, Elisabeth Morant, Sunny Consolvo

slide-2
SLIDE 2

Connection Security Indicators

slide-3
SLIDE 3

Connection Security Indicators

CHROME: FIREFOX: EDGE:

slide-4
SLIDE 4

TLS and HTTPS

What guarantees do you get?

slide-5
SLIDE 5

TLS and HTTPS

What guarantees do you get? What assumptions do you make?

slide-6
SLIDE 6

TLS and HTTPS

What guarantees do you get? What assumptions do you make? What guarantees do you not get?

slide-7
SLIDE 7

Summarize all that in 100x100 pixels...

FIREFOX: CHROME: EDGE:

slide-8
SLIDE 8

Miscommunication

FIREFOX: CHROME: EDGE:

https://www.indiamart.com/proddetail /non-woven-shopping-bag-14414682 991.html https://www.charmingcharlie.com/handbag s https://www.freepik.com/free-ve ctor/empty-shopping-bag-mocku p_1177172.htm

slide-9
SLIDE 9

How To Convey the Guarantees of TLS in UI

Grab paper and pen Draw a full-page connection security indicator

slide-10
SLIDE 10

What was missing in our design process?

Measurement of current state Actual user input to identify helpful changes Measurement of success after change is made

slide-11
SLIDE 11

Research Question

How can we improve connection security indicators?

slide-12
SLIDE 12

Research Question

What were their goals? How do we know when connection security indicators are ‘improved’?

slide-13
SLIDE 13

Research Question

Was it the right question?

slide-14
SLIDE 14

Problems to Be Solved

How to measure current security indicator effectiveness How to improve connection security indicators Measure effectiveness after deployment

slide-15
SLIDE 15

Historical Indicators

slide-16
SLIDE 16

Measuring Current Indicators

Most people understand at least partially the green lock More people are confused what the HTTP indicators are telling them

slide-17
SLIDE 17

Icon/Color Selection

slide-18
SLIDE 18

Icon/Color Selection

slide-19
SLIDE 19

Text Selection

“secure” “https” “not secure”

slide-20
SLIDE 20
slide-21
SLIDE 21

Why Does Chrome Not Use These Indicators Today?

What changed?

slide-22
SLIDE 22

Why Does Chrome Not Use These Indicators?

https://blog.chromium .org/2018/05/evolving

  • chromes-security-ind

icators.html

slide-23
SLIDE 23

What Will Future Work Look Like?