Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Evaluating ambiguity of privacy indicators in a secure email app
STOJKOVSKI, Borce; LENZINI, Gabriele
2020In Loreti, Michele; Spalazzi, Luca (Eds.) Proceedings of the Fourth Italian Conference on Cyber Security, Ancona Italy, February 4th to 7th, 2020
Peer reviewed
 

Documents


Texte intégral
Stojkovski et Lenzini - Evaluating ambiguity of privacy indicators in a secure email app - ITASEC v3.pdf
Postprint Auteur (927.1 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Résumé :
[en] Informing laymen of security situations is a notoriously hard problem. Users are usually not cognoscenti of all the various secure and insecure situations that may arise, and this can be further worsened by certain visual indicators that instead of helping users, fail to convey clear and unambiguous messages. Even in well-established and studied applications, like email clients providing end-to-end encryption, the problem seems far from being solved. Motivated to verify this claim, we studied the communication qualities of four privacy icons (in the form of coloured shapes) in conveying specific security messages, relevant for a particular secure emailing system called p≡p. We questioned 42 users in three different sessions, where we showed them 10 privacy ratings, along with their explanations, and asked them to match the rating and explanation with the four privacy icons. We compared the participants’ associations to those made by the p≡p developers. The results, still preliminary, are not encouraging. Except for the two most extreme cases, Secure and trusted and Under attack, users almost entirely missed to get the indicators’ intended messages. In particular, they did not grasp certain concepts such as Unsecure email and Secure email, which in turn were fundamental for the engineers. Our work has certain limitations and further investigation is required, but already at this stage our research calls for a closer collaboration between app engineers and icon designers. In the context of p≡p, our work has triggered a deeper discussion on the icon design choices and a potential revamp is on the way.
Centre de recherche :
- Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Other
Disciplines :
Sciences informatiques
Auteur, co-auteur :
STOJKOVSKI, Borce ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
LENZINI, Gabriele  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
Evaluating ambiguity of privacy indicators in a secure email app
Date de publication/diffusion :
2020
Nom de la manifestation :
Fourth Italian Conference on Cyber Security (ITASEC 20)
Lieu de la manifestation :
Ancona, Italie
Date de la manifestation :
4-2-2020 to 7-2-2020
Titre de l'ouvrage principal :
Proceedings of the Fourth Italian Conference on Cyber Security, Ancona Italy, February 4th to 7th, 2020
Editeur scientifique :
Loreti, Michele
Spalazzi, Luca
Maison d'édition :
CEUR-WS.org
Collection et n° de collection :
CEUR Workshop Proceedings
Pagination :
223--234
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR10621687 - Security And Privacy For System Protection, 2015 (01/01/2017-30/06/2023) - Sjouke Mauw
Intitulé du projet de recherche :
PRIDE15/10621687/SPsquared
Organisme subsidiant :
FNR - Fonds National de la Recherche
Commentaire :
2597
Disponible sur ORBilu :
depuis le 26 mai 2020

Statistiques


Nombre de vues
423 (dont 29 Unilu)
Nombre de téléchargements
160 (dont 7 Unilu)

citations Scopus®
 
2
citations Scopus®
sans auto-citations
1

Bibliographie


Publications similaires



Contacter ORBilu