Communication publiée dans un périodique (Colloques, congrès, conférences scientifiques et actes)
Making Encryption Feel Secure: Investigating how Descriptions of Encryption Impact Perceived Security
DISTLER, Verena; LALLEMAND, Carine; KOENIG, Vincent
2020In The 5th European Workshop on Usable Security (EuroUSEC 2020)
Peer reviewed
 

Documents


Texte intégral
eusec20-Distler.pdf
Postprint Auteur (939.66 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Usable Security and Privacy; User Experience; Encryption
Résumé :
[en] When communication about security to end users is ineffective, people frequently misinterpret the protection offered by a system. The discrepancy between the security users perceive a system to have and the actual system state can lead to potentially risky behaviors. It is thus crucial to understand how security perceptions are shaped by interface elements such as text-based descriptions of encryption. This article addresses the question of how encryption should be described to non-experts in a way that enhances perceived security. We tested the following within-subject variables in an online experiment (N=309): a) how to best word encryption, b) whether encryption should be described with a focus on the process or outcome, or both c) whether the objective of encryption should be mentioned d) when mentioning the objective of encryption, how to best describe it e) whether a hash should be displayed to the user. We also investigated the role of context (between subjects). The verbs “encrypt” and “secure” performed comparatively well at enhancing perceived security. Overall, participants stated that they felt more secure not knowing about the objective of encryption. When it is necessary to state the objective, positive wording of the objective of encryption worked best. We discuss implications and why using these results to design for perceived lack of security might be of interest as well. This leads us to discuss ethical concerns, and we give guidelines for the design of user interfaces where encryption should be communicated to end users.
Disciplines :
Sciences informatiques
Auteur, co-auteur :
DISTLER, Verena ;  University of Luxembourg > Faculty of Language and Literature, Humanities, Arts and Education (FLSHASE) > Education, Culture, Cognition and Society (ECCS)
LALLEMAND, Carine  ;  University of Luxembourg > Faculty of Language and Literature, Humanities, Arts and Education (FLSHASE) > Education, Culture, Cognition and Society (ECCS)
KOENIG, Vincent ;  University of Luxembourg > Faculty of Language and Literature, Humanities, Arts and Education (FLSHASE) > Education, Culture, Cognition and Society (ECCS)
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Making Encryption Feel Secure: Investigating how Descriptions of Encryption Impact Perceived Security
Date de publication/diffusion :
2020
Nom de la manifestation :
The 5th European Workshop on Usable Security (EuroUSEC 2020)
Date de la manifestation :
07-09-2020
Manifestation à portée :
International
Titre du périodique :
The 5th European Workshop on Usable Security (EuroUSEC 2020)
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR10621687 - Security And Privacy For System Protection, 2015 (01/01/2017-30/06/2023) - Sjouke Mauw
Disponible sur ORBilu :
depuis le 30 juillet 2020

Statistiques


Nombre de vues
185 (dont 9 Unilu)
Nombre de téléchargements
407 (dont 9 Unilu)

citations Scopus®
 
8
citations Scopus®
sans auto-citations
7
citations OpenAlex
 
9
citations WoS
 
5

Bibliographie


Publications similaires



Contacter ORBilu