共 1 条
Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with Autoethnography
被引:2
|作者:
Fassl, Matthias
[1
,2
]
Krombholz, Katharina
[1
]
机构:
[1] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[2] Saarland Univ, Saarbrucken, Germany
来源:
PROCEEDINGS OF THE 2023 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI 2023)
|
2023年
关键词:
End-to-End-Encrypted Messaging;
MitM Attacks;
Authentication Ceremonies;
Social Cybersecurity;
Autoethnography;
D O I:
10.1145/3544548.3581508
中图分类号:
TP [自动化技术、计算机技术];
学科分类号:
0812 ;
摘要:
Authentication ceremonies detect and mitigate Man-in-the-Middle (MitM) attacks on end-to-end encrypted messengers, such as Signal, WhatsApp, or Threema. However, prior work found that adoption remains low as non-expert users have difculties using them correctly. Anecdotal evidence suggests that security researchers also have trouble authenticating others. Since their issues are probably unrelated to user comprehension or usability, the root causes may lie deeper. This work explores these root causes using autoethnography. The frst author kept a fve-month research diary of their experience with authentication ceremonies. The results uncover points of failure while planning and conducting authentication ceremonies. They include cognitive load, forgetfulness, social awkwardness, and explanations required by a communication partner. Additionally, this work identifes and discusses how sociocultural aspects afect authentication ceremonies. Lastly, this work discusses a design approach for cooperative security that employs cultural transcoding to improve sociocultural aspects of security by design.
引用
收藏
页数:15
相关论文