Sciweavers

SOUPS
2009
ACM

Conditioned-safe ceremonies and a user study of an application to web authentication

14 years 6 months ago
Conditioned-safe ceremonies and a user study of an application to web authentication
We introduce the notion of a conditioned-safe ceremony. A “ceremony” is similar to the conventional notion of a protocol, except that a ceremony explicitly includes human participants. Our formulation of a conditioned-safe ceremony draws on several ideas and lessons learned from the human factors and human reliability community: forcing functions, defense in depth, and the use of human tendencies, such as rule-based decision making. We propose design principles for building conditioned-safe ceremonies and apply these principles to develop a registration ceremony for machine authentication based on email. We evaluated our email registration ceremony with a user study of 200 participants. We designed our study to be as ecologically valid as possible: we employed deception, did not use a laboratory environment, and attempted to create an experience of risk. We simulated attacks against the users and found that email registration was significantly more secure than challenge question ...
Chris Karlof, J. D. Tygar, David Wagner
Added 28 May 2010
Updated 28 May 2010
Type Conference
Year 2009
Where SOUPS
Authors Chris Karlof, J. D. Tygar, David Wagner
Comments (0)