作者
Haidong Xia, José Carlos Brustoloni
发表日期
2005/5/10
图书
Proceedings of the 14th international conference on World Wide Web
页码范围
489-498
简介
Existing Web browsers handle security errors in a manner that often confuses users. In particular, when a user visits a secure site whose certificate the browser cannot verify, the browser typically allows the user to view and install the certificate and connect to the site despite the verification failure. However, few users understand the risk of man-in-the-middle attacks and the principles behind certificate-based authentication. We propose context-sensitive certificate verification (CSCV), whereby the browser interrogates the user about the context in which a certificate verification error occurs. Considering the context, the browser then guides the user in handling and possibly overcoming the security error. We also propose specific password warnings (SPW) when users are about to send passwords in a form vulnerable to eavesdropping. We performed user studies to evaluate CSCV and SPW. Our results suggest that …
引用总数
200520062007200820092010201120122013201420152016201720182019202020212022202336101289811910685653353
学术搜索中的文章
H Xia, JC Brustoloni - Proceedings of the 14th international conference on …, 2005