Publication | Closed Access
The Emperor's New Security Indicators An evaluation of website authentication and the effect of role playing on usability studies †
118
Citations
7
References
2007
Year
Unknown Venue
c©2007 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE. We evaluate website authentication measures that are designed to protect users from man-in-the-middle, ‘phish-ing’, and other site forgery attacks. We asked 67 bank customers to conduct common online banking tasks. Each time they logged in, we presented increasingly alarming clues that their connection was insecure. First, we re-moved HTTPS indicators. Next, we removed the par-ticipant’s site-authentication image—the customer-selected image that many websites now expect their users to ver-ify before entering their passwords. Finally, we replaced the bank’s password-entry page with a warning page. Af-
| Year | Citations | |
|---|---|---|
Page 1
Page 1