An Inconvenient Trust: User Attitudes toward Security and Usability Tradeoffs for Key-Directory Encryption Systems

An Inconvenient Trust: User Attitudes toward Security and Usability Tradeoffs for Key-Directory Encryption Systems
复制标题

不方便的信任:用户对密钥目录加密系统的安全性和可用性权衡的态度

DOI:
--
复制
发表时间:
2016
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
Doowon Kim
Doowon Kim
中科院分区:
--
文献类型:
--
作者:
Wei Bai;M. Namara;Yichen Qian;Patrick Gage Kelley;Michelle L. Mazurek;Doowon Kim

文献摘要

被引文献

相似文献

许多重要的通信现在都是以数字方式进行的,但最近的披露表明,这些通信往往可以被拦截。为了实现真正的消息隐私,用户需要端到端的消息加密,其中通信服务提供商无法解密内容。从历史上看,端到端加密已经被证明是非常难以正确使用的,但最近像苹果的iMessage和谷歌的端到端这样的工具已经通过使用密钥目录服务使其更广泛地访问。这些工具(以及其他类似工具)为了方便而牺牲了一些安全属性,这让一些安全专家感到震惊,但对于普通用户如何评估这些权衡,我们知之甚少。在一项52人的访谈研究中,我们要求参与者使用传统的密钥交换模型和基于密钥目录的注册模型来完成加密任务。我们还描述了每一个的安全属性(不同的演示顺序),并询问参与者的意见。我们发现,参与者很好地理解了这两个模型,并对何时进行不同的权衡做出了一致的评估。我们的参与者认识到,不太方便的交换模型总体上更安全,但发现注册模型的安全性对于许多日常用途来说“足够好”。
Many critical communications now take place digitally, but recent revelations demonstrate that these communications can often be intercepted. To achieve true message privacy, users need end-to-end message encryption, in which the communications service provider is not able to decrypt the content. Historically, end-to-end encryption has proven extremely difficult for people to use correctly, but recently tools like Apple’s iMessage and Google’s End-to-End have made it more broadly accessible by using key-directory services. These tools (and others like them) sacrifice some security properties for convenience, which alarms some security experts, but little is known about how average users evaluate these tradeoffs. In a 52-person interview study, we asked participants to complete encryption tasks using both a traditional key-exchange model and a key-directory-based registration model. We also described the security properties of each (varying the order of presentation) and asked participants for their opinions. We found that participants understood the two models well and made coherent assessments about when different tradeoffs might be appropriate. Our participants recognized that the less-convenient exchange model was more secure overall, but found the security of the registration model to be “good enough” for many everyday purposes.