A user study of off-the-record messaging

A user study of off-the-record messaging
复制标题

非记录消息传递的用户研究

DOI:
--
复制
发表时间:
2008
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
I. Goldberg
I. Goldberg
中科院分区:
--
文献类型:
--
作者:
R. Stedman;Kayo Yoshida;I. Goldberg

文献摘要

被引文献

相似文献

即时消息传递是Internet上流行的一种通信形式,但大多数即时消息传递服务对窃听者或冒名顶替者提供的安全性很低。现有的各种系统都旨在解决这一问题,但提供最高隐私级别的系统是非记录消息传递(OTR),它旨在为即时消息传递对话提供面对面对话中可用的隐私级别。在最近对OTR的重新设计中,以及增加协议的安全性,设计者的目标之一是使OTR更易于使用,而不需要用户了解计算机安全的细节,如密钥或指纹。 为了确定是否达到了这个设计目标,我们使用Think Aloud方法对Pidgin即时消息客户端的OTR插件进行了用户研究。作为这项研究的结果,我们发现了OTR设计中仍然存在的各种可用性缺陷。我们发现的这些缺陷有可能造成混淆,使程序无法使用,甚至降低OTR用户的安全级别。我们将讨论如何修复这些错误,并确定需要进一步研究以提高其可用性的领域。
Instant messaging is a prevalent form of communication across the Internet, yet most instant messaging services provide little security against eavesdroppers or impersonators. There are a variety of existing systems that aim to solve this problem, but the one that provides the highest level of privacy is Off-the-Record Messaging (OTR), which aims to give instant messaging conversations the level of privacy available in a face-to-face conversation. In the most recent redesign of OTR, as well as increasing the security of the protocol, one of the goals of the designers was to make OTR easier to use, without users needing to understand details of computer security such as keys or fingerprints. To determine if this design goal has been met, we conducted a user study of the OTR plugin for the Pidgin instant messaging client using the think aloud method. As a result of this study we have identified a variety of usability flaws remaining in the design of OTR. These flaws that we have discovered have the ability to cause confusion, make the program unusable, and even decrease the level of security to users of OTR. We discuss how these errors can be repaired, as well as identify an area that requires further research to improve its usability.