When S IGNAL hits the Fan : On the Usability and Security of State-ofthe-Art Secure Mobile Messaging

When S IGNAL hits the Fan : On the Usability and Security of State-ofthe-Art Secure Mobile Messaging
复制标题

当 SIGNAL 受到关注时:论最先进的安全移动消息传递的可用性和安全性

DOI:
10.14722/eurousec.2016.23012
复制
发表时间:
2016
影响因子:
2.3
通讯作者:
Markus Huber
Markus Huber
中科院分区:
环境科学与生态学2区
文献类型:
--
作者:
Svenja Schröder;Markus Huber

文献摘要

被引文献

相似文献

在本文中,我们分析了国家的最先进的安全移动的信使信号的安全性和可用性。在本文的第一部分中,我们讨论了当前安全移动的信使面临的威胁模型。在下文中,我们将进行用户研究,以检查SIGNAL安全功能的可用性。具体来说,我们的研究评估了用户是否能够检测和阻止对SIGNAL协议的中间人攻击。我们的研究结果表明,由于可用性问题和不完整的心理模型,大多数用户未能正确地将密钥与他们的会话伙伴进行比较以进行验证。因此,用户很可能会受到对当今安全消息应用程序的基本基础设施的攻击:交换加密密钥的中央服务。我们希望我们的研究结果能够促进对最先进的安全移动的信使的独特可用性和安全挑战的研究,从而最终为普通用户提供强有力的保护措施。
In this paper we analyze the security and usability of the state-of-the-art secure mobile messenger SIGNAL. In the first part of this paper we discuss the threat model current secure mobile messengers face. In the following, we conduct a user study to examine the usability of SIGNAL’s security features. Specifically, our study assesses if users are able to detect and deter man-in-the-middle attacks on the SIGNAL protocol. Our results show that the majority of users failed to correctly compare keys with their conversation partner for verification purposes due to usability problems and incomplete mental models. Hence users are very likely to fall for attacks on the essential infrastructure of today’s secure messaging apps: the central services to exchange cryptographic keys. We expect that our findings foster research into the unique usability and security challenges of state-of-theart secure mobile messengers and thus ultimately result in strong protection measures for the average user.