Crying Wolf: An Empirical Study of SSL Warning Effectiveness
Explore this paper's citation graph
Summary
A better approach may be to minimize the use of SSL warnings altogether by blocking users from making unsafe connections and eliminating warnings in benign situations.
- Type
- article
- Published
- 2009-08-10
- Cited by
- 506
- References
- 67
- Access
- Open access
- OpenAlex
- https://openalex.org/W1550000763
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:1538261
Keywords
Computer science, Internet privacy, Certificate, Computer security, The Internet
References
- Document Object Model
- Gathering evidence: use of visual security cues in web browsers
- Building a Secure Web Browser
- A Framework for Reasoning About the Human in the Loop
- Windows NT Thin Client Solutions: Implementing Terminal Server and Citrix MetaFrame
- Design of the EROS Trusted Window System
- HTTP State Management Mechanism
- Improving security decisions with polymorphic and audited dialogs
- Do security toolbars actually prevent phishing attacks?
- Sub-operating systems: a new approach to application security
- Native Client: A Sandbox for Portable, Untrusted x86 Native Code
- Protecting browsers from DNS rebinding attacks
- You've been warned: an empirical study of the effectiveness of web browser phishing warnings
- Hardening Web browsers against man-in-the-middle and eavesdropping attacks
- Securing frame communication in browsers
- Virtual Network Computing
- Why phishing works
- An analysis of browser domain-isolation bugs and a light-weight transparent defense mechanism
- Forcehttps: protecting high-security web sites from network attacks
- A safety-oriented platform for Web applications
Cited by
- How to Ask for Permission
- Improving Computer Security Dialogs: An Exploration of Attention and Habituation
- All Trust Is Local: Empowering Users' Authentication Decisions on the Internet
- Challenges in Access Right Assignment for Secure Home Networks
- Contextualized Security Interventions in Password Transmission Scenarios
- Providing Public Key Certificate Authorization and Policy with DNS
- Fuzzy security concepts for the Internet of the future
- An evaluation of smartphone communication (in)security
- Harvesting SSL Certificate Data to Mitigate Web-Fraud
- Verilogo : proactive phishing detection via logo recognition
- On the Effective Prevention of TLS Man-in-the-Middle Attacks in Web Applications
- Transparent Key Integrity (TKI): A Proposal for a Public-Key Validation Infrastructure (CMU-CyLab-12-016)
- Financial Cryptography and Data Security
- Public Key Infrastructures, Services and Applications
- CPTIAS: a new fast PKI authentication scheme based on certificate path trust index
- Towards Internet Voting in the State of Qatar
- Fake-Website Detection Tools: Identifying Elements that Promote Individuals' Use and Enhance Their Performance
- Man-in-the-browser-cache: Persisting HTTPS attacks via browser cache poisoning
- User-Centric IT Security - How to Design Usable Security Mechanisms
- User-controlled access management to resources on the Web
Related papers
- The Emperor's New Security Indicators
- Why phishing works
- Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness
- You've been warned: an empirical study of the effectiveness of web browser phishing warnings
- So long, and no thanks for the externalities: the rational rejection of security advice by users
- Do security toolbars actually prevent phishing attacks?
- Your attention please: designing security-decision UIs to make genuine risks harder to ignore
- A Framework for Reasoning About the Human in the Loop
- On the challenges in usable security lab studies: lessons learned from replicating a study on SSL warnings
- Bridging the Gap in Computer Security Warnings: A Mental Model Approach