Design and Field Evaluation of PassSec: Raising and Sustaining Web Surfer Risk Awareness

Melanie Volkamer, Karen Renaud, Kristoffer Braun, Gamze Canova, Benjamin Reinheimer

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

10 Citations (Scopus)

Abstract

This paper presents PassSec, a Firefox Add-on that raises user awareness about safe and unsafe password entry while they surf the web. PassSec comprises a two-stage approach: highlighting as the web page loads, then bringing up a just-in-time helpful dialogue when the user demonstrates an intention to enter a password on an unsafe web page. PassSec was developed using a human-centred design approach. We performed a field study with 31 participants that showed that PassSec significantly reduces the number of logins on websites where password entry is unsafe.
Original languageEnglish
Title of host publicationTrust and Trustworthy Computing: 8th International Conference, TRUST 2015
EditorsMauro Conti, Matthias Schunter, Ioannis Askoxylakis
Place of PublicationCham
PublisherSpringer
Pages104-122
Number of pages18
Volume9229
Edition1
ISBN (Electronic)9783319228464
ISBN (Print)9783319228457
DOIs
Publication statusPublished - 26 Aug 2015
EventInternational Conference on Trust and Trustworthy Computing - Heraklion, Greece
Duration: 24 Aug 201526 Aug 2015
https://www.bing.com/search?form=MOZLBR&pc=MOZI&q=International+Conference+on+Trust+and+Trustworthy+Computing+2015

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume9229
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Conference on Trust and Trustworthy Computing
Country/TerritoryGreece
CityHeraklion
Period24/08/1526/08/15
Internet address

Keywords

  • PassSec
  • embedded systems
  • hardware attacks and countermeasures
  • hardware-based security protocols
  • mobile systems
  • human-centered design approach
  • physical unclonable functions
  • privacy-preserving protocols
  • reputation systems
  • security and privacy
  • security in hardware
  • security protocols
  • social network security and privacy
  • software security engineering
  • TPM 2.0
  • tamper-proof and tamper-resistant designs
  • trust models
  • trusted computing
  • trusted platform module
  • trustworthy computing
  • dialogue help
  • password field

Fingerprint

Dive into the research topics of 'Design and Field Evaluation of PassSec: Raising and Sustaining Web Surfer Risk Awareness'. Together they form a unique fingerprint.

Cite this