[77379] in cryptography@c2.net mail archive
study shows "extended validation" TLS certs ineffective
daemon@ATHENA.MIT.EDU (Perry E. Metzger)
Fri Jan 26 15:51:45 2007
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
To: cryptography@metzdowd.com
From: "Perry E. Metzger" <perry@piermont.com>
Date: Fri, 26 Jan 2007 15:50:43 -0500
Abstract. In this usability study of phishing attacks and browser
anti-phishing defenses, 27 users each classfied 12 web sites as
fraudulent or legitimate. By dividing these users into three
groups, our controlled study measured both the effect of extended
validation certicates that appear only at legitimate sites and the
effect of reading a help file about security features in Internet
Explorer 7. Across all groups, we found that picture-in-picture
attacks showing a fake browser window were as effective as the best
other phishing technique, the homograph attack. Extended validation
did not help users identify either attack. Additionally, reading
the help file made users more likely to classify both real and fake
web sites as legitimate when the phishing warning did not appear.
http://www.usablesecurity.org/papers/jackson.pdf
--
Perry E. Metzger perry@piermont.com
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com