Will You Trust This TLS Certificate? Perceptions of People Working in IT (Extended Version)

07/23/2022
by   Martin Ukrop, et al.
0

Flawed TLS certificates are not uncommon on the Internet. While they signal a potential issue, in most cases they have benign causes (e.g., misconfiguration or even deliberate deployment). This adds fuzziness to the decision on whether to trust a connection or not. Little is known about perceptions of flawed certificates by IT professionals, even though their decisions impact high numbers of end users. Moreover, it is unclear how much the content of error messages and documentation influences these perceptions. To shed light on these issues, we observed 75 attendees of an industrial IT conference investigating different certificate validation errors. We also analyzed the influence of reworded error messages and redesigned documentation. We find that people working in IT have very nuanced opinions, with trust decisions being far from binary. The self-signed and the name-constrained certificates seem to be over-trusted (the latter also being poorly understood). We show that even small changes in existing error messages can positively influence resource use, comprehension, and trust assessment. At the end of the article, we summarize lessons learned from conducting usable security studies with IT professionals.

READ FULL TEXT

page 8

page 9

page 10

page 12

page 15

research
08/27/2019

Ideologically Motivated Biases in a Multiple Issues Opinion Model

It has been observed people tend to have opinions that are far more inte...
research
10/15/2020

Formalizing Trust in Artificial Intelligence: Prerequisites, Causes and Goals of Human Trust in AI

Trust is a central component of the interaction between people and AI, i...
research
03/04/2022

Adaptive Security and Trust Management for Autonomous Messaging Systems

With society's increased dependence on information communication systems...
research
01/24/2023

Influential Factors of Users' Trust in the Range Estimation Systems of Battery Electric Vehicles – A Survey Study in China

Although the rapid development of battery technology has greatly increas...
research
11/18/2022

What Makes An Apology More Effective? Exploring Anthropomorphism, Individual Differences, And Emotion In Human-Automation Trust Repair

Recent advances in technology have allowed an automation system to recog...
research
07/16/2020

SMEs Confidentiality Issues and Adoption of Good Cybersecurity Practices

Small and medium-sized enterprises (SME) are considered more vulnerable ...
research
05/11/2023

Traceability and Reuse Mechanisms, the most important Properties of Model Transformation Languages

Dedicated model transformation languages are claimed to provide many ben...

Please sign up or login with your details

Forgot password? Click here to reset