On the Usability of Deploying HTTPS

نویسندگان

  • Katharina Krombholz
  • Wilfried Mayer
  • Martin Schmiedecker
چکیده

Protecting communication content at scale is a difficult task, and TLS is the protocol most commonly used to do so. However, it has been shown that deploying it in a truly secure fashion is challenging for a large fraction of online service operators. While Let’s Encrypt was specifically built and launched to promote the adoption of HTTPS, this paper aims to understand the reasons for why it has been so hard to deploy TLS correctly and studies the usability of the deployment process for HTTPS. We performed a series of experiments with 28 knowledgable participants and revealed significant usability challenges that result in weak TLS configurations. Additionally, we conducted expert interviews with 7 experienced security auditors. Our results suggest that the deployment process is far too complex even for people with proficient knowledge in the field, and that server configurations should have stronger security by default. While the results from our expert interviews confirm the ecological validity of the lab study results, they additionally highlight that even educated users prefer solutions that are easy to use. An improved and less vulnerable workflow would be very beneficial to finding stronger configurations in the wild.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The Challenges and Trends of Deploying Blockchain in the Real World for the Users’ Need

Blockchain technology is a decentralized and open database maintained by a peer-to-peer network, offering a “trustless trust” for untrusted parties. Despite the fact that some researchers consider blockchain as a bubble, blockchain technology has the genuine potential to solve problems across industries. In this article, we provide an overview of the development that Blockchain technology has h...

متن کامل

بررسی کاربردپذیری سیستم اطلاعات رادیولوژی

Introduction: One of the health information systems used in health care settings is Radiology Information System. This system can increase the quality and accuracy of work processes in the radiology department and can reduce the number of human resources required to archive images as well as the hospital costs, and, finally, can lower the retrieval time of archived images. Lack of usability of ...

متن کامل

Discovering the Underlying Components Affecting the Usability of IoT in Iranian Libraries: A Theory Based on Context

Objective: The aim is to discover the underlying context components of IOT usability in Iranian libraries: A qualitative approach consistent with grounded theory. Method: This qualitative study was conducted based on grounded theory. Data were collected through semi-structured interviews with 13 faculty members of knowledge and information science based on purposeful and chain methods. Responsi...

متن کامل

Employees’ opinion in Tehran University of Medical Sciences (TUMS) on usability of in-service electronic training courses

Introduction: Usability is one of the issues that must be considered in designing effective e-learning courses. The aim of this study was evaluating employees’ opinion in Tehran University of Medical Sciences (TUMS) about usability of in-service electronic training courses. Methods: This descriptive cross sectional study was conducted on employees in Tehran University of Medical Sciences, work...

متن کامل

A Study of the Usability of Ergonomic Camera Vest Based on Spirometry Parameters

Background: Being a cameraman is one of those occupations that expose people to musculoskeletal disorders (MSDs). Therefore, control measures should be taken to protect cameramen’s health. To solve the given problem, a vest was designed for cameramen to prevent MSDs by reducing the pressure and contact stress while carrying the camera on their shoulder. However, the usability of vest had ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2017