Poster: Community-Based Security and Privacy Protection During Web Browsing
نویسنده
چکیده
When surfing the web today people want to be secure and their data to remain private. Internet users however do not see the protection of their privacy or security as the primary goal of their activity. They do not care for their online security and privacy actively [3]. Frequently appearing unnecessary warning messages constantly lower the users’ trust in those warnings. In this work, we present first ideas of a community based approach known from rating systems in online shopping to provide others with security and privacy relevant information on arbitrary websites. Such a system could then be used to warn users about critical websites and reestablish the users’ trust in warning messages. Using web browsers often leads to errors and warnings that do not denote any immediate danger to the user (e.g. blocking downloads). This leads to users constantly ignoring other warnings that would be really valuable to them [1]. On the other hand, there are cases (especially for phishing attacks) where the user is not alerted at all. Since the browsers security warnings are not absolutely correct, users quickly get habituated to them. We recommend a new approach by using community opinions as in rating systems to make people more comfortable about the source of the warnings. We do this by creating a browser plugin that will be capable of collecting and displaying security and privacy ratings for different web sites. Cranor et al. [2] presented in 2006 thoughts on ”User Interfaces for Privacy Agents” and came up with a particular user interface that was able to visualize the P3P privacy preferences of a website. They called it ”Privacy Bird”. A little bird icon at the top of the browser tells the user how well his privacy preferences match the ones provided by the website owner using P3P. A problem with visualizing P3P is that the information which is matched to the users preferences is provided by the website itself. Like that websites can simply fake their privacy appearance. Another idea to enhance user perception for security risks is security toolbars. Wu et al. [4] provided a good overview over existing toolbars in 2006. They categorized current approaches and compared them during a user study. They found people not noticing the warnings due to the fact that they have another primary goal besides their wish to be secure. Having users participate in classifying good and bad sites may raise the overall awareness for the problem space. Figure 1: Mockup images of the final plugin. Showing a) the browser screen b) the status-bar indication for a site c) the no-voters-yet-warning c) a critical privacy level and d) a critical security level.
منابع مشابه
On the Privacy of Private Browsing - A Forensic Approach
Private browsing has been a popular privacy feature built into all mainstream browsers since 2005. However, despite its prevalent use, the security of this feature has received little attention from the research community. In this paper, we present an up-to-date and comprehensive analysis of private browsing across four most popular web browsers: IE, Firefox, Chrome and Safari. We report that a...
متن کاملAnalyzing Tools and Algorithms for Privacy Protection and Data Security in Social Networks
The purpose of this research, is to study factors influencing privacy concerns about data security and protection on social network sites and its’ influence on self-disclosure. 100 articles about privacy protection, data security, information disclosure and Information leakage on social networks were studied. Models and algorithms types and their repetition in articles have been distinguished a...
متن کاملAn Architecture for Security and Protection of Big Data
The issue of online privacy and security is a challenging subject, as it concerns the privacy of data that are increasingly more accessible via the internet. In other words, people who intend to access the private information of other users can do so more efficiently over the internet. This study is an attempt to address the privacy issue of distributed big data in the context of cloud computin...
متن کاملTowards an Interactive Privacy Pattern Catalog
Copyright is held by the author/owner. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee. Poster presented at the 12th Symposium on Usable Privacy and Security (SOUPS 2016), June 22-24, 2016, Denver CO. Abstract A privacy pattern catalog provides guidance with respect to data protection requirements, to both technical and ...
متن کاملProtecting privacy in system design: the electronic voting case
Purpose – The purpose of the paper is to present Privacy Safeguard (PriS) a formal security requirements engineering methodology which, incorporates privacy requirements in the system design process and to demonstrate its applicability in an e-voting case. Design/methodology/approach – PriS provides a methodological framework for addressing privacy-related issues during system development. It p...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010