Symposium on Usable Security and Privacy - Day3

Welcome to the Symposium on Usable Security and Privacy happening in Hannover, Germany and being hosted by CISPA. The Symposium is

Blog posts:

Session: Usable Security Mechanisms & Emerging Threats

IdentitySign: Design and User Study of a Prototype Application for Digitally Signing Documents Using an Identity Wallet

Presenter: Yorick Last, Paderborn University

You can sign digital documents via electronic or digital signatures. Handwritten signatures work well but provide no guarentees of the authenticity or the integrity. Often because they are typed, or could be easily copied.

One way to make this easier and better for users is Digital Identity Wallets applications that collect various identity attributes, presented to the user in a card-based interface. These are decentralized user-centric means of identiy management. EU is rolling out a Digital Identity Wallet next year.

The project proposes such a prototype wallet: IdentitySign. Free and open-source web applicatoin, uses the Yivi identity wallet and lends cryptographic support from PostGuard.

Had a user study including an unmoderated usability test with 99 participants recruited accross the EU.

IdentitySign was generally found to be useable. But some users did not understand why such a signature was needed over just signing their name with a (digital) pen. Only 20% could detect a valid signature.

So the reasearchers tried to address the issue of missplaced trust. Also added some friction to the UI for verification to slow the user down.

Ran the study again with 74 participants. Again from across the EU and an unmoderated remote user study. The scenarios included 1 signing and 2 verification tasks.

Usability was still considered to be good. 82% could now correctly find broken signatures. 95% correctly identified a signature as correct.

A key lesson was that the UI needs to ballance being helpful without seeming to imply trustworthyness. It is important that users be able to judge if a signature is correct themselves.

Is It Real? Exploiting Virtual-Physical Discrimination Vulnerability in Mixed Reality

Presenter: Xueyang Wang

The visual-physical discrimination vulnerability - the point at which humans cannot differentiate between real and faked. This is also known as the uncanny valley.

This research project looks at ways that an attacker can inject virtual objects onto the user’s vision.

  • Endogenous injection
    • invisible duplicates of existing objects in the user vision
    • users have trouble detecting these
  • Exogenous Injection
  • Type-deceptive overlay
    • Modifying a part of the user vision. For example adding flowers to the top of a trash can so that it looks like a flower pot. The user can still see it but cannot figure out where the trash can is.
  • Attribute-overlay
    • Adding elements like putting logos on a white t-shirt can impact user decisions. Even when a user knows that the image was fake and had been added. This is well in alignment with marketing research.

Attacks with the highest behavioral success rates recieved the highest plausability, lowest workload, and highest usability ratings. In other words, if people thought the fake thing was real, they were happy to engage with it and were happy about it.

Research outcome: even if the user detects the fake, it still impacts their decision making and physical behavior.

Clear, Actionable and Confidence-Inspiring Recommendations? Comparative Study of AI-Generated and Human-Written PT Reports

Presenter: Katarina Galanska, Masaryk University

Interested in how recommendations were acted on. Security recommendations tend to be high-level and general so many possible actions could be taken based on them.

Suggestions for how to address a security vulnerability were written by humans and various of AI. Did a survey-based study asking users about the following three aspects of each suggestion.

  • Clarity
  • Actonability
  • Confidence

Lightning talks

  • Florin Martius, Registered Reports at SOUPS: Call for Discussion
    • Registered reports: comprehensive research plan is submitted to the reviewers rather than the final research paper. The idea is to not waste research time, and create more high-quality research.
    • Challenges exist though, it now shifts reviewing effort.
    • Kami’s opinion: Contextualization of results is important in a final publication. Because it is not just about the methods. It is also about the interpretation of the results which cannot be done up-front.
  • Simon Althaus, PIONEER - A PrIvacy companion for mOtivatioN and knowlEdge transfER
    • Rough motivation is to make it easier for users to handle privacy
    • App involves privacy and lessons and motivations
    • Can compare apps to each other to make decisions
  • Christina Detsika and Julia Justen, Age Groups for Security and Privacy Studies with Children
    • Deciding what age ranges of children to do research with is a bit complex because developmental stages can drastically impact cognitive understanding. The work aims to determine suitable age ranges for reserach in the USEC space as well as how to best talk about the population choices in research papers.
  • Twain Byrnes, Toward Design Principles for Information-flow Security Tools
  • Camille Cobb, How do we encourage students (and ourselves) to take meaningful action against dystopian technologies?
    • Advocating action-oriented tech ethics education
    • Current ethics materials focus on how to make judgements. But not much about how to take action after the judgement is made. Especially when the action is professionally risky or it is unclear how to do.

Session: Scams, Fraud & Misinformation

Kami Vaniea
Kami Vaniea
Associate Professor of Usable Privacy and Security

I research how people interact with cyber security and privacy technology.