Presentation is loading. Please wait.

Presentation is loading. Please wait.

The Human Element in Security

Similar presentations


Presentation on theme: "The Human Element in Security"— Presentation transcript:

1 The Human Element in Security
M. Angela Sasse Professor of Human-Centred Technology Head of Information Security Research Department of Computer Science University College London, UK

2 PAS

3 How it all began … Study on escalating cost of password resets at BT
Users faced with workload too high Leads them to shortcut security mechanisms Users don’t understand threats and risks Consequence: war between users and security department Adams & Sasse CACM 1999

4 What is the problem? People make mistakes People are asked too much

5 Allendoerfer & Pai (2005): Human Factors Considerations for Passwords and Other User Identification Techniques. US DOT/FAA/CT- 05/20

6 Usability and security
... are not “opponents” People won’t comply when they have to make too much effort – ‘compliance threshold’ People will bypass security that is too time-consuming, or difficult to figure out People will stay away from services with onerous security

7

8 What is a payment card for?
angela Chip & PIN example from Trustguide research so there are two issues here 1- unintentionally bad design by not designing for primary task completion, and 

9 Security that supports user goals
angela whereas he we have an approach that acknowledges that From a usability point of view, these are badly designed secondary tasks, and such bad design will always  1) annoy users  2) reduce their performance 3) increase cost of operating the solution overall - which counteracts economic benefits for both parties Think about your security measures in the same way Another example we could use is anti-phishing tools: passive security indicators like Spoofstick, and the training approach taken by Phishguru, require uses to check every website they go to - this is a disruptive, time-consuming and error-prone task.  A better designed solution is a tool that online interferes - pops up a visible warning:  if something is (likely to be) wrong - e.g. the SOLID anti-phishing tool, or the Camp's Trust Orb


Download ppt "The Human Element in Security"

Similar presentations


Ads by Google