Shop, Swipe and Smile. With SmartSwipe it is that easy.


Jul 27
2009

Carnegie Mellon University: Users Ignore Security Warnings

Posted by Greg Hluska in SmartSwipeSecurity

If you spend any amount of time on the web, you have definitely seen some security warnings. The question is, 'what do you do when you see one?'  Do you automatically click 'yes' to proceed?  If so, researchers from Carnegie Mellon University say that you are not alone.

In "Crying Wolf: An Empirical Study of SSL Warning Effectiveness", researchers at Carnegie Mellon University decided to find out what users do when they are confronted with a warning message like the one above.  So, they planned out a study and showed a sample of 400 people various warning messages to see how they react.  Results were stunning:

What Percentage of Users Ignored Security Warnings on Bank/Library Web Sites

 Firefox 2Firefox 3Internet Explorer 7
Bank90%55%90%
Library95%60%100%

90% of the participants who used either Firefox 2 or Internet Explorer 7 to access a major (unnamed) bank's online banking site ignored the security warning. The researchers concluded that users seem to think that SSL certificate errors are of little consequence because they see them on so many legitimate sites.  As Sunshine, Egelman, Almuhimedi, Atri, and Cranor said, "users have a completely backward understanding of the risk of man-in-the-middle attacks and assume that they are less likely to occur at trusted websites like those belonging to bank."  A statement like this has tremendous implications for security researchers/providers!

The researchers cited one very important limitation to their study.  The study was sanctioned by Carnegie Mellon University.  This would automatically fill the sample with more trust than they would usually have.  Would a university of Carnegie Mellon's stature put their participants at serious risk?

Finally, those of you who use SmartSwipe likely know that we provide one extra warning to our customers.  If you have SmartSwipe installed, our software will display the following error if you navigate to a page with certificate problems:

 

 

We not only show the user one more warning message, but we also disable SmartSwipe.  Our product cannot be used on any pages with certificate problems! 

 

Trackback(0)
Comments (6)Add Comment
0
Barato Louboutin Zapatos
written by Barato Louboutin Zapatos, September 25, 2011
Les voyageurs à la mode en sont venus à Las Brisas depuis 1957 pour ses vues panoramiques, des chambres au calme, les services de spa et club de plage privé.
Mondialement célèbre pour son hospitalité incomparable, la calidez de son peuple, les belles plages, couchers de soleil spectaculaires, la vie nocturne palpitante, et ses coutumes pittoresques et les traditions, l'Acapulco est une ville qui peut répondre à vos attentes.
Hôtels à Acapulco offrir
0
Office 2010
written by Office 2010, November 10, 2011
I will keep your new article. I really enjoyed reading this post, thanks for sharing.
0
http://toryburch-mall.us/tory-...c-170.html
written by Tory Burch Totes, December 18, 2011
nevertheless be recent fill take on do a handful of LVMH a opportunities Hermes to look at marker the city, live performance LVMH
0
Your blog is good
written by moncler jackets, December 30, 2011
Here http://www.airforceonetop.com/ is a look at a new drop of the http://www.airforceonetop.com/ in women’s sizes.
0
http://www.canada-goose-jackets1.com/
written by Canada goos jackets, January 06, 2012
HW-http://www.canadagoosejacket1.org/ , http://www.canadagoosejacket1.org/
0
...
written by swtor credits, February 05, 2012
A statement like this has tremendous implications for security researchers/providers!

Write comment
smaller | bigger

busy
Powered by Azrul's MyBlog for Joomla!