UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

"I don't know why I check this…" Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks

Mayer, Peter; Poddebniak, Damian; Fischer, Konstantin; Brinkmann, Marcus; Somorovsky, Juraj; Sasse, Angela; Schinzel, Sebastian; (2022) "I don't know why I check this…" Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks. In: Proceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022. (pp. pp. 77-96). USENIX, The Advanced Computing Systems Association: Boston, MA, USA. Green open access

[thumbnail of soups2022-mayer.pdf]
Preview
Text
soups2022-mayer.pdf - Published Version

Download (1MB) | Preview

Abstract

OpenPGP is one of the two major standards for end-to-end email security. Several studies showed that serious usability issues exist with tools implementing this standard. However, a widespread assumption is that expert users can handle these tools and detect signature spoofing attacks. We present a user study investigating expert users’ strategies to detect signature spoofing attacks in Thunderbird. We observed 25 expert users while they classified eight emails as either having a legitimate signature or not. Studying expert users explicitly gives us an upper bound of attack detection rates of all users dealing with PGP signatures. 52% of participants fell for at least one out of four signature spoofing attacks. Overall, participants did not have an established strategy for evaluating email signature legitimacy. We observed our participants apply 23 different types of checks when inspecting signed emails, but only 8 of these checks tended to be useful in identifying the spoofed or invalid signatures. In performing their checks, participants were frequently startled, confused, or annoyed with the user interface, which they found supported them little. All these results paint a clear picture: Even expert users struggle to verify email signatures, usability issues in email security are not limited to novice users, and developers may need proper guidance on implementing email signature GUIs correctly

Type: Proceedings paper
Title: "I don't know why I check this…" Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks
Event: Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)
ISBN-13: 9781939133304
Open access status: An open access version is available from UCL Discovery
Publisher version: https://www.usenix.org/conference/soups2022/techni...
Language: English
Additional information: This version is the version of record. For information on re-use, please refer to the publisher’s terms and conditions.
UCL classification: UCL
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science
URI: https://discovery.ucl.ac.uk/id/eprint/10174061
Downloads since deposit
21Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item