skip to main content
10.1145/2702123.2702442acmconferencesArticle/Chapter ViewAbstractPublication PageschiConference Proceedingsconference-collections
research-article
Open Access

Improving SSL Warnings: Comprehension and Adherence

Published:18 April 2015Publication History

ABSTRACT

Browsers warn users when the privacy of an SSL/TLS connection might be at risk. An ideal SSL warning would empower users to make informed decisions and, failing that, guide confused users to safety. Unfortunately, users struggle to understand and often disregard real SSL warnings. We report on the task of designing a new SSL warning, with the goal of improving comprehension and adherence. We designed a new SSL warning based on recommendations from warning literature and tested our proposal with microsurveys and a field experiment. We ultimately failed at our goal of a well-understood warning. However, nearly 30% more total users chose to remain safe after seeing our warning. We attribute this success to opinionated design, which promotes safety with visual cues. Subsequently, our proposal was released as the new Google Chrome SSL warning. We raise questions about warning comprehension advice and recommend that other warning designers use opinionated design.

References

  1. Akhawe, D., and Felt, A. P. Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness. In USENIX Security Symposium (2013). Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Almuhimedi, H., Felt, A. P., Reeder, R. W., and Consolvo, S. Your Reputation Precedes You: History, Reputation, and the Chrome Malware Warning. In SOUPS (2014).Google ScholarGoogle Scholar
  3. Anderson, R. E., and Jolson, M. A. Technical wording in advertising: implications for market segmentation. Journal of Marketing 44 (1980).Google ScholarGoogle Scholar
  4. ANSI. Product safety signs and labels: Z535.4.Google ScholarGoogle Scholar
  5. Arron, J., Egans, R., and Mela, D. Paradoxical Effect of a Nutrition Labeling Scheme in a Student Cafeteria. Nutritional Research 15 (September 1995).Google ScholarGoogle Scholar
  6. Bauer, L., Bravo-Lillo, C., Cranor, L. F., and Fragkaki, E. Warning design guidelines (cmu-cylab-13-002).Google ScholarGoogle Scholar
  7. Biddle, R., van Oorschot, P., Patrick, A. S., Sobey, J., and Whalen, T. Browser interfaces and extended validation ssl certificates: an empirical study. In ACM Workshop on Cloud Computing Security (2009). Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Braun, C. C., Greeno, B., and Silter, N. C. Differences in behavioral compliance as a function of warning color. In Human Factors and Ergonomics Society Annual Meeting (1998).Google ScholarGoogle Scholar
  9. Bravo-Lillo, C., Cranor, L., Komanduri, S., Schechter, S., and Sleeper, M. Harder to ignore?: Revisiting pop-up fatigue and approaches to prevent it. In SOUPS (2014).Google ScholarGoogle Scholar
  10. Bravo-Lillo, C., Cranor, L. F., Downs, J., and Komanduri, S. Bridging the gap in computer security warnings: A mental model approach. IEEE Security and Privacy 9, 2 (2011). Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. Bravo-Lillo, C., Cranor, L. F., Downs, J., Komanduri, S., Reeder, R. W., Schechter, S., and Sleeper, M. Your attention please: Designing security-decision uis to make genuine risks harder to ignore. In SOUPS (2013). Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. Breznitz, S. Cry Wolf: The Psychology of False Alarms.Google ScholarGoogle Scholar
  13. Bzostek, J. A., and Wogalter, M. S. Measuring visual search time for a product warning label as a function of icon, color, column, and vertical placement. In Human Factors and Ergonomics Society Annual Meeting (1999).Google ScholarGoogle ScholarCross RefCross Ref
  14. Dhamija, R., Tygar, J. D., and Hearst, M. A. Why phishing works. In CHI (2006). Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. Edworthy, J., and Adams, A. Warning design: a research perspective. Taylor and Francis, 1996.Google ScholarGoogle Scholar
  16. Egelman, S., Cranor, L. F., and Hong, J. You've been warned: an empirical study of the effectiveness of web browser phishing warnings. In CHI (2008). Google ScholarGoogle ScholarDigital LibraryDigital Library
  17. Egelman, S., and Schechter, S. The importance of being earnest {in security warnings}. In Financial Cryptography and Data Security, Lecture Notes in Computer Science. Springer Berlin Heidelberg, 2013.Google ScholarGoogle ScholarCross RefCross Ref
  18. Felt, A. P., Reeder, R. W., Almuhimedi, H., and Consolvo, S. Experimenting At Scale With Google Chrome's SSL Warning. In CHI (2014). Google ScholarGoogle ScholarDigital LibraryDigital Library
  19. Fischhoff, B., Riley, D., Kovacs, D. C., and Small, M. What information belongs in a warning? Psychology Marketing 15, 7 (1998).Google ScholarGoogle ScholarCross RefCross Ref
  20. Frantz, J. P. Effect of location and procedural explicitness on user process of and compliance with product warnings. Human Factors 36 (1994).Google ScholarGoogle Scholar
  21. Frutiger, A. Signs and symbols: their design and meaning. Von Nostrand Reinhold, 1989.Google ScholarGoogle Scholar
  22. Glover, B. L., and Wogalter, M. S. Using a computer simulated world to study behavior compliance with warnings: effect of salience and gender. In Human Factors Society Annual Meeting (1997).Google ScholarGoogle Scholar
  23. Hancock, H., Bowles, C. T., Rogers, W. A., and Fisk, A. D. Comprehension and retention of warning information. Handbook of warnings (2006).Google ScholarGoogle Scholar
  24. Hartley, J. Designing instructional text, 3 ed. Kagan Page and Nichols, 1994.Google ScholarGoogle Scholar
  25. Kalsher, M. J., Wogalter, M. S., and Racicot, B. M. Pharmaceutical container labels and warnings: preference and perceived readability of alternative designs and pictorials. International Journal of Industrial Ergonomics 18 (1996).Google ScholarGoogle Scholar
  26. Laughery, K. R., and Stanush, J. A. Effects of warning explicitness on product perceptions. In Human Factors Society (1989).Google ScholarGoogle ScholarCross RefCross Ref
  27. Laughery, K. R., and Vaubel, K. P. Explicitness in consequence information in warnings. Safety Science 16 (1993).Google ScholarGoogle Scholar
  28. Laughery, K. R., Young, S. L., Vaubel, K. P., and Brelsford, J. W. The noticeability of warnings on alcoholic beverage containers. Journal of Public Policy and Marketing 12 (1993).Google ScholarGoogle Scholar
  29. McDonald, P., Mohebbi, M., and Slatkin, B. Comparing Google Consumer Surveys to Existing Probability and Non-Probability Based Internet Survey. In Google Whitepaper (2012).Google ScholarGoogle Scholar
  30. McLaughlin, G. H. Smog grading -- a new readability formula. Journal of Reading (1969).Google ScholarGoogle Scholar
  31. Morrow, D. G., Hier, C. M., Mendard, W. E., and Leirer, V. O. Icons improve older and younger adults' comprehension of medication information. Journal of Gerontology: Psychological Sciences 53B (1998).Google ScholarGoogle Scholar
  32. Reeder, R., Kowalczyk, E. C., and Shostack, A. Poster: Helping engineers design NEAT security warnings. In SOUPS (2011).Google ScholarGoogle Scholar
  33. Research, P. A Comparison of Results from Surveys by the Pew Research Center and Google Consumer Surveys.Google ScholarGoogle Scholar
  34. Schechter, S. E., Dhamija, R., Ozment, A., and Fischer, I. The emperor's new security indicators. In IEEE Symposium on Security and Privacy (2007). Google ScholarGoogle ScholarDigital LibraryDigital Library
  35. Schwanda-Sosik, V., Bursztein, E., , Consolvo, S., Huffaker, D. A., Kossinets, G., Liao, K., McDonald, P., and Sedley, A. Online Microsurveys for User Experience Research. In CHI (Extended Abstracts) (2014). Google ScholarGoogle ScholarDigital LibraryDigital Library
  36. Silver, N., Leonard, D. C., Ponsi, K. A., and Wogalter, M. S. Warnings and purchase intentions for pest-control products. Forensic Reports 4 (1991).Google ScholarGoogle Scholar
  37. Sotirakopoulos, A., Hawkey, K., and Beznosov, K. On the Challenges in Usable Security Lab Studies: Lessons Learned from Replicating a Study on SSL Warnings. In SOUPS (2011). Google ScholarGoogle ScholarDigital LibraryDigital Library
  38. Sunshine, J., Egelman, S., Almuhimedi, H., Atri, N., and Cranor, L. F. Crying Wolf: An Empirical Study of SSL Warning Effectiveness. In USENIX Security Symposium (2009). Google ScholarGoogle ScholarDigital LibraryDigital Library
  39. Thorley, P., Hellier, E., and Edworthy, J. Habituation effects in visual warnings. Contemporary ergonomics (2001).Google ScholarGoogle Scholar
  40. Trommelen, M. Effectiveness of explicit warnings. Safety Science 25 (1997).Google ScholarGoogle Scholar

Index Terms

  1. Improving SSL Warnings: Comprehension and Adherence

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      CHI '15: Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems
      April 2015
      4290 pages
      ISBN:9781450331456
      DOI:10.1145/2702123

      Copyright © 2015 Owner/Author

      Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 18 April 2015

      Check for updates

      Qualifiers

      • research-article

      Acceptance Rates

      CHI '15 Paper Acceptance Rate486of2,120submissions,23%Overall Acceptance Rate6,199of26,314submissions,24%

      Upcoming Conference

      CHI '24
      CHI Conference on Human Factors in Computing Systems
      May 11 - 16, 2024
      Honolulu , HI , USA

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader