Proceedings 3rd European Workshop on Usable Security 2018
DOI: 10.14722/eurousec.2018.23018
|View full text |Cite
|
Sign up to set email alerts
|

A Usability Study of Secure Email Deletion

Abstract: Messaging applications like SnapChat illustrate that users are concerned about the permanence of information. We find that this concern extends to email. In this paper we present a usability study of an end-to-end secure email tool with the option to securely delete messages. This tool uses ephemeral keys, one per message thread, and default expiration times, with a user prompt to renew or delete keys. Deleting keys causes the messages in the thread to be unreadable for that user. We compare the usability of t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

2
5
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
2
1
1

Relationship

1
3

Authors

Journals

citations
Cited by 4 publications
(7 citation statements)
references
References 12 publications
2
5
0
Order By: Relevance
“…Secure message deletion Our study and other recent work [24] show that users are concerned about their data even after it arrives at the destination. One suggestion applicable to email is for senders to use short-lived encryption keys per message that can expire or be revoked [24], similar to popular chat applications such as WhatsApp and Signal [26].…”
Section: Discussionsupporting
confidence: 51%
See 2 more Smart Citations
“…Secure message deletion Our study and other recent work [24] show that users are concerned about their data even after it arrives at the destination. One suggestion applicable to email is for senders to use short-lived encryption keys per message that can expire or be revoked [24], similar to popular chat applications such as WhatsApp and Signal [26].…”
Section: Discussionsupporting
confidence: 51%
“…3 This service encodes an email as an image so the content cannot be printed and will be automatically deleted at a later time, after which the recipient will not be able to view the content. While we know of no direct research on the efficacy of this method, the approach of interceding during the email process has promise, as both surveys and prior work [6,24] suggest that email is a common approach for sending sensitive content, particularly when an alternative is unknown to either party.…”
Section: Discussionmentioning
confidence: 99%
See 1 more Smart Citation
“…However, the results also showed that all automation need to be carefully balanced with the remaining security guarantees, which is particularly crucial for users that are concerned with highly sensitive data. Monson et al (2018) focussed on a specific usability feature of secure emails that concern secure deletion of emails. The user study revealed the preference of the users to have an email tool that allows shortening the lifetime of their emails rather than just encrypting them.…”
Section: Discussion and Recommendationsmentioning
confidence: 99%
“…The storage of plaintext email at the server presents an attack surface in case of future account compromise. Research is beginning to explore email deletion capabilities that reduce the risk of future disclosure of sensitive messages that do not require long-term storage [25]. Another approach is to encrypt the plaintext email on the server with a locally stored encryption key and delete the plaintext copy [26].…”
Section: Fig 83mentioning
confidence: 99%