2019 IEEE European Symposium on Security and Privacy (EuroS&P) 2019
DOI: 10.1109/eurosp.2019.00037
|View full text |Cite
|
Sign up to set email alerts
|

In Encryption We Don’t Trust: The Effect of End-to-End Encryption to the Masses on User Perception

Abstract: With WhatsApp's adoption of the Signal Protocol as its default, end-to-end encryption by the masses happened almost overnight. Unlike iMessage, WhatsApp notifies users that encryption is enabled, explicitly informing users about improved privacy. This rare feature gives us an opportunity to study people's understandings and perceptions of secure messaging pre-and post-mass messenger encryption (pre/post-MME). To study changes in perceptions, we compared the results of two mental models studies: one conducted i… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
14
0
2

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
2
2

Relationship

0
9

Authors

Journals

citations
Cited by 23 publications
(25 citation statements)
references
References 23 publications
0
14
0
2
Order By: Relevance
“…Software based mass encryption technology can be used in the pharmaceutical industry to fight against counterfeit drugs. The same software is required to decrypt the digital code [7]. This technology requires a large database server to store the data.…”
Section: Mass Encryption Technologymentioning
confidence: 99%
“…Software based mass encryption technology can be used in the pharmaceutical industry to fight against counterfeit drugs. The same software is required to decrypt the digital code [7]. This technology requires a large database server to store the data.…”
Section: Mass Encryption Technologymentioning
confidence: 99%
“…Such misuse is likely explained by the fact that users have incorrect mental models about how security works [1,2,21,42]. This lack of understanding can also lead users to distrust tools making claims about security [8,12].…”
Section: Incorrect Mental Modelsmentioning
confidence: 99%
“…Educating app designers rather than users. Dechand et al [8] make the strong statement that educating users about encryption is not going to change their behavior. Based on our results, we agree.…”
Section: Improving Group Chat Toolsmentioning
confidence: 99%
“…The interface design showed various issues, including the use of inconsistent terminology and not making all security features clear to the user. A later study showed that users lacked both trust in and awareness of encryption in secure messaging tools, even though the tool explitely informed them that encrpytion was used [9]. Communication with end users in the context of connection security seems to be similarly challenging as shown in a qualitative study on end user and administrator mental models of HTTPS.…”
Section: Consequences Of Invisible and Ineffectively Communicated Encmentioning
confidence: 99%