Towards Human-Centric Endpoint Security


연구 분야: Safety



학회: Cambridge International Workshop on Security Protocols


초록

In a survey of six widely used end-to-end encrypted messaging applications, we consider the post-compromise recovery process from the perspective of what security audit functions, if any, are in place to detect and recover from attacks. Our investigation reveals audit functions vary in the extent to which they rely on the end user. We argue developers should minimize dependence on users and view them as a residual, not primary, risk mitigation strategy. To provide robust communications security, E2EE applications need to avoid protocol designs that dump too much responsibility on naive users and instead make system components play an appropriate role.


Author Profile
Awais Rashid

University of Bristol Bristol UK

정보 없음
Author Profile
Jenny Blessing

University of Cambridge Cambridge UK

정보 없음
Author Profile
Partha Das Chowdhury

University of Bristol Bristol UK

정보 없음

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가
사이트 Springer
좋아요 수 0

연관 논문 목록 (337건)