Improving Chrome’s
Security Warnings
Adrienne Porter Felt
Chrome Security (Enamel)
The role of warnings:
Browser warnings stand between users and dangerous situations (malware, phishing, surveillance)
”
“
Given a choice between
dancing pigs and security
the user will pick
dancing pigs every time
”
“
Given a choice between
dancing pigs and security
the user will pick
dancing pigs every time
Challenges:
How well do warnings work?
MALICIOUS DOWNLOAD
THREAT:�User tries to download & run bad binary
CTR: <5%
CONFIDENCE:�
MALWARE INTERSTITIAL
THREAT:�User at risk of drive-by download
CTR: ~18%
CONFIDENCE:�
NON-FATAL SSL INTERSTITIAL
THREAT:�Active network attacker
CTR: 68%
CONFIDENCE:�
Takeaway:
Case study: malicious downloads
We dramatically reduced the CTR with UX changes
30%
20%
10%
0%
new
old
1: DOWNLOAD SHELF
old
new
2: chrome://downloads
old
new
3: FINAL CONFIRMATION
old
new
4: BROWSER SHUTDOWN
old
new
5: GENERIC PDF WARNINGS
Case study: malware interstitial
MALWARE INTERSTITIAL
CTR: ~18%
CONFIDENCE:�
THREAT:�User at risk of drive-by download
FIELD STUDY: OCTOBER 2013
15% | 15% | 15% | 16% | 15% | 15% | 16% |
17% | 21% | 21% | 23% | 15% | 15% | 18% |
16% | 18% | 15% | 11% | 10% | 12% | 14% |
21% | 18% | 24% | 27% | 14% | 14% | 15% |
EFFECT OF PRIOR EXPERIENCE
Mechanical Turk experiment:
Does the reputation of the destination affect perception?
Low-reputation
High-reputation
Mechanical Turk experiment:
Does the reputation of the destination affect perception? Yes
Low-reputation 5% (471)
High-reputation 38% (357)
REPUTATION
I have never heard
of this site so I wouldn’t trust it.
Youtube is a well-known and
highly trusted site.
I frequent youtube.com
a lot and I have never gotten any malware
INVINCIBLE
I would still proceed knowing I have an anti virus
Because I own a mac
and i don’t worry about that stuff
I use Linux I’m not afraid of anything
Takeaway:
We need to figure out how to override normal indicators of trustworthiness
Case study: non-fatal SSL interstitial
NON-FATAL SSL INTERSTITIAL
CTR: 68%
CONFIDENCE:�
THREAT:�Active network attacker
A few reasons for false positives:
Works in progress:
FIREFOX’S SSL ERROR
CTR: 33%
CONFIDENCE:�
Firefox experiment:
Is the Firefox warning UI better?�
Conditions:
Firefox experiment:
Is the Firefox warning UI better?�Yes, but that’s not the whole story
Conditions:
Firefox experiment:
Is the Firefox warning UI better?�Yes, but that’s not the whole story
Conditions:
WORK IN PROGRESS
M O C K
Do warnings work?
Case study: malicious downloads
Case study: malware interstitial
Case study: non-fatal SSL interstitial
felt@chromium.org
Mustafa Acer
Alex Ainslie
Alan Bettes
Sunny Consolvo
Hazim Almuhimedi
Robert Reeder
Chris Palmer
Somas Thyagaraja
Joel Weinberger
CREDITS...