首页> 外文会议>Cryptographers' track at the RSA conference >Why Johnny the Developer Can't Work with Public Key Certificates An Experimental Study of OpenSSL Usability
【24h】

Why Johnny the Developer Can't Work with Public Key Certificates An Experimental Study of OpenSSL Usability

机译:为什么开发人员Johnny不能使用公钥证书OpenSSL可用性的实验研究

获取原文

摘要

There have been many studies exposing poor usability of security software for the common end user. However, only a few inspect the usability challenges faced by more knowledgeable users. We conducted an experiment to empirically assess usability of the command line interface of OpenSSL, a well known and widely used cryptographic library. Based on the results, we try to propose specific improvements that would encourage more secure behavior. We observed 87 developers/administrators at two certificate-related tasks in a controlled environment. Furthermore, we collected participant opinions on both the tool interface and available documentation. Based on the overall results, we deem the OpenSSL usability insufficient according to both user opinions and standardized measures. Moreover, the perceived usability seems to be correlated with previous experience and used resources. There was a great disproportion between the participant views of a successful task accomplishment and the reality. A general dissatisfaction with both OpenSSL interface and its manual page was shared among the majority of the participants. As hinted by a participant, OpenSSL gradually "turned into a complicated set of sharp kitchen knives" - it can perform various jobs very well, but laymen risk stabbing themselves in the process. This highlights the necessity of a usable design even for tools targeted at experienced users (Supplementary material available at crocs.fi.muni.cz/papers/rsa2018).
机译:已经有许多研究揭示了普通最终用户使用安全软件的可用性较差。但是,只有少数人检查更多知识渊博的用户所面临的可用性挑战。我们进行了一项实验,以经验评估OpenSSL命令行界面的可用性,OpenSSL是一种众所周知且广泛使用的密码库。根据结果​​,我们尝试提出一些具体的改进措施,以鼓励更安全的行为。我们在受控环境中的两个与证书相关的任务中观察到87位开发人员/管理员。此外,我们收集了有关工具界面和可用文档的参与者意见。基于总体结果,我们根据用户意见和标准化措施认为OpenSSL可用性不足。此外,感知的可用性似乎与以前的经验和使用的资源相关。参与者对成功完成任务的看法与现实之间存在很大的差异。大多数参与者都对OpenSSL界面及其手册页普遍不满意。正如一位参与者所暗示的那样,OpenSSL逐渐“变成了一套复杂的锋利的厨房刀”-它可以很好地执行各种工作,但是外行人士可能会在此过程中刺伤自己。这凸显了即使针对有经验的用户的工具也要使用设计的必要性(crocs.fi.muni.cz/papers/rsa2018中提供了补充材料)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号