首页> 外文会议>Cryptographers Track at the RSA Conference >Why Johnny the Developer Can't Work with Public Key Certificates An Experimental Study of OpenSSL Usability
【24h】

Why Johnny the Developer Can't Work with Public Key Certificates An Experimental Study of OpenSSL Usability

机译:为什么Johnny开发人员无法使用公钥证书,对OpenSSL可用性的实验研究

获取原文

摘要

There have been many studies exposing poor usability of security software for the common end user. However, only a few inspect the usability challenges faced by more knowledgeable users. We conducted an experiment to empirically assess usability of the command line interface of OpenSSL, a well known and widely used cryptographic library. Based on the results, we try to propose specific improvements that would encourage more secure behavior. We observed 87 developers/administrators at two certificate-related tasks in a controlled environment. Furthermore, we collected participant opinions on both the tool interface and available documentation. Based on the overall results, we deem the OpenSSL usability insufficient according to both user opinions and standardized measures. Moreover, the perceived usability seems to be correlated with previous experience and used resources. There was a great disproportion between the participant views of a successful task accomplishment and the reality. A general dissatisfaction with both OpenSSL interface and its manual page was shared among the majority of the participants. As hinted by a participant, OpenSSL gradually "turned into a complicated set of sharp kitchen knives" - it can perform various jobs very well, but laymen risk stabbing themselves in the process. This highlights the necessity of a usable design even for tools targeted at experienced users (Supplementary material available at crocs.fi.muni.cz/papers/rsa2018).
机译:已经有许多研究暴露了共同的最终用户的安全软件可用性差。但是,只有少数人检查更多知识渊博的用户所面临的可用性挑战。我们进行了一个实验,以验证评估Openssl的命令行界面的可用性,众所周知的和广泛使用的加密库。根据结果​​,我们试图提出要鼓励更安全行为的具体改进。我们在受控环境中观察了87个相关任务的87个开发人员/管理员。此外,我们在工具界面和可用文档中收集了参与者的意见。根据整体结果,我们认为根据用户意见和标准化措施,我们认为openssl可用性不足。此外,感知的可用性似乎与以前的经验和使用资源相关联。成功完成任务成就和现实的参与者观点之间存在巨大的歧视。与OpenSSL界面及其手册页面的一般不满在大多数参与者之间共享。作为暗示由参与者,OpenSSL的逐步“变成了复杂的一套锋利的菜刀” - 它可以执行各种工作得很好,但外行人风险刺向自己的过程。即使在经验丰富的用户(Crocs.fi.muni.cz/popers/rsa2018)的有经验的用户(补充材料提供的补充材料提供的工具,这也突出了可用设计的必要性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号