Top Banner
78

Security vs UX: Why UX is an important factor in designing secure systems

Jan 15, 2017

Download

Software

elttam
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Security vs UX: Why UX is an important factor in designing secure systems
Page 2: Security vs UX: Why UX is an important factor in designing secure systems
Page 3: Security vs UX: Why UX is an important factor in designing secure systems
Page 4: Security vs UX: Why UX is an important factor in designing secure systems
Page 5: Security vs UX: Why UX is an important factor in designing secure systems

Page 6: Security vs UX: Why UX is an important factor in designing secure systems
Page 7: Security vs UX: Why UX is an important factor in designing secure systems
Page 8: Security vs UX: Why UX is an important factor in designing secure systems
Page 9: Security vs UX: Why UX is an important factor in designing secure systems
Page 10: Security vs UX: Why UX is an important factor in designing secure systems

• BakerHostetler: Privacy and Data protection report in 2014• Ponemon: the new leading cause of data breach report 2015• CompTIA: Survey of hundreds of US companies 2015

All these research studies had the same conclusions.

Page 11: Security vs UX: Why UX is an important factor in designing secure systems
Page 12: Security vs UX: Why UX is an important factor in designing secure systems

Yes, 9 characters. ISM new requirements.

Page 13: Security vs UX: Why UX is an important factor in designing secure systems

2 in 1: A sticky note + a weak password.

Remote Second Factor Auth (R2FA)!

Page 14: Security vs UX: Why UX is an important factor in designing secure systems

Lets be professional and call him a UX factor!

Page 15: Security vs UX: Why UX is an important factor in designing secure systems
Page 16: Security vs UX: Why UX is an important factor in designing secure systems

Feel

Usability

Look

Page 17: Security vs UX: Why UX is an important factor in designing secure systems

Confidentiality

Integrity

Availability

Page 18: Security vs UX: Why UX is an important factor in designing secure systems

Feel

Usability

Look

Confidentiality

Integrity

Availability

Page 19: Security vs UX: Why UX is an important factor in designing secure systems
Page 20: Security vs UX: Why UX is an important factor in designing secure systems
Page 21: Security vs UX: Why UX is an important factor in designing secure systems
Page 22: Security vs UX: Why UX is an important factor in designing secure systems

More on these later.

Page 23: Security vs UX: Why UX is an important factor in designing secure systems
Page 24: Security vs UX: Why UX is an important factor in designing secure systems
Page 25: Security vs UX: Why UX is an important factor in designing secure systems
Page 26: Security vs UX: Why UX is an important factor in designing secure systems
Page 27: Security vs UX: Why UX is an important factor in designing secure systems
Page 28: Security vs UX: Why UX is an important factor in designing secure systems
Page 29: Security vs UX: Why UX is an important factor in designing secure systems
Page 30: Security vs UX: Why UX is an important factor in designing secure systems
Page 31: Security vs UX: Why UX is an important factor in designing secure systems

Don’t ask how tall you are!

Many don’t have a middle name!

It must be easier that remembering a password.

Page 32: Security vs UX: Why UX is an important factor in designing secure systems
Page 33: Security vs UX: Why UX is an important factor in designing secure systems

Don’t prompt the same question.

Page 34: Security vs UX: Why UX is an important factor in designing secure systems
Page 35: Security vs UX: Why UX is an important factor in designing secure systems

This shows an empty space. There are no more pros.

Page 36: Security vs UX: Why UX is an important factor in designing secure systems

* http://research.google.com/pubs/pub43783.html

Page 37: Security vs UX: Why UX is an important factor in designing secure systems
Page 38: Security vs UX: Why UX is an important factor in designing secure systems
Page 39: Security vs UX: Why UX is an important factor in designing secure systems
Page 40: Security vs UX: Why UX is an important factor in designing secure systems

Good UX point.

Page 41: Security vs UX: Why UX is an important factor in designing secure systems

e.g. SecureRandom class

At the time of writing.

Page 42: Security vs UX: Why UX is an important factor in designing secure systems
Page 43: Security vs UX: Why UX is an important factor in designing secure systems

This shows an empty space. There are no more pros.

Page 44: Security vs UX: Why UX is an important factor in designing secure systems

So, reduce the attack window with time limitation.

You increase chance of successful Social Engineering attacks.

Page 45: Security vs UX: Why UX is an important factor in designing secure systems
Page 46: Security vs UX: Why UX is an important factor in designing secure systems
Page 47: Security vs UX: Why UX is an important factor in designing secure systems
Page 48: Security vs UX: Why UX is an important factor in designing secure systems
Page 49: Security vs UX: Why UX is an important factor in designing secure systems

This is perhaps the best use-case.

Good UX point.

Page 50: Security vs UX: Why UX is an important factor in designing secure systems

Banks, please don’t use it

$20,000 Phone porting scamJune 2015

Page 51: Security vs UX: Why UX is an important factor in designing secure systems

Banks, please don’t use it

Page 52: Security vs UX: Why UX is an important factor in designing secure systems
Page 53: Security vs UX: Why UX is an important factor in designing secure systems
Page 54: Security vs UX: Why UX is an important factor in designing secure systems
Page 55: Security vs UX: Why UX is an important factor in designing secure systems

At the time of writing.

Check References slide.

Page 56: Security vs UX: Why UX is an important factor in designing secure systems

6.4% adoption of Google 2FA*http://users.ics.forth.gr/~elathan/papers/eurosec15.pdf

Page 57: Security vs UX: Why UX is an important factor in designing secure systems
Page 58: Security vs UX: Why UX is an important factor in designing secure systems

This could be your weakest link.More on this later.

Page 59: Security vs UX: Why UX is an important factor in designing secure systems
Page 60: Security vs UX: Why UX is an important factor in designing secure systems
Page 61: Security vs UX: Why UX is an important factor in designing secure systems
Page 62: Security vs UX: Why UX is an important factor in designing secure systems
Page 63: Security vs UX: Why UX is an important factor in designing secure systems
Page 64: Security vs UX: Why UX is an important factor in designing secure systems

Google educate user on 2FA.

Page 65: Security vs UX: Why UX is an important factor in designing secure systems

A bad way of educating by LinkedIn.

Page 66: Security vs UX: Why UX is an important factor in designing secure systems
Page 67: Security vs UX: Why UX is an important factor in designing secure systems

List emails that user should expect from you.

Include also a sample email and type of things being requested in the email.

Page 68: Security vs UX: Why UX is an important factor in designing secure systems

Facebook tells users what emails not to expect.

Page 69: Security vs UX: Why UX is an important factor in designing secure systems

Good example by Amazon: “Don’t ask for code on this device”

Page 70: Security vs UX: Why UX is an important factor in designing secure systems

Good example by Google: Simple and clear what action to take

Page 71: Security vs UX: Why UX is an important factor in designing secure systems
Page 72: Security vs UX: Why UX is an important factor in designing secure systems

Page 73: Security vs UX: Why UX is an important factor in designing secure systems
Page 75: Security vs UX: Why UX is an important factor in designing secure systems
Page 77: Security vs UX: Why UX is an important factor in designing secure systems