Seamless And Always-on Security in a Bring-Your-Own-Application World
Paulo Hecht, Sidney Fels, Júnia Coutinho Anacleto · 2015
This paper describes a usable security experiment with xmail, a prototype that enhances Gmail's webmail client security with end-to-end encryption making user content unreadable by the service provider. The prototype follows a seamless and always-on approach requiring minimal changes to the Gmail user interface and task flow. Many studies have pointed out problems with email security usability, but they usually take an adversarial context as reference. The focus of this work is on peacetime information disclosure with service providers when adopting third party web applications. This context is a remarkable characteristic in the trending Bring-Your-Own-Application phenomenon and raises many privacy and confidentiality concerns. Although users could successful benefit from the security approach and protect their messages without much extra work, many long-term adoption obstacles were detected in informal user observations.