A usability test of whitelist and blacklist-based anti-phishing application
Linfeng Li, Marko Helenius, Eleni Berki · 2012
Anti-phishing tools on a web browser warn about spoofing pages or/and prompt to essential and necessary information that assists users to identify spoofing and potentially harmful pages. In order to discover how well users can identify phishing pages with these tools after they understand how the tools work, we designed and conducted usability tests for two detection mechanisms of anti-phishing tools: the blacklist-based and whitelist-based anti-phishing toolbars. As a result, we report that no significant performance differences between the blacklist-based and whitelist-based applications were found; but some other interesting findings and observations were collected. The most valuable observation is that due to the deficiency of existing web identities on the web pages and web browsers, e.g. abstract and professional web page security certificate information, anti-phishing toolbars need to be more illustrative and instructional in order to assist users to find reliable information for identifying the authenticity of the content on the web pages.