Publication:
How Safe Is Safety Number? A User Study on SIGNAL's Fingerprint and Safety Number Methods for Public Key Verification

cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.orcid#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtualsource.department2c0f3235-df99-46d7-8a29-4f72c775c391
cris.virtualsource.orcid2c0f3235-df99-46d7-8a29-4f72c775c391
dc.contributor.affiliationTOBB Ekonomi ve Teknoloji University; Turkish Aeronautical Association; Turk Hava Kurumu University
dc.contributor.authorBicakci, Kemal; Altuncu, Enes; Sahkulubey, Muhammet Sakir; Kiziloz, Hakan Ezgi; Uzunay, Yusuf
dc.date.accessioned2024-06-25T11:45:00Z
dc.date.available2024-06-25T11:45:00Z
dc.date.issued2018
dc.description.abstractCommunication security has become an indispensable demand of smartphone users. End-to-end encryption is the key factor for providing communication security, which mainly relies on public key cryptography. The main and unresolved issue for public key cryptography is to correctly match a public key with its owner. Failing to do so could lead to man-in-the-middle attacks. Different public key verification methods have been proposed in the literature. The methods which are based on verification by the users themselves are preferable with respect to cost and deployability than the methods such as digital certificates that involve the use of trusted third parties. One of these methods, fingerprinting was recently replaced by a method called safety number in the open source messaging application, SIGNAL. The developers of SIGNAL claimed this change would bring usability and security advantages however no formal user study was conducted supporting this claim. In this study, we compare the usability and security aspects of these two methods with a user study on 42 participants. The results indicate with significance that the safety number method leads to more successful results in less time for public key verification as compared to the fingerprint method.
dc.description.doi10.1007/978-3-319-99136-8_5
dc.description.endpage98
dc.description.pages14
dc.description.researchareasComputer Science; Engineering
dc.description.startpage85
dc.description.urihttp://dx.doi.org/10.1007/978-3-319-99136-8_5
dc.description.volume11060
dc.description.woscategoryComputer Science, Theory & Methods; Engineering, Electrical & Electronic
dc.identifier.issn0302-9743
dc.identifier.urihttps://acikarsiv.thk.edu.tr/handle/123456789/1210
dc.language.isoEnglish
dc.publisherSPRINGER INTERNATIONAL PUBLISHING AG
dc.relation.journalINFORMATION SECURITY (ISC 2018)
dc.subjectPublic key verification; Safety number; Fingerprint; Usability; SIGNAL
dc.titleHow Safe Is Safety Number? A User Study on SIGNAL's Fingerprint and Safety Number Methods for Public Key Verification
dc.typeProceedings Paper
dspace.entity.typePublication

Files