Risk
7/15/2013
01:45 PM
Connect Directly
RSS
E-Mail
50%
50%

Chrome Users More Likely To Ignore Security Warnings

Security messages affect user behavior -- as long as they're well-designed, according to study of Chrome and Firefox users.

9 Android Apps To Improve Security, Privacy
9 Android Apps To Improve Security, Privacy
(click image for larger view)
Chrome browser users: Are you feeling invulnerable?

That question seems pertinent after a new study that compared people's reactions to 25 million security warning messages found a curious difference between users of two different types of browsers. Specifically, users continued through 25% of Google Chrome's malware and phishing warnings, but only 10% of equivalent warnings from Mozilla Firefox. Similarly, users clicked through Chrome's SSL warning a whopping 70% of the time, versus only 33% for Firefox.

Those findings were detailed in "Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness,", a research paper written by Devdatta Akhawe, a computer science graduate student at the University of California, Berkeley, who recently collaborated on a study to assess the value of bug bounty programs; and Adrienne Porter Felt, who earned her Ph.D. from Berkeley last year and is now a Google research scientist at Google, focusing on Chrome security and privacy problems. Their research is due to be presented at next month's USENIX Security Symposium in Washington.

[ Amazon 1Button extension for Chrome reports user activity back to Amazon. Read more at Jay-Z App, Amazon Extension Slammed On Privacy. ]

The researchers said they gathered their data via Mozilla Firefox and Google Chrome's in-browser telemetry -- which users can enable to share anonymous performance data with the respective browser manufacturers -- which allowed them to observe over 25 million warning impressions in situ. The researchers emphasized, however, that at no time did they have access to personally identifiable information.

The discovery that users react to Chrome and Firefox's warning messages in different ways is good and bad news. The upside is that "security warnings can be effective in practice," the researchers note, and that "the user experience of a warning can have a significant impact on user behavior." That seems to refute the notion that many users simply dismiss warnings and can't be relied on to parse security-related details and come to a safe browsing decision. Or as noted by the authors of Securing Java, in a quotation cited by the "Warningland" report's authors: "Given a choice between dancing pigs and security, the user will pick dancing pigs every time."

But not all warning messages are created equal, as demonstrated by the fact that 70% of Google's SSL warnings were ignored by users, versus only 33% for Firefox users. Either that, or Google Chrome junkies are a bunch of self-selecting danger monkeys.

In fact, the researchers traced some high click-through rates to more advanced users -- namely, users of pre-release or Linux versions of Chrome. "Technically advanced users might feel more confident in the security of their computers, be more curious about blocked websites, or feel patronized by warnings," said the researchers, who recommended further studies of this group of users to help design warnings better tailored to their expectations.

Based on the study results, the researchers said, "The user experience of warnings can have an enormous impact on user behavior, justifying efforts to build usable warnings." They also noted that Google has also begun testing ways to make more Chrome users heed its SSL warnings. "Such a high click-through rate is undesirable: either users are not heeding valid warnings, or the browser is annoying users with invalid warnings and possibly causing warning fatigue."

Another interesting finding was that increasing the number of clicks required to bypass warning messages didn't appear to have any effect. In fact, despite having to click an "advanced" link followed by a "proceed" button, Chrome users still bypassed more warning messages than Firefox users, who had to click only a single, simpler warning. "We find this result surprising," said the researchers. "Common wisdom in e-commerce holds that extra clicks decrease click-through rates -- hence, one-click shopping. Google Chrome's warning designers introduced the extra step in the malware/phishing warning because they expected it to serve as a strong deterrent."

One likely explanation for Chrome's security warning not being as effective is that after a user decides to bypass the warning, up to a certain difficulty level, they simply won't be stopped. Furthermore, few users clicked on Chrome's "more information" link, suggesting that user attention is a finite resource, the researchers said. Accordingly, unless user experience designers get their browser safety messages right, don't expect most users to pay attention.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-4988
Published: 2014-07-09
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

CVE-2014-0207
Published: 2014-07-09
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVE-2014-0537
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-0539
Published: 2014-07-09
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 allow attackers to bypass intended access restrictions via uns...

CVE-2014-3309
Published: 2014-07-09
The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.