Security-Centered Design: Don't Just Plan for Security; Design For It

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Security-Centered Design: Don't Just Plan for Security; Design For It - Presentation Transcript

    1. Security-Centered Design Chris Shiflett shiflett.org 1
    2. Talk Outline ‣ Cognitive Psychology Ambient Signifiers Change Blindness ‣ Phishing ‣ Examples SmugMug Bank Insecurity 2
    3. For Your Consideration ‣ Good is the absence of bad, so bad examples are more useful than good. ‣ Security must be part of the design; design means more than just technical design. ‣ Human behavior should always be considered. ‣ Reality is more important than theory. ‣ Perception is almost as important as reality. 3
    4. 4
    5. Ambient Signifiers 5
    6. 6
    7. Secure or Not? 7
    8. Change Blindness 8
    9. 9
    10. 10
    11. 11
    12. Derren Brown Video 12
    13. 13
    14. 14
    15. 15
    16. Phishing 16
    17. http://login.yahoo.com/ 17
    18. Obfuscating Links in Email <a href=\"http://evil/\">http://good/</a> 18
    19. facebook.com 19
    20. dopplr.com 20
    21. SmugMug 21
    22. 22
    23. 23
    24. 24
    25. 25
    26. Bank Insecurity 26
    27. 27
    28. ‣ Roughly half the sites requested login information on an insecure page. ‣ Over a quarter of the sites had poor policies on the username/password combination. ‣ Many sites provided insecure access to critical information, sometimes via email. ‣ Some financial activities required that the user be sent to a site run by a different company, meaning they were no longer interacting with the original domain. 28
    29. \"Design flaws differ from typical software bugs that can be fixed by applying patches. Design flaws are a result of decisions made during the website design phase, such as how to implement security features. These design decisions promote insecure user behavior.\" http://cups.cs.cmu.edu/soups/2008/proceedings/p117Falk.pdf 29
    30. Related Posts Security and User Experience http://shiflett.org/blog/2008/jan/security-and-user-experience Ambient Signifiers http://shiflett.org/blog/2007/feb/ambient-signifiers 30
    31. 31
    32. Thanks for Listening ‣ http://shiflett.org/ ‣ http://omniti.com/ Slides http://shiflett.org/security-centered-design.pdf 32

    + ZendConZendCon, 9 months ago

    custom

    785 views, 0 favs, 0 embeds more stats

    Anyone who has ever disabled a certain proprietary more

    More Info

    © All Rights Reserved

    Go to text version
    • Total Views 785
      • 785 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 84
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as innappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel

    Categories