Show simple item record

Files in this item

Thumbnail

Item metadata

dc.contributor.authorWhalen, Tara
dc.contributor.authorMeunier, Thibault
dc.contributor.authorKodali, Mrudula
dc.contributor.authorDavidson, Alex
dc.contributor.authorFayed, Marwan
dc.contributor.authorFaz-Hernández, Armando
dc.contributor.authorLadd, Watson
dc.contributor.authorMaram, Deepak
dc.contributor.authorSullivan, Nick
dc.contributor.authorWolters, Benedikt Christoph
dc.contributor.authorGuerreiro, Maxime
dc.contributor.authorGalloni, Andrew
dc.date.accessioned2024-04-17T11:30:01Z
dc.date.available2024-04-17T11:30:01Z
dc.date.issued2022
dc.identifier299375847
dc.identifierbf33990b-61b7-41b0-b76e-3bacbf5c4f4f
dc.identifier85140884289
dc.identifier.citationWhalen , T , Meunier , T , Kodali , M , Davidson , A , Fayed , M , Faz-Hernández , A , Ladd , W , Maram , D , Sullivan , N , Wolters , B C , Guerreiro , M & Galloni , A 2022 , Let the right one in : attestation as a usable CAPTCHA alternative . in Proceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022 . Proceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022 , USENIX Association , pp. 599-612 , 18th Symposium on Usable Privacy and Security, SOUPS 2022 , Boston , United States , 7/08/22 .en
dc.identifier.citationconferenceen
dc.identifier.isbn9781939133304
dc.identifier.otherORCID: /0000-0002-0970-7972/work/153451590
dc.identifier.urihttps://hdl.handle.net/10023/29695
dc.description.abstractCAPTCHAs are necessary to protect websites from bots and malicious crawlers, yet are increasingly solvable by automated systems. This has led to more challenging tests that require greater human effort and cultural knowledge; they may prevent bots effectively but sacrifice usability and discourage the human users they are meant to admit.We propose a new class of challenge: a Cryptographic Attestation of Personhood (CAP) as the foundation of a usable, pro-privacy alternative. Our challenge is constructed using the open Web Authentication API (WebAuthn) that is supported in most browsers. We evaluated the CAP challenge through a public demo, with an accompanying user survey. Our evaluation indicates that CAP has a strong likelihood of adoption by users who possess the necessary hardware, showing good results for effectiveness and efficiency as well as a strong expressed preference for using CAP over traditional CAPTCHA solutions. In addition to demonstrating a mechanism for more usable challenge tests, we identify some areas for improvement for the WebAuthn user experience, and reflect on the difficult usable privacy problems in this domain and how they might be mitigated.
dc.format.extent14
dc.format.extent644690
dc.language.isoeng
dc.publisherUSENIX Association
dc.relation.ispartofProceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022en
dc.relation.ispartofseriesProceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022en
dc.subjectComputer Networks and Communicationsen
dc.subjectSafety, Risk, Reliability and Qualityen
dc.subjectNDASen
dc.titleLet the right one in : attestation as a usable CAPTCHA alternativeen
dc.typeConference itemen
dc.contributor.institutionUniversity of St Andrews. School of Computer Scienceen
dc.identifier.urlhttps://www.usenix.org/conference/soups2022/presentation/whalenen


This item appears in the following Collection(s)

Show simple item record