Authentication security advice is given with the goal of guiding users and organisations towards secure actions and practices. In this paper, we demonstrate that security advice can be ambiguous, contradictory and at times may not even have any clear benefits. We expand on current work by defining a formal approach to identifying costs of security advice and instigate a user study to identify the costs that apply to a large range of authentication advice. We also apply a simple framework for analysing the authentication related security benefits of advice. This allows us to identify costs and benefits for all classes of security advice.
翻译:提供安全认证建议的目的是指导用户和组织采取安全行动和做法;在本文件中,我们证明安全咨询可能含糊不清、相互矛盾,有时甚至没有明显的好处;我们扩大目前的工作,确定确定安全咨询费用的正式办法,并发起用户研究,确定适用于大量认证咨询的费用;我们还采用一个简单的框架,分析咨询与认证有关的安全惠益;这使我们能够确定各类安全咨询的成本和效益。