The security of messaging applications against person-in-the-middle attacks relies on the authenticity of the exchanged keys. For users unable to meet in person, a manual key fingerprint verification is necessary to ascertain key authenticity. Such fingerprints can be exchanged visually or verbally, and it is not clear in which condition users perform best. This paper reports the results of a 62-participant study that investigated differences in performance and perceived usability of visual and verbal comparisons of word-based key fingerprints, and the influence of the individual's cognitive learning style. The results show visual comparisons to be more effective against non-security critical errors and are perceived to provide increased confidence, yet participants perceive verbal comparisons to be easier and require less mental effort. Besides, limited evidence was found on the influence of the individual's learning style on their performance.
翻译:对于无法亲自会见的用户来说,必须用手动关键指纹核查来确定关键真实性。这些指纹可以用视觉或口头方式交换,而且不清楚用户在什么情况下表现最佳。本文报告了62个参与者研究的结果,调查了基于文字的关键指纹的性能差异和视觉和口头比较的可使用性,以及个人认知学习风格的影响。结果显示,视觉比较对非安全的关键错误更有效,并被认为增加了信心,但参与者认为,口头比较更容易,需要的心理努力较少。此外,还发现了关于个人学习风格对其表现的影响的有限证据。