TY - CHAP A1 - Mayer, Peter A1 - Poddebniak, Damian A1 - Fischer, Konstantin A1 - Brinkmann, Marcus A1 - Somorovsky, Juraj A1 - Schinzel, Sebastian A1 - Volkamer, Melanie T1 - "I don’t know why I check this...'' - Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks T2 - Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022) N2 - OpenPGP is one of the two major standards for end-to-end email security. Several studies showed that serious usability issues exist with tools implementing this standard. However, a widespread assumption is that expert users can handle these tools and detect signature spoofing attacks. We present a user study investigating expert users' strategies to detect signature spoofing attacks in Thunderbird. We observed 25 expert users while they classified eight emails as either having a legitimate signature or not. Studying expert users explicitly gives us an upper bound of attack detection rates of all users dealing with PGP signatures. 52% of participants fell for at least one out of four signature spoofing attacks. Overall, participants did not have an established strategy for evaluating email signature legitimacy. We observed our participants apply 23 different types of checks when inspecting signed emails, but only 8 of these checks tended to be useful in identifying the spoofed or invalid signatures. In performing their checks, participants were frequently startled, confused, or annoyed with the user interface, which they found supported them little. All these results paint a clear picture: Even expert users struggle to verify email signatures, usability issues in email security are not limited to novice users, and developers may need proper guidance on implementing email signature GUIs correctly. Y1 - 2022 UR - https://www.usenix.org/conference/soups2022/presentation/mayer SN - 978-1-939133-30-4 SP - 77 EP - 96 PB - USENIX Association CY - Boston, MA ER - TY - CHAP A1 - Poddebniak, Damian A1 - Somorovsky, Juraj A1 - Schinzel, Sebastian A1 - Lochter, Manfred A1 - Rösler, Paul T1 - Attacking Deterministic Signature Schemes using Fault Attacks T2 - 3rd IEEE European Symposium on Security and Privacy Y1 - 2018 ER - TY - CHAP A1 - Poddebniak, Damian A1 - Dresen, Christian A1 - Müller, Jens A1 - Ising, Fabian A1 - Schinzel, Sebastian A1 - Friedberg, Simon A1 - Somorovsky, Juraj A1 - Schwenk, Jörg T1 - Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels T2 - USENIX Security 2018 Y1 - 2018 SN - 978-1-931971-46-1 CY - Baltimore, MD, USA ET - 27th ER - TY - JOUR A1 - Brinkmann, Marcus A1 - Dresen, Christian A1 - Merget, Robert A1 - Poddebniak, Damian A1 - Müller, Jens A1 - Somorovsky, Juraj A1 - Schwenk, Jörg A1 - Schinzel, Sebastian T1 - ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication JF - 30th USENIX Security Symposium Y1 - 2021 UR - https://www.usenix.org/conference/usenixsecurity21/presentation/brinkmann ER -