Session 2: (Mis)communicating Security Properties

10:30 am – 11:15 am


Users should be able to use a system effectively and safely without needing to understand the nuance of how the system works, under the covers. The user's implicit mental models of associated with system functionality should not encourage behaviors that may harm the user's security and privacy interests.

  • Presentation: Weakly enforced versus strongly enforced security settings
  • Presentation: The semantics of a master password change aren't what you might think
  • Presentation: When 2FA (2-factor authentication) is not 2FA.
  • Discussion followup
