proomt

Search

Search posts, papers, and topics

Hall of Fame

Hall of FameAlma Whitten, J. D. Tygar199949 min readpaperintermediate

Why Johnny Can't Encrypt

Summary

Whitten and Tygar evaluated PGP 5.0 with a cognitive walkthrough and a 90‑minute lab test, finding that most novices could not successfully encrypt or sign email. The study shows that general UI principles are insufficient for security tools and that dedicated usability standards are needed.

  • Even a polished GUI like PGP 5.0 failed to let most novice users encrypt/sign email within 90 minutes.
  • Cognitive walkthrough uncovered specific UI flaws such as ambiguous key selection and missing feedback that cause dangerous errors.
  • Usable security demands its own design criteria; general consumer UI guidelines do not address security’s unique properties.
  • Combining walkthrough analysis with user testing yields a more comprehensive assessment of security software usability.

Security engineers and UX designers need to see that poor usability directly compromises cryptographic protection, making security‑specific UI design essential.

8/10

Related reading

  1. Why Does an NPM Math Library Need an Encrypted Loader?

    SafeDep discovered that several npm packages masquerading as mathjs contain an encrypted loader that only activates when a caller passes a particular matrix to the LU solver, using the matrix’s lower‑triangular factor as the decryption password. The loader decrypts and executes a multi‑stage remote‑access implant that talks to Slack, Telegram and a blockchain contract, and the same technique is r…

    Hacker News front pagesafedep.io10 minHN13741
  2. ImpossibleRubrics: Stress-Testing Generated Rubrics as Reward Signals

    ImpossibleRubrics introduces a 169‑task benchmark of “impossible” prompts, each with a formal oracle certificate defining what an honest answer can claim. The authors generate rubrics downstream and test them adversarially, finding that many rubric generators are exploitable (8‑36% of the time) and that a single generic rubric (“be decisive, penalize hedging”) is exploited 64% of the time, while…

    Hugging Face Daily Papersarxiv.org1 minpaper
  3. Poisoned Documents, Real Risks: Sebastián Passaro Puts AI’s Weakest Link to the Test at Testear.la 2026

    Sebastián Passaro (Qubika) demonstrated a live RAG pipeline attack at Testear.la 2026, showing how a single poisoned document can hijack LLM outputs and trigger unsafe actions. He tied the demo to the OWASP LLM Top 10, highlighted open‑source tooling for finding such weaknesses, and advocated a defense‑in‑depth threat model for QA teams. The talk reframed AI from a testing aid to a security surfa…

    Moove-itqubika.com4 min
  4. Article: Architecting Secure and Scalable Facial Verification Systems

    A real‑world post‑mortem of a high‑volume face verification service that moved from a naïve synchronous API to an async, layered pipeline (edge validation, preprocessing, decoupled detection/verification, decision engine) to achieve 8.5k rpm, p99 < 1.8 s, 30 % cost savings, and strict privacy controls.

    InfoQinfoq.com15 min
  5. Article: Your Next DSL Author Is a Language Model

    Typed Domain Grounding (TDG) embeds a DSL inside a mainstream language the LLM already knows (e.g., Kotlin) and uses the host compiler as an oracle. The author describes five building blocks—embedding, choosing a host language with high training‑data frequency, compiler‑driven type safety, a generate‑compile‑repair loop, and an on‑demand teaching tool—and shows measured results from kUML, a Kotli…

    InfoQinfoq.com18 min