Hall of FameAlma Whitten, J. D. Tygar199949 min readpaperintermediate
Why Johnny Can't Encrypt
Summary
Whitten and Tygar evaluated PGP 5.0 with a cognitive walkthrough and a 90‑minute lab test, finding that most novices could not successfully encrypt or sign email. The study shows that general UI principles are insufficient for security tools and that dedicated usability standards are needed.
- Even a polished GUI like PGP 5.0 failed to let most novice users encrypt/sign email within 90 minutes.
- Cognitive walkthrough uncovered specific UI flaws such as ambiguous key selection and missing feedback that cause dangerous errors.
- Usable security demands its own design criteria; general consumer UI guidelines do not address security’s unique properties.
- Combining walkthrough analysis with user testing yields a more comprehensive assessment of security software usability.
Security engineers and UX designers need to see that poor usability directly compromises cryptographic protection, making security‑specific UI design essential.
8/10


