TY - GEN
T1 - Let the right one in
T2 - 18th Symposium on Usable Privacy and Security, SOUPS 2022
AU - Whalen, Tara
AU - Meunier, Thibault
AU - Kodali, Mrudula
AU - Davidson, Alex
AU - Fayed, Marwan
AU - Faz-Hernández, Armando
AU - Ladd, Watson
AU - Maram, Deepak
AU - Sullivan, Nick
AU - Wolters, Benedikt Christoph
AU - Guerreiro, Maxime
AU - Galloni, Andrew
PY - 2022
Y1 - 2022
N2 - CAPTCHAs are necessary to protect websites from bots and malicious crawlers, yet are increasingly solvable by automated systems. This has led to more challenging tests that require greater human effort and cultural knowledge; they may prevent bots effectively but sacrifice usability and discourage the human users they are meant to admit.We propose a new class of challenge: a Cryptographic Attestation of Personhood (CAP) as the foundation of a usable, pro-privacy alternative. Our challenge is constructed using the open Web Authentication API (WebAuthn) that is supported in most browsers. We evaluated the CAP challenge through a public demo, with an accompanying user survey. Our evaluation indicates that CAP has a strong likelihood of adoption by users who possess the necessary hardware, showing good results for effectiveness and efficiency as well as a strong expressed preference for using CAP over traditional CAPTCHA solutions. In addition to demonstrating a mechanism for more usable challenge tests, we identify some areas for improvement for the WebAuthn user experience, and reflect on the difficult usable privacy problems in this domain and how they might be mitigated.
AB - CAPTCHAs are necessary to protect websites from bots and malicious crawlers, yet are increasingly solvable by automated systems. This has led to more challenging tests that require greater human effort and cultural knowledge; they may prevent bots effectively but sacrifice usability and discourage the human users they are meant to admit.We propose a new class of challenge: a Cryptographic Attestation of Personhood (CAP) as the foundation of a usable, pro-privacy alternative. Our challenge is constructed using the open Web Authentication API (WebAuthn) that is supported in most browsers. We evaluated the CAP challenge through a public demo, with an accompanying user survey. Our evaluation indicates that CAP has a strong likelihood of adoption by users who possess the necessary hardware, showing good results for effectiveness and efficiency as well as a strong expressed preference for using CAP over traditional CAPTCHA solutions. In addition to demonstrating a mechanism for more usable challenge tests, we identify some areas for improvement for the WebAuthn user experience, and reflect on the difficult usable privacy problems in this domain and how they might be mitigated.
UR - https://www.usenix.org/conference/soups2022/presentation/whalen
M3 - Conference contribution
AN - SCOPUS:85140884289
T3 - Proceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022
SP - 599
EP - 612
BT - Proceedings of the 18th Symposium on Usable Privacy and Security, SOUPS 2022
PB - USENIX Association
Y2 - 7 August 2022 through 9 August 2022
ER -