[cap-talk] Webkeys vs. the web

Toby Murray toby.murray at comlab.ox.ac.uk
Thu Apr 2 12:17:42 EDT 2009


On Thu, 2009-04-02 at 15:56 +0000, Karp, Alan H wrote:
> The projects we do in the Virus Safe Computing Initiative at HP Labs improve usability by adding security.
> 
> Polaris: by protecting the user if the application has a virus, enables you to turn off all the warning dialog boxes and turn on all the features, such as macros and scripting.
> 
> SCoopFS: by providing server authentication, client authorization, and encryption, lets the user collaborate without needing to think about phishing, spam, and snooping.
> 
> Anti-phishing toolbar (aka PassPet): by combining the petname tool with a password calculator, the user gets strong passwords and protection from keyloggers yet only clicks a button to log in.

I've always admired this work precisely because it demonstrates that
usability and security can share a common maxima. Now if we could see
any of them *released* so that this insight might spread further, that
would really be cool. I think this is one of those lessons that can
spread only via demonstrations.

Cheers

Toby


More information about the cap-talk mailing list