Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Towards Usable Checksums: Automating the Integrity Verification ofWeb Downloads for the Masses
 
conference paper

Towards Usable Checksums: Automating the Integrity Verification ofWeb Downloads for the Masses

Cherubini, Mauro
•
Meylan, Alexandre
•
Chapuis, Bertil
Show more
January 1, 2018
Proceedings Of The 2018 Acm Sigsac Conference On Computer And Communications Security (Ccs'18)
ACM SIGSAC Conference on Computer and Communications Security (CCS)

Internet users can download software for their computers from app stores (e.g., Mac App Store and Windows Store) or from other sources, such as the developers' websites. Most Internet users in the US rely on the latter, according to our representative study, which makes them directly responsible for the content they download. To enable users to detect if the downloaded files have been corrupted, developers can publish a checksum together with the link to the program file; users can then manually verify that the checksum matches the one they obtain from the downloaded file. In this paper, we assess the prevalence of such behavior among the general Internet population in the US (N = 2,000), and we develop easy-to-use tools for users and developers to automate both the process of checksum verification and generation. Specifically, we propose an extension to the recent W3C specification for sub-resource integrity in order to provide integrity protection for download links. Also, we develop an extension for the popular Chrome browser that computes and verifies checksums of downloaded files automatically, and an extension for the WordPress CMS that developers can use to easily attach checksums to their remote content. Our in situ experiments with 40 participants demonstrate the usability and effectiveness issues of checksums verification, and shows user desirability for our extension.

  • Details
  • Metrics
Type
conference paper
DOI
10.1145/3243734.3243746
Web of Science ID

WOS:000461315900080

Author(s)
Cherubini, Mauro
Meylan, Alexandre
Chapuis, Bertil
Humbert, Mathias  
Bilogrevic, Igor  
Huguenin, Kevin  
Date Issued

2018-01-01

Publisher

ASSOC COMPUTING MACHINERY

Publisher place

New York

Published in
Proceedings Of The 2018 Acm Sigsac Conference On Computer And Communications Security (Ccs'18)
ISBN of the book

978-1-4503-5693-0

Start page

1256

End page

1271

Subjects

Computer Science, Theory & Methods

•

Engineering, Electrical & Electronic

•

Computer Science

•

Engineering

•

checksums

•

web downloads

•

security

•

usability

•

perceptions

•

psychology

•

harm

Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
LDS  
Event nameEvent placeEvent date
ACM SIGSAC Conference on Computer and Communications Security (CCS)

Toronto, CANADA

Oct 15-19, 2018

Available on Infoscience
June 18, 2019
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/157560
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés