Skip to main navigation Skip to search Skip to main content

Position: The user is the enemy

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

11 Scopus citations

Abstract

The Human Factor has long been recognized as the weakest link in computer systems security, yet, nothing technically significant has been done to address this problem in an attack agnostic manner. In this paper, we introduce the mantra of "The User is the Enemy" for security designers and developers alike as an underlying current towards addressing the weak human factor. We present different notions of the user and the system and argue from parallel tracks that user actions, both ignorant and non-compliant, are detrimental to the organization. We further show how the paradigm has been applied in a rather unconscious manner and contend that security mechanisms borne out of a conscious application will be more effective towards addressing this systemic problem. Our position is not meant to be a cynical attitude towards users; rather, it is meant to be the focal point of security design attitude, similar to the mantra "All user input is evil" for addressing buffer overflow attacks.

Original languageEnglish
Title of host publicationProceedings - New Security Paradigms Workshop 2007, NSPW 2007
Pages75-80
Number of pages6
DOIs
StatePublished - 2007
Event2007 Workshop on New Security Paradigms, NSPW 2007 - North Conway, NH, United States
Duration: Sep 18 2007Sep 21 2007

Publication series

NameProceedings New Security Paradigms Workshop

Conference

Conference2007 Workshop on New Security Paradigms, NSPW 2007
Country/TerritoryUnited States
CityNorth Conway, NH
Period09/18/0709/21/07

Keywords

  • Non-compliant users
  • User centered security

Fingerprint

Dive into the research topics of 'Position: The user is the enemy'. Together they form a unique fingerprint.

Cite this