Eric Spero 0001

dblp:143/9858-1 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0002-9130-2148ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Language as Lure: A Naturalistic Study on Pasifika Phishing Susceptibility
Eric Spero 0001, Isa Seow, Lucas Betts, Eddie Fuatimau, Robert Biddle, Danielle Lottridge, Giovanni Russello
SOUPS1
2025 Site Inspector: Improving Browser Communication of Website Security Information
abstract
Phishing sites exploit users’ limited understanding of website identity to mimic legitimate sites. While X.509 certificates can provide crucial cues regarding a website’s identity, current browsers fail to effectively communicate this information to users, even as phishing becomes an increasingly serious issue. To address this, we developed Site Inspector (SI), a UI tool that conveys website identity and connection encryption information, along with brief explanations of the relevant underlying security concepts. SI is implemented as a Mozilla Firefox browser extension, but the basic design could be integrated into any web browser. SI organizes content in a three-tiered abstraction hierarchy, drawing on Ecological Interface Design. The top level presents an indicator of the website owner, if known, and also whether the connection is encrypted. The second and third levels offer progressively detailed explanations of the verification process. SI adheres to design principles aimed at educating users about security through the UI while overcoming associated challenges. Its text is concise and direct, respecting limitations in users’ attentional resources and motivation to engage with security matters. As a proof of concept for SI’s principled design, we conducted a user study with 30 participants to evaluate its effectiveness in helping users differentiate real from fraudulent websites. Results suggested that SI improved users’ ability to identify fraudulent sites. Future work will involve further testing with a larger user base, integrated SI directly into browsers, and ultimately a more widespread and improved validation process for certificates, with stronger verification and transparency.
Eric Spero 0001, Robert Biddle
ACM Trans. Priv. Secur.1
2022 What is Beautiful is Secure
abstract
Visual appeal has been shown to influence perceptions of usability and credibility, and we hypothesize that something similar is happening with user judgments of website security: What is beautiful is secure . Web certificates provide reliable information about a website’s level of security, presented in browser interfaces. Users should use this to inform their trust decisions online, but evidence from laboratory studies and real-world usage suggests that they do not. We conducted two studies—one in lab, and one online—in which participants view and interact with websites with high and low visual appeal, and various security levels, and then make security-related judgments. In both studies, participants consistently rated visually appealing websites as more secure, and indicated they would be more likely to enter sensitive information into visually appealing websites—even when they were less secure. Our results provide evidence that users rely on visual appeal when making security and trust decisions on websites. We discuss how these results may be used to help users.
Milica Stojmenovic, Eric Spero 0001, Milos Stojmenovic, Robert Biddle
ACM Trans. Priv. Secur.2
2020 Out of Sight, Out of Mind: UI Design and the Inhibition of Mental Models of Security
abstract
In this paper we make the case that UI design inhibits mental models of security by concealing most of the security-relevant aspects of software functionality. Users are frequently required to make decisions that have important security implications, that requires a mental model of software infrastructure to know what actions are ‘safe’ versus ‘unsafe’. People build internal causal models of what they experience that have explanatory and predictive power, and therefore form the basis of the decision-making faculty. By concealing security information, user interfaces hinder the user from building the kinds of models that will keep them safer, and only the small minority who are willing to go beyond the interface will acquire this knowledge. We suggest increasing the visibility of some essential information about the security-relevant aspects of software functionality in a way that ordinary users will be able to make sense of, so that through normal interactions with software everyone develops the kind of knowledge needed to better support security. We review the cognitive science and cybersecurity literature on mental models, present three ‘case studies’ which embody the security concealment problem, and present preliminary suggestions for how UI design might amend this problem.
Eric Spero 0001, Robert Biddle
NSPW1
2019 Mixed Pictures: Mental Models of Malware
abstract
Malware is a serious problem for users, who become affected as a result of the decisions they make online. This paper presents a study examining mental models related to malware and regular software, in hopes of finding clues to that will help us understand what users know about malware, and what we can do to help them make better decisions online. The study involved two drawing tasks, where participants were asked to draw their understanding of how a word processor and malware work, respectively. Several concerning patterns emerged. Participants seemed to regard malware as a fundamentally different kind of entity than regular software. They make black-and-white distinctions between malware and regular software in terms of whether the software is helpful or harmful, who the software serves, and who controls it. Finally, participants showed lesser knowledge of malware compared to regular software.
Eric Spero 0001, Milica Stojmenovic, Zahra Hassanzadeh, Sonia Chiasson, Robert Biddle
PST1
2019 Website Identity Notification: Testing the Simplest Thing That Could Possibly Work
abstract
Users are used to authenticating themselves to websites, but not for websites to authenticate to them. One readily available mechanism that may help users make safer online decisions lies in website certificates that contain website identity information. Fraudulent websites are now short-lived and present valid certificates without any identity information. Our goal was to create and test the effectiveness of simpler certificate interfaces, made to help users differentiate between identity-verified websites and those without such verification, and thus, potentially fraudulent. We conducted a study with a certificate interface prototype with simple identity notification types. Our findings suggest that presenting identity information to users can help them differentiate between real and potentially fraudulent websites. Some users were suspicious of the notifications and incorrectly felt that they could make decisions based on website appearance, so building user background knowledge is essential.
Milica Stojmenovic, Eric Spero 0001, Temitayo Oyelowo, Robert Biddle
PST2