Design and Field Evaluation of PassSec: Raising and Sustaining Web Surfer Risk Awareness

This paper presents PassSec, a Firefox Add-on that raises user awareness about safe and unsafe password entry while they surf the web. PassSec comprises a two-stage approach: highlighting as the web page loads, then bringing up a just-in-time helpful dialog when the user demonstrates an intention to enter a password on an unsafe web page. PassSec was developed using a human-centered design approach. We performed a field study with 31 participants that showed that PassSec significantly reduces the number of logins on websites where password entry is unsafe.
