SlideShare a Scribd company logo
SECURITY-
                  CENTERED
                   DESIGN
                           Chris Shiflett
                            shiflett.org
                             @shiflett




Tuesday, February 21, 12
Tuesday, February 21, 12
STOP




Tuesday, February 21, 12
STOP
                           Collaborate & Listen




Tuesday, February 21, 12
Tuesday, February 21, 12
Web craftsman from Brooklyn, NY, working on
                           Who am I?   Mapalong and Brooklyn Beta from Studiomates.




Tuesday, February 21, 12
TALK OUTLINE


                      Psychology Fun
                      – Ambient Signifiers, Change Blindness

                      Authentication & Phishing
                      – Password Anti-Pattern, OAuth, Facebook Connect

                      Examples
                      – SmugMug Privacy, Facebook Worm, Twitter Don’t Click




Tuesday, February 21, 12
AMBIENT SIGNIFIERS




Tuesday, February 21, 12
Tokyo Subway




Tuesday, February 21, 12
Tokyo Subway




Tuesday, February 21, 12
Ambient Umbrella




Tuesday, February 21, 12
Ambient SSL




Tuesday, February 21, 12
Login Seals




Tuesday, February 21, 12
CHANGE BLINDNESS




Tuesday, February 21, 12
Tuesday, February 21, 12
STOP




Tuesday, February 21, 12
STOP
                           Hammertime




Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
DERREN BROWN




Tuesday, February 21, 12
PASSWORD
                           ANTI-PATTERN




Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
OAUTH
                    http://shiflett.org/blog/2010/sep/twitter-oauth




Tuesday, February 21, 12
Tuesday, February 21, 12
FACEBOOK CONNECT




Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
THE WEB IS NOT
                             OBVIOUS




Tuesday, February 21, 12
Tuesday, February 21, 12
OPENID                 OAUTH
                           http://openid.net/    http://oauth.net/

               OPENID & OAUTH HYBRID
                                   http://j.mp/openidoauth

                 SHARED RESPONSIBILITY
           http://simonwillison.net/2009/Jul/16/responsibility/



Tuesday, February 21, 12
SMUGMUG PRIVACY




Tuesday, February 21, 12
Tuesday, February 21, 12
Accommodate users’ expectations and tendencies;
               Pave the cow paths.   don’t try to modify them.




Tuesday, February 21, 12
Tuesday, February 21, 12
Be Humble




Tuesday, February 21, 12
FACEBOOK WORM




Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
TWITTER DON’T CLICK




Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
Tuesday, February 21, 12
RELATED POSTS

                      Security and User Experience
                      – http://shiflett.org/blog/2008/jan/security-and-user-experience

                      Ambient Signifiers
                      – http://shiflett.org/blog/2007/feb/ambient-signifiers

                      Facebook Worm
                      – http://shiflett.org/blog/2008/nov/facebook-worm

                      Twitter Don’t Click Exploit
                      – http://shiflett.org/blog/2009/feb/twitter-dont-click-exploit




Tuesday, February 21, 12
PHOTOS


                      Tree
                      – http://flickr.com/photos/stuckincustoms/529110230

                      Cow path
                      – http://flickr.com/photos/suda/672714986

                      My backyard
                      – http://flickr.com/photos/shiflett/3261447115




Tuesday, February 21, 12
Tuesday, February 21, 12
FEEDBACK?


                      Follow me on Twitter
                      – @shiflett

                      Comment on my blog
                      – shiflett.org

                      Email me
                      – chris@shiflett.org




Tuesday, February 21, 12

More Related Content

PDF
Tweview Presentation from #brandwatchers Client Event
PDF
Hollinger.wayde.visual resumestoryboard
PDF
Social Media in the Classroom
PPTX
How Leaders Tweet 2012
PDF
Evolution Of Web Security
PDF
WordPress Security
PDF
Using Twitter - An Introduction
PDF
The Future of Computing, TEDx Austin
Tweview Presentation from #brandwatchers Client Event
Hollinger.wayde.visual resumestoryboard
Social Media in the Classroom
How Leaders Tweet 2012
Evolution Of Web Security
WordPress Security
Using Twitter - An Introduction
The Future of Computing, TEDx Austin

Similar to Security-Centered Design (20)

PDF
Lecture 1: Social Web Introduction (2012)
KEY
Web 2.0 - Teaching and Learning in the Cloud
PDF
mistaeks i’ve made developing software products
KEY
Scratch: Constructivist Learning Environment
PDF
TwitterOne
PDF
Making learning collaborative
PDF
How People are using Twitter at Conferences
ZIP
Social Media For Journalists
PDF
Firefoxos bcndevcon
KEY
In Search of The Social Web - Future of Web Apps Miami
PDF
Using Twitter: An introduction
ZIP
Using Blogs and Wikis for Professional Development
ZIP
The Interaction Design Of APIs
PDF
Networked Administrator 12213
PDF
Social Media Presentation 2009 04
PDF
The page is dead - SXSWi 2012
PDF
Twitter: small form big strategy, big content
PDF
Social Media 101
PDF
Streetmarc Presentation
Lecture 1: Social Web Introduction (2012)
Web 2.0 - Teaching and Learning in the Cloud
mistaeks i’ve made developing software products
Scratch: Constructivist Learning Environment
TwitterOne
Making learning collaborative
How People are using Twitter at Conferences
Social Media For Journalists
Firefoxos bcndevcon
In Search of The Social Web - Future of Web Apps Miami
Using Twitter: An introduction
Using Blogs and Wikis for Professional Development
The Interaction Design Of APIs
Networked Administrator 12213
Social Media Presentation 2009 04
The page is dead - SXSWi 2012
Twitter: small form big strategy, big content
Social Media 101
Streetmarc Presentation
Ad

Recently uploaded (20)

PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
KodekX | Application Modernization Development
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Approach and Philosophy of On baking technology
PDF
Encapsulation theory and applications.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPT
Teaching material agriculture food technology
PPTX
Cloud computing and distributed systems.
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Advanced methodologies resolving dimensionality complications for autism neur...
KodekX | Application Modernization Development
The Rise and Fall of 3GPP – Time for a Sabbatical?
The AUB Centre for AI in Media Proposal.docx
Review of recent advances in non-invasive hemoglobin estimation
Chapter 3 Spatial Domain Image Processing.pdf
cuic standard and advanced reporting.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Dropbox Q2 2025 Financial Results & Investor Presentation
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Approach and Philosophy of On baking technology
Encapsulation theory and applications.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Teaching material agriculture food technology
Cloud computing and distributed systems.
Reach Out and Touch Someone: Haptics and Empathic Computing
Ad

Security-Centered Design