Put Your Warning Where Your Link Is: Improving and Evaluating Email Phishing Warnings

Honorable Mention
Dark Patterns RecognitionOnline Harassment & Counter-ToolsCybersecurity EngineersPrivacy Policy Makers

Phishing emails often disguise a link's actual URL. Thus, common anti-phishing advice is to check a link's URL before clicking, but email clients do not support this well. Automated phishing detection enables email clients to warn users that an email is suspicious, but current warnings are often not specific. We evaluated the effects on phishing susceptibility of (1) moving phishing warnings close to the suspicious link in the email, (2) displaying the warning on hover interactions with the link, and (3) forcing attention to the warning by deactivating the original link, forcing users to click the URL in the warning. We assessed the effectiveness of such link-focused phishing warning designs in a between-subjects online experiment (n=701). We found that link-focused phishing warnings reduced phishing click-through rates compared to email banner warnings; forced attention warnings were most effective. We discuss the implications of our findings for phishing warning design.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/6720/2019

AdRecommended

Learn AI Coding at CodeNow

At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2019
emoji_events
Award
Honorable Mention
group
Authors
3 authors
sell
Subtopics
Dark Patterns Recognition, Online Harassment & Counter-Tools
work
Professions
Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Abstract only
hub
Related Papers
0 related papers