Usable security reading list

A starter guide by felt@

Introduction

Reading list

How users think about security

Warning overexposure

Phishing

Permissions

SSL and encryption

Going meta (methodology)

Introduction

This is a reading list for people who want an overview of usable security. It highlights work that I consider seminal or useful on a daily basis as an engineer in this field.

Short on time?

I’ve marked my very favorite papers with **.  Those might be a good place to start.

New to academic literature?

Here’s how to read these papers:

  1. Skim judiciously. Academic papers are highly structured, and you do not need to read linearly. You can get the key ideas of most papers just by reading the introduction, limitation, and discussion sections. After that, dive deeper into the other sections if you’re interested.
  2. Be skeptical. This is a list of seminal or interesting papers, not the list of best papers. Some have methodological flaws, so always read critically.

Looking for a more comprehensive list?

I highly recommend Lorrie Cranor’s longer reading list. If you want even more, follow references in related work sections and/or look at the proceedings of SOUPS and CHI.

Reading list

How users think about security

Warning overexposure

Phishing

Permissions

SSL and encryption

Going meta (methodology)