Security-Centered Design: Exploring the Impact of Human Behavior

Chris Shiflett (27.Feb.2009)
Talk at PHP UK Conference 2009 (English - US)

Rating: 5 of 5

Security is more than filtering input and escaping output (FIEO), and it's more than cross-site scripting (XSS) and cross-site request forgeries (CSRF). Security isn't even always black and white. In order to create a more secure user experience, we need to understand how people think. Perception can be as important as reality, and meeting user expectations is a fundamental of good security. In this multifarious talk, I'll introduce some of what I have learned about cognitive psychology, exploring topics such as change blindness and ambient signifiers, and I'll show some real-world examples that demonstrate the profound impact human behavior can have on security.

Who are you?

Claim talk

By clicking this button you are declaring that you are the speaker responsible for it and a claim request will be sent to the administrator of the event.

If the claim is approved you will be able to edit the information for this talk.

Are you sure?

 
Comments closed.

Comments

Rating: 5 of 5

28.Feb.2009 at 08:19 by Stefan Koopmanschap

An excellent talk, giving insight into more than just technical PHP stuff, which I like a lot.

Rating: 4 of 5

28.Feb.2009 at 08:55 by T Barnes

Great talk taking an interesting tangent from the usual technical viewpoint.

Rating: 5 of 5

28.Feb.2009 at 14:26 by Stuart Lowes

Great talk and very entertaining. Was great to see a security talk that covered more than the usual topics. I will certainly be more aware from now on

Rating: 5 of 5

28.Feb.2009 at 14:43 by Rob Allen

Great talk - glad to see a security talk that made me think about the wider context.

Rating: 5 of 5

28.Feb.2009 at 22:21 by Nick Belhomme

Great talk, Chris has a certain calm over himself which is really inspiring and made the talk really enjoyable to watch. Also the way he does the coverage of the topic is great. Everything felt really natural and seemed to come from a vast knowledge on the topic. A++

Rating: 5 of 5

28.Feb.2009 at 22:45 by Marc Gear

This was a very professional presentation. The topic of how interaction design affects the security of an application offered some new and interesting perspectives. It was great to hear Chris discuss a topic about which he has become interested in recently, his excitement for the content was clear, and yet delivered in an understated way. Full of quick-witted humor and obvious intelligence. By far the best talk of the conference.

Rating: 5 of 5

01.Mar.2009 at 22:52 by

Not the usual security talk, which is what made it more interesting. It was the highlight of the conference for me.

Rating: 5 of 5

01.Mar.2009 at 23:39 by Jon Gibbins

A really interesting and engaging talk exploring security from a very human perspective, rather than concentrating on the usual technicalities. Lots of food for thought. Well done, Chris.

Rating: 5 of 5

02.Mar.2009 at 08:30 by Lorna Mitchell

This isn't the first time I've seen this talk and I was still completely blown away by it. The ideas are so simple but powerful, and the presentation was impeccably well delivered

Cloud server hosting by Combell Combell      © Joind.in 2012