发表机构
Delft University of Technology(代尔夫特理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对消费级物联网安全建议,通过28名荷兰参与者的168次会话实验,发现多数用户无法按建议完成密码和固件设置,且实际设备与建议描述的凭证情况不符,明确了通用安全建议在实际应用中的适用性问题。
AI 中文摘要
公共宣传活动敦促人们更改物联网(IoT)设备的默认密码并保持更新,前提是用户能够独立判断该建议是否适用。我们在荷兰招募了28名参与者,向他们提供两份反映多国指导方针的政府发布建议,要求他们尝试将每份建议应用于从畅销榜中选出的6款消费级设备中的3款(共168个会话),该协议要求对每项操作进行演示而非完成。在84个密码操作会话中,33个会话未设置密码,50个会话达到账户级设置,1个会话达到设备级设置;在84个更新会话中,27个会话未更新,19个会话完成配套应用更新,38个会话完成经验证的固件更新。没有产品存在建议中所述的跨设备共享的制造商设置凭证;唯一的设备级凭证是该设备单元独有的。我们对通用建议及其所针对的设备能让用户确定、执行和验证的内容进行了说明。
英文摘要
Public campaigns urge people to update their Internet of Things (IoT) devices and change default passwords. What happens when people try? We gave 28 participants in the Netherlands two pieces of government-issued advice and asked them to try applying each to three of six bestselling IoT devices (168 sessions). We located no manufacturer-set password shared across units, the kind the advice describes; the only device-level credential located was unique to its unit. Fewer than half the update sessions established firmware status. Told that a setting might not apply, no participant concluded it did not: they treated whatever related setting the interface offered as the target, and located the difficulty in themselves rather than in the advice or device. Generic advice asks people to judge what only manufacturers can state and only devices can report. Campaigns must be coordinated with device design, or replaced by secure defaults that remove the task.
Comments44 pages, 2 figures, 12 tables