Session
Your Warning Is Technically Correct and Completely Useless
This session examines security warnings as controls operating at the human-machine boundary, where attackers actively shape how users interpret risk.
Security teams may successfully detect a threat, generate an accurate warning, and still fail to stop the attack.
The alert appears. The user clicks through.
The block page explains the risk. The user disables the control.
The notification says the transaction may be fraudulent. The victim follows the attacker’s instructions anyway.
The failure is often blamed on the user. But attackers actively shape the conditions in which security controls are interpreted. They manufacture urgency, authority, fear, secrecy, cognitive overload, and social pressure. They coach victims around warnings, reinterpret security friction as evidence that the false story is real, and keep the target moving before doubt can form.
This session treats security warnings as controls operating inside an adversarial system.
We will decompose warnings into detection trigger, timing, message, action choices, default behavior, escalation path, recovery path, and measurable outcome. Using realistic attack narratives, we will test how common warning patterns perform when an attacker is present in the decision loop.
The session introduces the Adversarial Warning Model, a framework for testing whether a control interrupts harmful action or merely transfers the decision to a compromised human state.
Attendees will leave able to threat-model attacker coaching, design safer interruption patterns, instrument behavioral outcomes, and treat ignored warnings as failed controls rather than successful notifications.
Session format
Conference session
Level
300: Advanced
Session duration
45 minutes
Technical content
Warning architecture and control decomposition
Human-machine trust boundaries
Attacker-in-the-loop decision modeling
Social-engineering pretext integration
Warning timing and contextual relevance
Default actions and forced friction
Authority and urgency manipulation
Attacker coaching around controls
Escalation and trusted-contact pathways
Recovery and reversible action design
Behavioral telemetry and outcome measurement
Security usability testing under adversarial conditions
Threat modeling at the human decision layer
Demonstration
A controlled interactive comparison of warning designs under the same attack narrative:
Passive informational warning
Standard confirm-or-cancel modal
Contextual explanation
Friction-based interruption
Delayed high-risk action
Trusted escalation
Reversible quarantine or hold
The demonstration will show why technically accurate wording can fail when timing, defaults, attacker presence, and recovery options are poorly designed.
Attendee takeaways
Threat-model warnings with the attacker present in the user’s decision loop
Distinguish notifications from controls that meaningfully interrupt harmful action
Design and instrument safer defaults, escalation, delay, and recovery around high-risk decisions
Original framework
The Adversarial Warning Model evaluates seven dimensions:
Trigger: Was the right risk detected?
Timing: Did the control appear before commitment?
Interpretation: Can the attacker plausibly explain the warning away?
Default: What happens when the user acts quickly?
Friction: Does the control meaningfully interrupt momentum?
Escalation: Can the user reach a trusted source outside the attacker’s narrative?
Recovery: Can the action be delayed, reversed, or contained?
Speaker notes
This is not a security-awareness presentation. It is a technical and behavioral analysis of warnings as security controls. The session is applicable to application security, identity, financial systems, fraud prevention, browser warnings, endpoint controls, consumer security, and enterprise workflows.
Catherine (Cat) Karow
Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.
Jacksonville, Florida, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top