Understanding Users' Interaction with Login Notifications
Authors
Document Title
Understanding Users' Interaction with Login Notifications
Document Information
- Subject Area: Research on user interaction with login notifications, focusing on user behavior and cognition.
- Keywords: Login notifications, email, authentication, risk-based authentication, password change, security notifications
Research Background and Issues
-
Identified Problems or Challenges:
- Login notifications aim to help users identify and prevent unauthorized account access, but the triggers for such notifications (e.g., device or location changes) may cause confusion.
- Users often do not understand the reasons behind notification triggers or are uncertain about the correct response to malicious logins.
- Certain notification designs may lead to alert fatigue, causing users to gradually ignore important notifications.
- The content and format of current notifications may fail to effectively convey information, increasing the cognitive burden on users when making decisions.
-
Significance: With the widespread adoption of online services, account security has become critically important. Effective notifications can enhance overall system security without overburdening users.
-
Research Motivation and Related Work:
- Previous studies have explored challenge-based information seeking, mental models, and secondary authentication notifications.
- This study differs from prior work by focusing on how the content and design of login notifications influence user understanding and behavior.
- Earlier research has shown that despite the existence of security notifications, most websites have not fully implemented risk measures or designed user-friendly notification templates.
Solution
-
Proposed Research Methodology:
- Collect and analyze real login notifications from 72 services to develop a baseline notification design.
- Design a three-phase user study to simulate real-world scenarios and measure user responses and perceptions of legitimate and malicious login notifications.
- Phase 1: Create accounts and complete tasks (mental rotation test).
- Phase 2: Send legitimate or malicious login notifications.
- Phase 3: Record user behavior and conduct questionnaire analysis.
-
Innovations and Key Techniques:
- Separate evaluation of the impact of legitimate and malicious login notifications, using the mental rotation test to distract users and simulate authentic reactions.
- Provide in-depth analysis of the content elements and design patterns included in login notifications.
- Use statistical methods to determine the significance of malicious login simulation parameters, maximizing contextual realism.
Research Findings
-
Specific Findings:
- Login notifications can enhance account security, but response rates are limited. In cases of malicious logins, only 22% of users changed their passwords.
- Users' understanding of notification triggers was significantly affected, especially when faced with malicious logins.
- Approximately 66% of users believed notifications should be sent after suspicious activity, but 89% did not want to receive notifications for every login. Frequent notifications may lead to alert fatigue.
-
Advantages Over Existing Solutions:
- By combining interdisciplinary approaches with cognitive and behavioral analysis, this study provides deeper insights than purely technical notification designs.
- Detailed analysis of how individual notification elements influence user understanding and response offers a practical framework for design improvements.
-
Experimental or Evaluation Results:
- Notification content (e.g., device, location, time) significantly influenced users' decisions to change passwords.
- Users in the malicious group (who did not change their passwords) reported a lack of understanding of the notification content, highlighting deficiencies in current design translation and interpretation.
-
Limitations and Future Directions:
- The use of artificial accounts may limit ecological validity; future studies should analyze real account scenarios.
- The study did not examine users from different cultural backgrounds; future research could expand to non-U.S. user groups.
- Incorporating more intuitive trigger descriptions and multilingual support in notification design could improve user comprehension and response rates.
Recommendations and Conclusion
-
Practical Recommendations:
- Optimize Notification Triggers: Send notifications only for device or location changes or when suspicious activity is detected, to reduce user fatigue.
- Add Contextual Information: Include a "reason for trigger" component to explain the cause of the notification.
- Enhance Design Details: Avoid technical jargon that may cause misunderstandings, such as using clear device names and location descriptions.
- Provide Clear Action Guidance: Offer explicit steps, such as completing verification on the website rather than relying on email links.
- Increase User Trust: Improve the visual and linguistic design of notifications to emphasize service reliability.
-
Conclusion: Login notifications moderately improve account security but face challenges in design and user engagement. By optimizing notification triggers, enhancing information transparency, and improving user experience, service providers can strengthen security while minimizing the burden on users.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How do the content and design of login notifications affect users' understanding of trigger reasons and behavior?Category: Mobile Notifications, Timing Management, and Reminder DesignSimilar questionsarrow_forward
- Which notification elements most improve users' response speed to malicious logins?Category: Mobile Notifications, Timing Management, and Reminder DesignSimilar questionsarrow_forward
- Does frequent delivery of login notifications cause alert fatigue among users?Category: Mobile Notifications, Timing Management, and Reminder DesignSimilar questionsarrow_forward
Practical Problems
1- Users often struggle to understand why login notifications are triggered and how to respond correctly.Category: Mobile Notifications, Timing Management, and Reminder DesignSimilar questionsarrow_forward
- 100%
"Wait, Do I Know This Person?": Understanding Misdirected Email
CHI '19· Privacy by Design & User Control +1
- 100%
RepliCueAuth: Validating the Use of a Lab-Based Virtual Reality Setup for Evaluating Authentication Systems
CHI '21· Privacy by Design & User Control +1
- 100%
LociMotion: Towards Learning a Strong Authentication Secret in a Single Session
CHI '21· Privacy by Design & User Control +1
- 100%
"They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in Germany
CHI '25· Privacy by Design & User Control +1
- 100%
Delusio - Plausible Deniability For Face Recognition
MobileHCI '24· Privacy by Design & User Control +1
- 67%
Veritaps: Truth Estimation from Mobile Interaction
CHI '18· Explainable AI (XAI) +2
- 67%
Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection Practices
CHI '20· Privacy by Design & User Control +2
- 67%
How Mandatory Second Factor Affects the Authentication User Experience
CHI '20· Privacy by Design & User Control +1
- 67%
Users' Expectations About and Use of Smartphone Privacy and Security Settings
CHI '22· Privacy by Design & User Control +2
- 67%
Understanding Home Router Configuration Habits & Attitudes
CHI '25· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)