A Comparative Long-Term Study of Fallback Authentication Schemes
Honorable MentionAuthors
Title of the Paper
A Comparative Long-Term Study of Fallback Authentication Schemes
Paper Information
- Domain: Network Security and User Authentication
- Keywords: Fallback authentication, email, SMS, personal knowledge questions, trusted contacts, long-term study, password reset, usability, account security
Research Background and Issues
-
Problems and Challenges:
- Fallback authentication mechanisms are used to regain account access when primary authentication methods are unavailable. However, there is limited long-term research on the effectiveness of these mechanisms, making it difficult to determine whether they can reliably help users recover their accounts.
- Previous studies have often focused on testing one or two schemes, lacking systematic comparisons.
- The time gap between registration and account recovery can span months or even years, impacting the usability and security of these mechanisms.
-
Motivation and Importance:
- Forgetting passwords or losing security tokens is a common issue in account management.
- Long time spans place higher demands on the reliability and usability of fallback authentication, requiring mechanisms to ensure users can still reset passwords effectively years later.
- With increasing cybersecurity threats, attackers often exploit weaknesses in fallback authentication mechanisms to compromise accounts, highlighting the need for safer and more user-friendly solutions.
-
Related Work Analysis:
- Some studies have measured the memorability and security of different fallback authentication methods, but most focus on short-term data.
- Bonneau et al. studied the long-term use of fallback authentication and found a linear relationship between time span and account recovery rates.
- Mechanisms such as personal knowledge questions (PKQs), SMS, and email have respective issues, including poor memorability and vulnerability to attacks.
Solutions
-
Research Methods and Design:
- Conducted an 18-month user study comparing the usability of four common fallback authentication mechanisms: email, SMS, personal knowledge questions (PKQs), and trusted contacts (designated trustees).
- Used a randomized experimental design, assigning participants to different fallback authentication schemes and callback intervals (6 months, 12 months, 18 months).
- Simulated real-world user scenarios through a disguised study (main task was a mental rotation test) to collect data.
-
Innovations:
- Built upon previous research by conducting a systematic cross-scheme comparison.
- Designed a long-term study (up to 18 months) that better reflects real-world user scenarios.
- Evaluated the effectiveness of fallback authentication at different time intervals and proposed improvement suggestions.
-
Implementation Steps and Techniques:
- Registration Phase: Users created accounts and selected a fallback authentication method (entered an email address, phone number, answered security questions, or provided a trusted contact's email).
- Short-Term Callback Phase (2 weeks): Participants received email notifications to complete tasks, reinforcing their engagement in the study.
- Long-Term Callback Phase (6 to 18 months): Participants were required to reset their passwords, and the success rate, time taken, and user experience were evaluated.
Research Findings
-
Specific Results:
- Success Rate Analysis:
- Email had a 100% success rate, SMS 92%, trusted contacts 83%, and PKQs the lowest at 57%.
- Reset Time:
- PKQs were the fastest, with an average reset time of 30 seconds; email followed at 31 seconds; SMS took 52 seconds; and the trusted contact scheme was the slowest, averaging 111 seconds (even longer when relying on others).
- User Usability Scores:
- Using the System Usability Scale (SUS), email scored 80, SMS 74, PKQs 63, and the trusted contact scheme 60.
- Success Rate Analysis:
-
Advantages and Significance:
- Comparative Performance: Email and SMS demonstrated the highest success rates and usability scores, being convenient and familiar to users.
- The security of the trusted contact scheme depends on actual contacts, but users tended to avoid relying on others, often opting for multiple self-controlled email addresses instead.
- PKQs had the poorest user experience, with significant memorability issues. Long-term studies support discontinuing this type of scheme.
-
Limitations and Future Directions:
- Limitations:
- The experimental accounts created by users had low value, limiting the applicability of results to real-world account scenarios.
- The participant sample was relatively young and highly educated, which may not fully generalize to broader user populations.
- Future Directions:
- Investigate how fallback authentication mechanisms will evolve and be applied in a passwordless future (e.g., FIDO2 passwordless technologies).
- Explore improvements to the trusted contact scheme, such as reducing reliance on third-party interactions.
- Encourage service providers to prompt users to update fallback information and support multiple fallback authentication methods to enhance long-term usability.
- Limitations:
Conclusions and Recommendations
-
Recommended Schemes:
- Prioritize email and SMS schemes to balance user experience and security.
- Discontinue the use of PKQs and improve the trusted contact scheme to make it more efficient and less dependent on others.
- Encourage users to register multiple fallback options to increase overall recovery success rates.
-
Recommendations for Service Providers:
- Offer multiple fallback authentication options and educate users on appropriate security practices.
- Regularly remind users to update account recovery information (e.g., email addresses, phone numbers).
- Simulate real-world scenarios to evaluate the long-term effectiveness of different fallback mechanisms.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- What are the long-term success rates and UX of different backup authentication mechanisms (e.g., email, SMS, personal knowledge questions, trusted contacts)?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- Does the effectiveness of backup authentication change significantly as time intervals increase?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- How can existing trusted contact schemes be improved to enhance UX and security?Category: Authentication and Identity SecuritySimilar questionsarrow_forward
Practical Problems
1- When users forget passwords or lose security credentials, they struggle to recover accounts securely through existing mechanisms.Category: Authentication and Identity SecuritySimilar questionsarrow_forward
- 100%
Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design Patterns
CHI '25· Passwords & Authentication +1
- 100%
Choose From a List: A User Study of Random Password Memorability
CHI '25· Passwords & Authentication +1
- 100%
On the Long-Term Effects of Continuous Keystroke Authentication: Keeping User Frustration Low through Behavior Adaptation
UbiComp '23· Passwords & Authentication +1
- 67%
Towards Understanding the Link Between Age and Smartphone Authentication
CHI '19· Aging-Friendly Technology Design +2
- 67%
Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection Practices
CHI '20· Privacy by Design & User Control +2
- 67%
The Role of Eye Gaze in Security and Privacy Applications: Survey and Future HCI Research Directions
CHI '20· Eye Tracking & Gaze Interaction +2
- 67%
Users' Expectations About and Use of Smartphone Privacy and Security Settings
CHI '22· Privacy by Design & User Control +2
- 67%
Of Secrets and Seedphrases: Conceptual misunderstandings and security challenges for seed phrase management among cryptocurrency users
CHI '25· Passwords & Authentication +1
- 67%
Understanding Home Router Configuration Habits & Attitudes
CHI '25· Privacy by Design & User Control +2
- 67%
Don't lose your coin! Investigating security practices of cryptocurrency users
DIS '20· Passwords & Authentication +1
Based on Jaccard similarity of research subtopics & professions (≥60%)