A Comparative Long-Term Study of Fallback Authentication Schemes

Honorable Mention
Passwords & AuthenticationPrivacy Perception & Decision-Making

Title of the Paper

A Comparative Long-Term Study of Fallback Authentication Schemes

Paper Information

  • Domain: Network Security and User Authentication
  • Keywords: Fallback authentication, email, SMS, personal knowledge questions, trusted contacts, long-term study, password reset, usability, account security

Research Background and Issues

  • Problems and Challenges:

    1. Fallback authentication mechanisms are used to regain account access when primary authentication methods are unavailable. However, there is limited long-term research on the effectiveness of these mechanisms, making it difficult to determine whether they can reliably help users recover their accounts.
    2. Previous studies have often focused on testing one or two schemes, lacking systematic comparisons.
    3. The time gap between registration and account recovery can span months or even years, impacting the usability and security of these mechanisms.
  • Motivation and Importance:

    • Forgetting passwords or losing security tokens is a common issue in account management.
    • Long time spans place higher demands on the reliability and usability of fallback authentication, requiring mechanisms to ensure users can still reset passwords effectively years later.
    • With increasing cybersecurity threats, attackers often exploit weaknesses in fallback authentication mechanisms to compromise accounts, highlighting the need for safer and more user-friendly solutions.
  • Related Work Analysis:

    • Some studies have measured the memorability and security of different fallback authentication methods, but most focus on short-term data.
    • Bonneau et al. studied the long-term use of fallback authentication and found a linear relationship between time span and account recovery rates.
    • Mechanisms such as personal knowledge questions (PKQs), SMS, and email have respective issues, including poor memorability and vulnerability to attacks.

Solutions

  • Research Methods and Design:

    • Conducted an 18-month user study comparing the usability of four common fallback authentication mechanisms: email, SMS, personal knowledge questions (PKQs), and trusted contacts (designated trustees).
    • Used a randomized experimental design, assigning participants to different fallback authentication schemes and callback intervals (6 months, 12 months, 18 months).
    • Simulated real-world user scenarios through a disguised study (main task was a mental rotation test) to collect data.
  • Innovations:

    1. Built upon previous research by conducting a systematic cross-scheme comparison.
    2. Designed a long-term study (up to 18 months) that better reflects real-world user scenarios.
    3. Evaluated the effectiveness of fallback authentication at different time intervals and proposed improvement suggestions.
  • Implementation Steps and Techniques:

    1. Registration Phase: Users created accounts and selected a fallback authentication method (entered an email address, phone number, answered security questions, or provided a trusted contact's email).
    2. Short-Term Callback Phase (2 weeks): Participants received email notifications to complete tasks, reinforcing their engagement in the study.
    3. Long-Term Callback Phase (6 to 18 months): Participants were required to reset their passwords, and the success rate, time taken, and user experience were evaluated.

Research Findings

  • Specific Results:

    1. Success Rate Analysis:
      • Email had a 100% success rate, SMS 92%, trusted contacts 83%, and PKQs the lowest at 57%.
    2. Reset Time:
      • PKQs were the fastest, with an average reset time of 30 seconds; email followed at 31 seconds; SMS took 52 seconds; and the trusted contact scheme was the slowest, averaging 111 seconds (even longer when relying on others).
    3. User Usability Scores:
      • Using the System Usability Scale (SUS), email scored 80, SMS 74, PKQs 63, and the trusted contact scheme 60.
  • Advantages and Significance:

    • Comparative Performance: Email and SMS demonstrated the highest success rates and usability scores, being convenient and familiar to users.
    • The security of the trusted contact scheme depends on actual contacts, but users tended to avoid relying on others, often opting for multiple self-controlled email addresses instead.
    • PKQs had the poorest user experience, with significant memorability issues. Long-term studies support discontinuing this type of scheme.
  • Limitations and Future Directions:

    • Limitations:
      • The experimental accounts created by users had low value, limiting the applicability of results to real-world account scenarios.
      • The participant sample was relatively young and highly educated, which may not fully generalize to broader user populations.
    • Future Directions:
      • Investigate how fallback authentication mechanisms will evolve and be applied in a passwordless future (e.g., FIDO2 passwordless technologies).
      • Explore improvements to the trusted contact scheme, such as reducing reliance on third-party interactions.
      • Encourage service providers to prompt users to update fallback information and support multiple fallback authentication methods to enhance long-term usability.

Conclusions and Recommendations

  • Recommended Schemes:

    1. Prioritize email and SMS schemes to balance user experience and security.
    2. Discontinue the use of PKQs and improve the trusted contact scheme to make it more efficient and less dependent on others.
    3. Encourage users to register multiple fallback options to increase overall recovery success rates.
  • Recommendations for Service Providers:

    1. Offer multiple fallback authentication options and educate users on appropriate security practices.
    2. Regularly remind users to update account recovery information (e.g., email addresses, phone numbers).
    3. Simulate real-world scenarios to evaluate the long-term effectiveness of different fallback mechanisms.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/148199/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642889
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
Honorable Mention
group
Authors
5 authors
sell
Subtopics
Passwords & Authentication, Privacy Perception & Decision-Making
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
10 related papers