"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections

Privacy by Design & User ControlPasswords & AuthenticationPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersCybersecurity EngineersPrivacy Policy Makers

Title of the Paper

"I’m Surprised So Much Is Connected": A Study on Users’ Online Accounts

Document Information

  • Subject Area: Research on the security of users' online accounts
  • Keywords: Online account security, user study, access graph, password management, two-factor authentication, single sign-on, account recovery, user mental models, security recommendations, security practices

Research Background and Issues

  • Identified Problems and Challenges: Personal online security systems are closely tied to the various accounts users utilize, with certain critical accounts (e.g., email accounts) often having a disproportionately large impact on the overall security structure. The interconnected nature and personalized settings of these accounts make it difficult to apply generic security advice effectively.
  • Significance: The links between user accounts and recovery mechanisms may introduce security risks, which can easily be overlooked without a clear understanding and proper management.
  • Research Motivation and Related Work: While previous studies have explored users’ attitudes toward security advice and password management strategies, there has been little investigation into the security implications of the complex interconnections between user accounts and how to provide personalized recommendations effectively.

Proposed Solution

  • Proposed Methods or Solutions:
    • Developed a systematic method to analyze users’ online account settings using "Account Access Graphs" to model and analyze the connections between accounts.
    • Conducted a user study with 20 participants, combining semi-structured interviews to obtain account access graphs and performing both manual and automated analyses.
  • Innovations:
    • Utilized account access graphs to systematically model individual account setups, uncovering structural characteristics in users’ security settings, such as access patterns, loops, and partitioning, which have not been systematically addressed in prior research.
    • Identified and emphasized the importance of critical accounts and devices within the overall structure, providing theoretical support for the development and validation of personalized security recommendations.
  • Implementation Steps:
    • Phase 1: Conducted a survey on users’ access devices, accounts, password management tools, and authentication methods to construct account access graphs.
    • Phase 2: Presented account access graphs visually to users, encouraging them to reflect on and discuss their settings and potential risks.
    • Performed manual and automated analyses of the graphs to identify major security vulnerabilities, such as "backdoor accounts" and the weakest links in account chains.
  • Key Technologies:
    • A formal modeling method for "account access graphs" to represent dependencies between accounts, devices, and authentication information.
    • Analytical tools for automated detection of critical security threats, such as backdoor accounts.

Research Results

  • Specific Findings:
    • The model revealed that users’ personal account setups are complex and unique, exhibiting structural characteristics such as loops (mutual dependencies between accounts) and partitioning (segregation of accounts into independent sections).
    • Users often have cognitive biases regarding the importance of certain accounts, such as underestimating the centrality of email accounts and devices in their setups.
    • Participants frequently used SMS verification codes for account recovery, but the ability to preview SMS on locked devices posed a risk of creating "insecure backdoors."
  • Advantages:
    • Provided more precise and personalized security strategies compared to traditional generic security advice.
    • Revealed security vulnerabilities that users might not easily perceive, helping them proactively improve their setups.
  • Experimental and Evaluation Results:
    • 15% of participants expressed "surprise" at the high level of interconnectedness between their accounts.
    • The use of "account access graphs" clarified weak points in users’ security setups, such as the risk of SMS recovery methods being exploited through SIM-swapping attacks.
    • Highlighted two-factor authentication (2FA) as an effective protective measure, though some users were reluctant to adopt 2FA due to usability concerns or privacy considerations.
  • Limitations and Future Directions:
    • Limitations: The study sample was relatively small and primarily consisted of users with some level of internet experience and interest, reflecting behaviors mainly of English- and German-speaking users.
    • Future Directions:
      • Conduct large-scale studies by using automated tools to collect account graph data from a broader user base.
      • Explore the automated generation and dissemination of personalized security recommendations and their impact on different demographic and cultural groups.
      • Investigate how to enhance users’ willingness to adopt security recommendations through technical means, such as enabling default security features or proactively suggesting options during account setup.

Summary of Findings

This paper introduces the account access graph method in the study of users’ online account security, systematically modeling and revealing the complex interconnections between accounts. This approach effectively addresses the need for detailed account security analysis, which has been overlooked in previous research, and lays the foundation for future studies on more personalized security recommendations.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/68756/2022

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/abs/10.1145/3491102.3502125
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2022
emoji_events
Award
No award tagged
group
Authors
5 authors
sell
Subtopics
Privacy by Design & User Control, Passwords & Authentication, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers