"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
Authors
Title of the Paper
"I’m Surprised So Much Is Connected": A Study on Users’ Online Accounts
Document Information
- Subject Area: Research on the security of users' online accounts
- Keywords: Online account security, user study, access graph, password management, two-factor authentication, single sign-on, account recovery, user mental models, security recommendations, security practices
Research Background and Issues
- Identified Problems and Challenges: Personal online security systems are closely tied to the various accounts users utilize, with certain critical accounts (e.g., email accounts) often having a disproportionately large impact on the overall security structure. The interconnected nature and personalized settings of these accounts make it difficult to apply generic security advice effectively.
- Significance: The links between user accounts and recovery mechanisms may introduce security risks, which can easily be overlooked without a clear understanding and proper management.
- Research Motivation and Related Work: While previous studies have explored users’ attitudes toward security advice and password management strategies, there has been little investigation into the security implications of the complex interconnections between user accounts and how to provide personalized recommendations effectively.
Proposed Solution
- Proposed Methods or Solutions:
- Developed a systematic method to analyze users’ online account settings using "Account Access Graphs" to model and analyze the connections between accounts.
- Conducted a user study with 20 participants, combining semi-structured interviews to obtain account access graphs and performing both manual and automated analyses.
- Innovations:
- Utilized account access graphs to systematically model individual account setups, uncovering structural characteristics in users’ security settings, such as access patterns, loops, and partitioning, which have not been systematically addressed in prior research.
- Identified and emphasized the importance of critical accounts and devices within the overall structure, providing theoretical support for the development and validation of personalized security recommendations.
- Implementation Steps:
- Phase 1: Conducted a survey on users’ access devices, accounts, password management tools, and authentication methods to construct account access graphs.
- Phase 2: Presented account access graphs visually to users, encouraging them to reflect on and discuss their settings and potential risks.
- Performed manual and automated analyses of the graphs to identify major security vulnerabilities, such as "backdoor accounts" and the weakest links in account chains.
- Key Technologies:
- A formal modeling method for "account access graphs" to represent dependencies between accounts, devices, and authentication information.
- Analytical tools for automated detection of critical security threats, such as backdoor accounts.
Research Results
- Specific Findings:
- The model revealed that users’ personal account setups are complex and unique, exhibiting structural characteristics such as loops (mutual dependencies between accounts) and partitioning (segregation of accounts into independent sections).
- Users often have cognitive biases regarding the importance of certain accounts, such as underestimating the centrality of email accounts and devices in their setups.
- Participants frequently used SMS verification codes for account recovery, but the ability to preview SMS on locked devices posed a risk of creating "insecure backdoors."
- Advantages:
- Provided more precise and personalized security strategies compared to traditional generic security advice.
- Revealed security vulnerabilities that users might not easily perceive, helping them proactively improve their setups.
- Experimental and Evaluation Results:
- 15% of participants expressed "surprise" at the high level of interconnectedness between their accounts.
- The use of "account access graphs" clarified weak points in users’ security setups, such as the risk of SMS recovery methods being exploited through SIM-swapping attacks.
- Highlighted two-factor authentication (2FA) as an effective protective measure, though some users were reluctant to adopt 2FA due to usability concerns or privacy considerations.
- Limitations and Future Directions:
- Limitations: The study sample was relatively small and primarily consisted of users with some level of internet experience and interest, reflecting behaviors mainly of English- and German-speaking users.
- Future Directions:
- Conduct large-scale studies by using automated tools to collect account graph data from a broader user base.
- Explore the automated generation and dissemination of personalized security recommendations and their impact on different demographic and cultural groups.
- Investigate how to enhance users’ willingness to adopt security recommendations through technical means, such as enabling default security features or proactively suggesting options during account setup.
Summary of Findings
This paper introduces the account access graph method in the study of users’ online account security, systematically modeling and revealing the complex interconnections between accounts. This approach effectively addresses the need for detailed account security analysis, which has been overlooked in previous research, and lays the foundation for future studies on more personalized security recommendations.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How do complex connections among users' online accounts affect their security?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- How can account access graphs (modeling individual account settings) identify online account security risks?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- Which specific accounts and devices are most critical in users' security structures yet easily overlooked?Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
Practical Problems
1- Users easily overlook critical accounts and potential weaknesses when maintaining security across all online accounts.Category: Social Platform Safety, Content Governance, and Online HarmSimilar questionsarrow_forward
- 86%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 83%
Security During Application Development: an Application Security Expert Perspective
CHI '18· Privacy by Design & User Control +1
- 83%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 83%
'Think secure from the beginning': A Survey with Software Developers
CHI '19· Privacy by Design & User Control +2
- 83%
The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
CHI '25· Privacy by Design & User Control +2
- 71%
SIGCHI Outstanding Dissertation Award – Supporting Password Decisions with Data
CHI '18· Explainable AI (XAI) +2
- 71%
"Pretty Close to a Must-Have:" Balancing Usability Desire and Security Concern in Biometric Adoption
CHI '19· Privacy by Design & User Control +2
- 71%
Sensor Illumination: Exploring Design Qualities and Ethical Implications of Smart Cameras and Image/Video Analytics
CHI '20· Privacy by Design & User Control +2
- 71%
Permission vs. App Limiters: Profiling Smartphone Users to Understand Differing Strategies for Mobile Privacy Management
CHI '22· Privacy by Design & User Control +2
- 71%
Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
CHI '24· AI Ethics, Fairness & Accountability +2
Based on Jaccard similarity of research subtopics & professions (≥60%)