UCL Discovery
UCL home » Library Services » Electronic resources » UCL Discovery

Of Two Minds about Two-Factor: Understanding Everyday FIDO U2F Usability through Device Comparison and Experience Sampling

Ciolino, S; Parkin, S; Dunphy, P; (2019) Of Two Minds about Two-Factor: Understanding Everyday FIDO U2F Usability through Device Comparison and Experience Sampling. In: Proceedings of the 15th Symposium on Usable Privacy and Security 2019. (pp. pp. 339-356). USENIX Association: Santa Clara, CA, USA. Green open access

[thumbnail of SOUPS_19_Ciolino.pdf]
Preview
Text
SOUPS_19_Ciolino.pdf - Accepted Version

Download (1MB) | Preview

Abstract

Security keys are phishing-resistant two-factor authentication (2FA) tokens based upon the FIDO Universal 2nd Factor (U2F) standard. Prior research on security keys has revealed intuitive usability concerns, but there are open challenges to better understand user experiences with heterogeneous devices and to determine an optimal user experience for everyday Web browsing. In this paper we contribute to the growing usable security literature on security keys through two user studies: (i) a lab-based study evaluating the first-time user experience of a cross-vendor set of security keys and SMS-based one-time passcodes; (ii) a diary study, where we collected 643 entries detailing how participants accessed accounts and experienced one particular security key over the period of one week. In the former we discovered that user sentiment towards SMS codes was typically higher than for security keys generally. In the latter we discovered that only 28% of accesses to security key-enabled online accounts actually involved a button press on a security key. Our findings confirm prior work that reports user uncertainty about the benefits of security keys and their security purpose. We conclude that this can be partly explained by experience with online services that support security keys, but may nudge users away from regular use of those security keys.

Type: Proceedings paper
Title: Of Two Minds about Two-Factor: Understanding Everyday FIDO U2F Usability through Device Comparison and Experience Sampling
Event: Symposium on Usable Privacy and Security (SOUPS)
Location: Santa Clara, CA, USA
Dates: 12 August 2019 - 13 August 2019
Open access status: An open access version is available from UCL Discovery
Publisher version: https://www.usenix.org/sites/default/files/soups20...
Language: English
Additional information: This version is the version of record. For information on re-use, please refer to the publisher’s terms and conditions.
UCL classification: UCL
UCL > Provost and Vice Provost Offices
UCL > Provost and Vice Provost Offices > UCL BEAMS
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science
UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science
URI: https://discovery.ucl.ac.uk/id/eprint/10079412
Downloads since deposit
369Downloads
Download activity - last month
Download activity - last 12 months
Downloads by country - last 12 months

Archive Staff Only

View Item View Item