USENIX Security2023Top-tier venue
A Study of Multi-Factor and Risk-Based Authentication Availability
Anthony Gavazzi, Ryan Williams, Engin Kirda, Long Lu, Andre King, Andy Davis, Tim Leek
Abstract
Password-based authentication (PBA) remains the most popular form of user authentication on the web despite its long-understood insecurity. Given the deficiencies of PBA, many online services support multi-factor authentication (MFA) and/or risk-based authentication (RBA) to better secure user accounts. The security, usability, and implementations of MFA and RBA have been studied extensively, but attempts to measure their availability among popular web services have lacked breadth. Additionally, no study has analyzed MFA and RBA prevalence together or how the presence of Single-Sign-On (SSO) providers affects the availability of MFA and RBA on the web. In this paper, we present a study of 208 popular sites in the Tranco top 5K that support account creation to understand the availability of MFA and RBA on the web, the additional authentication factors that can be used for MFA and RBA, and how logging into sites through more secure SSO providers changes the landscape of user authentication security. We find that only 42.31% of sites support any form of MFA, and only 22.12% of sites block an obvious account hijacking attempt. Though most sites do not offer MFA or RBA, SSO completely changes the picture. If one were to create an account for each site through an SSO provider that offers MFA and/or RBA, whenever available, 80.29% of sites would have access to MFA and 72.60% of sites would stop an obvious account hijacking attempt. However, this proliferation through SSO comes with a privacy trade-off, as nearly all SSO providers that support MFA and RBA are major third-party trackers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1b83da8b-345e-418d-9f06-516feae69103Cited by top-tier papers8
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 13 citations
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
- Inconsistent, Incomplete, and Insecure: A Survey of Account Security InterfacesArkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini et al.USENIX Security 2026
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
- Exploring and Mitigating Adversarial Manipulation of Voting-Based LeaderboardsYangsibo Huang, Milad Nasr, Anastasios Nikolas Angelopoulos, Nicholas Carlini et al.ICML 2025
Builds on9
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
Related papers
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich et al.USENIX Security 2018 · 63 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the WebTommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov et al.S&P 2025
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu et al.CCS 2026
- Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the WebAvinash Sudhodanan, Andrew PaverdUSENIX Security 2022
