A Tale of Two Studies: The Best and Worst of YubiKey Usability
Joshua Reynolds, Trevor Smith, Ken Reese, Luke Dickinson, Scott Ruoti, Kent E. Seamons
Abstract
Two-factor authentication (2FA) significantly improves the security of password-based authentication. Recently, there has been increased interest in Universal 2nd Factor (U2F) security keys-small hardware devices that require users to press a button on the security key to authenticate. To examine the usability of security keys in non-enterprise usage, we conducted two user studies of the YubiKey, a popular line of U2F security keys. The first study tasked 31 participants with configuring a Windows, Google, and Facebook account to authenticate using a YubiKey. This study revealed problems with setup instructions and workflow including users locking themselves out of their operating system or thinking they had successfully enabled 2FA when they had not. In contrast, the second study had 25 participants use a YubiKey in their daily lives over a period of four weeks, revealing that participants generally enjoyed the experience. Conducting both a laboratory and longitudinal study yielded insights into the usability of security keys that would not have been evident from either study in isolation. Based on our analysis, we recommend standardizing the setup process, enabling verification of success, allowing shared accounts, integrating with operating systems, and preventing lockouts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1ba4d862-23e2-4017-aed0-667b6d0d75faCited by top-tier papers22
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design PatternsMaximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri et al.USENIX Security 2021 · 48 citations
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres et al.CCS 2019 · 46 citations
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesNicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar et al.S&P 2021 · 37 citations
Builds on1
Related papers
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 1 citation
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas SchreckS&P 2026
- "If I could do this, I feel anyone could: " The Design and Evaluation of a Secondary Authentication Factor ManagerGarrett Smith, Tarun Kumar Yadav, Jonathan Dutson, Scott Ruoti et al.USENIX Security 2023
- Empirical Measurement of Systemic 2FA UsabilityJoshua Reynolds, Nikita Samarin, Joseph D. Barnes, Taylor Judd et al.USENIX Security 2020
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 3 citations
