USENIX Security2023Top-tier venue
Account Security Interfaces: Important, Unintuitive, and Untrustworthy
Alaa Daffalla, Marina Sanusi Bohuk, Nicola Dell, Rosanna Bellini, Thomas Ristenpart
Abstract
Online services increasingly rely on user-facing interfaces to communicate important security-related account information-for example, which devices are logged into a user's account and when recent logins occurred. These are used to assess the security status of an account, which is particularly critical for at-risk users likely to be under active attack. To date, however, there has been no investigation into whether these interfaces work well. We begin to fill this gap by partnering with a clinic that supports survivors of intimate partner violence (IPV). We investigated hundreds of transcripts to identify ones capturing interactions between clinic consultants and survivors seeking to infer the security status of survivor accounts, and we performed a qualitative analysis of 28 transcripts involving 19 consultants and 22 survivors. Our findings confirm the importance of these interfaces for assessing a user's security, but we also find that these interfaces suffer from a number of limitations that cause confusion and reduce their utility. We go on to experimentally investigate the lack of integrity of information contained in device lists and session activity logs for four major services. For all the services investigated, we show how an attacker can either hide accesses entirely or spoof access details to hide illicit logins from victims.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 29fd3fe8-dfae-4175-b711-133ac508e5adCited by top-tier papers9
- Mitigating Trauma in Qualitative Research Infrastructure: Roles for Machine Assistance and Trauma-Informed DesignEmily Tseng, Thomas Ristenpart, Nicola DellCSCW 2025 · 10 citations
- Shortchanged: Uncovering and Analyzing Intimate Partner Financial Abuse in Consumer ComplaintsArkaprabha Bhattacharya, Kevin Lee, Vineeth Ravi, Jessica Staddon et al.CHI 2024 · 7 citations
- Navigating Traumatic Stress Reactions During Computer Security InterventionsLana Ramjit, Natalie Dolci, Francesca Rossi, Ryan Garcia et al.USENIX Security 2024 · 5 citations
- Legal Evidence of Technology-Facilitated Abuse in Wisconsin: Surfacing Barriers Within and Beyond the CourtroomSophie Stephenson, Naman Gupta, Akhil Polamarasetty, Kyle Huang et al.CSCW 2025 · 2 citations
- Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data ExportsJulia Nonnenkamp, Naman Gupta, Abhimanyu Dev Gupta, Rahul ChatterjeeCCS 2025
Builds on15
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 273 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy et al.USENIX Security 2019 · 118 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
Related papers
- Inconsistent, Incomplete, and Insecure: A Survey of Account Security InterfacesArkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini et al.USENIX Security 2026
- The Digital-Safety Risks of Financial Technologies for Survivors of Intimate Partner ViolenceRosanna Bellini, Kevin Lee, Megan A. Brown, Jeremy Shaffer et al.USENIX Security 2023
- Data Stewardship in Clinical Computer Security: Balancing Benefit and Burden in Participatory SystemsEmily Tseng, Rosanna Bellini, Yeuk-Yu Lee, Alana Ramjit et al.CSCW 2024 · 24 citations
- A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat ModelsAlaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee et al.USENIX Security 2025
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi et al.CHI 2022 · 77 citations
