USENIX Security2026Top-tier venue
Inconsistent, Incomplete, and Insecure: A Survey of Account Security Interfaces
Arkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini, Nicola Dell, Thomas Ristenpart
Abstract
Despite improvements in account security, compromise remains widespread and damaging, especially when the attacker has close physical or social proximity to the victim (e.g., in terpersonal abuse settings). To help users identify unauthorized access, web services provide account security interfaces (ASIs): notifications and logs that provide information to help infer adversarial compromise. We present the largest measurement study of ASIs to date, evaluating 100 popular services. Our study highlights an unsatisfying status quo: 29 services provided users with no way to distinguish account accesses. After categorizing ASIs using a new typology, we show that services were inconsistent in the types they deployed. Further, ASIs were often incomplete and confusing, even for expert researchers. Finally, of 61 services that offered an ASI to convey device or location descriptions, 41 (67.2%) were vulnerable to spoofing attacks that successfully obfuscate the source of the access. Based on these findings, we present six principles for improving future ASI deployments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 367b8f98-d0cd-49bd-b2d7-9be8fd1c533dBuilds on19
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- Computer Security and Privacy for Refugees in the United StatesLucy Simko, Ada Lerner, Samia Ibtasam, Franziska Roesner et al.S&P 2018 · 77 citations
- Oh, the Places You've Been! User Reactions to Longitudinal Transparency About Third-Party Web Tracking and InferencingBen Weinshel, Miranda Wei, Mainack Mondal, Euirim Choi et al.CCS 2019 · 73 citations
Related papers
- Account Security Interfaces: Important, Unintuitive, and UntrustworthyAlaa Daffalla, Marina Sanusi Bohuk, Nicola Dell, Rosanna Bellini et al.USENIX Security 2023
- Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data ExportsJulia Nonnenkamp, Naman Gupta, Abhimanyu Dev Gupta, Rahul ChatterjeeCCS 2025
- Encrypted Access Logging for Online Accounts: Device Attributions without Device TrackingCarolina Ortega Pérez, Alaa DaffallaUSENIX Security 2025
- Araña: Discovering and Characterizing Password Guessing Attacks in PracticeMazharul Islam, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart et al.USENIX Security 2023
- One Email, Many Faces: A Deep Dive into Identity Confusion in Email AliasesMengying Wu, Geng Hong, Jiatao Chen, Baojun Liu et al.NDSS 2026
