Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication
Xin Zhang, Xiaohan Zhang, Huijun Zhou, Bo Zhao
Abstract
—Cross-device authentication ( XDAuth ) has become an essential mechanism for seamless account access across multiple devices. In this paradigm, a user can sign in on one device (the target device ) by completing authentication on another trusted device (the authentication device ) that holds an active session or stored credentials, improving user experience. However, the decoupling of the authentication device and target device introduces new risks: the physical and contextual separation disrupts the usual authentication flow, creates information asymmetry, and makes it hard for users to assess the legitimacy of an authentication request. Consequently, users may inadvertently approve malicious logins and face account compromise, especially when key contextual details, explicit confirmation, or revocation mechanisms are missing. To address these risks, we start from a user-centric perspective grounded in three fundamental user rights: the right to know , the right to consent , and the right to control , to safeguard the security and usability of XDAuth systems. We investigate how these rights are supported in practice by examining 27 major services spanning three typical XDAuth schemes. Our findings are concerning: over half of the services do not provide any information about the target device during authentication, not all services enforce explicit user confirmation, and six lack a way to revoke suspicious authorizations. We responsibly disclosed these issues to the affected vendors, several of whom acknowledged the problems and responded positively. We further conduct a user study with 100 participants, uncovering that the vast majority consider these rights essential and expect them to be upheld in XDAuth . Our study reveals a clear gap between current implementations and user expectations, underscoring the need for stronger user rights support to develop more secure, user-centered XDAuth .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on15
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- A Privacy Analysis of Cross-device TrackingSebastian Zimmeck, Jie S. Li, Hyungtae Kim, Steven M. Bellovin et al.USENIX Security 2017 · 72 citations
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 48 citations
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 35 citations
Related papers
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked WebsitesSanam Ghorbani Lyastani, Michael Backes, Sven BugielNDSS 2023
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in WearablesDoguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh et al.S&P 2024 · 12 citations
- Foot in the Door: Uncovering the Multi-Step Authorization Exploitation in Mobile ApplicationsYizhe Shi, Zhemin Yang, Qiaodan Hou, Lukai Cui et al.CCS 2026
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
