USENIX Security2025Top-tier venue
SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic Proposals
Md Mojibur Rahman Redoy Akanda, Amanda Lacy, Nitesh Saxena
Abstract
Despite the proliferation of advanced authentication methods in the academic research literature, it is not clear whether these methods would be suitable for blind and visually impaired users in terms of accessibility and security. To address this issue, we first developed the Authentication Literature Evaluation for Security and Accessibility (ALESA) framework consisting of 5 accessibility and 8 security features to measure the accessibility and security of these methods. Then, using this framework, we systematically evaluated 37 selected general-purpose academic authentication schemes if they were to be used by blind and visually impaired users and also explored 13 selected authentication schemes specifically designed for blind and visually impaired users, categorizing each type of scheme according to its underlying user interaction method. Our analysis reveals that many studied schemes may not only be insecure but also often fail to meet the specific needs of blind and visually impaired users, even when specifically designed for them. We found that most schemes struggle to balance accessibility and security, with many security issues arising from accessibility challenges, particularly in screen reader-assisted interaction scenarios. Our research urges researchers, developers, and policymakers to address these gaps and develop secure, accessible solutions for blind users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- Smartphone Usage by Expert Blind UsersMohit Jain, Nirmalendu Diwakar, Manohar SwaminathanCHI 2021 · 40 citations
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 13 citations
Related papers
- Broken Access: On the Challenges of Screen Reader Assisted Two-Factor and Passwordless AuthenticationMd Mojibur Rahman Redoy Akanda, Ahmed Tanvir Mahdad, Nitesh SaxenaWWW 2025
- A Mixed-Methods Analysis of Account Creation & Authentication Inaccessibility for Blind and Low Vision UsersAdryana Hutchinson, Smirity Kaushik, Matthias Fassl, Adam J. AvivCCS 2026
- From PINs to Gestures: Analyzing Knowledge-Based Authentication Schemes for Augmented and Virtual RealityNaheem Noah, Sanchari DasIEEE VR 2025 · 13 citations
- How Blind and Low-Vision Users Manage Their PasswordsAlexander Ponticello, Filipo Sharevski, Simon Anell, Katharina KrombholzCCS 2025
- A Probabilistic Model and Metrics for Estimating Perceived Accessibility of Desktop Applications in Keystroke-Based Non-Visual InteractionsMd. Touhidul Islam, Donald E. Porter, Syed Masum BillahCHI 2023 · 7 citations
