USENIX Security2021Top-tier venue
Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design Patterns
Maximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri, Elissa M. Redmiles
Abstract
Two-factor authentication (2FA) is one of the primary mechanisms for defending end-user accounts against phishing and password reuse attacks. Unfortunately, getting users to adopt 2FA remains a difficult challenge. While prior work at the intersection of measurement and usability has examined how to persuade people to avoid dangerous behavior (e. g., clicking through TLS warnings), relatively little work has conducted measurements at industry scale about how to persuade people to adopt protective behaviors. In this work, we focus on improving end user security in the wild by examining whether (i) messaging that addresses users' motivations, mental models, and concerns about 2FA and (ii) UX design patterns found effective in other fields can effectively improve 2FA adoption. To do so, we conduct a series of large-scale in-the-wild, controlled messaging experiments on Facebook, with an average of 622, 419 participants per experiment. Based on our results, we distill a set of best-practice design patterns for most effectively encouraging protective behavior, in the context of promoting 2FA adoption. Finally, we suggest concrete directions for future work on encouraging digital security behavior through security prompts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aecb7904-da97-48a5-b357-00ddd20b1116Cited by top-tier papers13
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 35 citations
- SoK (or SoLK?): On the Quantitative Study of Sociodemographic Factors and Computer Security BehaviorsMiranda Wei, Jaron Mink, Yael Eiger, Tadayoshi Kohno et al.USENIX Security 2024 · 18 citations
- How Language Formality in Security and Privacy Interfaces Impacts Intended ComplianceJackson Stokes, Tal August, Robert A Marver, Alexei Czeskis et al.CHI 2023 · 9 citations
- "Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure AuthenticationJan H. Klemmer, Marco Gutfleisch, Christian Stransky, Yasemin Acar et al.CCS 2023 · 8 citations
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
Builds on11
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- I Think They're Trying to Tell Me Something: Advice Sources and Selection for Digital SecurityElissa M. Redmiles, Amelia R. Malone, Michelle L. MazurekS&P 2016 · 151 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- A Tale of Two Studies: The Best and Worst of YubiKey UsabilityJoshua Reynolds, Trevor Smith, Ken Reese, Luke Dickinson et al.S&P 2018 · 95 citations
- Adapting Security Warnings to Counter Online DisinformationBen Kaiser, Jerry Wei, Eli Lucherini, Kevin Lee et al.USENIX Security 2021 · 81 citations
Related papers
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 1 citation
- A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked WebsitesSanam Ghorbani Lyastani, Michael Backes, Sven BugielNDSS 2023
- "Should I Worry?" A Cross-Cultural Examination of Account Security Incident ResponseElissa M. RedmilesS&P 2019 · 53 citations
- "If I could do this, I feel anyone could: " The Design and Evaluation of a Secondary Authentication Factor ManagerGarrett Smith, Tarun Kumar Yadav, Jonathan Dutson, Scott Ruoti et al.USENIX Security 2023
- "It's Time. Time for Digital Security.": An End User Study on Actionable Security and Privacy AdviceAnna Lena Rotthaler, Harshini Sri Ramulu, Lucy Simko, Sascha Fahl et al.S&P 2025
