A Comparative Long-Term Study of Fallback Authentication Schemes
Leona Lassak, Philipp Markert, Maximilian Golla, Elizabeth Stobert, Markus Dürmuth
Abstract
Fallback authentication, the process of re-establishing access to an account when the primary authenticator is unavailable, holds critical significance. Approaches range from secondary channels like email and SMS to personal knowledge questions (PKQs) and social authentication. A key difference to primary authentication is that the duration between enrollment and authentication can be much longer, typically months or years. However, few systems have been studied over extended timeframes, making it difficult to know how well these systems truly help users recover their accounts. We also lack meaningful comparisons of schemes as most prior work examined two mechanisms at most. We report the results of a long-term user study of the usability of fallback authentication over 18 months to provide a fair comparison of the four most commonly used fallback authentication methods. We show that users prefer email and SMS-based methods, while mechanisms based on PKQs and trustees lag regarding successful resets and convenience.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Understanding How Users Prepare for and React to Smartphone TheftDivyanshu Bhardwaj, Sumair Ijaz Hashmi, Katharina Krombholz, Maximilian GollaUSENIX Security 2025
- Selling the Dream: How Intimate Insiders and Identity-Based Attackers Disrupt Micro-businessesNazanin Sabri, Arkaprabha Bhattacharya, Sterling Williams-Ceci, Daniel V. Bailey et al.USENIX Security 2026
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the WebLouis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov et al.USENIX Security 2026
Builds on5
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy et al.USENIX Security 2019 · 118 citations
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi et al.CHI 2022 · 77 citations
- The Password Reset MitM AttackNethanel Gelernter, Senia Kalma, Bar Magnezi, Hen PorcilanS&P 2017 · 45 citations
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 35 citations
- Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with AutoethnographyMatthias Fassl, Katharina KrombholzCHI 2023 · 18 citations
Related papers
- Effect of Mood, Location, Trust, and Presence of Others on Video-Based Social AuthenticationCheng Guo, Brianne Campbell, Apu Kapadia, Michael K. Reiter et al.USENIX Security 2021 · 9 citations
- "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in GermanyEva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith et al.CHI 2025 · 1 citation
- A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted ServiceSandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge et al.USENIX Security 2024 · 6 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 1 citation
