Account Security Interfaces: Important, Unintuitive, and Untrustworthy
Alaa Daffalla, Marina Sanusi Bohuk, Nicola Dell, Rosanna Bellini, Thomas Ristenpart
摘要
Online services increasingly rely on user-facing interfaces to communicate important security-related account information-for example, which devices are logged into a user's account and when recent logins occurred. These are used to assess the security status of an account, which is particularly critical for at-risk users likely to be under active attack. To date, however, there has been no investigation into whether these interfaces work well. We begin to fill this gap by partnering with a clinic that supports survivors of intimate partner violence (IPV). We investigated hundreds of transcripts to identify ones capturing interactions between clinic consultants and survivors seeking to infer the security status of survivor accounts, and we performed a qualitative analysis of 28 transcripts involving 19 consultants and 22 survivors. Our findings confirm the importance of these interfaces for assessing a user's security, but we also find that these interfaces suffer from a number of limitations that cause confusion and reduce their utility. We go on to experimentally investigate the lack of integrity of information contained in device lists and session activity logs for four major services. For all the services investigated, we show how an attacker can either hide accesses entirely or spoof access details to hide illicit logins from victims.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Mitigating Trauma in Qualitative Research Infrastructure: Roles for Machine Assistance and Trauma-Informed DesignEmily Tseng, Thomas Ristenpart, Nicola DellCSCW 2025 · 被引用 10 次
- Shortchanged: Uncovering and Analyzing Intimate Partner Financial Abuse in Consumer ComplaintsArkaprabha Bhattacharya, Kevin Lee, Vineeth Ravi, Jessica Staddon 等CHI 2024 · 被引用 7 次
- Navigating Traumatic Stress Reactions During Computer Security InterventionsLana Ramjit, Natalie Dolci, Francesca Rossi, Ryan Garcia 等USENIX Security 2024 · 被引用 5 次
- Legal Evidence of Technology-Facilitated Abuse in Wisconsin: Surfacing Barriers Within and Beyond the CourtroomSophie Stephenson, Naman Gupta, Akhil Polamarasetty, Kyle Huang 等CSCW 2025 · 被引用 2 次
- Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data ExportsJulia Nonnenkamp, Naman Gupta, Abhimanyu Dev Gupta, Rahul ChatterjeeCCS 2025
它引用的顶会 Paper15
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 被引用 273 次
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio 等NDSS 2016 · 被引用 151 次
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes 等S&P 2020 · 被引用 124 次
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy 等USENIX Security 2019 · 被引用 118 次
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul 等S&P 2022 · 被引用 101 次
相关 Paper
- Inconsistent, Incomplete, and Insecure: A Survey of Account Security InterfacesArkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini 等USENIX Security 2026
- The Digital-Safety Risks of Financial Technologies for Survivors of Intimate Partner ViolenceRosanna Bellini, Kevin Lee, Megan A. Brown, Jeremy Shaffer 等USENIX Security 2023
- Data Stewardship in Clinical Computer Security: Balancing Benefit and Burden in Participatory SystemsEmily Tseng, Rosanna Bellini, Yeuk-Yu Lee, Alana Ramjit 等CSCW 2024 · 被引用 24 次
- A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat ModelsAlaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee 等USENIX Security 2025
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi 等CHI 2022 · 被引用 77 次
