A Comparative Long-Term Study of Fallback Authentication Schemes
Leona Lassak, Philipp Markert, Maximilian Golla, Elizabeth Stobert, Markus Dürmuth
摘要
Fallback authentication, the process of re-establishing access to an account when the primary authenticator is unavailable, holds critical significance. Approaches range from secondary channels like email and SMS to personal knowledge questions (PKQs) and social authentication. A key difference to primary authentication is that the duration between enrollment and authentication can be much longer, typically months or years. However, few systems have been studied over extended timeframes, making it difficult to know how well these systems truly help users recover their accounts. We also lack meaningful comparisons of schemes as most prior work examined two mechanisms at most. We report the results of a long-term user study of the usability of fallback authentication over 18 months to provide a fair comparison of the four most commonly used fallback authentication methods. We show that users prefer email and SMS-based methods, while mechanisms based on PKQs and trustees lag regarding successful resets and convenience.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Understanding How Users Prepare for and React to Smartphone TheftDivyanshu Bhardwaj, Sumair Ijaz Hashmi, Katharina Krombholz, Maximilian GollaUSENIX Security 2025
- Selling the Dream: How Intimate Insiders and Identity-Based Attackers Disrupt Micro-businessesNazanin Sabri, Arkaprabha Bhattacharya, Sterling Williams-Ceci, Daniel V. Bailey 等USENIX Security 2026
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the WebLouis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov 等USENIX Security 2026
它引用的顶会 Paper5
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy 等USENIX Security 2019 · 被引用 118 次
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi 等CHI 2022 · 被引用 77 次
- The Password Reset MitM AttackNethanel Gelernter, Senia Kalma, Bar Magnezi, Hen PorcilanS&P 2017 · 被引用 45 次
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 被引用 35 次
- Why I Can't Authenticate - Understanding the Low Adoption of Authentication Ceremonies with AutoethnographyMatthias Fassl, Katharina KrombholzCHI 2023 · 被引用 18 次
相关 Paper
- Effect of Mood, Location, Trust, and Presence of Others on Video-Based Social AuthenticationCheng Guo, Brianne Campbell, Apu Kapadia, Michael K. Reiter 等USENIX Security 2021 · 被引用 9 次
- "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in GermanyEva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 等CHI 2025 · 被引用 1 次
- A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted ServiceSandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge 等USENIX Security 2024 · 被引用 6 次
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause 等CCS 2023 · 被引用 14 次
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 被引用 1 次
