“Maybe there’s only one passkey?”: Challenges Investigating and Remediating Adversarial Passkeys
Alaa Daffalla, Grace Myers, Rosanna Bellini, Thomas Ristenpart, Nicola Dell
摘要
Passkeys are being actively rolled out by hundreds of web services who market them as a promising passwordless authentication method. However, it remains unclear whether people understand how to manage passkeys as part of their broader account security management, particularly in the aftermath of account compromise. We conducted a qualitative lab-based study that explores how people investigate and remediate suspicious activity when passkeys are used as a vector for illicit account access on three popular, passkey-supporting services: Google, PayPal, and LinkedIn. We recruited 31 participants with diverse technical backgrounds and tasked them with: (1) investigating a potential incident of compromise involving passkeys and (2) taking steps needed to re-secure the account.
Participants struggled to manage passkeys within account security settings and on devices, even when supported by service-provided email notifications, account security interfaces (ASIs), and streamlined wizards. The design and content of notifications and ASIs were often confusing or unclear, while the service-provided wizards were incomplete or misleading. This resulted in participants missing key steps required to discover adversarial passkeys and fully secure the account to prevent continued adversarial access. We discuss design implications and opportunities for future work to improve passkey management tools in ways that better support people experiencing account compromise.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh 等S&P 2021 · 被引用 175 次
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes 等S&P 2020 · 被引用 124 次
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy 等USENIX Security 2019 · 被引用 118 次
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul 等S&P 2022 · 被引用 101 次
- Provable Security Analysis of FIDO2Manuel Barbosa, Alexandra Boldyreva, Shan Chen, Bogdan WarinschiCRYPTO 2021 · 被引用 42 次
相关 Paper
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 被引用 1 次
- A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat ModelsAlaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee 等USENIX Security 2025
- Was This You? Investigating the Design Considerations for Suspicious Login NotificationsSena Sahin, Burak Sahin, Frank LiNDSS 2025
- Moving Beyond Passwords: Investigating the Effect of Digital Nudges on Passkey AdoptionTobias Reittinger, Magdalena Glas, Günther PernulCHI 2026 · 被引用 2 次
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the WebLouis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov 等USENIX Security 2026
