User Perceptions of the Usability and Security of Smartphones as FIDO2 Roaming Authenticators

User Perceptions of the Usability and Security of Smartphones as FIDO2 Roaming Authenticators
复制标题

用户对智能手机作为 FIDO2 漫游身份验证器的可用性和安全性的看法

DOI:
--
复制
发表时间:
2021
期刊:
SOUPS @ USENIX Security Symposium
影响因子:
--
通讯作者:
Blase Ur
Blase Ur
中科院分区:
--
文献类型:
--
作者:
Kentrell Owens;Olabode Anise;Amanda Krauss;Blase Ur

文献摘要

参考文献

被引文献

相似文献

FIDO2标准旨在用公钥密码术取代密码,以便在Web上进行用户身份验证。这样做在可用性(例如,不需要记住密码)和安全性(例如,消除网络钓鱼)方面都有好处(fit)。用户可以通过以下两种方式之一使用FIDO2进行身份验证。使用平台验证器,用户可以在访问网站的同一设备上对受信任的硬件进行身份验证。然而,他们必须在每台设备上分别为每个网站重新注册。使用漫游验证器(如USB安全密钥),它们只需注册一次,即可跨设备传输安全密钥。然而,用户可能不愿意为usb安全密钥买单,不愿随身携带,也不愿通过fi了解如何将其插入不同的设备。这些缺陷推动了最近的努力,使智能手机能够充当漫游验证器。我们进行了fi第一次用户研究,使用智能手机作为漫游认证器进行了FIDO2无密码认证。在受试者之间的设计中,97名参与者要么使用他们的智能手机作为FIDO2漫游验证器(通过名为Neo的原型),要么使用密码登录fi银行两周。我们发现,参与者准确地认识到Neo比密码更安全的fi。然而,尽管Neo在概念上的可用性对fit有利,但参与者发现Neo在客观衡量标准(例如,完成任务的时间)和感知方面都比密码的可用性低得多。他们对Neo的批评包括对手机可用性、账户恢复/备份以及设置fi邪教的担忧。我们的结果突出了推动采用智能手机作为FIDO2漫游验证器的关键挑战和机遇。
The FIDO2 standard aims to replace passwords with public-key cryptography for user authentication on the web. Doing so has benefits for both usability (e.g., not needing to remember passwords) and security (e.g., eliminating phishing). Users can authenticate with FIDO2 in one of two ways. With platform authenticators, users authenticate to trusted hardware on the same device on which they are accessing a website. However, they must re-register for each website separately on each device. With roaming authenticators, such as USB security keys, they only need to register once, transferring the security key across devices. However, users might not be willing to pay for a USB security key, carry it around, or figure out how to plug it into different devices. These drawbacks have driven recent efforts to enable smartphones to serve as roaming authenticators. We conducted the first user study of FIDO2 passwordless authentication using smartphones as roaming authenticators. In a between-subjects design, 97 participants used either their smartphone as a FIDO2 roaming authenticator (via a prototype called Neo) or a password to log into a fictitious bank for two weeks. We found that participants accurately recognized Neo’s strong security benefits over passwords. However, despite Neo’s conceptual usability benefits, participants found Neo substantially less usable than passwords both in objective measures (e.g., timing to accomplish tasks) and in perception. Their critiques of Neo included concerns about phone availability, account recovery/backup, and setup difficulties. Our results highlight key challenges and opportunities for spurring adoption of smartphones as FIDO2 roaming authenticators.
Pico in the Wild:一次更换一个站点的密码
DOI: --
发表时间: 2017
期刊: --
影响因子: --
作者:
Aebischer S
通讯作者: Aebischer S