vix.ing · top · new · best · stats · spec

"`They brought in the horrible key ring thing!" Analysing the Usability\n of Two-Factor Authentication in UK Online Banking

2015/01/19 by Kat Krol, Eleni Philippou, Krol, Kat +5 · 1 citation
Computer Science · Social Sciences · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Human-Computer Interaction (cs.HC) #Information and Cyber Security #Privacy, Security, and Data Protection #User Authentication and Security Systems

paper · pdf · doi:10.48550/arxiv.1501.04434

openalex publication_date 2015/01/19 · openalex created_date 2022/10/03 · openalex updated_date 2026/07/28

Abstract

To prevent password breaches and guessing attacks, banks increasingly turn to\ntwo-factor authentication (2FA), requiring users to present at least one more\nfactor, such as a one-time password generated by a hardware token or received\nvia SMS, besides a password. We can expect some solutions -- especially those\nadding a token -- to create extra work for users, but little research has\ninvestigated usability, user acceptance, and perceived security of deployed\n2FA.\n This paper presents an in-depth study of 2FA usability with 21 UK online\nbanking customers, 16 of whom had accounts with more than one bank. We\ncollected a rich set of qualitative and quantitative data through two rounds of\nsemi-structured interviews, and an authentication diary over an average of 11\ndays. Our participants reported a wide range of usability issues, especially\nwith the use of hardware tokens, showing that the mental and physical workload\ninvolved shapes how they use online banking. Key targets for improvements are\n(i) the reduction in the number of authentication steps, and (ii) removing\nfeatures that do not add any security but negatively affect the user\nexperience.\n

Cited by

Related