Skip to main content
USENIX
  • Conferences
  • Students
Sign in
  • Overview
  • Proceedings
  • Past Symposia

twitter

Tweets by @usenix

usenix conference policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

You are here

Home » On the Impact of Touch ID on iPhone Passcodes
Tweet

connect with us

On the Impact of Touch ID on iPhone Passcodes

Authors: 

Ivan Cherapau, Ildar Muslukhov, Nalin Asanka, and Konstantin Beznosov, University of British Columbia

Abstract: 

Smartphones today store large amounts of data that can be confidential, private or sensitive. To protect such data, all mobile OSs have a phone lock mechanism, a mechanism that requires user authentication before granting access to applications and data on the phone. iPhone’s unlocking secret (a.k.a., passcode in Apple’s terminology) is also used to derive a key for encrypting data on the device. Recently, Apple has introduced Touch ID, that allows a fingerprint-based authentication to be used for unlocking an iPhone. The intuition behind the technology was that its usability would allow users to use stronger passcodes for locking their iOS devices, without substantially sacrificing usability. To this date, it is unclear, however, if users take advantage of Touch ID technology and if they, indeed, employ stronger passcodes. It is the main objective and the contribution of this paper to fill this knowledge gap. In order to answer this question, we conducted three user studies (a) an in-person survey with 90 participants, (b) interviews with 21 participants, and (c) an online survey with 374 Amazon Mechanical Turks. Overall, we found that users do not take an advantage of Touch ID and use weak unlocking secrets, mainly 4-digit PINs, similarly to those users who do not use Touch ID. To our surprise, we found that more than 30% of the participants in each group did not know that they could use passwords instead of 4-digit PINs. Some other participants indicated that they adopted PINs due to better usability, in comparison to passwords. Most of the participants agreed that Touch ID, indeed, offers usability benefits, such as convenience, speed and ease of use. Finally, we found that there is a disconnect between users’ desires for security that their passcodes have to offer and the reality. In particular, only 12% of participants correctly estimated the security their passcodes provide. 

Ivan Cherapau, University of British Columbia

Ildar Muslukhov, University of British Columbia

Nalin Asanka, University of British Columbia

Konstantin Beznosov, University of British Columbia

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {192398,
author = {Ivan Cherapau and Ildar Muslukhov and Nalin Asanka and Konstantin Beznosov},
title = {On the Impact of Touch {ID} on {iPhone} Passcodes},
booktitle = {Eleventh Symposium On Usable Privacy and Security (SOUPS 2015)},
year = {2015},
isbn = {978-1-931971-249},
address = {Ottawa},
pages = {257--276},
url = {https://www.usenix.org/conference/soups2015/proceedings/presentation/cherapau},
publisher = {USENIX Association},
month = jul,
}
Download
Cherapau PDF
  • Log in or    Register to post comments

© USENIX

  • Privacy Policy
  • Contact Us