Tangible 2FA – An In-the-Wild Investigation of User-Defined Tangibles for Two-Factor Authentication

Authors: 

Mark Turner, University of Glasgow; Martin Schmitz, Saarland University Saarbrücken; Morgan Masichi Bierey and Mohamed Khamis, University of Glasgow; Karola Marky, University of Glasgow and Ruhr-University Bochum

Abstract: 

Although two-factor authentication (2FA) mechanisms can be usable, they poorly integrate into users' daily routines, especially during mobile use. Using tangibles for 2FA is a promising alternative that beneficially combines customisable authentication routines and object geometries, personalisable to each user. Yet, it remains unclear how they integrate into daily routines. In this paper, we first let 226 participants design 2FA tangibles to understand user preferences. Second, we prototyped the most common shapes and performed a one-week long in-the-wild study (N=15) to investigate how 2FA tangibles perform in different environments. We show that most users prefer objects that a) fit in wallets, b) connect to daily items or c) are standalone. Users enjoyed interacting with 2FA tangibles and considered them a viable and more secure alternative. Yet, they voiced concerns on portability. We conclude by an outlook for a real world implementation and distribution of 2FA tangibles addressing user concerns.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {289484,
author = {Mark Turner and Martin Schmitz and Morgan Masichi Bierey and Mohamed Khamis and Karola Marky},
title = {Tangible {2FA} {\textendash} An {In-the-Wild} Investigation of {User-Defined} Tangibles for {Two-Factor} Authentication},
booktitle = {Nineteenth Symposium on Usable Privacy and Security (SOUPS 2023)},
year = {2023},
isbn = {978-1-939133-36-6},
address = {Anaheim, CA},
pages = {245--261},
url = {https://www.usenix.org/conference/soups2023/presentation/turner},
publisher = {USENIX Association},
month = aug
}

Presentation Video