From TOTPs to Security Keys: Studying the Reality of Passwordless FIDO2 Authentication With PIN and Biometrics in a Corporate Environment

Leona Lassak, Nicklas Lindemann, and Marvin Kowalewski, Ruhr University Bochum

Phishing remains a major threat to companies. Many organizations use multi-factor authentication (MFA) methods like SMS or TOTPs which unfortunately still leave them vulnerable to attacks and even add cognitive, physical, and time strain for employees. Passwordless authentication with FIDO2 security keys could offer a promising alternative with strong phishing resistance and better usability, yet real-world adoption in corporate settings is underexplored. In a five-week field study at a mid-sized IT company, we compared security keys (PIN and biometrics) to passwords with TOTPs using authentication logs, surveys, and interviews with 34 employees. While biometric security keys reduced login times by nearly five seconds, PIN-based keys were not significantly faster. Despite this, and despite usability challenges such as hardware compatibility, employees were significantly more satisfied with both on-device authentication methods. Security perception remained unchanged, as employees already considered existing authentication secure. Critically, overall inconsistencies and complexities of authentication workflows were frequently criticized, suggesting that the authentication method itself may not always be the core issue and highlighting the need for organizations to analyze root causes of problems before adopting new authentication methods as quick fixes for fundamentally flawed infrastructures.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {308911,
author = {Leona Lassak and Nicklas Lindemann and Marvin Kowalewski},
title = {From {TOTPs} to Security Keys: Studying the Reality of Passwordless {FIDO2} Authentication With {PIN} and Biometrics in a Corporate Environment},
booktitle = {Twenty-First Symposium on Usable Privacy and Security (SOUPS 2025)},
year = {2025},
isbn = {978-1-939133-51-9},
address = {Seattle, WA},
pages = {371--389},
url = {https://www.usenix.org/conference/soups2025/presentation/lassak},
publisher = {USENIX Association},
month = aug
}