Authors
Stuart Schechter, Serge Egelman, Robert W Reeder
Publication date
2009/4/4
Book
Proceedings of the sigchi conference on human factors in computing systems
Pages
1983-1992
Description
Backup authentication mechanisms help users who have forgotten their passwords regain access to their accounts-or at least try. Today's systems fall short in meeting both security and reliability requirements. We designed, built, and tested a new backup authentication system that employs a social-authentication mechanism. The system employs trustees previously appointed by the account holder to verify the account holder's identity. We ran three experiments to determine whether the system could (1) reliably authenticate account holders, (2) resist email attacks that target trustees by impersonating account holders, and (3) resist phone-based attacks from individuals close to account holders. Results were encouraging: seventeen of the nineteen participants who made the effort to call trustees authenticated successfully. However, we also found that users must be reminded of who their trustees are. While email …
Total citations
20092010201120122013201420152016201720182019202020212022202320243510891016141243105773
Scholar articles
S Schechter, S Egelman, RW Reeder - Proceedings of the sigchi conference on human factors …, 2009