首页> 外文会议>IEEE International Conference on Collaboration and Internet Computing >Security Mandates are Pervasive: An Inter-School Study on Analyzing User Authentication Behavior
【24h】

Security Mandates are Pervasive: An Inter-School Study on Analyzing User Authentication Behavior

机译:安全授权无处不在:关于分析用户身份验证行为的校际研究

获取原文

摘要

Two-factor authentication (2FA) technologies are designed to increase the security and usability of authentication. Adoption of 2FA hardware devices that generate one- time passwords has proven to be effective as a risk mitigating strategy. Despite 2FA addressing user data security concerns, individuals appear either disinterested or unable to adopt 2FA tools. Many institutions are now mandating 2FA to better secure their network and user data. Some have more rigid requirements than others (e.g., offering only one 2FA method vs. offering multiple 2FA options). To better understand the impact of mandatory 2FA policies, we conducted a study of the usability, adoption, and acceptability of 2FA at three different universities. In our study, using the Yubico FIDO U2F security token, we found that mandating the use of 2FA without complementary risk communication is often inadequate. In our interviews, we found that mandatory 2FA did not necessarily increase security, instead leading to less secure user behavior, such as sharing 2FA tokens, storing credentials for a longer time in public devices, and other security avoidance behaviors.
机译:两要素身份验证(2FA)技术旨在提高身份验证的安全性和可用性。实践证明,采用生成一次性密码的2FA硬件设备可以有效地降低风险。尽管2FA解决了用户数据安全问题,但是个人似乎不感兴趣或无法采用2FA工具。现在,许多机构都在要求2FA更好地保护其网络和用户数据。有些要求比其他要求更为严格(例如,仅提供一种2FA方法,而不是提供多种2FA选项)。为了更好地理解2FA强制性政策的影响,我们对三所不同大学中2FA的可用性,采用和可接受性进行了研究。在我们的研究中,使用Yubico FIDO U2F安全令牌,仅强制使用2FA而不进行补充风险沟通通常是不够的。在我们的采访中,我们发现强制性2FA并不一定会提高安全性,反而会导致安全性较低的用户行为,例如共享2FA令牌,在公共设备中较长时间存储凭据以及其他避免安全行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号