Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication

05/26/2021
by   Johannes Kunke, et al.
0

Threats to passwords are still very relevant due to attacks like phishing or credential stuffing. One way to solve this problem is to remove passwords completely. User studies on passwordless FIDO2 authentication using security tokens demonstrated the potential to replace passwords. However, widespread acceptance of FIDO2 depends, among other things, on how user accounts can be recovered when the security token becomes permanently unavailable. For this reason, we provide a heuristic evaluation of 12 account recovery mechanisms regarding their properties for FIDO2 passwordless authentication. Our results show that the currently used methods have many drawbacks. Some even rely on passwords, taking passwordless authentication ad absurdum. Still, our evaluation identifies promising account recovery solutions and provides recommendations for further studies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/16/2023

Lost and not Found: An Investigation of Recovery Methods for Multi-Factor Authentication

Multi-Factor Authentication is intended to strengthen the security of pa...
research
01/04/2023

Privacy Considerations for Risk-Based Authentication Systems

Risk-based authentication (RBA) extends authentication mechanisms to mak...
research
08/18/2020

Evaluation of Risk-based Re-Authentication Methods

Risk-based Authentication (RBA) is an adaptive security measure that imp...
research
12/16/2022

A Survey on Biometrics Authentication

Nowadays, traditional authentication methods are vulnerable to face atta...
research
12/16/2020

A novel Two-Factor HoneyToken Authentication Mechanism

The majority of systems rely on user authentication on passwords, but pa...
research
05/01/2023

How effective is multifactor authentication at deterring cyberattacks?

This study investigates the effectiveness of multifactor authentication ...
research
01/20/2018

Web password recovery --- a necessary evil?

Web password recovery, enabling a user who forgets their password to re-...

Please sign up or login with your details

Forgot password? Click here to reset