"I Knew It Was Me": Understanding Users' Interaction with Login Notifications

12/14/2022
by   Philipp Markert, et al.
0

Login notifications are intended to inform users about recent sign-ins and help them protect their accounts from unauthorized access. The notifications are usually sent if a login occurs from a new location or device, which could indicate malicious activity. They mostly contain information such as the location, date, time, and device used to sign in. Users are challenged to verify whether they recognize the login (because it has been them or someone they know) or to proactively protect their account from unwanted access by changing their password. In two user studies, we explore users' comprehension, reactions, and expectations of login notifications. We utilize two treatments to measure users' behavior in response to login notifications sent for a login they initiated themselves or based on a malicious actor relying on statistical sign-in information. Users feel relatively confident identifying legitimate logins but demonstrate various risky and insecure behaviors when it comes to malicious sign-ins. We discuss the identified problems and give recommendations for service providers to ensure usable and secure logins for everyone.

READ FULL TEXT

page 3

page 11

page 18

page 19

research
04/08/2022

Gone Quishing: A Field Study of Phishing with Malicious QR Codes

The COVID-19 pandemic enabled "quishing", or phishing with malicious QR ...
research
02/24/2020

EL PASSO: Privacy-preserving, Asynchronous Single Sign-On

We introduce EL PASSO, a privacy-preserving, asynchronous Single Sign-On...
research
03/27/2021

Dark Patterns in the Interaction with Cookie Banners

Dark patterns are interface designs that nudge users towards behavior th...
research
11/19/2018

Anonymous Single Sign-on with Proxy Re-Verification

An anonymous Single Sign-On (ASSO) scheme allows users to access multipl...
research
10/06/2021

Detecting and Quantifying Malicious Activity with Simulation-based Inference

We propose the use of probabilistic programming techniques to tackle the...
research
11/20/2021

Malicious Selling Strategies in Livestream Shopping: A Case Study of Alibaba's Taobao and ByteDance's Douyin

Livestream shopping is getting more and more popular as a new shopping f...
research
10/01/2021

Phonology Recognition in American Sign Language

Inspired by recent developments in natural language processing, we propo...

Please sign up or login with your details

Forgot password? Click here to reset