”Nah, it’s just annoying!” A Deep Dive into User Perceptions of Two-Factor AuthenticationShow others and affiliations
2022 (English)In: ACM Transactions on Computer-Human Interaction, ISSN 1073-0516, E-ISSN 1557-7325, Vol. 29, no 5, p. 1-32Article in journal (Refereed) Published
Abstract [en]
Two-factor authentication (2FA) is a recommended or imposed authentication mechanism for valuable online assets. However, 2FA mechanisms usually exhibit user experience issues that create user friction and even lead to poor acceptance, hampering the wider spread of 2FA. In this article, we investigate user perceptions of 2FA through in-depth interviews with 42 participants, revealing key requirements that are not well met today despite recently emerged 2FA solutions. First, we investigate past experiences with authentication mechanisms emphasizing problems and aspects that hamper good user experience. Second, we investigate the different authentication factors more closely. Our results reveal particularly interesting preferences regarding the authentication factor "ownership"in terms of properties, physical realizations, and interaction. These findings suggest a path toward 2FA mechanisms with considerably better user experience, promising to improve the acceptance and hence, the proliferation of 2FA for the benefit of security in the digital world.
Place, publisher, year, edition, pages
Association for Computing Machinery (ACM) , 2022. Vol. 29, no 5, p. 1-32
National Category
Human Computer Interaction
Identifiers
URN: urn:nbn:se:kth:diva-329512DOI: 10.1145/3503514ISI: 000910184600005Scopus ID: 2-s2.0-85131690358OAI: oai:DiVA.org:kth-329512DiVA, id: diva2:1772138
Note
QC 20230907
2023-06-212023-06-212023-09-07Bibliographically approved