An overview of the present and future of user authentication

MA Al Kabir, W Elmedany - 2022 4th IEEE Middle East and …, 2022 - ieeexplore.ieee.org
Cybersecurity is an ever-evolving discipline that aims to protect every aspect of an
information system, including its users, from digital threats, adversaries and attacks. When it …

Pump up password security! Evaluating and enhancing risk-based authentication on a real-world large-scale online service

S Wiefling, PR Jørgensen, S Thunem… - ACM Transactions on …, 2022 - dl.acm.org
Risk-based authentication (RBA) aims to protect users against attacks involving stolen
passwords. RBA monitors features during login, and requests re-authentication when …

Account security interfaces: important, unintuitive, and untrustworthy

A Daffalla, M Bohuk, N Dell, R Bellini… - 32nd USENIX Security …, 2023 - usenix.org
Online services increasingly rely on user-facing interfaces to communicate important
security-related account information—for example, which devices are logged into a user's …

SoK: Web Authentication in the Age of End-to-End Encryption

J Blessing, D Hugenroth, RJ Anderson… - arxiv preprint arxiv …, 2024 - arxiv.org
The advent of end-to-end encrypted (E2EE) messaging and backup services has brought
new challenges for usable authentication. Compared to regular web services, the nature of …

Evaluation of real-world risk-based authentication at online services revisited: complexity wins

JP Makowski, D Pöhn - … of the 18th International Conference on …, 2023 - dl.acm.org
Risk-based authentication (RBA) aims to protect end-users against attacks involving stolen
or otherwise guessed passwords without requiring a second authentication method all the …

Risk-Based Authentication for OpenStack: A Fully Functional Implementation and Guiding Example

V Unsel, S Wiefling, N Gruschka… - Proceedings of the …, 2023 - dl.acm.org
Online services have difficulties to replace passwords with more secure user authentication
mechanisms, such as Two-Factor Authentication (2FA). This is partly due to the fact that …

F-RBA: A Federated Learning-based Framework for Risk-based Authentication

H Fereidouni, AS Hafid, D Makrakis… - arxiv preprint arxiv …, 2024 - arxiv.org
The proliferation of Internet services has led to an increasing need to protect private data.
User authentication serves as a crucial mechanism to ensure data security. Although robust …

A Privacy Measure Turned Upside Down? Investigating the Use of HTTP Client Hints on the Web

S Wiefling, M Hönscheid, L Lo Iacono - Proceedings of the 19th …, 2024 - dl.acm.org
HTTP client hints are a set of standardized HTTP request headers designed to modernize
and potentially replace the traditional user agent string. While the user agent string exposes …

[PDF][PDF] Usability, security, and privacy of risk-based authentication

S Wiefling - 2023 - researchgate.net
Weaknesses in password-based authentication have always shaken password security,
especially with the rise of data breaches. Credential stuffing and password spraying attacks …