Understanding Users' Interaction with Login Notifications

要旨

Login notifications intend to inform users about sign-ins and help them protect their accounts from unauthorized access. Notifications are usually sent if a login deviates from previous ones, potentially indicating malicious activity. They contain information like the location, date, time, and device used to sign in. Users are challenged to verify whether they recognize the login (because it was them or someone they know) or to protect their account from unwanted access. In a user study, we explore users' comprehension, reactions, and expectations of login notifications. We utilize two treatments to measure users' behavior in response to notifications sent for a login they initiated or based on a malicious actor relying on statistical sign-in information. We find that users identify legitimate logins but need more support to halt malicious sign-ins. We discuss the identified problems and give recommendations for service providers to ensure usable and secure logins for everyone.

著者
Philipp Markert
Ruhr University Bochum, Bochum, Germany
Leona Lassak
Ruhr University Bochum, Bochum, Germany
Maximilian Golla
CISPA Helmholtz Center for Information Security, Saarbrücken, Germany
Markus Dürmuth
Leibniz University Hannover, Hannover, Germany
論文URL

doi.org/10.1145/3613904.3642823

動画

会議: CHI 2024

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2024.acm.org/)

セッション: Smart Homes and Environments

313C
5 件の発表
2024-05-15 01:00:00
2024-05-15 02:20:00