Using strong passwords doesn’t mean that your user account is safe. Large-scale password database leaks and intelligent password guessing attacks can still compromise your accounts.
Risk-based Authentication (RBA) is an approach to improve account security on websites without forcing users to use Two-factor Authentication (2FA).
During login, RBA estimates a risk score based on the login behavior.
RBA is getting more and more important.
We studied popular online services and found evidence that Google, Facebook, LinkedIn, Amazon and GOG.com are using it.
Want to know more about their state of practice?
We studied this question with 65 users in our usability lab. The results show that
However, these impressions strongly depend on the type of online service that deploys RBA. For more details:
We observed 780 users over 1.8 years to find out more. We also found out which features are sensible to be used for RBA systems to achieve good security and usability.
For the full analysis:
Users currently obtain RBA’s high security and usability benefits at the cost of disclosing potentially sensitive data.
However, it is possible to enhance privacy for RBA:
On medium risk, users are asked for re-authentication.
But how long does this take and how do users feel about it? We tested three RBA re-authentication schemes with over 500 participants to find out more.
Want to know which scheme performs best?