Back to Search
Start Over
Costs and Benefits of Authentication Advice.
- Source :
- ACM Transactions on Privacy & Security; Aug2023, Vol. 26 Issue 3, p1-35, 35p
- Publication Year :
- 2023
-
Abstract
- Authentication security advice is given with the goal of guiding users and organisations towards secure actions and practices. In this article, a taxonomy of 270 pieces of authentication advice is created, and a survey is conducted to gather information on the costs associated with following or enforcing the advice. Our findings indicate that security advice can be ambiguous and contradictory, with 41% of the advice collected being contradicted by another source. Additionally, users reported high levels of frustration with the advice and identified high usability costs. The study also found that end-users disagreed with each other 71% of the time about whether a piece of advice was valuable or not. We define a formal approach to identifying security benefits of advice. Our research suggests that cost-benefit analysis is essential in understanding the value of enforcing security policies. Furthermore, we find that organisation investment in security seems to have better payoffs than mechanisms with high costs to users. [ABSTRACT FROM AUTHOR]
Details
- Language :
- English
- ISSN :
- 24712566
- Volume :
- 26
- Issue :
- 3
- Database :
- Complementary Index
- Journal :
- ACM Transactions on Privacy & Security
- Publication Type :
- Academic Journal
- Accession number :
- 170017041
- Full Text :
- https://doi.org/10.1145/3588031