Passwords and the Evolution of Imperfect Authentication.¶
Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2015). Passwords and the Evolution of Imperfect Authentication. Communications of the ACM, 58(7), 78-87.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Intervention-Coupled Harm
- The four moves appear in security dress: accept (cost the productivity loss into the security budget), compensate (passwordless recovery flows that target lockout on a separate channel), switch (phishing-resistant cryptographic authentication, where the coupled harm becomes procurement cost rather than daily login friction), and combine (risk-based authentication invoking MFA only on anomalous sessions, letting a different mechanism bear part of the load).
This sourceTreats the security-usability coupling of authentication mechanisms and risk-based/alternative authentication as ways to redistribute the friction-versus-security trade-off.
- The four moves appear in security dress: accept (cost the productivity loss into the security budget), compensate (passwordless recovery flows that target lockout on a separate channel), switch (phishing-resistant cryptographic authentication, where the coupled harm becomes procurement cost rather than daily login friction), and combine (risk-based authentication invoking MFA only on anomalous sessions, letting a different mechanism bear part of the load).
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:bd4aa1f4e01c · see in the full table