More than just good passwords? A study on usability and security perceptions of risk-based authentication

S Wiefling, M Dürmuth, L Lo Iacono - Proceedings of the 36th Annual …, 2020 - dl.acm.org
Risk-based Authentication (RBA) is an adaptive security measure to strengthen password-
based authentication. RBA monitors additional features during login, and when observed …

Pump up password security! Evaluating and enhancing risk-based authentication on a real-world large-scale online service

S Wiefling, PR Jørgensen, S Thunem… - ACM Transactions on …, 2022 - dl.acm.org
Risk-based authentication (RBA) aims to protect users against attacks involving stolen
passwords. RBA monitors features during login, and requests re-authentication when …

Verify it's you: how users perceive risk-based authentication

S Wiefling, M Dürmuth, LL Iacono - IEEE Security & Privacy, 2021 - ieeexplore.ieee.org
Risk-based authentication (RBA) is an adaptive security measure used to strengthen
password-based authentication against account takeover attacks. Our study on 65 …

Is this really you? An empirical study on risk-based authentication applied in the wild

S Wiefling, L Lo Iacono, M Dürmuth - … and Privacy Protection: 34th IFIP TC …, 2019 - Springer
Risk-based authentication (RBA) is an adaptive security measure to strengthen password-
based authentication. RBA monitors additional implicit features during password entry such …

" As soon as it's a risk, I want to require {MFA"}: How Administrators Configure Risk-based Authentication

P Markert, T Schnitzler, M Golla… - Eighteenth Symposium on …, 2022 - usenix.org
Risk-based authentication (RBA) complements standard password-based logins by using
knowledge about previously observed user behavior to prevent malicious login attempts …

A Study of {Multi-Factor} and {Risk-Based} Authentication Availability

A Gavazzi, R Williams, E Kirda, L Lu, A King… - 32nd USENIX Security …, 2023 - usenix.org
Password-based authentication (PBA) remains the most popular form of user authentication
on the web despite its long-understood insecurity. Given the deficiencies of PBA, many …

Privacy considerations for risk-based authentication systems

S Wiefling, J Tolsdorf, LL Iacono - 2021 IEEE European …, 2021 - ieeexplore.ieee.org
Risk-based authentication (RBA) extends authentication mechanisms to make them more
robust against account takeover attacks, such as those using stolen passwords. RBA is …

Evaluation of risk-based re-authentication methods

S Wiefling, T Patil, M Dürmuth, L Lo Iacono - IFIP International Conference …, 2020 - Springer
Risk-based Authentication (RBA) is an adaptive security measure that improves the security
of password-based authentication by protecting against credential stuffing, password …

Strengthening password-based authentication

S Ruoti, J Andersen, K Seamons - Twelfth Symposium on Usable …, 2016 - usenix.org
Even with years of research into new authentication technologies, passwords still dominate
the authentication landscape. This is due primarily to a combination of security …

PassShapes: utilizing stroke based authentication to increase password memorability

R Weiss, A De Luca - Proceedings of the 5th Nordic conference on …, 2008 - dl.acm.org
Authentication today mostly relies on passwords or personal identification numbers (PINs).
Therefore the average user has to remember an increasing amount of PINs and passwords …