/* ---- Google Analytics Code Below */

Monday, October 05, 2020

Risk Based Authentication

Had seen this before, not called this.    Here in  Schneier.  As I recall in our brief look, a higher level of false negatives.  Here a more serious look.

On Risk-Based Authentication    

Interesting usability study: “More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication“:

Abstract: Risk-based Authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional features during login, and when observed feature values differ significantly from previously seen ones, users have to provide additional authentication factors such as a verification code. RBA has the potential to offer more usable authentication, but the usability and the security perceptions of RBA are not studied well.  .... '

No comments: