Jan. 5, 2023, 2:10 a.m. | Stephan Wiefling, Jan Tolsdorf, Luigi Lo Iacono

cs.CR updates on arXiv.org arxiv.org

Risk-based authentication (RBA) extends authentication mechanisms to make
them more robust against account takeover attacks, such as those using stolen
passwords. RBA is recommended by NIST and NCSC to strengthen password-based
authentication, and is already used by major online services. Also, users
consider RBA to be more usable than two-factor authentication and just as
secure. However, users currently obtain RBA's high security and usability
benefits at the cost of exposing potentially sensitive personal data (e.g., IP
address or browser information). …

account account takeover account takeover attacks attacks authentication benefits cost exposing factor high major ncsc nist online services password passwords privacy risk risk-based authentication security services stolen stolen passwords systems takeover usability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)