Feb. 17, 2023, 2:10 a.m. | Hazel Murray, David Malone

cs.CR updates on arXiv.org arxiv.org

Authentication security advice is given with the goal of guiding users and
organisations towards secure actions and practices. In this paper, we
demonstrate that security advice can be ambiguous, contradictory and at times
may not even have any clear benefits. We expand on current work by defining a
formal approach to identifying costs of security advice and instigate a user
study to identify the costs that apply to a large range of authentication
advice. We also apply a simple framework …

actions advice authentication authentication security benefits current identify large may practices security security advice study work

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Researcher, SIEM

@ Huntress | Remote Canada

Senior Application Security Engineer

@ Revinate | San Francisco Bay Area

Cyber Security Manager

@ American Express Global Business Travel | United States - New York - Virtual Location

Incident Responder Intern

@ Bentley Systems | Remote, PA, US

SC2024-003533 Senior Online Vulnerability Assessment Analyst (CTS) - THU 9 May

@ EMW, Inc. | Mons, Wallonia, Belgium