aislop.day
WEDNESDAY, 13 JULY 2022

Annual Review of Login Code Chase

A code has been sent. The code expires in thirty seconds. The phone is in another room.

3 MIN READonline fatigue

Annual Review: Login Code Chase Observational Record, July 2021 to July 2022


Overview

Two-factor authentication has been enabled on all accounts where the option exists. This was done for security reasons. The security reasons are valid. The system has introduced a secondary condition that was not anticipated at the time of setup.

The phone is rarely in the same room as the computer.

The Pattern

The login sequence proceeds as follows. The user enters credentials on the computer. The system sends a six-digit code to the user's phone. The system specifies that the code expires in thirty seconds or, in one notable case, sixty seconds, which was initially interpreted as a generous improvement and quickly proven insufficient.

The phone is charging in the bedroom. The user is in the office. The office and the bedroom are separated by a hallway, which is twelve feet, which is a distance the user has traversed rapidly enough to lose the code on three separate occasions this year, in one instance because the code arrived during a window the user was not watching, and in two instances because the code expired while the user was reading it.

Behavioral Adaptations Observed

The user now moves the phone to the desk before initiating any login process that is anticipated. This adaptation is effective for anticipated logins. Unanticipated logins, which represent the majority of logins requiring two-factor authentication because anticipated logins tend to have remembered sessions, are not covered by this adaptation.

A secondary adaptation: the user leaves the current device screen visible while moving to retrieve the phone, which allows visual confirmation that the login session has not timed out. This requires the session timeout to be shorter than the phone retrieval window, which is not always the case.

The Governing Rule

The security measure that requires the user to sprint to another room to complete a login has introduced a physical component to the authentication process that no threat model anticipated. The system was designed for the case where the phone is on the desk. The phone is on the desk approximately 40 percent of the time during active use hours.

The code has never arrived before the user reaches the phone. This is not a technical observation. This is a behavioral pattern documented over fourteen months.

Consequence 1

The user has added two-factor authentication to accounts where it was previously optional and has encountered the code delivery timing problem in fourteen of seventeen such accounts. The accounts use different delivery methods. The timing problem is consistent.

Consequence 2

The user has begun treating the thirty-second transit to retrieve the phone as a forced micro-break from the computer screen. The walk counts as movement. The urgency is mild exercise.

This is not the intended function of two-factor authentication. It is the observed function.

Assessment

The system works. The security objective is met. The twelve feet of hallway are an externality. The externality is manageable and has been managed for fourteen months.

The phone will remain in the bedroom at night. This decision is final and has been reviewed.

TAGSonline fatigue
Share this