aislop.day
WEDNESDAY, 3 NOVEMBER 2021

Preliminary Findings on Device Login Fatigue

A person logged into an account. The account sent a verification code to a device the person was not holding. The device was in another room. The person considered whether the task was worth walking to the other room.

3 MIN READott subscription stack

Transcript: Device Login Fatigue Formal Review Hearing Remote. Unscheduled. Second device not present.


CHAIR: Describe the situation.

WITNESS: A person attempted to log into an account on a laptop. The account required two-factor authentication. A six-digit code was sent to a registered phone number.

CHAIR: Was the phone available?

WITNESS: It was in another room. The person evaluated the distance to the other room, the urgency of the task they were trying to complete, and the number of times they had performed this sequence in the previous thirty days.

CHAIR: What was the result of that evaluation?

WITNESS: They closed the laptop.

CHAIR: The task was abandoned?

WITNESS: For that session. They returned to it the following morning when the phone was within reach.

CHAIR: Is this behavior documented elsewhere?

WITNESS: Across twelve distinct accounts in this person's profile, authentication codes are sent to one of three devices. Those devices are not always in the same location as the device initiating the login. In the period under review, six login attempts were abandoned before completion. Four were completed after a delay. Two resulted in the person requesting the code a second time because the first expired during the retrieval interval.

CHAIR: What is the forensic concern?

WITNESS: The security measure assumes the user controls both the device receiving the code and the device requesting it. This assumption holds until it does not. When it does not, the security measure becomes a friction cost paid by the authorized user while an unauthorized user with physical access to the phone would face no additional difficulty.

CHAIR: Is that an accurate characterization of the security model?

WITNESS: It is an accurate characterization of the situation in practice. The theoretical model is more favorable to the security measure.

CHAIR: What happens after repeated fatigue events?

WITNESS: The person begins to consolidate. Apps that require frequent authentication get installed on the device that also receives codes. This device becomes the primary device. The intended separation of the two-factor model collapses into a single device that holds both the account access and the verification mechanism.

The security architecture is preserved in name. It is not preserved in structure.

CHAIR: Has anyone at the account level observed this pattern?

WITNESS: No. The account sees successful authentications and abandoned sessions. It does not see why the session was abandoned. It does not see that the authentication succeeded because both factors arrived on the same device.

CHAIR: Is there a recommendation?

WITNESS: Keep the phone nearby. This recommendation has been made before. It has not resolved the underlying issue, which is that there are now fourteen accounts and three devices and no consistent assignment between them.

CHAIR: Thank you. Hearing adjourned.

TAGSott subscription stack
Share this