Highlights
Fallback authentication
Fallback authentication recovers user access in case a user is unable to log back in or has forgotten the password. Security questions are one of the means for fallback authentication. However, security questions are not as robust as we think and can cause a security breach by enabling unauthorized access. Along with security, usability is a growing concern for the effective use of security questions.
It is crucial to expose the vulnerability of security questions and establish a new approach to improve its usability. We conduct an online user survey to validate user opinions for the usability of text-based security questions. We then conduct another on-campus study in a span of six weeks to specifically examine the memorability aspect of security
INTRODUCTION
Nowadays, security has become one of the most pressing issues of the Internet. Passwords have been extensively used for primary authentication mechanisms
[1]. Choosing a robust password is imperative for maintaining account security. Along with keeping a secure password, one must ensure that the fallback authentication is resilient to threats since a weak password recovery mechanism will also render passwords insecure. Security questions are a popular and extensively utilized fallback authentication mechanism. A recent Google study emphasized that security questions alone are not robust enough to be used as a single fallback authentication mechanism
[2]. They can be easily inferred through social engineering attacks. It is also important to analyze the usability of security questions. Memorability is a fundamental factor while considering the usability of security questions. Unlike passwords, security questions are less frequently accessed, so their recall rate is relatively low [3]. Poor usability and inadequate level of security have motivated us to seek different authentication approaches.
Overview
Conducting user surveys helped us get feedback about the current fallback mechanisms. It also guided us to design a more robust and usable fallback authentication. We conducted two surveys. The first survey focused on getting users’ views on the usability and security of security questions. The results of the first survey signified that users are not satisfied with the usability of security questions and mentioned that their security needed improvement. The second survey was a two-round survey to specifically investigate the memorability aspect of these questions. Users were asked to recall their answers to security questions after a six-week gap. The recall rate was observed to be very low, and users were not able to answer any questions accurately. Analyzing both surveys helped me understand the usability concerns of security questions as well as what measures needed to be taken to improve the memorability. The surveys were vital in guiding us to find an alternative approach.
Security questions can be breached by man-in-the-middle attacks, brute force attacks, or keystroke logging attacks. We implemented a known password reset man-in-the-middle attack (PR-MITM) attack [4]. The purpose of this MITM attack was to expose that if the password reset mechanisms are weak, a user’s account can get compromised. The TheMITM attack was able to compromise thevictim’ssecurity questions and proceed with the password reset on the victim’s mail account.
Organization
The remainder of the report is organized as follows. In Chapter 2, we survey the previous research work and lay a conceptual foundation for the study. We analyze the characteristics and shortcomings of security questions in Chapter 3. We present a user study that highlights user opinions and user perception on security questions in Chapter 4. We then investigate the types of threats to security questions and implement a password reset man-in-the-middle attack in Chapter 5. In Chapter 6, we propose a novel knowledge-based approach that uses visual and audio associations to improve the usability of fallback authentication. In Chapter 7, we provide a conclusion and a direction for future work.
Appendix A: Screening Survey
Q-What is your age?
Q-What is your gender?
Q-What is your highest education level?
Q-Which of the following describes your primary occupation?
Q- To what extent do you agree or disagree that someone might try to break into your primary personal email account using your security questions?
Q-To what extent do you agree or disagree with this statement: “Security questions have poor security.”
Q-What fallback authentication method you prefer presupposing you forget the password?
This IT Assignment has been solved by our IT Experts at onlineassignmentbank. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment Experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.