Abstract
This research compared three different two-factor methods of eBanking authentication. Three devices employing incremental security layers in the generation of one time passcodes (OTPs) were compared in a repeated-measures, controlled experiment with 50 eBanking customers. Attitudes towards usability and usage logs were taken for each experience. Comparisons of the devices in terms of overall quality, security and convenience as perceived by participants were also recorded. There were significant differences between all three methods in terms of usability measures, perceived quality, convenience and security ratings – with the perceived security ratings following a reverse order to the other measures. Almost two thirds of the participant sample chose the device they perceived the least secure as their preference. Participants were asked to use their preferred method again and tended to find their chosen device more usable. This research illustrates the usability-security trade off, where convenience, quality and usability are sacrificed when increasing layers of security are required. In their preferences, customers were driven by their attitudes towards usability and convenience rather than their perceptions of security.
Original language | English |
---|---|
Pages (from-to) | 47-62 |
Number of pages | 16 |
Journal | Computers and Security |
Volume | 28 |
Issue number | 1-2 |
DOIs | |
Publication status | Published - Feb 2009 |
Keywords / Materials (for Non-textual outputs)
- Usability engineering
- Internet Banking
- Authentication
- Security
- Empirical study
- Evaluation