Visible to the public See You Next Time: A Model for Modern Shoulder Surfers

TitleSee You Next Time: A Model for Modern Shoulder Surfers
Publication TypeConference Paper
Year of Publication2016
AuthorsWiese, Oliver, Roth, Volker
Conference NameProceedings of the 18th International Conference on Human-Computer Interaction with Mobile Devices and Services
Date PublishedSeptember 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4408-1
Keywordsauthentication, Collaboration, composability, Human Behavior, insider threats, Metrics, mobile devices, peer to peer security, pubcrawl, Resiliency, Scalability, shoulder surfing
Abstract

Friends, family and colleagues at work may repeatedly observe how their peers unlock their smartphones. These "insiders" may combine multiple partial observations to form a hypothesis of a target's secret. This changing landscape requires that we update the methods used to assess the security of unlocking mechanisms against human shoulder surfing attacks. In our paper, we introduce a methodology to study shoulder surfing risks in the insider threat model. Our methodology dissects the authentication process into minimal observations by humans. Further processing is based on simulations. The outcome is an estimate of the number of observations needed to break a mechanism. The flexibility of this approach benefits the design of new mechanisms. We demonstrate the application of our methodology by performing an analysis of the SwiPIN scheme published at CHI 2015. Our results indicate that SwiPIN can be defeated reliably by a majority of the population with as few as 6 to 11 observations.

URLhttps://dl.acm.org/doi/10.1145/2935334.2935388
DOI10.1145/2935334.2935388
Citation Keywiese_see_2016