Click This, Not That: Extending Web Authentication with Deception


Paper Artifacts

The paper artifacts will be available on this github repository on the artifacts branch.


Example Videos

Video 1. Ritual creation.
This video demonstrates how a user creates a ritual using our browser extension interface. They start the ritual recording, then click on Family, Social, Contacts, Mail. They finish by clicking save in the overlay box.
Video 2. Tripwire creation.
This video demonstrates how a user creates a tripwire using our browser extension interface. In this example they create a new tripwire folder called work by selecting the neighboring folder, duplicating the element, and modifying the content and path. They preview and save this tripwire which then persists after refreshing. While the UI is enabled it highlights existing tripwires in blue and they can be removed by clicking on them.
Video 3. Rituals in action.
This video shows how rituals work in action. With the ritual created in Video 2, the user is expected to click on Family, Social, Contacts, Mail. After the first login, the ritual is not completed and the user is logged out. After logging back in and completing the ritual, they can continue as normal.
Video 4. Tripwires in action.
This video shows how tripwires work in action. A policy for this user causes them to be logged out after touching two tripwires. After logging in again and touching a third, another policy is triggered which blocks this device.
Video 5. User study.
This video demonstrates a participant going through the first two parts of the study, testing tripwires and creating a login ritual.