Knock, Knock. Who's There? On the Security of LG's Knock Codes

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Samuel, Raina, Markert, Philipp, Aviv, Adam J., Neamtiu, Iulian
Format: Preprint
Veröffentlicht: 2020
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911819602329600
author Samuel, Raina
Markert, Philipp
Aviv, Adam J.
Neamtiu, Iulian
author_facet Samuel, Raina
Markert, Philipp
Aviv, Adam J.
Neamtiu, Iulian
contents Knock Codes are a knowledge-based unlock authentication scheme used on LG smartphones where a user enters a code by tapping or "knocking" a sequence on a 2x2 grid. While a lesser used authentication method, as compared to PINs or Android patterns, there is likely a large number of Knock Code users; we estimate, 700,000--2,500,000 in the US alone. In this paper, we studied Knock Codes security asking participants to select codes on mobile devices in three settings: a control treatment, a blocklist treatment, and a treatment with a larger, 2x3 grid. We find that Knock Codes are significantly weaker than other deployed authentication, e.g., PINs or Android patterns. In a simulated attacker setting, 2x3 grids offered no additional security, but blocklisting was more beneficial, making Knock Codes' security similar to Android patterns. Participants expressed positive perceptions of Knock Codes, but usability was challenged. SUS values were "marginal" or "ok" across treatments. Based on these findings, we recommend deploying blacklists for selecting a Knock Code because it improves security but has limited impact on usability perceptions.
format Preprint
id arxiv_https___arxiv_org_abs_2006_03556
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Knock, Knock. Who's There? On the Security of LG's Knock Codes
Samuel, Raina
Markert, Philipp
Aviv, Adam J.
Neamtiu, Iulian
Cryptography and Security
Human-Computer Interaction
Knock Codes are a knowledge-based unlock authentication scheme used on LG smartphones where a user enters a code by tapping or "knocking" a sequence on a 2x2 grid. While a lesser used authentication method, as compared to PINs or Android patterns, there is likely a large number of Knock Code users; we estimate, 700,000--2,500,000 in the US alone. In this paper, we studied Knock Codes security asking participants to select codes on mobile devices in three settings: a control treatment, a blocklist treatment, and a treatment with a larger, 2x3 grid. We find that Knock Codes are significantly weaker than other deployed authentication, e.g., PINs or Android patterns. In a simulated attacker setting, 2x3 grids offered no additional security, but blocklisting was more beneficial, making Knock Codes' security similar to Android patterns. Participants expressed positive perceptions of Knock Codes, but usability was challenged. SUS values were "marginal" or "ok" across treatments. Based on these findings, we recommend deploying blacklists for selecting a Knock Code because it improves security but has limited impact on usability perceptions.
title Knock, Knock. Who's There? On the Security of LG's Knock Codes
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2006.03556