DocumentCode
61501
Title
The Effectiveness of Security Images in Internet Banking
Author
Lee, Joel ; Bauer, Lujo ; Mazurek, Michelle L.
Author_Institution
Carnegie Mellon Univ., Pittsburgh, PA, USA
Volume
19
Issue
1
fYear
2015
fDate
Jan.-Feb. 2015
Firstpage
54
Lastpage
62
Abstract
Internet banking websites often use security images as part of the login process, under the theory that they can help foil phishing attacks. Previous studies, however, have yielded inconsistent results about users´ ability to notice that a security image is missing. This article describes an online study of 482 users that attempts to clarify the extent to which users notice and react to the absence of security images. Most participants (73 percent) entered their password when the security image and caption were removed. The authors found that changing the appearance and other characteristics of the security image generally had little effect on whether users logged in when the security image was absent. Additionally, they subjected the passwords created by participants to a password-cracking algorithm and found that participants with stronger passwords were less likely (64.7 percent versus 80.1 percent) to enter their passwords when the security image was missing.
Keywords
Internet; Web sites; bank data processing; computer crime; message authentication; unsolicited e-mail; Internet banking websites; login process; password-cracking algorithm; phishing attacks; security images; Banking; Computer security; Electronic mail; Internet; Maintenance engineering; Online banking; Visualization; Web sites; Internet banking; human factors; security; security images; usability;
fLanguage
English
Journal_Title
Internet Computing, IEEE
Publisher
ieee
ISSN
1089-7801
Type
jour
DOI
10.1109/MIC.2014.108
Filename
6894474
Link To Document