• DocumentCode
    61501
  • Title

    The Effectiveness of Security Images in Internet Banking

  • Author

    Lee, Joel ; Bauer, Lujo ; Mazurek, Michelle L.

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA, USA
  • Volume
    19
  • Issue
    1
  • fYear
    2015
  • fDate
    Jan.-Feb. 2015
  • Firstpage
    54
  • Lastpage
    62
  • Abstract
    Internet banking websites often use security images as part of the login process, under the theory that they can help foil phishing attacks. Previous studies, however, have yielded inconsistent results about users´ ability to notice that a security image is missing. This article describes an online study of 482 users that attempts to clarify the extent to which users notice and react to the absence of security images. Most participants (73 percent) entered their password when the security image and caption were removed. The authors found that changing the appearance and other characteristics of the security image generally had little effect on whether users logged in when the security image was absent. Additionally, they subjected the passwords created by participants to a password-cracking algorithm and found that participants with stronger passwords were less likely (64.7 percent versus 80.1 percent) to enter their passwords when the security image was missing.
  • Keywords
    Internet; Web sites; bank data processing; computer crime; message authentication; unsolicited e-mail; Internet banking websites; login process; password-cracking algorithm; phishing attacks; security images; Banking; Computer security; Electronic mail; Internet; Maintenance engineering; Online banking; Visualization; Web sites; Internet banking; human factors; security; security images; usability;
  • fLanguage
    English
  • Journal_Title
    Internet Computing, IEEE
  • Publisher
    ieee
  • ISSN
    1089-7801
  • Type

    jour

  • DOI
    10.1109/MIC.2014.108
  • Filename
    6894474