Hardware security keys undoubtedly have advantage for users as "usability" pain is trivial compared to the maximum "security" gain in authentication. Naturally, the hardware factor in the authentication received a widespread adoption amongst average users, as it is ergonomically less demanding than phone texts or authentication prompts. This ergonomic advantage in particular is essential for users who are blind or low vision, as their interaction with a phone is impractical. However, the "usability" for low vision or blind users pain might be much higher than an average well-bodied user for the same "security" gain. In an effort to learn more we conducted a usability assessment with ten low vision or blind users setting up the OnlyKey two-factor authentication key. First, the setup process was insurmountable for more than half of the participants, resulting in a situation where the hardware key was abandoned. Secondly, the lack of tactile orientation led participants to consider it as both impractical, and prone to difficulties locating or loosing it. We discuss the implications of our findings for future improvements in usable authentication for visually impaired users.
翻译:硬件安全密钥在认证中对用户无疑具有优势,因为与最大化的"安全性"收益相比,其"可用性"负担微不足道。自然,硬件因素在认证中获得了普通用户的广泛采用,因为它在人机工程学上比手机短信或认证提示要求更低。这种人机工程学优势对于盲人或低视力用户尤为重要,因为他们与手机的交互不切实际。然而,对于低视力或盲人用户而言,为获得相同"安全性"收益所承受的"可用性"负担可能远高于普通健全用户。为深入了解这一情况,我们邀请了十名低视力或盲人用户设置OnlyKey双因素认证密钥,并进行了可用性评估。首先,超过半数的参与者无法完成设置过程,导致硬件密钥被弃用。其次,缺乏触觉导向使参与者认为它既不实用,又容易在定位或保管时出现问题。我们讨论了这些发现对未来改进视障用户可用认证的意义。