Extended- Force vs Nudge : Comparing Users' Pattern Choices on SysPal and TinPal
Harshal Tupsamudre, Sukanya Vaddepalli, Vijayanand Banahatti, Sachin, Lodha

TL;DR
This study compares two interface modifications, SysPal and TinPal, designed to improve the security of Android's pattern lock by influencing user choices, demonstrating that TinPal produces more complex and guess-resistant patterns without sacrificing memorability.
Contribution
It provides a comparative analysis of SysPal and TinPal interfaces, showing TinPal's effectiveness in generating more secure patterns without usability loss.
Findings
TinPal patterns are longer and more complex.
TinPal enhances guessability resistance.
No significant difference in memorability across interfaces.
Abstract
Android's 3X3 graphical pattern lock scheme is one of the widely used authentication method on smartphone devices. However, users choose 3X3 patterns from a small subspace of all possible 389,112 patterns. The two recently proposed interfaces, SysPal by Cho et al. and TinPal by the authors, demonstrate that it is possible to influence users 3X3 pattern choices by making small modifications in the existing interface. While SysPal forces users to include one, two or three system-assigned random dots in their pattern, TinPal employs a highlighting mechanism to inform users about the set of reachable dots from the current selected dot. Both interfaces improved the security of 3X3 patterns without affecting usability, but no comparison between SysPal and TinPal was presented. To address this gap, we conduct a new user study with 147 participants and collect patterns on three SysPal…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Malware Detection Techniques · Privacy, Security, and Data Protection
