SoK: Web Authentication in the Age of End-to-End Encryption
Jenny Blessing, Daniel Hugenroth, Ross J. Anderson, Alastair R., Beresford

TL;DR
This paper systematically reviews the challenges and solutions for web authentication in the context of end-to-end encryption, focusing on security, privacy, usability, and recoverability issues across industry and academic practices.
Contribution
It provides a comprehensive survey of existing E2EE authentication methods, analyzes their limitations, and identifies research gaps for future work.
Findings
E2EE authentication faces unique recoverability challenges.
Passwordless authentication is increasingly adopted but device-bound.
Significant gaps exist between industry practices and academic research.
Abstract
The advent of end-to-end encrypted (E2EE) messaging and backup services has brought new challenges for usable authentication. Compared to regular web services, the nature of E2EE implies that the provider cannot recover data for users who have forgotten passwords or lost devices. Therefore, new forms of robustness and recoverability are required, leading to a plethora of solutions ranging from randomly-generated recovery codes to threshold-based social verification. These implications also spread to new forms of authentication and legacy web services: passwordless authentication ("passkeys") has become a promising candidate to replace passwords altogether, but are inherently device-bound. However, users expect that they can login from multiple devices and recover their passwords in case of device loss--prompting providers to sync credentials to cloud storage using E2EE, resulting in the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · IPv6, Mobility, Handover, Networks, Security · Network Security and Intrusion Detection
