Broken Access: On the Challenges of Screen Reader Assisted Two-Factor and Passwordless Authentication
Md Mojibur Rahman Redoy Akanda (1), Ahmed Tanvir Mahdad (1), and Nitesh Saxena (1) ((1) Texas A&M University)

TL;DR
This paper investigates the security and accessibility challenges of screen reader-assisted authentication methods for blind and visually impaired users, revealing significant weaknesses and proposing an evaluation framework to identify issues early.
Contribution
It introduces the AWARE framework for systematic assessment of screen reader-assisted authentication, highlighting vulnerabilities and guiding designers to improve accessibility and security.
Findings
All observed scenarios show weaknesses in authentication methods.
Accessibility issues caused by imprecise screen reader instructions lead to vulnerabilities.
The AWARE framework helps identify security and accessibility problems early.
Abstract
In today's technology-driven world, web services have opened up new opportunities for blind and visually impaired people to interact independently. Securing interactions with these services is crucial; however, currently deployed authentication mainly concentrate on sighted users, overlooking the needs of the blind and visually impaired community. In this paper, we address this gap by investigating the security and accessibility aspects of these authentication when adopted by blind and visually impaired users. We model web authentication for such users as screen reader assisted authentication and introduce an evaluation framework called AWARE. Using AWARE, we then systematically assessed popular PC and smartphone-based screen readers against different authentication methods, including variants of 2FA and passwordless schemes, to simulate real-world scenarios. We analyzed these screen…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Tactile and Sensory Interactions · Digital Accessibility for Disabilities
