How to use this reference
For an owned design, connect the approving interface to meaningful target-device and request context, a deliberate consent decision, and accessible session review and revocation. Verify that a revocation decision reaches the actual authorization checks. UI confirmation alone cannot establish backend enforcement.
Before reading
- Cross-device login approval and session lifecycle
- Difference between interface consent and server-side authorization
Context and limits
- The study documents implementation and user-expectation gaps, including six services without revocation controls. These are historical observations, not a present-day exposure inventory.
- The paper reports continued chat-history access in one revoked-session case; broad account-compromise risk is a consequence discussed by the authors, not a measured compromise rate across all 27 services.
- The main user study used videos and screenshots and primarily U.S. participants; a separate ten-person interactive study is supportive but small. Self-report and sampling limitations remain.
- Developer acknowledgments and roadmap commitments do not establish completed remediation. Context-specific interface patterns and broader validation remain future work.
- Published in NDSS 2026 proceedings; the paper acknowledges anonymous reviewers. This is not a protocol-wide proof or a claim that all cross-device authentication is insecure.
Sources and provenance
- Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication Internet Society / NDSS Symposium · reviewed 2026-10-03
- Publisher-hosted proceedings paper Internet Society / NDSS Symposium · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.