vulns.co
/
GKData.io MCP

Internet Society / NDSS Symposium · 2 min read

Cross-device authentication: bind informed consent to session authority

An evaluation of 27 services and a 100-participant user study examines missing context, explicit consent and post-login control in cross-device authentication. Conceptual boundary: an already trusted device may approve access on another device, but possession of that trusted session alone does not establish the user’s informed intent for the new session.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

For an owned design, connect the approving interface to meaningful target-device and request context, a deliberate consent decision, and accessible session review and revocation. Verify that a revocation decision reaches the actual authorization checks. UI confirmation alone cannot establish backend enforcement.

Before reading

  • Cross-device login approval and session lifecycle
  • Difference between interface consent and server-side authorization

Context and limits

  • The study documents implementation and user-expectation gaps, including six services without revocation controls. These are historical observations, not a present-day exposure inventory.
  • The paper reports continued chat-history access in one revoked-session case; broad account-compromise risk is a consequence discussed by the authors, not a measured compromise rate across all 27 services.
  • The main user study used videos and screenshots and primarily U.S. participants; a separate ten-person interactive study is supportive but small. Self-report and sampling limitations remain.
  • Developer acknowledgments and roadmap commitments do not establish completed remediation. Context-specific interface patterns and broader validation remain future work.
  • Published in NDSS 2026 proceedings; the paper acknowledges anonymous reviewers. This is not a protocol-wide proof or a claim that all cross-device authentication is insecure.

Sources and provenance

  1. Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication Internet Society / NDSS Symposium · reviewed 2026-10-03
  2. Publisher-hosted proceedings paper Internet Society / NDSS Symposium · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software