CISPA
Browse

A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations

Download (1.02 MB)
conference contribution
posted on 2025-06-06, 07:27 authored by Jan-Ulrich HoltgraveJan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha FahlSascha Fahl
Public administrations provide critical services and manage sensitive data for a country’s citizens. Recent phishing campaigns targeting public sector employees highlight their attractiveness as targets. Deploying state-of-the-art authentication technologies, such as FIDO2, can improve overall security. We conducted a mixedmethods study in Germany to understand better the practices and challenges of deploying passwordless authentication in the public sector. First, we conducted an online survey (N=108) among German public sector employees to gain insights into their experiences and challenges. Next, we partnered with an e-government vendor and performed an in-situ experiment. We let 11 employees from the public sector experience FIDO2 under real-world conditions. Our results show that only a minority of our participants were aware of current passwordless authentication procedures. In our experiment, FIDO2-based methods left an overall positive impression. Hierarchical and heterogeneous public sector structures and the need for more technical expertise and equipment were barriers to adoption.

History

Related Materials

  1. 1.
    ISBN - Is identical to urn:isbn:979-8-4007-1394-1
  2. 2.

Editor

Yamashita N ; Evers V ; Yatani K ; Ding SX ; Lee B ; Chetty M ; Dugas POT

Primary Research Area

  • Empirical and Behavioral Security

Name of Conference

International Conference on Human Factors in Computing Systems (CHI)

CISPA Affiliation

  • Yes

Journal

CHI

Page Range

1-16

Publisher

Association for Computing Machinery (ACM)

Open Access Type

  • Not Open Access

BibTeX

@conference{Holtgrave:Klivan:Marky:Fahl:2025, title = "A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations", author = "Holtgrave, Jan-Ulrich" AND "Klivan, Sabrina" AND "Marky, Karola" AND "Fahl, Sascha", editor = "Yamashita, Naomi" AND "Evers, Vanessa" AND "Yatani, Koji" AND "Ding, Sharon Xianghua" AND "Lee, Bongshin" AND "Chetty, Marshini" AND "Dugas, Phoebe O Toups", year = 2025, month = 4, journal = "CHI", pages = "1--16", publisher = "Association for Computing Machinery (ACM)", doi = "10.1145/3706598.3713252" }

Usage metrics

    Categories

    No categories selected

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC