Passwordless Authentication on the Web - Summer Term 2026

#Seminar #Master
Last update: June 18, 2026

FIDO2

  • About

Prerequisites:

Many key concepts in computer security arise in user authentication, from cryptography, over usability, to Web standardization processes. This seminar aims at master's students in Computer Science or related fields, as it requires an understanding of the full stack of how cybersecurity is built in real systems.

Learning Objectives:

Students will gain a deep understanding of passwordless authentication schemes, enabling them to reason about their  usability,  deployability, and  security properties.

Seminar Content:

Starting with how passwords are used, why they are not secure, and how to reinforce them, the seminar will shed light on secure, usable alternatives to passwords on the Web. We will review research papers that study usability issues, misconceptions, security guarantees, or report on real-world deployments of passwordless authentication solutions like passkeys, hardware security keys, and legacy solutions like social logins or magic links. Students will read various recent scientific publications on passwordless user authentication solutions and write & review a seminar paper . During a hands-on experience, students are asked to present one passwordless authentication system, reason about its usability benefits, and explain how this authentication system might fail in practice.

Special Notes:

The seminar can host up to 12 students. The seminar will be hybrid with Zoom meetings and in-person presentations. Students are expected to write a 4-6 pages seminar paper (~4000 words), review a seminar paper (~500 words), and co-present their topic in front of class in a 20-minutes presentation.

Recommended Reading:

Papers will be shared via Stud.IP.


  • Seminar Schedule

Week Date Time Room Meeting Your Task
15 April 9, 2026 10:15-11:45 Online via Zoom Introduction: FIDO & Topic Assignment Attend
16 April 16, 2026 10:15-11:45 Online via Zoom Background: Passwords Attend
17 April 23, 2026 10:15-11:45 Online via Zoom Method: How to Read and Write Scientific Papers Attend
18 April 30, 2026 - - No meeting Read and write
19 May 7, 2026 - - Method: How to Review and Present + LaTeX 101 Attend
20 May 14, 2026 - - No meeting (Public Holiday) Read and write
21 May 21, 2026 - - No meeting Read and write
22 May 28, 2026 - - No meeting (LUH Excursion Week) Read and write
23 June 4, 2026 - - No meeting Read and write
24 June 11, 2026 - - No meeting Read and write
24 June 12, 2026 11:59pm HotCRP ~4000 Words Seminar Paper Submit
25 June 18, 2026 - - No meeting Review
26 June 25, 2026 - - No meeting Prepare Talk
26 June 26, 2026 11:59pm HotCRP ~500 Words Review Submit
27 July 2, 2026 - - No meeting Prepare Talk
28 July 9, 2026 - Room H121 Presentations #1 Co-Present & Discuss
29 July 16, 2026 - Room H121 Presentations #2 Co-Present & Discuss
29 July 17, 2026 11:59pm HotCRP Seminar Paper with Feedback Incorporated Submit

  • Seminar Paper

Task:

Based on the provided and additional literature, the student is expected to provide an overview of the topic in regards to its potential security and usability benefits and problems. The seminar paper should explain how the topic effectively integrates usability or human factors with security or privacy, and clearly indicate the innovative aspects or lessons learned and cite relevant related work.

Formatting:

Papers must use the formatting template and be submitted as a PDF via HotCRP (a conference paper submission system). Submissions must be 4-6 pages (excluding bibliography, and appendices, double column, ~4000 words). All submissions must clearly relate to the human aspects of security or privacy. Your paper should be gender neutral, inclusive, and respectful. A variety of guidance exists on this topic.

Topics:
# Name Keywords
0 Passwords Memorability, Management, Coping Strategies, Threats (Phishing, Reuse), Reinforcement (Password Manager, 2FA, RBA, Alerting)
1 Legacy Systems Magic Links, Apps, QR Codes, Federated Identity
2 FIDO & Security Keys Costs, Training and Initial Setup, Key Management, Blinking Button, Phishing Resistance, Uncertain Benefits, Deployment, Time Required, Fear of Losing, Recovery, Compatibility
3 FIDO & Adoption Convince Users, Nudging, Willingness, Concerns, Misconceptions, UX and Deployment Obstacles, Conditional Create, Signal API
4 FIDO & Phones caBLE, QR Codes, Availability, Recovery, Setup Difficulties, Account Delegation
5 FIDO & Passkeys Synced/Device-Bound Passkeys, Cross-Device Authentication, Discoverable Credentials/Conditional UI, E2EE, Persistent Linking, Related Origin Requests, Conditional Create, Signal API
6 FIDO & Attacks Malware, Browser Extension, Attestation, Real-Time Phishing, BitB-Style Attacks, Downgrade Attacks, TLS Channel Binding, Social Engineering, MFA Fatigue
7 FIDO & eIDs FIDELIO, elektronischer Personalausweis (nPA), AusweisApp, FeIDo, FIDO-AC

Some recommended related literature can be found on Stud.IP.

Additional Resources:

  • Review

Students are expected to read and review (~500 words) one seminar paper. The reviewing details are provided during the in-person meeting. I like to emphasize the importance of kind and constructive reviews.

Here are 3 easy steps to improve your review:

  1. Start with thanking the authors and mentioning something positive.
    "Thank you for your work on improving ... I appreciate the effort to ..."
  2. Be kind and constructive and describe a path forward.
    "I suggest clarifying the high-level idea of the approach by adding a paragraph at the beginning of Section 3."
  3. Do not refer to the authors directly in your review, but direct comments toward the seminar paper. We are reviewing the paper, not the authors.
    "The paper should more precisely explain how ..."

Reviewers are responsible for all text they submit as part of their review. As such, you should ensure your reviews are accurate and constructive. All seminar papers are considered confidential and should not be publicly discussed or shared.


  • Talk (Co-Presented)

Presenters:

As a hands-on experience, students are asked to demonstrate their authentication scheme and co-present their topic in front of the class (about 15 minutes incl. demo). The idea of this presentation is to provide an overview of the topic and reason about potential usability issues and benefits of the presented authentication scheme.

Here are two easy steps to improve your talk:

  1. Outline your talk without PowerPoint. What is a good motivation? What is the most important result? What is the main takeaway at the end?
  2. Practice! Please rehearse your talk multiple times. There is nothing more distressing than a presenter who is surprised by their own slides.
Audience:

Members of the audience are expected to actively contribute to a discussion by asking questions and engaging with the topic.

Talk Schedule:
# Date Time Topic Location
1 July 9, 2026 10:15am-11:45am FIDO & Adoption Room H121, Building 1101 (Main Building)
2 July 9, 2026 10:15am-11:45am FIDO & eID Room H121, Building 1101 (Main Building)
3 July 9, 2026 10:15am-11:45am FIDO & Attacks Room H121, Building 1101 (Main Building)
4 July 16, 2026 10:15am-11:45am FIDO & Phones Room H121, Building 1101 (Main Building)
5 July 16, 2026 10:15am-11:45am FIDO & Passkeys Room H121, Building 1101 (Main Building)

  • Time and Location

Date:

The seminar will take place on Thursdays, starting April 9, 2026.

Time:

10.00 - 12.00 (c.t.).

Location: