Many key concepts in computer security arise in user authentication, from cryptography, over usability, to Web standardization processes. This seminar aims at master's students in Computer Science or related fields, as it requires an understanding of the full stack of how cybersecurity is built in real systems.
Students will gain a deep understanding of passwordless authentication schemes, enabling them to reason about their usability, deployability, and security properties.
Starting with how passwords are used, why they are not secure, and how to reinforce them, the seminar will shed light on secure, usable alternatives to passwords on the Web. We will review research papers that study usability issues, misconceptions, security guarantees, or report on real-world deployments of passwordless authentication solutions like passkeys, hardware security keys, and legacy solutions like social logins or magic links. Students will read various recent scientific publications on passwordless user authentication solutions and write & review a seminar paper . During a hands-on experience, students are asked to present one passwordless authentication system, reason about its usability benefits, and explain how this authentication system might fail in practice.
The seminar can host up to 12 students. The seminar will be hybrid with Zoom meetings and in-person presentations. Students are expected to write a 4-6 pages seminar paper (~4000 words), review a seminar paper (~500 words), and co-present their topic in front of class in a 20-minutes presentation.
Papers will be shared via Stud.IP.
| Week | Date | Time | Room | Meeting | Your Task |
|---|---|---|---|---|---|
| 15 | April 9, 2026 | 10:15-11:45 | Online via Zoom | Introduction: FIDO & Topic Assignment | Attend |
| 16 | April 16, 2026 | 10:15-11:45 | Online via Zoom | Background: Passwords | Attend |
| 17 | April 23, 2026 | 10:15-11:45 | Online via Zoom | Method: How to Read and Write Scientific Papers | Attend |
| 18 | April 30, 2026 | - | - | No meeting | Read and write |
| 19 | May 7, 2026 | - | - | Method: How to Review and Present + LaTeX 101 | Attend |
| 20 | May 14, 2026 | - | - | No meeting (Public Holiday) | Read and write |
| 21 | May 21, 2026 | - | - | No meeting | Read and write |
| 22 | May 28, 2026 | - | - | No meeting (LUH Excursion Week) | Read and write |
| 23 | June 4, 2026 | - | - | No meeting | Read and write |
| 24 | June 11, 2026 | - | - | No meeting | Read and write |
| 24 | June 12, 2026 | 11:59pm | HotCRP | ~4000 Words Seminar Paper | Submit |
| 25 | June 18, 2026 | - | - | No meeting | Review |
| 26 | June 25, 2026 | - | - | No meeting | Prepare Talk |
| 26 | June 26, 2026 | 11:59pm | HotCRP | ~500 Words Review | Submit |
| 27 | July 2, 2026 | - | - | No meeting | Prepare Talk |
| 28 | July 9, 2026 | - | Room H121 | Presentations #1 | Co-Present & Discuss |
| 29 | July 16, 2026 | - | Room H121 | Presentations #2 | Co-Present & Discuss |
| 29 | July 17, 2026 | 11:59pm | HotCRP | Seminar Paper with Feedback Incorporated | Submit |
Based on the provided and additional literature, the student is expected to provide an overview of the topic in regards to its potential security and usability benefits and problems. The seminar paper should explain how the topic effectively integrates usability or human factors with security or privacy, and clearly indicate the innovative aspects or lessons learned and cite relevant related work.
Papers must use the formatting template and be submitted as a PDF via HotCRP (a conference paper submission system). Submissions must be 4-6 pages (excluding bibliography, and appendices, double column, ~4000 words). All submissions must clearly relate to the human aspects of security or privacy. Your paper should be gender neutral, inclusive, and respectful. A variety of guidance exists on this topic.
| # | Name | Keywords |
|---|---|---|
| 0 | Passwords | Memorability, Management, Coping Strategies, Threats (Phishing, Reuse), Reinforcement (Password Manager, 2FA, RBA, Alerting) |
| 1 | Legacy Systems | Magic Links, Apps, QR Codes, Federated Identity |
| 2 | FIDO & Security Keys | Costs, Training and Initial Setup, Key Management, Blinking Button, Phishing Resistance, Uncertain Benefits, Deployment, Time Required, Fear of Losing, Recovery, Compatibility |
| 3 | FIDO & Adoption | Convince Users, Nudging, Willingness, Concerns, Misconceptions, UX and Deployment Obstacles, Conditional Create, Signal API |
| 4 | FIDO & Phones | caBLE, QR Codes, Availability, Recovery, Setup Difficulties, Account Delegation |
| 5 | FIDO & Passkeys | Synced/Device-Bound Passkeys, Cross-Device Authentication, Discoverable Credentials/Conditional UI, E2EE, Persistent Linking, Related Origin Requests, Conditional Create, Signal API |
| 6 | FIDO & Attacks | Malware, Browser Extension, Attestation, Real-Time Phishing, BitB-Style Attacks, Downgrade Attacks, TLS Channel Binding, Social Engineering, MFA Fatigue |
| 7 | FIDO & eIDs | FIDELIO, elektronischer Personalausweis (nPA), AusweisApp, FeIDo, FIDO-AC |
Some recommended related literature can be found on Stud.IP.
Students are expected to read and review (~500 words) one seminar paper. The reviewing details are provided during the in-person meeting. I like to emphasize the importance of kind and constructive reviews.
Here are 3 easy steps to improve your review:
"Thank you for your work on improving ... I appreciate the effort to ..."
"I suggest clarifying the high-level idea of the approach by adding a paragraph at the beginning of Section 3."
"The paper should more precisely explain how ..."
Reviewers are responsible for all text they submit as part of their review. As such, you should ensure your reviews are accurate and constructive. All seminar papers are considered confidential and should not be publicly discussed or shared.
As a hands-on experience, students are asked to demonstrate their authentication scheme and co-present their topic in front of the class (about 15 minutes incl. demo). The idea of this presentation is to provide an overview of the topic and reason about potential usability issues and benefits of the presented authentication scheme.
Here are two easy steps to improve your talk:
Members of the audience are expected to actively contribute to a discussion by asking questions and engaging with the topic.
| # | Date | Time | Topic | Location |
|---|---|---|---|---|
| 1 | July 9, 2026 | 10:15am-11:45am | FIDO & Adoption | Room H121, Building 1101 (Main Building) |
| 2 | July 9, 2026 | 10:15am-11:45am | FIDO & eID | Room H121, Building 1101 (Main Building) |
| 3 | July 9, 2026 | 10:15am-11:45am | FIDO & Attacks | Room H121, Building 1101 (Main Building) |
| 4 | July 16, 2026 | 10:15am-11:45am | FIDO & Phones | Room H121, Building 1101 (Main Building) |
| 5 | July 16, 2026 | 10:15am-11:45am | FIDO & Passkeys | Room H121, Building 1101 (Main Building) |
The seminar will take place on Thursdays, starting April 9, 2026.
10.00 - 12.00 (c.t.).