SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic Proposals

Md Mojibur Rahman Redoy Akanda (Texas A&M University)

34th USENIX Security Symposium (USENIX Security '25) · Day 1 · Usable Privacy and Security 1

Overview

This talk, presented by Md Mojibur Rahman Redoy Akanda from Texas A&M University, along with co-author Amanda Lacy and supervisor Nitar Sakenna, delves into a critical yet often overlooked area of cybersecurity: the authentication challenges faced by blind and visually impaired (BVI) users. Titled "SoK: Inaccessible & Insecure," the presentation outlines a comprehensive Systemization of Knowledge (SoK) paper that systematically evaluates the accessibility and security of 50 state-of-the-art academic authentication proposals. The core objective was to determine if these mechanisms, both general-purpose and those specifically designed for BVI individuals, adequately serve this diverse user group.

Watch on YouTube · Read the paper · Download the PDF (PDF) · Slides

Paper abstract

Smart contracts are immutable programs hosted on the blockchain that power decentralized applications. With the growth of decentralized finance (DeFi), many services interact with contracts that must be trusted to manage digital assets. To this end, several Ethereum standards (e.g., ERC20, ERC721) introduced an approval mechanism that allows decentralized applications to trade digital assets (or "tokens") on behalf of others. After receiving an approval, the (approved) application can invoke the token's transferFrom function to trade the approved tokens. Unfortunately, approved applications often contain vulnerabilities. If an attacker maliciously controls the parameters of a transferFrom call, they can steal not only the application's assets but also the assets of any user who previously approved the application. We refer to this widespread issue as Approved Controllable TransferFrom (ACT), which has already led to losses exceeding 65 million USD. We present Osprey, an end-to-end system that detects ACT vulnerabilities and automatically generates proof-of-concept attacks. Our evaluation across the entire Ethereum ecosystem identified 32,582 potentially vulnerable contracts, with 410 confirmed exploitable at the time of writing. Our findings reveal previously unknown attack vectors threatening digital assets worth over 3.4 million USD.

Visual summary for SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic Proposals by Md Mojibur Rahman Redoy Akanda
Visual summary for SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic Proposals by Md Mojibur Rahman Redoy Akanda

Key moments

  1. 0:00 Introduction and problem: authentication challenges for BVI users.
  2. 2:15 Scale of the problem: 2.2 billion people with vision problems.
  3. 3:50 Our contribution: evaluating 50 mechanisms with Alissa framework.
  4. 4:40 Detailed process for selecting authentication methods for analysis.
  5. 6:20 Introducing Alissa framework: 5 accessibility, 8 security metrics.
  6. 7:50 How metrics were applied using a detailed codebook.
  7. 9:00 First major finding: most general authentication methods inaccessible.

SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic Proposals

Speakers: Md Mojibur Rahman Redoy Akanda

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=Pvp9qdITQcQ

Overview

This talk, presented by Md Mojibur Rahman Redoy Akanda from Texas A&M University, along with co-author Amanda Lacy and supervisor Nitar Sakenna, delves into a critical yet often overlooked area of cybersecurity: the authentication challenges faced by blind and visually impaired (BVI) users. Titled "SoK: Inaccessible & Insecure," the presentation outlines a comprehensive Systemization of Knowledge (SoK) paper that systematically evaluates the accessibility and security of 50 state-of-the-art academic authentication proposals. The core objective was to determine if these mechanisms, both general-purpose and those specifically designed for BVI individuals, adequately serve this diverse user group.

The research highlights a disturbing truth: a significant portion of proposed authentication solutions, including those ostensibly developed for BVI users, fail to meet fundamental standards of accessibility and security when assessed from the perspective of screen reader-assisted individuals. This oversight has profound implications, as 2.2 billion people worldwide live with some form of vision impairment, with 1.2 billion experiencing incurable conditions. Many of these individuals rely on online accounts for employment and daily life, making them potential targets. If an attacker compromises a BVI user within an organization, it could lead to severe internal data breaches, underscoring the critical importance of secure and accessible authentication for this population.

The talk introduces the ELISA framework, a novel evaluation tool comprising five accessibility and eight security metrics, specifically tailored to assess authentication schemes for BVI users. Through a rigorous application of this framework, the researchers expose a pervasive imbalance: authentication methods tend to be either accessible but insecure, or secure but inaccessible. This comprehensive analysis serves as a stark call to action for the cybersecurity research community, urging a paradigm shift towards truly inclusive and robust authentication design that prioritizes both security and accessibility for all users.

Background

▶ Watch: Introduction and problem: authentication challenges for BVI users. (0:00)

Authentication mechanisms are the bedrock of online security, verifying user identity before granting access to digital accounts. Traditionally, these mechanisms have evolved from single-factor authentication (SFA), which typically relies on a username and password, to more robust approaches like two-factor authentication (2FA) and multi-factor authentication (MFA), requiring two or more distinct factors for verification. However, the continuous innovation of cybercriminals necessitates an equally dynamic response from security researchers, leading to the development of sophisticated defenses such as login terminal interaction, user-assisted authentication, automatic authentication, and behavioral authentication.

A critical question arises: do these advanced authentication methods, designed to combat emerging attacks, adequately consider the needs of diverse user populations, particularly screen reader-assisted users who are blind or visually impaired? The speaker emphasizes that this demographic is far from negligible, encompassing 2.2 billion people globally with vision-related problems, 1.2 billion of whom face incurable conditions. These individuals are active online, often holding jobs in various organizations, and rely heavily on screen readers and other assistive technologies to navigate digital interfaces. The security implications are significant; a compromised BVI user within an organization represents an insider threat that could facilitate devastating data breaches.

Recognizing this gap, some researchers have indeed developed authentication mechanisms specifically dedicated to BVI users. These include methods based on typing on a terminal, gesture-based authentication, vibration-based authentication, behavioral authentication, and special hardware-based authentication. While these efforts are commendable in their intent, the fundamental question remains: are these dedicated mechanisms truly accessible and secure against the ever-evolving landscape of cyber threats, or do they inadvertently introduce new vulnerabilities or accessibility barriers? The research presented in this talk systematically addresses this crucial question, providing a comprehensive evaluation of the current state of academic proposals.

Key Findings

▶ Watch: Our contribution: evaluating 50 mechanisms with Alissa framework. (3:50)

The central contribution of this research is the systematic evaluation of 50 academic authentication mechanisms – 37 general-purpose and 13 specifically designed for BVI users – using the newly developed ELISA framework. This framework, consisting of five accessibility and eight security metrics, provided a structured approach to assess adherence, non-adherence, or partial adherence of each mechanism. The findings reveal significant shortcomings across the board.

For general-purpose authentication methods, the accessibility evaluation yielded concerning results: the vast majority were found to be inaccessible from the perspective of BVI users. While automatic authentication schemes were noted for their ease of use, requiring minimal user interaction, they demonstrated vulnerabilities against attacks such as shoulder surfing, device theft, and concurrency attacks. In terms of security, general methods performed only "average," meaning that despite their inaccessibility, they still failed to provide adequate security for BVI users in most evaluated cases.

The scenario for dedicated authentication schemes for BVI users was, surprisingly, even more dire. Although they offered marginally better accessibility compared to general methods, the improvement was minimal. Critically, many proposals failed to even mention screen reader compatibility, a fundamental requirement for BVI users. User studies within these dedicated schemes further highlighted the problem: only 4 out of 10 mechanisms received positive accessibility feedback, with the remaining 6 being reported as inaccessible by users. From a security standpoint, dedicated schemes were found to be "really insecure," offering very few security features. Even when claims of security against specific attacks like shoulder surfing were made, the researchers found these schemes to be vulnerable.

The broader takeaways from this extensive evaluation paint a clear picture:

  • Despite a focus on a broader user base, general authentication schemes consistently overlook diverse users, particularly BVI individuals.
  • Automatic authentication schemes, while convenient, introduce significant vulnerabilities to shoulder surfing, device theft, and concurrency.
  • Schemes explicitly designed for BVI users frequently fail to meet their intended criteria in both accessibility and security.
  • There exists a pervasive imbalance between accessibility and security: schemes that are accessible tend to be less secure, and vice-versa.
  • Many of the identified vulnerabilities are directly linked to how screen reader interaction is (or isn't) considered and implemented within authentication workflows.

These findings underscore a critical gap in current academic research, demonstrating that the needs of BVI users are often an afterthought, leading to authentication solutions that are either unusable or easily compromised for this population.

Technical Deep Dive

▶ Watch: Detailed process for selecting authentication methods for analysis. (4:40)

The rigorous methodology employed in this Systemization of Knowledge (SoK) paper is crucial to its robust findings. The process began with a systematic selection of authentication methods, aiming for a representative sample of academic proposals. For general authentication, keywords like "two-factor authentication," "multi-factor authentication," "authentication methods," and "systems" were used. To identify dedicated schemes, the search was refined with terms such as "authentication method for blind and visually impaired users" or "two factor authentication for blind and visually impaired users."

The selection involved a multi-phase screening process. Initially, titles and abstracts were screened to remove papers that were analyses, studies, or reviews rather than proposals for new authentication mechanisms. In the second phase, an in-depth screening of abstracts, methodologies, authentication workflows, and full texts was performed. A critical criterion at this stage was whether the authentication workflow was implemented or illustrated and tested, either technically or with participants. Only mechanisms meeting this requirement progressed. The final selection step involved assessing the reputation of the venue or a citation count of 10 or more, or the overall relevance of the authentication method. This rigorous filtering resulted in the final set of 50 authentication mechanisms. These were then categorized based on user interaction, including typing on terminal, automatic, gesture-based, and vibration-based authentication.

The core of the evaluation was the ELISA framework, a set of five accessibility and eight security metrics. This framework was adapted from prior work by Bonu et al. and significantly expanded to specifically address the unique needs and challenges of BVI users. For each metric, the researchers articulated its importance from a BVI perspective and its impact based on existing literature. For instance, the presence of an accessible interface was identified as paramount because, without it, screen readers cannot convey crucial screen information to the user, rendering authentication impossible. Similarly, for security metrics, the evaluation considered not just general authentication attacks but how these attacks specifically impact BVI users. An example mentioned was how a generic attack like shoulder surfing could be particularly problematic for BVI users interacting with certain authentication interfaces.

To apply these metrics consistently across all 50 mechanisms, a detailed codebook was developed. Each entry in the codebook included:

  • Code (Metric Name): The specific accessibility or security metric being evaluated.
  • Definition: A concise explanation of the metric.
  • What to Look For: Specific indicators or keywords to search for within the academic papers. For example, to assess screen reader compatibility, the codebook would instruct evaluators to look for explicit mentions of "screen reader" or related compatibility features.
  • Example Indicator: Concrete examples to guide evaluators on what constitutes adherence or non-adherence.

Evaluators used this codebook to systematically review each authentication proposal. For every input authentication mechanism, they searched for the criteria outlined in the codebook, ultimately determining the adherence, non-adherence, or partial adherence of each metric. This structured, systematic approach ensured a consistent and objective evaluation, providing the robust data that formed the basis of the key findings regarding the widespread inaccessibility and insecurity of current academic authentication proposals for blind and visually impaired users.

Demo / Proof of Concept

▶ Watch: How metrics were applied using a detailed codebook. (7:50)

As this work is a Systemization of Knowledge (SoK) paper, its primary contribution lies in the comprehensive analysis and evaluation of existing academic proposals, rather than the development or demonstration of a new authentication mechanism. Therefore, the presentation did not include a live demo or a proof of concept developed by the speakers themselves.

However, the research inherently relies on the understanding of how various authentication workflows are intended to function and how they were demonstrated or illustrated in the original papers under review. The selection criteria for the 50 authentication mechanisms explicitly required that their workflows be "implemented or illustrated and tested either technically or with participants." This means that while the authors of the SoK did not present new demonstrations, their analysis was based on the demonstrable aspects and user experiences reported in the literature they evaluated. The findings regarding inaccessibility and insecurity directly stem from how these existing mechanisms performed when assessed against the stringent criteria of the ELISA framework, including their interaction with screen readers and their resilience against specific attack vectors.

Defensive Implications

▶ Watch: First major finding: most general authentication methods inaccessible. (9:00)

The findings of this SoK paper present critical implications for various stakeholders, particularly for researchers, developers, and organizations employing BVI users. The pervasive issues of inaccessibility and insecurity demand a fundamental shift in how authentication mechanisms are designed and implemented.

For Researchers and Developers of Authentication Schemes:

  • Inclusive Design from Inception: It is imperative to integrate inclusive design principles from the very beginning of the development lifecycle. This means explicitly considering BVI users and their reliance on screen readers and other assistive technologies, rather than treating accessibility as an afterthought. Designing for screen reader compatibility must be a core requirement, not an optional feature.
  • Balance Accessibility and Security: The identified imbalance between accessibility and security highlights the need for solutions that robustly address both. Researchers must strive to develop authentication mechanisms that are simultaneously easy for BVI users to operate and resilient against a wide array of cyber threats. Sacrificing one for the other creates an unacceptable vulnerability.
  • Integrate AI/OS-Level Support: The paper proposes the integration of AI or operating system (OS) level support to mitigate accessibility-driven security risks. This includes functionalities such as detecting and flagging phishing links, identifying malicious links, and recognizing concurrent authentication prompts that could indicate an attack. Such built-in safeguards can significantly enhance the security posture for BVI users, especially given the challenges of visual verification.
  • Real-World Validation: Future work must prioritize real-world validation of proposed authentication schemes with diverse BVI user groups. Academic proposals often lack this crucial step, leading to mechanisms that perform poorly in practical scenarios.
  • Expand Framework for Other Impairments: While this research focused on BVI users, the authors suggest expanding the ELISA framework to include other diverse users, such as those with ADHD, dyslexia, motor impairments, or older adults. This holistic approach can foster truly universal authentication solutions.

For Organizations Employing BVI Users:

  • Awareness of Heightened Risk: Organizations must be acutely aware that their BVI employees, due to the inherent limitations of current authentication technologies, may be at a heightened risk of compromise. This understanding should inform security policies and technology procurement.
  • Prioritize Proven Accessible and Secure Solutions: When selecting authentication solutions, organizations should actively seek out and prioritize those that have been rigorously tested and proven to be both accessible for BVI users and secure against modern threats. Relying solely on general-purpose solutions without specific BVI accessibility audits is insufficient.
  • Enhanced Training and Support: Provide specialized training for BVI employees on the unique challenges they might face with authentication and how to identify potential threats that may exploit their assistive technologies (e.g., screen reader manipulation in phishing attacks). Offer robust technical support for troubleshooting authentication issues related to assistive technology.
  • Advocate for Inclusive Standards: Organizations should advocate for the development and adoption of inclusive authentication standards within the industry, pushing vendors and developers to build solutions that inherently cater to diverse user needs.

Ultimately, the defensive implications call for a collaborative effort between academia, industry, and policymakers to bridge the current gap, ensuring that authentication, a fundamental aspect of digital security, is truly equitable and robust for all users, regardless of their abilities.

Key Takeaways

  • Current academic authentication schemes, both general-purpose and those specifically designed for blind and visually impaired (BVI) users, largely fail to meet fundamental standards of accessibility and security for screen reader-assisted individuals.
  • The ELISA framework, comprising five accessibility and eight security metrics tailored for BVI users, provides a systematic and robust method for evaluating authentication proposals, revealing critical gaps in existing solutions.
  • A pervasive imbalance exists: authentication schemes are often either accessible but insecure, or secure but inaccessible, highlighting a critical design flaw in current research.
  • General authentication schemes frequently overlook diverse user needs, while dedicated BVI schemes, despite their intent, often lack crucial features like explicit screen reader compatibility and demonstrate significant security vulnerabilities, even against attacks they claim to mitigate (e.g., shoulder surfing).
  • Many identified vulnerabilities stem directly from how screen reader interaction is handled or neglected within authentication workflows, making BVI users susceptible to attacks like phishing and concurrent authentication prompts.
  • Future research and development must prioritize inclusive authentication mechanisms from the outset, incorporating AI/OS-level support for threat detection, real-world validation with BVI users, and a concerted effort to balance both accessibility and security for all diverse user groups.

About the Speaker(s)

The research presented in this talk was led by Md Mojibur Rahman Redoy Akanda, who delivered the presentation. He is affiliated with Texas A&M University. His work was conducted in collaboration with co-author Amanda Lacy and under the supervision of Nitar Sakenna, both also associated with Texas A&M University. Their collective effort at Texas A&M University culminated in this Systemization of Knowledge paper, shedding light on critical accessibility and security challenges in authentication for blind and visually impaired users.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate SoK work that fills a real gap — nobody has systematically audited academic authentication proposals against BVI accessibility criteria at this scale, and the finding that even dedicated BVI schemes fail their own stated goals is genuinely useful. The ELISA framework gives the community a reproducible lens, but the talk itself is methodological scaffolding more than a security revelation, and the recommendations land in familiar 'design for inclusion from the start' territory.

Heather Calloway (CISO) — WEAK

Rigorous, methodologically sound research that exposes a real and underappreciated gap in authentication design — but it stops well short of producing anything an operator or security leader can act on. The work diagnoses the academic failure; it does not tell organizations, CISOs, or policymakers what to do with that diagnosis.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)