October 10, 2026
What I Learned About Tangible Two-Factor Authentication
Introduction
By Mahmudul
4 min read
Introduction
Nowadays, people use online services for many purposes, such as communication, banking, education, and social networking. However, as people become more dependent on these services, protecting personal information and online accounts has become a major concern. Passwords are the most common way to protect online accounts, but they are not always enough to keep them secure. Two-factor authentication (2FA) is one way to provide extra security. However, some people find existing 2FA methods inconvenient because they require additional steps, devices, or time.
The paper "Tangible 2FA โ An In-the-Wild Investigation of User-Defined Tangibles for Two-Factor Authentication" by Turner et al. discusses another approach to 2FA using physical objects. Before reading this paper, I mainly thought of 2FA as receiving a verification code on my phone or approving a login request through an application. However, after reading this research, I learned that physical objects can also be used for authentication. It also made me realize that security is not only about protecting accounts but also about making the process easy for people to use in their daily lives.
1. The Most Interesting Thing
The most interesting thing I learned from this paper is that making a security system stronger is not the only thing researchers need to consider. They should also think about how people will use it in their everyday lives. A security system may provide good protection, but if it is difficult or inconvenient to use, people may not want to use it regularly.
The researchers studied whether physical objects, called tangibles, could make two-factor authentication more convenient and personal. Users could choose objects with different shapes, sizes, and designs based on their preferences. The main purpose was to understand what kinds of physical objects people preferred and how useful these objects were in real-life situations.
The researchers conducted two studies. In the first study, 226 participants designed their preferred tangible authentication objects. In the second study, 15 participants used prototype objects in their daily lives for one week. The results showed that participants generally liked the idea of using physical objects for authentication. However, they also experienced some problems, especially when carrying and using the objects in different situations.
1.1 User Preferences for Physical Authentication Objects
One thing I found interesting was that people had different preferences about their authentication objects. The researchers identified three main types: standalone objects, objects that could fit into a wallet or pocket, and objects that could be attached to everyday items or worn as accessories.
Many participants preferred simple shapes, such as cubes and squares, instead of complicated designs. Some also preferred objects shaped like credit cards, coins, or key rings, while others liked wearable objects. This showed me that people may feel more comfortable using a security device when its design matches their personal preferences and daily habits.
I think this is an important point because people do not always consider convenience when choosing a security method. For example, an authentication device may work perfectly, but users may not want to carry an extra object everywhere they go. If the device could be connected to something they already carry, such as a key ring or phone case, it might become easier to use.
2. What I Learned from This Paper
Before reading this paper, I used to think authentication is a technical process used to verify someone's identity. However, this research helped me understand that human behavior is also an important part of security. A system should not only protect users' accounts but also be convenient enough for them to use it regularly.
Another lesson I learned is that personalization can make technology more suitable for different people. If users can choose the shape, size, and design of their authentication objects, they may find them more comfortable to use. However, personalization alone is not enough. The objects should also be easy to carry and use, and they should not be too easy to lose or forget.
I also realized that security and usability are closely connected. If a security method creates too many difficulties, people may become less interested to use it. Therefore, developers should consider users' expectations when designing a security systems. They should not only test whether a system works technically but also understand how will people use it in their everyday lives.
3. My Thoughts and Future Research
After reading this paper, I started thinking about how tangible authentication could be made more convenient for people who regularly use smartphones. For example, an authentication mechanism could be integrated into a phone case, key ring, or wearable accessory. This might reduce the need to carry a separate device. However, researchers would need to test these designs to find out whether they are both secure and convenient.
One question that came to my mind was: Would people be more willing to use tangible 2FA if the authentication device were included in something they already use every day?
I think this would be an interesting topic for future research. People have different lifestyles, so their needs may also be different. For example, a student who carries a backpack every day might prefer one type of device, while someone who frequently travels might prefer something smaller.
Future studies could involve more participants and allow them to use these devices for a longer time. Researchers could also compare tangible authentication with authentication apps and security keys. This could help them understand which methods people find more convenient and whether they continue using them after the first few weeks.
Conclusion
Overall, this paper helped me understand how security, usability, and human behavior are connected together. I learned that physical objects could be an alternative way to perform two-factor authentication and I understood that allowing users to customize these objects may improve their experience. However, there are still some challenges, such as carrying the objects, remembering to bring them, and using them in different environments.
The main thing I learned from this paper is that a good security system should not only protect users but also fit into their everyday lives. In my opinion, future research should focus on finding a balance between security, convenience, and users' personal preferences. This paper also made me think more carefully about how the design of a technology can influence people's willingness to use it in real-life situations.
Reference
Turner, M., Schmitz, M., Bierey, M. M., Khamis, M., & Marky, K. (2023). Tangible 2FA โ An In-the-Wild Investigation of User-Defined Tangibles for Two-Factor Authentication. Proceedings of the Nineteenth Symposium on Usable Privacy and Security (SOUPS 2023).