User Tools

Site Tools


security:authentication

This is an old revision of the document!


Authentication as Deployed: Login, SSO, MFA and Passkeys

You are about to measure what a website offers at its login boundary — whether it has a login at all, which identity providers it accepts, whether a second factor is available, whether it supports passkeys, what its password policy is, and what session state a login leaves in the browser. This page is the field's methods and denominators for that question. It is not a tutorial on OAuth, and it is not about breaking these mechanisms — attack papers are here only where they report per-site incidence across a sampled population, because “n of N relying parties were vulnerable” is a deployment figure: read the OAuth 2.0 Security BCP or the WebAuthn specification for how the protocols work.

The population behind every corpus figure below is 45 papers from the publication corpus (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P, 2010–2026, 5,859 extracted papers) whose object is authentication as deployed by services the authors do not control. 42 of the 45 carry the web platform label — 2.6% of the 1,622 web-platform papers; the other three measure an operator's own login logs, which is not a web-platform study. 25 of the 45 ran a crawl (2.2% of the 1,120 papers that did); the rest are hand audits and telemetry analyses. They were hand-picked out of 184 candidates: three quarters of anything a login-shaped keyword matches is something else. The audit, the inclusion rule and the per-paper verdicts are on authentication.

Two neighbours own the adjacent question, and this page does not repeat them.

  • Registration — logging in or registering as an instrument, so you can crawl what is behind the login. That page owns Shepherd [1Jonker, Hugo; Karsch, Stefan; Krumnow, Benjamin; Sleegers, Marc (2020): "Shepherd: a Generic Approach to Automating Website Login", in: Proceedings of the Workshop on Measurements, Attacks, and Defenses for the Web. (DOI)], CAPTCHA and SMS plumbing, and the registration success rates. If your login is a means, start there; this page is for when the login itself is the measurement.
  • Email authentication — SPF, DKIM, DMARC, MTA-STS. The mail sibling of this page: same “is it deployed” question, different protocol family, separate population.

Also deliberately outside: passwords as secrets (guessability, cracking, password managers), usability and perception studies that do not measure a deployment, and library and protocol analysis. Fifteen password papers, thirteen password-manager papers and eight SDK or protocol-verification papers were audited and excluded; they are named with reasons on the provenance page.

What to Read First

Paper Why this one
Ardi et al., IMC 2023, The Prevalence of Single Sign-On on the Web [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] The only paper in this population that measures how many sites have a login at all before measuring SSO: 51% of the CrUX Top 10K, and 57.8% of those offer third-party SSO. Every SSO percentage you read elsewhere is one of these two denominators
Al Roomi and Li, USENIX Security 2023, A Large-Scale Measurement of Website Login Policies [3Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)] The largest login-surface crawl in the corpus: automated signup and login across the CrUX top 1M, and a catalogue of what a login policy even consists of
Jannett et al., USENIX Security 2026, The State of Passkeys [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] How you find passkey deployments in 2026 — three discovery channels merged, 872 sites, 208 hand-confirmed — and why the number is so small
Gavazzi et al., USENIX Security 2023, Multi-Factor and Risk-Based Authentication Availability [5Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)] The MFA availability baseline, and the only MFA paper here that follows the factor through the SSO providers a site accepts
Ghasemisharif et al., IEEE S&P 2022, SAAT [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] What a deployment audit looks like when it goes past detection into account and session management: revocation, logout, merging
Drakonakis et al., CCS 2020, Cookie Hunter [7Drakonakis, Kostas; Ioannidis, Sotiris; Polakis, Jason (2020): "The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] The scale-registration instrument other people reuse, and the post-login cookie audit it enables
Blessing et al., PoPETs 2025, SoK: Web Authentication and Recovery [8Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)] The field's own map, including the observation that 41.6% of academic authentication research is about passwords — which is why this page's population is 45 papers and not 450

The Denominator Is the Whole Argument

“How many websites support SSO” has been answered, correctly, as 6.30%, 7.23%, 27% and 57.8%. The papers do not disagree. They divide by different things.

Paper Numerator Denominator it divides by Result
SSOScan, USENIX Security 2014 [9Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)] 1,660 sites with Facebook SSO 17,913 valid sites from a Quantcast 20K crawl 9.3%
O Single Sign-Off, USENIX Security 2018 [10Ghasemisharif, Mohammad; Ramesh, Amrutha; Checkoway, Stephen; Kanich, Chris; Polakis, Jason (2018): "O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] 57,555 domains with any detected SSO 912,206 processed domains of the Alexa 1M 6.30%
SSOmething, PoPETs 2023 [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)] 6,211 sites with an OAuth button reachable sites of the CrUX 100K — the crawler failed on 14,104 (14.1%), leaving ≈85.9K 7.23%
DISTINCT, CCS 2022 [12Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] 273 sites supporting SSO login Tranco top 1,000 27%
Prevalence of SSO, IMC 2023 [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] 2,742 sites with third-party SSO the 4,743 sites of the CrUX Top 10K that have a login at all 57.8%

Three lessons a reviewer will expect you to have internalised:

  • Rank depth drives the number more than the year does. DISTINCT found SSO on 27% of the Tranco top 1,000 in 2022 [12Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]; the IMC study's two 2023 figures imply 2,742 of the CrUX Top 10K, which is 27.4% of that list — arithmetic from their published numbers, not a figure they print, and the only reason to do it is to make the two comparable. At 100K and 1M depth the same phenomenon is 6–7%. A “growth” claim built from papers at different depths is measuring the ranking list.
  • “Sites with a login” is the denominator most questions actually want, and four papers publish a version of it, none of them as their headline: 51% of the CrUX Top 10K in 2023 [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]; 4,570 of 9,159 reachable Alexa top-10K sites in 2017 [13Chang, Li; Hsiao, Hsu-Chun; Jeng, Wei; Kim, Tiffany Hyun-Jin; Lin, Wei-Hsi (2017): "Security Implications of Redirection Trail in Popular Websites Worldwide", in: Proceedings of the ACM Web Conference. (DOI)]; 585 of the 841 Tranco top-1K sites that loaded, in 2023 [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]; and 358.9K login pages found across the CrUX 1M in 2023, which is a crawler's lower bound rather than a census [3Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)]. Read together: about half the top 10K, and about a third at 1M depth. If you divide by all sites, a third to a half of your denominator cannot have the feature you are looking for.
  • Reachability is not a footnote. 14.1% of the CrUX 100K did not load for SSOmething [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)]; the published 7.23% is of what loaded. State both, or your rate is a mixture of prevalence and crawl failure. Biases has the general version of this.

Six Questions, Six Instruments

1. Does this site have a login at all?

Nothing else works until this does, and it is harder than it looks: there is no standard place for a login link. Three approaches appear in this population, in order of age:

  • URL and link keywords. Follow same-domain links and guess paths (/login, /signin). Phish in Sheep's Clothing located the login pages of 11,527 of the Alexa top 20K this way [15Lin, Xu; Ilia, Panagiotis; Solanki, Saumya; Polakis, Jason (2022): "Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting", in: Proceedings of the USENIX Security Symposium. (Link)]; Connecting the Dots derived its keyword list by reading the login pages of the Similarweb top 300 in Korea first, then harvested 85,053 authentication webpages with it [16Kang, Junkyu; Lee, Soyoung; Kwon, Yonghwi; Son, Sooel (2026): "Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging Apps", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] — a reminder that the keyword list is language- and market-specific.
  • Detect the password field. The redirection-trail study defines the login page as the page containing input type=“password” [13Chang, Li; Hsiao, Hsu-Chun; Jeng, Wei; Kim, Tiffany Hyun-Jin; Lin, Wei-Hsi (2017): "Security Implications of Redirection Trail in Popular Websites Worldwide", in: Proceedings of the ACM Web Conference. (DOI)]. Robust, and it misses every passwordless and email-code flow — which is the part of the login surface that the passkey measurements below are about.
  • Click the login control, then verify. The IMC 2023 crawler finds and clicks common login buttons with DOM regular expressions and then checks where it landed. It reports its own success rate — 64% of sites, hand-labelled against the Top 1K [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. That number is the most useful single figure on this page: a login-page finder with unreported recall makes every downstream percentage unfalsifiable.

Report your finder's recall against a hand-labelled sample. At least two papers here do: [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] publishes 64% crawler success against hand labels, and [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)] manually re-checks 100 sites where its algorithm found nothing. Most do not.

2. Which identity providers does it accept?

  • Button and logo detection. The current form combines a DOM pass with logo detection, because the button often contains no text [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. SSOmething detects OAuth buttons by keyword and reports 10,304 buttons on 6,211 sites, 1.66 per site [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)].
  • Endpoint detection. Collect each identity provider's authorization endpoints and look for them in the HTML and scripts of candidate pages. This is how WPSE identified OAuth deployments in the Alexa 100K, finding Facebook on 1,666 sites and Google on 1,071 — although its authors state plainly that the crawl “is not meant to provide a comprehensive coverage of the deployment of OAuth 2.0 on the web”, which is why this page treats those counts as a by-product rather than a census.1)
  • Traffic and redirect reconstruction. Parse authorization-request URLs out of recorded flows. Corre et al. did it with a browser extension over the Alexa top 500 and recovered 103 relying parties and 23 provider domains [17Corre, Kevin; Barais, Olivier; Sunyé, Gerson; Frey, Vincent; Crom, Jean-Michel (2017): "Why can't users choose their identity providers on the web?", in: Proceedings on Privacy Enhancing Technologies. (DOI)]; the brokered-SSO study did it at scale over a public dataset of 88,983 recorded login flows and found 249 brokers on 8,241 sites, 25% of the sites with SSO [18Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)].
  • Do not confuse a button with a login. Detecting a button is not completing a flow. DISTINCT traced flows to find that 153 of 273 SSO sites (56%) use a dual-window flow rather than the textbook redirect [12Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], and SAAT found that 17.6% of the relying parties it tested had non-functional SSO — the button is there and the login errors out [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. If you publish a prevalence of buttons, call it a prevalence of buttons.

Which providers you test is a denominator. Studies limited to Facebook SSO ([9Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)], [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]) cannot see the market that replaced it: by 2023, having an account with just Google, Apple and Facebook was enough to log in to 47.2% of CrUX-Top-10K sites that have authentication [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)]. Publish the provider list you looked for.

3. Is a second factor available?

This one mostly cannot be answered from outside the account: three of these papers create accounts and walk the settings, which caps the sample at hundreds, and one reads what the site publishes instead:

  • Gavazzi et al. audited 208 sites drawn from the Tranco top 5K by hand: 88 (42.3%) support any form of MFA, 46 (22.1%) blocked an obviously suspicious login, and 23 more sent an alert without blocking [5Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)]. Their SSO-inheritance step is the design worth copying: 80.29% of their sites either had MFA or could inherit it from an identity provider they accept — a site with no MFA of its own is not necessarily an account without MFA.
  • Klivan et al. read the published recovery documentation of 1,303 sites from 2fa.directory and then tested recovery on 71 of them: mobile-app TOTP is the most documented method (1,036 sites, 79.51%), SMS second (559, 42.90%), and 321 sites (24.64%) publish no recovery information at all. Of 71 real accounts locked out on purpose, 37 (52.11%) were recovered, 26 of those by email access alone [19Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)].
  • Ghorbani Lyastani et al. coded the full 2FA journey on 85 popular websites along 14 factors and found the average site differs from the others in 6–7 of them [20Lyastani, Sanam Ghorbani; Backes, Michael; Bugiel, Sven (2023): "A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. If you are designing a coding frame for enrolment flows, start from theirs.
  • Two 2025 papers measure the notifications rather than the factors: 161 risk-based-authentication emails from 251 Tranco sites [21Wei, Tongxin; Wang, Ding; Li, Yutong; Wang, Yuehuan (2025): ""Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)], and suspicious-login notifications from 34 of the Tranco top 100 [22Sahin, Sena; Sahin, Burak; Li, Frank (2025): "Was This You? Investigating the Design Considerations for Suspicious Login Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)].

A sampling frame made of a community directory carries that directory's inclusion rule. Two papers here sample from 2fa.directory ([19Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], [20Lyastani, Sanam Ghorbani; Backes, Michael; Bugiel, Sven (2023): "A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]); it lists sites because someone cared about their 2FA, so it is a frame for “what do 2FA-relevant sites do”, not for “what does the web do”. And it is incomplete in a way you can measure: 114 of the 208 sites Gavazzi et al. audited by hand were not in it [5Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)]. Say which frame you mean, and check its coverage against your own sample rather than assuming it.

4. Does it support passkeys?

The only second factor whose deployment can be read from the outside without an account (identity-provider acceptance, section 2, is the other account-free signal) — and the four measurements of it use four different instruments:

Year Instrument Frame Found
2022 [23Kepkowski, Michal; Hanzlik, Lucjan; Wood, Ian; Kaafar, Mohamed Ali (2022): "How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy", in: Proceedings on Privacy Enhancing Technologies. (DOI)] crawl JavaScript for navigator.credentials.create with a public-key type Cisco Umbrella top 1M DNS records, Dec 2020 684 WebAuthn deployments, almost all second-factor with non-resident keys
2023 [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] manual inspection plus semi-automated configuration assessment, after abandoning an automated 100K pilot Tranco top 1K: 1,000 → 841 that load → 585 with a login or signup page 85 domains supporting WebAuthn, aggregating to 40 relying parties, 29 they could create an account on
2025 [8Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)] hand-walk the login and signup flow of every site top 300 of an Alexa top-1M list, deduplicated to 162 17 (10.5%) direct passkey support; 87 (53.7%) including indirect support through an SSO provider
2026 [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] merge community directories, /.well-known/webauthn scans and WebAuthn API detection Tranco 1M and CrUX 18M plus 12 directories 872 sites, of which 208 confirmed independent implementations, 103 security-tested

Four method points fall out of that table:

  • A string match for the WebAuthn API is not a census. Kuchhal et al. tried exactly that on the Tranco top 100K first: the navigator.credentials.create string pair appeared on 135 sites, of which 82 were enterprise identity-and-access SDKs the site had merely imported, while services they knew supported FIDO2 — Google, PayPal — were not detected at all. That is why the paper's published figures come from 1,000 sites walked by hand [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Search-engine queries for FIDO2 support failed the same way, on pages discussing FIDO2.
  • “Supports WebAuthn” and “supports passkeys” are different claims. In 2020 essentially every deployment used non-resident keys as a second factor [23Kepkowski, Michal; Hanzlik, Lucjan; Wood, Ian; Kaafar, Mohamed Ali (2022): "How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy", in: Proceedings on Privacy Enhancing Technologies. (DOI)]; a passkey is a discoverable (resident) credential usable as the first. A crawl that greps for navigator.credentials counts both.
  • Direct versus inherited support changes the answer by 5× — 10.5% against 53.7% on the same 162 sites [8Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)]. Same problem as MFA inheritance above.
  • The deployment side has been asked directly, and it is not a measurement. Lassak et al. interviewed 32 company, vendor and FIDO experts about why passwordless deployment stalls [24Lassak, Leona; Pan, Elleen; Ur, Blase; Golla, Maximilian (2024): "Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless Authentication", in: Proceedings of the USENIX Security Symposium. (Link)] — the best available answer to “why is that number so small”, and a reminder that an interview study and a census answer different halves of one question.
  • Discovery is now multi-channel, and the 2026 study is explicit that no single channel suffices: directories are incomplete, the well-known file is optional, and API detection needs the login page. It also shows what the measurement is worth doing for: all 103 sites it tested had at least one issue, 68 leaked account existence through passkey authentication, and one lapsed domain in a related-origins allowlist would have covered 72 origins [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)].

5. What does it require of a password, and what does it leak while you try?

The largest-scale instrument in this literature, and the least glamorous: sign up repeatedly with varied inputs and record what the server accepts. Two 2023 crawls define the genre, both by automating account creation over the CrUX or Tranco top million.

  • Password policy. 20,119 domains successfully analysed: about 12% accept a single-character password, over 30% reject spaces, Unicode or emoji, and 88% accept a password known to be breached [25Alroomi, Suood; Li, Frank (2023): "Measuring Website Password Creation Policies At Scale", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. The policy is inferred by binary-searching the accepted length and probing character classes — you never see the policy, you see the rejections.
  • Login policy, which is a different thing. Across the login pages found in the CrUX 1M: nearly 2,000 domains serve the login page over HTTP only; 5.9K (19%) leak whether a username exists; only 4,335 of the 18.0K fully evaluated (24%) rate-limit repeated failures; 570 domains email the password back in plaintext; 273 accept a typo'd password; and 82.7% of login pages carry a third-party script [3Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)].
  • What the form itself does. Password masking is universal but the toggle is not: all 66 evaluable sites of a CrUX top-100 sample mask by default and 41 of them offer no way to unmask [26Hu, Yuqi; Alroomi, Suood; Sahin, Sena; Li, Frank (2024): "Unmasking the Security and Usability of Password Masking", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Login pages also fingerprint slightly more than ordinary pages — 10.2% against 9.2% [27Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)] — and half the fingerprinting scripts on them are classified as tracking rather than security.
  • Identifier handling at the boundary. Nine of 18 tested platforms accept every alias form their mail provider supports, so “one account per email address” is not a property the platform enforces [28Wu, Mengying; Hong, Geng; Chen, Jiatao; Liu, Baojun; Liu, Mingxuan; Yang, Min (2026): "One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases", in: Proceedings of the Network and Distributed System Security Symposium. (Link)].

Two cautions. The third-party-script figure is a share of login pages, not of sites — and a login page is where credentials are typed, so it is the one page where that share is interesting; do not compare it to a homepage figure without saying so. And the crawls that produce these numbers create real accounts on real services at scale: see Ethics below, and Registration for the mechanics.

A companion to the policy crawls asks the operators instead of the servers: Sahin et al. surveyed and interviewed 11 website administrators about the password policies they run and why they do not change them [29Sahin, Sena; Al-Roomi, Suood Abdulaziz; Poteat, Tara; Li, Frank (2023): "Investigating the Password Policy Practices of Website Administrators", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]. Eleven is not a population, and it is the only account of intent behind a password policy in this literature; the equivalent for passkeys is Lassak et al.'s 32 deployment experts [24Lassak, Leona; Pan, Elleen; Ur, Blase; Golla, Maximilian (2024): "Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless Authentication", in: Proceedings of the USENIX Security Symposium. (Link)].

6. What does the login leave behind?

Once you are logged in, the session is the artefact, and it is measurable at scale:

  • Cookie flags and cookie exposure. Cookie Hunter's funnel is the one to copy the shape of: crawl 1.5M domains, find over 200,000 that support account creation, fully audit almost 25,000 of those (about 12%), and report against that audited set — 12,014 (48.43%) not protecting authentication cookies with Secure and 5,680 (22.9%) without HttpOnly, 5,099 of the latter also embedding third-party script [7Drakonakis, Kostas; Ioannidis, Sotiris; Polakis, Jason (2020): "The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Four denominators, one paper, all of them stated. The 2015 cookie-integrity study is the reason the flags matter: only 1,252 domains (0.13%) of an Alexa 1M scan had full HSTS [30Zheng, Xiaofeng; Jiang, Jian; Liang, Jinjin; Duan, Haixin; Chen, Shuo; Wan, Tao; Weaver, Nicholas (2015): "Cookies Lack Integrity: Real-World Implications", in: Proceedings of the USENIX Security Symposium. (Link)].
  • Session-hardening adoption. SameSite reached 18.94% of sites on a valid policy by March 2021 [31Khodayari, Soheil; Pellegrino, Giancarlo (2022): "The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]; cookie prefixes (__Host-, __Secure-) are measured against HTTP Archive by Cookie Crumbles [32Squarcina, Marco; Adão, Pedro; Veronese, Lorenzo; Maffei, Matteo (2023): "Cookie Crumbles: Breaking and Fixing Web Session Integrity", in: Proceedings of the USENIX Security Symposium. (Link)]. Note that neither SameSite nor the prefixes are in a published RFC: RFC 6265bis is still an Internet-Draft (version 22, submitted to the IESG), so “the standard says” is the wrong phrasing — “every major browser implements” is the right one.2)
  • Paired logged-in and logged-out crawls. To Auth or Not To Auth ran four security experiments on 200 popular sites in both states [33Rautenstrauch, Jannis; Mitkov, Metodi; Helbrecht, Thomas; Hetterich, Lorenz; Stock, Ben (2024): "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] — the design to copy if your question is whether the post-login web is a different web. The instrument side (how they kept 200 logins alive) is on Registration.
  • Session termination is a deployment property too, and it is mostly absent. 89.5% of the relying parties in the SSO study offered no way to invalidate active sessions [10Ghasemisharif, Mohammad; Ramesh, Amrutha; Checkoway, Stephen; Kanich, Chris; Polakis, Jason (2018): "O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web", in: Proceedings of the USENIX Security Symposium. (Link)]; SAAT found 67% still allowing access ten days after the user revoked the identity provider's access, 40.5% after an explicit logout, and only 13 of 1,622 relying parties (0.8%) properly re-authenticating [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)].

Methods, and Which Ones Are Current

The corpus rewards whatever was fashionable mid-window, so each of these is dated deliberately. Population: the 45 papers; years are the years those papers appeared.

Current practice, and what a 2026 reviewer expects

  • Multi-channel discovery with a published recall figure. Directory merge plus well-known-file scan plus API detection for passkeys [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)]; DOM plus logo detection with a hand-labelled success rate for SSO [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)].
  • Automated account creation at five figures. Al Roomi and Li's two crawls [3Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)] [25Alroomi, Suood; Li, Frank (2023): "Measuring Website Password Creation Policies At Scale", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] and Cookie Hunter [7Drakonakis, Kostas; Ioannidis, Sotiris; Polakis, Jason (2020): "The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] are the reference designs. Note the scale honestly: the crawls start at a million domains and the accounts end in the tens of thousands — ~25K audited for Cookie Hunter, 20,119 password policies evaluated, 18.0K domains fully evaluated for rate limiting. Expect to report your signup success rate, not just your finding.
  • Dynamic testing of the flow, not the page. Tracing in-browser messages [12Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], manipulating WebAuthn parameters [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)], replaying redirect chains [18Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)].
  • Small-n hand audits, published as such. A hundred sites, 208 sites, 27 services — with a written protocol and two coders. This is not a weakness of the field; for anything behind an account it is the only honest instrument. Across every site-unit population[] entry the 45 papers declare (85 entries), the median is 872 sites and 39 entries are under 500.
  • Operator telemetry, where you can get it. Four papers measure from inside a deployment [34Bonneau, Joseph; Bursztein, Elie; Caron, Ilan; Jackson, Rob; Williamson, Mike (2015): "Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google", in: Proceedings of the ACM Web Conference. (DOI)] [35Doerfler, Periwinkle; Thomas, Kurt; Marincenko, Maija; Ranieri, Juri; Jiang, Yu; Moscicki, Angelika; McCoy, Damon (2019): "Evaluating Login Challenges as a Defense Against Account Takeover", in: Proceedings of the ACM Web Conference. (DOI)] [36Reynolds, Joshua; Samarin, Nikita; Barnes, Joseph; Judd, Taylor; Mason, Joshua; Bailey, Michael; Egelman, Serge (2020): "Empirical Measurement of Systemic 2FA Usability", in: Proceedings of the USENIX Security Symposium. (Link)] [37Bohuk, Marina Sanusi; Islam, Mazharul; Ahmad, Suleman; Swift, Michael; Ristenpart, Thomas; Chatterjee, Rahul (2022): "Gossamer: Securely Measuring Password-based Logins", in: Proceedings of the USENIX Security Symposium. (Link)]. It answers what no crawl can — 2FA error and abandonment in more than one in twenty ceremonies [36Reynolds, Joshua; Samarin, Nikita; Barnes, Joseph; Judd, Taylor; Mason, Joshua; Bailey, Michael; Egelman, Serge (2020): "Empirical Measurement of Systemic 2FA Usability", in: Proceedings of the USENIX Security Symposium. (Link)], device-based challenges blocking over 94% of phishing-rooted hijacks [35Doerfler, Periwinkle; Thomas, Kurt; Marincenko, Maija; Ranieri, Juri; Jiang, Yu; Moscicki, Angelika; McCoy, Damon (2019): "Evaluating Login Challenges as a Defense Against Account Takeover", in: Proceedings of the ACM Web Conference. (DOI)] — and it requires a partner and an ethics story.

Historical: read them, do not copy the design

  • Single-provider crawls. Facebook-only SSO detection [9Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)] [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] made sense when Facebook Login dominated; today it undercounts by construction.
  • Manual flaw hunts on a handful of high-profile systems [38Wang, Rui; Chen, Shuo; Wang, XiaoFeng (2012): "Signing Me onto Your Accounts through Facebook and Google: A Traffic-Guided Security Study of Commercially Deployed Single-Sign-On Web Services", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] [39Sun, San-Tsai; Beznosov, Konstantin (2012): "The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Foundational — the 2012 IEEE S&P study is where web-SSO security measurement starts — but a modern paper needs per-site incidence over a sampled frame.
  • Secret questions as a recovery mechanism. Measured and demolished in 2015: 40% of English-speaking US users could not recall their answers, and recovery succeeded 81% of the time by SMS against 61% by secret question [34Bonneau, Joseph; Bursztein, Elie; Caron, Ilan; Jackson, Rob; Williamson, Mike (2015): "Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google", in: Proceedings of the ACM Web Conference. (DOI)].
  • Alexa as a frame. Eleven of the 45 papers sample from Alexa, and one of them is from 2025 — a top-300 drawn from an Alexa top-1M dataset republished on Kaggle [8Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)], three years after the list was retired. Website selection covers why that matters; in this literature it matters twice, because login availability correlates strongly with rank.

What nobody in this population has done yet

Nobody classifies with an LLM. Of the 45 papers, zero carry a classification tuple whose method is llm. Corpus-wide that value appears in 177 papers — 2 in 2023, 27 in 2024, 77 in 2025, 71 in 2026 — so this is not a corpus that cannot see LLM methods; it is a subfield that has not adopted them. Given that the recurring bottlenecks here are exactly the ones an LLM is now used for elsewhere (finding the login control, reading a recovery help page, coding an enrolment flow), that is either an opportunity or a submitted-but-not-yet-published gap. Note also that the 2025–2026 slice of the corpus is the thinnest and most provisional part of it (see corpus), so treat “nobody” as “nobody in these seven venues up to the 2026 volumes that exist”.

Two more gaps, stated as gaps and checked against the whole corpus rather than the population. FedCM appears in the full text of exactly one of the 5,859 papers — three occurrences in [18Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], all of them a bibliography entry for the explainer — so nobody has measured the API that is meant to replace the redirect flows counted above. And no paper measures enterprise SSO as deployed: 39 papers mention Okta, Entra, Azure AD, ADFS or Google Workspace at all, and judged from their titles none has enterprise identity as its object — they are email-filtering bypasses, cloud-misconfiguration interviews, employee privacy perceptions. The nearest thing to an exception is in this population: the CCS 2024 poster whose frame is 100 European companies rather than a ranking list [40Nsieyanji Tchokodeu, Kevin; Schulmann, Haya; Sobol, Gil; Waidner, Michael (2024): "Poster: Security of Login Interfaces in Modern Organizations", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)].3)

What Changed Under You in 2025–2026

Every row was fetched on 2026-09-11 from the primary source named. If you are reading this much later, re-check them; this is the fastest-moving material on the page.

Thing State as of 2026-09-11 Why a measurement person cares
W3C WebAuthn Level 3 is a Recommendation, 25 August 2026 (TR) It adds the surfaces you would measure with: getClientCapabilities(), Related Origin Requests, and a /.well-known/webauthn well-known URI — the file the 2026 passkey census scans for
FIDO CTAP 2.3, Proposed Standard, 26 February 2026, with 2.3.1 in Working Draft since 29 May 2026 (FIDO specs) Authenticator-side; matters if you are reading MDS certification levels, as 4% of the 160 MDS authenticators had L2 in 2023 [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]
FedCM Spec still a First Public Working Draft (20 August 2024). Shipping: IdentityCredential in Chrome 108+, not in Firefox, not in Safari; the Login Status API (navigator.login) in Chrome 120+ and Firefox 138+ 4) A cross-browser SSO measurement in 2026 measures redirect-based OAuth. Firefox shipping only the Login Status API is the kind of split that makes a single-browser crawl an unrepresentative one
OAuth security guidance RFC 9700, Best Current Practice for OAuth 2.0 Security, January 2025. OAuth 2.1 is still a draft (draft-ietf-oauth-v2-1-16, 3 September 2026) The normative yardstick for “is this deployment correct” changed in 2025. A paper citing only RFC 6749 and RFC 6819 is citing the superseded pair
OpenID Federation 1.0 Final, 17 February 2026 (spec) The multilateral-trust story behind brokered SSO [18Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] [41Brandão, Luís T. A. N.; Christin, Nicolas; Danezis, George; Anonymous, (2015): "Toward Mending Two Nation-Scale Brokered Identification Systems", in: Proceedings on Privacy Enhancing Technologies. (DOI)] now has a finished spec; no paper in this population has measured its deployment
SAML 2.0 Unchanged since 17 March 2005, not deprecated. Microsoft Entra's own guidance: “Both protocols are secure, and Microsoft Entra ID fully supports each one”, while recommending OIDC by default for new apps 5) “SAML is dead” is not a claim a primary source supports. It is also invisible to every crawl here: SAML deployment is enterprise-side
Third-party cookies in Chrome Not being deprecated. “Chrome will maintain our current approach to offering users third-party cookie choice in Chrome” (Privacy Sandbox update, 17 October 2025) Several SSO flows and session checks depend on third-party cookies in iframes. The deprecation that would have broken them, and made a 2024-style measurement urgent, is off
RFC 6265bis Still an Internet-Draft (v22): IESG-approved and sitting in the RFC Editor's queue, not yet published SameSite and the cookie prefixes are implemented everywhere and standardised nowhere. Cite the draft, or cite browser behaviour

Tools, Datasets and Directories

Every row was checked on 2026-09-11: the HTTP status is one I observed with curl -L, and every repository date is from the GitHub commits API rather than from pushed_at, which lags and misleads.

What Where State on 2026-09-11 Use it for
2fa.directory site, github.com/2factorauth/twofactorauth, API at api.2fa.directory/v3/all.json Alive. 2,570 entries (I fetched the API and counted the array; the repository's entries/ tree agrees). Last commit 2026-09-07, 3,458 stars The sampling frame two MFA papers drew from [19Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] [20Lyastani, Sanam Ghorbani; Backes, Michael; Bugiel, Sven (2023): "A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites", in: Proceedings of the Network and Distributed System Security Symposium. (Link)]. A third used it the other way round, as a coverage check: of Gavazzi et al.'s 208 hand-audited sites, 114 were not documented in 2fa.directory [5Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)]. Machine-readable, one JSON file per site
2factorauth/passkeys github.com/2factorauth/passkeys Alive. 270 entries, last commit 2026-09-03, CC-BY-4.0 The same organisation's passkey list, in the same format. The reusable one
passkeys.directory site Alive (200). Run by 1Password; “a community-driven index of websites, apps, and services that offer signing in with passkeys”. No entry count, no export and no last-updated date on the page Browsing and cross-checking. Not a frame you can snapshot and cite
PASSKEYS-RADAR and passkeys.tools github.com/RUB-NDS/state-of-passkeys-artifacts, passkeys.tools, live radar at radar.passkeys.tools Alive. Artifacts last commit 2026-04-21 (“add new radar data for april 2026”), Apache-2.0; the tools repo last commit 2026-03-31 The 2026 census [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] in reusable form: a radar that tracks 12 directories, a well-known-file detector aimed at CrUX 18M, and an attack toolkit
FIDO Metadata Service (MDS3) mds3.fidoalliance.orgmds.fidoalliance.org 301, then HTTP 429 on every attempt today, from two different networks, with the 429 itself served cacheable at the edge. Public and token-free when it answers Authenticator models and certification levels — the source for the “4% at Level 2” figure [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. Budget for rate limiting, and do not report a count you did not fetch
login-security-landscape github.com/cispa/login-security-landscape Alive. Last commit 2025-12-19, MIT, 13 stars The pre- and post-login artifact of [33Rautenstrauch, Jannis; Mitkov, Metodi; Helbrecht, Thomas; Hetterich, Lorenz; Stock, Ben (2024): "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)]: an account framework plus a Python and a TypeScript crawler. The closest thing to a reusable logged-in crawling stack
double_edged_sword_data github.com/asumansenol/double_edged_sword_data Alive but static: last commit 2024-02-12, no licence file Training data and notebooks for a login/signup page classifier [27Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)]. Intact, unmaintained, and unlicensed — ask before redistributing
SSOScan ssoscan.org The project page still answers 200. The service and code are a 2014 artefact [9Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)] History. Do not plan a 2026 study around it

Three negative results, each checked rather than assumed:

  • There is no maintained, general-purpose login-page or SSO-button detector. Targeted searches turned up one actively developed extension that is an end-user phishing blocker rather than a measurement tool, and one recently created personal repository whose own commit log shows it was written by an AI assistant. Neither is a research instrument. The reusable detectors are the paper artifacts above.
  • Shepherd has no maintained public repository that could be located — a project page exists, but treat “available and maintained” as unverified; Registration cites the paper [1Jonker, Hugo; Karsch, Stefan; Krumnow, Benjamin; Sleegers, Marc (2020): "Shepherd: a Generic Approach to Automating Website Login", in: Proceedings of the Workshop on Measurements, Attacks, and Defenses for the Web. (DOI)] for the method, not the code.
  • HTTP Archive's Web Almanac has no identity or authentication chapter. The 2025 edition has sixteen content chapters and none of them is about login; its Security chapter mentions WebAuthn and passkeys zero times. Cloudflare Radar published no passkey or WebAuthn metric that could be fetched (its adoption page returned 403). If you want a longitudinal login-deployment series, nobody is publishing one for you.

Industry figures, and why they do not answer your question

Two primary sources are worth knowing, both verified by fetching the page and reading the sentence:

  • The FIDO Alliance announced on 7 May 2026 that “an estimated 5 billion passkeys are now in use worldwide”, alongside survey findings that 75% of people have enabled a passkey on at least one account and 68% of organisations have deployed or are deploying passkeys for employee sign-in. The methodology is stated, which is why it is quotable: two Sapio Research studies in April 2026, 11,000 consumers (±0.9pp at 95%) and 1,400 workforce decision-makers across ten countries.6)
  • Microsoft reported on 1 May 2025 “nearly a million passkeys registered every day” on Microsoft accounts, and a sign-in success rate of “about 98% versus 32%” for passkeys against passwords. The same post's “more than 15 billion user accounts can now sign in using passkeys” is Microsoft citing the FIDO Alliance, not Microsoft's own measurement — do not re-cite it as two sources.7)

Those denominators are credentials, users and enterprise respondents. Yours is websites. The academic census that counts websites found 872 with a passkey implementation, 208 of them confirmed independent [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)]. Five billion passkeys and 872 sites are both true and they are not in tension: a handful of very large relying parties account for almost all credentials. If you cite an industry total next to a site-side rate, say which is which in the same sentence.

Rejected during this pass, and recorded so the next run does not re-add them: “State of Passkeys” benchmark sites and vendor blogs (Corbado, Descope, MojoAuth and similar) that present adoption percentages with no stated methodology or population; the widely repeated Google “800 million accounts / 2.5 billion sign-ins” pair, which traces to a May 2024 post and therefore cannot support a 2026 claim; and every Apple-attributed adoption percentage found, none of which came from Apple. Also note twofactorauth.org, the old name of 2fa.directory: it now 301-redirects to a commercial bootcamp's marketing page, so a paper citing that URL today sends readers somewhere else entirely.

Ethics: You Are Creating Accounts on Other People's Services

Most of the instruments above require an account you do not own, on a service whose terms you are probably breaking, and several of them then test whether the service is broken. (Sections 1, 2 and the passkey-detection half of 4 do not; everything that walks a settings page does.) This population handles that better than the corpus average, and still not well:

  • An ethics review is reported by 20 of 44 papers with an ethics object — 45.5%, against 36.4% for web-platform papers and 35.8% corpus-wide. Twenty-four say nothing.
  • Notifying the affected party is reported by 30 of 44 (68.2%, against 52.1% for web papers): 22 yes, 6 partial, 2 explicitly no. This is the one number where the subfield clearly leads, and the reason is structural — most of these papers find exploitable flaws in named services. Notifying websites has the response rates.
  • Nobody is pretending it is easy. SAAT wrote the terms-of-service problem down explicitly rather than eliding it; Cookie Hunter refused a human CAPTCHA-solving farm; the password-policy crawl instead paid an automated CAPTCHA solver, which solved 94% of the CAPTCHAs it met [25Alroomi, Suood; Li, Frank (2023): "Measuring Website Password Creation Policies At Scale", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)]. (What you will be solving is measured too: CAPTCHA prevalence on 200 popular sites [42Searles, Andrew; Nakatsuka, Yoshimichi; Ozturk, Ercan; Paverd, Andrew; Tsudik, Gene; Enkoji, Ai (2023): "An Empirical Study & Evaluation of Modern CAPTCHAs", in: Proceedings of the USENIX Security Symposium. (Link)] — filed under Registration, because a bot challenge guards many flows and is not a claim about an identity.) Those are three different answers and all three are defensible because they are stated.
  • The scanning-ethics checklist, the acceptable-use argument and crawler identification are on Ethics — this page does not duplicate them.

What to Report

  • Both denominators. Sites measured, and sites that could have had the feature (have a login / support SSO / accept an account). If you publish one rate, publish the other.
  • Crawl failure. How many of the frame did not load, and whether your rate is of the frame or of what loaded.
  • How you found the login, and its recall against a hand-labelled sample. An unmeasured login-page finder invalidates everything downstream.
  • Whether you completed the flow or only detected the control. Buttons, attempted logins and successful logins are three numbers.
  • Which identity providers, factors or authenticators you tested for — the list is a denominator.
  • Accounts created, attempted, verified, and the failure modes. Include the CAPTCHA, SMS and email-verification decisions, and whether you paid anyone.
  • Inheritance. Whether a feature counted as present because the site has it, or because an identity provider it accepts has it.
  • The date, the list version and its depth. Login availability and passkey support both move within months, the ranking lists move under you, and depth decides the number more than the year does: 2fa.directory and passkeys.directory are living documents, so cite the snapshot as well as the rank range.
  • Whether the profile persisted between visits, and what you did with the cookie banner. In a literature about sessions, only seven of the 23 crawls here say either.
  • Direct versus indirect passkey support, and resident versus non-resident keys.
  • The ethics story: review outcome, terms-of-service position, disclosure, and whether anyone was notified.

Use in Publications

The population is a hand audit, not a query

There is no field in the extraction schema for “measures authentication deployment”. The population was built by five title-and-summary probes plus a full-text recall probe, unioned into 184 candidates, every one of which was then judged by hand against a written inclusion rule: the object must be authentication as deployed by services the authors do not control; the unit must be a population of at least ten such services or an operator's own login telemetry; and the question must be what is deployed rather than whether an attack works or what users think.

45 candidates survived — 24.5%. The other 139 are the reason the roadmap gated this page on an audit: 26 are abuse-and-fraud papers, 20 are attacks without population incidence, 18 belong to an adjacent page, 16 are user studies, 15 are about passwords as secrets, 13 about password managers, 12 propose a system or defence, 11 are homonyms and 8 are library or protocol analyses. The homonyms are worth knowing about: MFA is “Made for AdSense” in a 2011 search-spam paper, OpenID matches “OpenIDEO”, and an RPKI relying party is a route-origin validator.

Slice Papers Of what
The population 45 of which 42 are web-platform papers (2.6% of 1,622) and 25 ran a crawl (2.2% of 1,120)
SSO / OAuth / OIDC / SAML deployment 12 2012–2026
MFA, 2FA and risk-based authentication 7 2021–2025
Passkeys and WebAuthn 6 2022–2026
The login surface (pages, policies, account creation) 12 2017–2026
What the login leaves behind (sessions, cookies, post-login) 4 2015–2024
Operator-side login telemetry 4 2015–2022
Branded-mechanism slice only (SSO + MFA + passkeys) 25 the roadmap's ~20-paper gate, met without the login-surface papers

The 45 papers

Generated by scripts/auth_report.mjs –wikitable from the audit, so the table and the population cannot drift apart. The last column is the largest site-unit n the paper declares, which is the frame it drew from rather than the set it analysed — and for four papers (a phishing corpus, a breach dataset, a password leak, a 5,000-site frame narrowed to 200) it is not even the frame for the deployment part of the work. The analysed figures are in the sections above and in the per-paper prevalence dump on authentication.

Year Venue Paper Measures Largest n in population[]
2012 CCS The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems [39Sun, San-Tsai; Beznosov, Konstantin (2012): "The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] SSO 96 websites (Google's Top 1,000 Most-Visited Websites)
2014 USENIX Sec SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities [9Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)] SSO 20,000 websites (Quantcast)
2015 USENIX Sec Cookies Lack Integrity: Real-World Implications [30Zheng, Xiaofeng; Jiang, Jian; Liang, Jinjin; Duan, Haixin; Chen, Shuo; Wan, Tao; Weaver, Nicholas (2015): "Cookies Lack Integrity: Real-World Implications", in: Proceedings of the USENIX Security Symposium. (Link)] post-login 961,857 domains (Alexa top one million websites)
2015 TheWebConf Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google [34Bonneau, Joseph; Bursztein, Elie; Caron, Ilan; Jackson, Rob; Williamson, Mike (2015): "Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google", in: Proceedings of the ACM Web Conference. (DOI)] operator 32,000,000 other (RockYou)
2017 PoPETs Why can’t users choose their identity providers on the web? [17Corre, Kevin; Barais, Olivier; Sunyé, Gerson; Frey, Vincent; Crom, Jean-Michel (2017): "Why can't users choose their identity providers on the web?", in: Proceedings on Privacy Enhancing Technologies. (DOI)] SSO 500 websites (Alexa ranking)
2017 TheWebConf Security Implications of Redirection Trail in Popular Websites Worldwide [13Chang, Li; Hsiao, Hsu-Chun; Jeng, Wei; Kim, Tiffany Hyun-Jin; Lin, Wei-Hsi (2017): "Security Implications of Redirection Trail in Popular Websites Worldwide", in: Proceedings of the ACM Web Conference. (DOI)] login surface 1,000,000 websites (Alexa top 1M list)
2018 USENIX Sec O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web [10Ghasemisharif, Mohammad; Ramesh, Amrutha; Checkoway, Stephen; Kanich, Chris; Polakis, Jason (2018): "O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] SSO 1,000,000 websites (Alexa)
2019 TheWebConf Evaluating Login Challenges as aDefense Against Account Takeover [35Doerfler, Periwinkle; Thomas, Kurt; Marincenko, Maija; Ranieri, Juri; Jiang, Yu; Moscicki, Angelika; McCoy, Damon (2019): "Evaluating Login Challenges as a Defense Against Account Takeover", in: Proceedings of the ACM Web Conference. (DOI)] operator 400,000 other (three existing threat intelligence feeds)
2020 CCS The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws [7Drakonakis, Kostas; Ioannidis, Sotiris; Polakis, Jason (2020): "The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] login surface 1,585,964 domains (Alexa Top 1 million)
2020 USENIX Sec Empirical Measurement of Systemic 2FA Usability [36Reynolds, Joshua; Samarin, Nikita; Barnes, Joseph; Judd, Taylor; Mason, Joshua; Bailey, Michael; Egelman, Serge (2020): "Empirical Measurement of Systemic 2FA Usability", in: Proceedings of the USENIX Security Symposium. (Link)] operator 32,366,721 other (UCB anonymized 2FA log events)
2021 USENIX Sec Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols [43Ulqinaku, Enis; Assal, Hala; Abdou, AbdelRahman; Chiasson, Sonia; Capkun, Srdjan (2021): "Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols", in: Proceedings of the USENIX Security Symposium. (Link)] MFA/RBA 100 websites (Alexa's top 100 websites)
2021 TheWebConf An Investigation of Identity-Account Inconsistency in Single Sign-On [44Liu, Guannan; Gao, Xing; Wang, Haining (2021): "An Investigation of Identity-Account Inconsistency in Single Sign-On", in: Proceedings of the ACM Web Conference. (DOI)] SSO 100 websites (Alexa top 1,000 websites)
2022 CCS DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On [12Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] SSO 1,000 domains (Tranco)
2022 IEEE S&P Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments [6Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] SSO 100,000 websites (Majestic)
2022 IEEE S&P The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies [31Khodayari, Soheil; Pellegrino, Giancarlo (2022): "The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] post-login 500,000 websites (Alexa top 500K)
2022 PoPETs How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy [23Kepkowski, Michal; Hanzlik, Lucjan; Wood, Ian; Kaafar, Mohamed Ali (2022): "How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy", in: Proceedings on Privacy Enhancing Technologies. (DOI)] passkey 1,000,000 domains (Cisco Umbrella set)
2022 USENIX Sec Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting [15Lin, Xu; Ilia, Panagiotis; Solanki, Saumya; Polakis, Jason (2022): "Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting", in: Proceedings of the USENIX Security Symposium. (Link)] MFA/RBA 173,269 websites (APWG)
2022 USENIX Sec Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web [45Sudhodanan, Avinash; Paverd, Andrew (2022): "Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] login surface 75 websites (Alexa global website rankings)
2022 USENIX Sec Gossamer: Securely Measuring Password-based Logins [37Bohuk, Marina Sanusi; Islam, Mazharul; Ahmad, Suleman; Swift, Michael; Ristenpart, Thomas; Chatterjee, Rahul (2022): "Gossamer: Securely Measuring Password-based Logins", in: Proceedings of the USENIX Security Symposium. (Link)] operator 1,300,000,000 other (breach data used in prior work)
2023 CCS “We've Disabled MFA for You”: An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments [19Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] MFA/RBA 1,303 websites (2fa.directory)
2023 CCS Evaluating the Security Posture of Real-World FIDO2 Deployments [14Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] passkey 100,000 domains (Tranco)
2023 CCS Measuring Website Password Creation Policies At Scale [25Alroomi, Suood; Li, Frank (2023): "Measuring Website Password Creation Policies At Scale", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] login surface 1,000,000 domains (Tranco)
2023 IMC The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] SSO 10,000 websites (Chrome UX Report (CrUX))
2023 NDSS A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites [20Lyastani, Sanam Ghorbani; Backes, Michael; Bugiel, Sven (2023): "A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] MFA/RBA 120 websites (Tranco)
2023 PoPETs Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)] SSO 100,000 websites (Chrome User Experience Report (CrUX))
2023 USENIX Sec A Study of Multi-Factor and Risk-Based Authentication Availability [5Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)] MFA/RBA 5,000 websites (Tranco)
2023 USENIX Sec A Large-Scale Measurement of Website Login Policies [3Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)] login surface 1,000,000 domains (Google Chrome User Experience Report (CrUX))
2023 USENIX Sec Cookie Crumbles: Breaking and Fixing Web Session Integrity [32Squarcina, Marco; Adão, Pedro; Veronese, Lorenzo; Maffei, Matteo (2023): "Cookie Crumbles: Breaking and Fixing Web Session Integrity", in: Proceedings of the USENIX Security Symposium. (Link)] post-login 100,000 websites (HTTP Archive dataset)
2024 CCS Poster: Security of Login Interfaces in Modern Organizations [40Nsieyanji Tchokodeu, Kevin; Schulmann, Haya; Sobol, Gil; Waidner, Michael (2024): "Poster: Security of Login Interfaces in Modern Organizations", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] login surface 73,431 web-pages (custom seed list)
2024 CCS Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication [46Yan, Kailun; Zhang, Xiaokuan; Diao, Wenrui (2024): "Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] login surface 18 websites (DappRadar's Top Decentralized Marketplaces list)
2024 CCS Unmasking the Security and Usability of Password Masking [26Hu, Yuqi; Alroomi, Suood; Sahin, Sena; Li, Frank (2024): "Unmasking the Security and Usability of Password Masking", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] login surface 100 domains (Google CrUX Top 1K domains list)
2024 IEEE S&P To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape [33Rautenstrauch, Jannis; Mitkov, Metodi; Helbrecht, Thomas; Hetterich, Lorenz; Stock, Ben (2024): "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] post-login 5,000 websites (CrUX)
2024 TheWebConf The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior [27Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)] login surface 100,000 domains (Chrome User Experience Report (CrUX))
2025 IEEE S&P “Only as Strong as the Weakest Link”: On the Security of Brokered Single Sign-On on the Web [18Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)] SSO 1,000,000 websites (Tranco)
2025 NDSS ”Who is Trying to Access My Account?” Exploring User Perceptions and Reactions to Risk-based Authentication Notifications [21Wei, Tongxin; Wang, Ding; Li, Yutong; Wang, Yuehuan (2025): ""Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] MFA/RBA 251 websites (Tranco)
2025 NDSS Was This You? Investigating the Design Considerations for Suspicious Login Notifications [22Sahin, Sena; Sahin, Burak; Li, Frank (2025): "Was This You? Investigating the Design Considerations for Suspicious Login Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] MFA/RBA 100 websites (Tranco)
2025 PoPETs SoK: Web Authentication and Recovery in the Age of End-to-End Encryption [8Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)] passkey 300 websites (Alexa Top 1M dataset)
2025 USENIX Sec Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms [47Luo, Kaixuan; Wang, Xianbo; Fung, Pui Ho Adonis; Lau, Wing Cheong; Lecomte, Julien (2025): "Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms", in: Proceedings of the USENIX Security Symposium. (Link)] SSO 24 other (custom curated list of integration platforms)
2025 USENIX Sec A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models [48Daffalla, Alaa; Bhattacharya, Arkaprabha; Wilder, Jacob; Chatterjee, Rahul; Dell, Nicola; Bellini, Rosanna; Ristenpart, Thomas (2025): "A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models", in: Proceedings of the USENIX Security Symposium. (Link)] passkey 200 websites (Tranco)
2025 USENIX Sec Demystifying the (In)Security of QR Code-based Login in Real-world Deployments [49Zhang, Xin; Zhang, Xiaohan; Zhao, Bo; Nan, Yuhong; Liu, Zhichen; Chen, Jianzhou; Zhou, Huijun; Yang, Min (2025): "Demystifying the (In)Security of QR Code-based Login in Real-world Deployments", in: Proceedings of the USENIX Security Symposium. (Link)] login surface 100,000 websites (Tranco top 100K list)
2026 NDSS Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging Apps [16Kang, Junkyu; Lee, Soyoung; Kwon, Yonghwi; Son, Sooel (2026): "Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging Apps", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] SSO 85,053 web-pages (custom seed list of authentication webpages)
2026 NDSS Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication [50Zhang, Xin; Zhang, Xiaohan; Zhou, Huijun; Zhao, Bo (2026): "Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] passkey 100 websites (Tranco top site list)
2026 NDSS One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases [28Wu, Mengying; Hong, Geng; Chen, Jiatao; Liu, Baojun; Liu, Mingxuan; Yang, Min (2026): "One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases", in: Proceedings of the Network and Distributed System Security Symposium. (Link)] login surface 100 domains (Tranco)
2026 USENIX Sec The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] passkey 18,000,000 websites (CrUX 18M)
2026 USENIX Sec Inconsistent, Incomplete, and Insecure: A Survey of Account Security Interfaces [51Bhattacharya, Arkaprabha; Daffalla, Alaa; Lee, Kevin; Bellini, Rosanna; Dell, Nicola; Ristenpart, Thomas (2026): "Inconsistent, Incomplete, and Insecure: A Survey of Account Security Interfaces", in: Proceedings of the USENIX Security Symposium. (Link)] login surface 100 websites (Tranco list (ID: 7XN5X))

Where the papers are

Window Papers Corpus papers in the window Share
2010–2012 1 386 0.3%
2013–2015 3 481 0.6%
2016–2018 3 667 0.4%
2019–2021 5 1,185 0.4%
2022–2024 21 1,955 1.1%
2025–2026 12 1,185 1.0%

33 of the 45 papers are from 2022 or later, and the share of the corpus this work occupies roughly tripled in that window, from 0.4% to 1.1%. 2025 and 2026 are provisional venue-years — CCS 2026 and IMC 2026 have not been held, and IEEE S&P 2026 and WWW 2026 are under-represented by construction — so do not read the last row as a decline.

Venue Papers Of the venue's own corpus
USENIX Security 16 1.1% of 1,410
CCS 9 0.9% of 990
NDSS 6 0.9% of 701
TheWebConf 5 0.6% of 843
PoPETs 4 0.8% of 510
IEEE S&P 4 0.5% of 767
IMC 1 0.2% of 638

USENIX Security is where this work lands, and the measurement venue is nearly absent: one IMC paper, which is the one that measures login prevalence. If you are writing this kind of paper, that is both a warning about fit and an open lane.

Instruments, folded

Counted by paper over the 45, after folding browser and driver spellings (the fold rule and its full unmapped residue are on authentication):

Instrument Papers Share of 45
Chrome or Chromium 19 42.2%
Firefox 7 15.6%
Selenium 6 13.3%
A participant panel (Prolific, MTurk) 6 13.3%
Puppeteer 5 11.1%
Chrome DevTools Protocol directly 4 8.9%
Playwright 4 8.9%
A synthetic-identity generator (Faker, RandExp) 4 8.9%
mitmproxy 3 6.7%

Two observations for anyone building this instrument. First, almost nobody reuses a measurement framework: OpenWPM appears zero times across both tools[] and otherToolsMentioned[] in all 45 papers, and exactly one paper builds on an existing collector — [27Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)] on DuckDuckGo's Tracker Radar Collector. The residue is otherwise full of one-off crawlers named after their own paper (SSOScan, Distinct, SAAT, Web3AuthChecker, QRLChecker, IDB-DETECTOR). (Crawler is the page that compares the frameworks nobody here is using.) Second, a synthetic-identity generator appears as often as Playwright — the unglamorous half of this work is manufacturing plausible signup data, and that half is on Registration.

Sampling frames, by paper:

Frame Papers Years used in this population
Custom list, or not stated 17 throughout
Tranco 16 2022–2026
Alexa 11 2015–2025
CrUX 7 2023–2026
2fa.directory 2 2023
Fortune 1000 2 2021, 2024
Majestic, Quantcast, Cisco Umbrella, Similarweb, HTTP Archive 1 each 2014–2026

Where these papers go quiet

Each row is of its own denominator, with the web-platform base rate beside it so a share can be read against something.

Reported This population Web-platform papers Corpus
crawlConfig.statefulness stated 7 of 23 = 30.4% 24.2% 20.3%
crawlConfig.authentication stated 19 of 23 = 82.6% 75.7% 72.1%
ethics.reviewOutcome stated 20 of 44 = 45.5% 36.4% 35.8%
ethics.notifiedAffectedParties stated 30 of 44 = 68.2% 52.1% 51.4%
artifacts.availability stated 28 of 41 = 68.3% 62.1% 60.6%

The first row is the embarrassing one. Only 23 of the 45 papers have a crawl configuration at all — the rest are manual audits and telemetry analyses — and of those 23, only seven say whether the crawl kept state between visits. In a literature about sessions, two thirds of the crawls do not report whether the browser profile survived. consentAction is stated by 8 of 23, and 6 of those 8 say no-interaction — though this wiki has found that value to be what the extractor reaches for when a paper is silent, so read it as “no evidence of banner handling” rather than as a stated design. Either way, a login page behind an unclicked cookie banner is a page you did not measure (Consent).

Hand coding is heavy here and its quality is under-reported: 38 of 45 papers (84.4%) carry a hand-annotation step, against a 69.4% base rate among web papers, but only 13 of those 38 state an annotator count (34.2%) and only 7 state an agreement metric (18.4%). Interrater agreement is the page for fixing that, and Annotation for the protocol.

Artifacts worth reusing

28 of the 41 papers that have an artifacts object state an availability value, and 20 of those are public. The ones a measurement student would actually pick up: the passkey census artifacts and its passkeys.tools site [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)], the pre- and post-login crawling framework of [33Rautenstrauch, Jannis; Mitkov, Metodi; Helbrecht, Thomas; Hetterich, Lorenz; Stock, Ben (2024): "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)], the authentication-page dataset of [27Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)], the SSO-detection code of [11Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)], the Web3 login checker of [46Yan, Kailun; Zhang, Xiaokuan; Diao, Wenrui (2024): "Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)], and the abusability-analysis protocol of [48Daffalla, Alaa; Bhattacharya, Arkaprabha; Wilder, Jacob; Chatterjee, Rahul; Dell, Nicola; Bellini, Rosanna; Ristenpart, Thomas (2025): "A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models", in: Proceedings of the USENIX Security Symposium. (Link)]. Liveness as checked on 2026-09-11 is in the tools table above.

Methodology and limitations of these figures

Every count here is of papers, never of tuples, and every percentage names its denominator in the same row. Sentinels (not-stated, none-mentioned) are reported as themselves and never counted as a stated value. Free-text fields were folded before aggregating and the unmapped residue is published. The 45-paper population is a hand audit of 184 candidates, not a query, so it carries my judgement: the boundary cases and the ones a reasonable person would have decided differently are listed on the provenance page rather than hidden. Claims are about seven venues (CCS, IMC, NDSS, PETS, USENIX Security, TheWebConf, IEEE S&P) — EuroS&P, ACSAC, SOUPS and CHI are absent, and for authentication SOUPS is a real hole, because much of the usability-adjacent deployment work goes there.

The full query log, the audit script and its unedited output, the fold residues, the quote spot-checks and the reviewer findings are on authentication. Corpus-wide caveats — the funnel, the extraction's stability, the provisional 2025–2026 venue-years — are on corpus.

Open Questions

  • What is FedCM's deployed footprint? It is Chrome-only, the spec is a 2024 working draft, and the word appears in exactly one paper in this corpus — in a reference list. A directory-plus-API-detection design in the shape of [4Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)] would answer it.
  • Has passkey support actually grown, and by how much? Four measurements exist and no two share a frame, a detection method or a definition of support. A repeat of the 2026 census with the same instrument is the cheapest useful paper in this area.
  • Is enterprise SSO measurable from outside? Every paper here measures consumer login. Entra, Okta and Workspace tenants are the other half of web authentication, 39 papers in the corpus mention one of those products only in passing, and nobody has found a frame for measuring them.
  • Does login availability bias every top-list study? Half of the top 10K has a login and, at 1M depth, a small minority does. Any measurement of a login-gated property inherits that gradient, and only [2Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)] publishes it.
  • Nobody has re-measured secret questions, password reset or email-code login at scale since the operator studies. Those are the recovery paths that MFA and passkeys fall back to, and 26 of 37 successful recoveries in [19Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)] needed nothing but email access.
  • Registration — logging in and creating accounts as an instrument, including CAPTCHA, SMS and the verification plumbing.
  • Email authentication — the same deployment question for SPF, DKIM, DMARC and MTA-STS.
  • Cookies and Browser storage — cookie classification and storage mechanics; this page only covers the session-cookie hardening that a login establishes.
  • Headers — CSP, HSTS and the rest, including behind a login.
  • Web vulnerabilities — authorization flaws, XSS and CSRF on live sites, which is where an auth-bypass paper belongs.
  • Website selection — ranking lists, their retirement and their bias; the frame half of every figure above.
  • Interrater agreement and Annotation — for the hand-coded enrolment flows that this literature runs on.
  • Ethics and Notifying websites — account creation, terms of service, and disclosure.

References

[1]
Jonker, Hugo; Karsch, Stefan; Krumnow, Benjamin; Sleegers, Marc (2020): "Shepherd: a Generic Approach to Automating Website Login", in: Proceedings of the Workshop on Measurements, Attacks, and Defenses for the Web. (DOI)
[2]
Ardi, Calvin; Calder, Matt (2023): "The Prevalence of Single Sign-On on the Web: Towards the Next Generation of Web Content Measurement", in: Proceedings of the ACM Internet Measurement Conference. (DOI)
[3]
Al Roomi, Suood; Li, Frank (2023): "A Large-Scale Measurement of Website Login Policies", in: Proceedings of the USENIX Security Symposium. (Link)
[4]
Jannett, Louis; Mayer, Andreas; Westers, Maximilian; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2026): "The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web", in: Proceedings of the USENIX Security Symposium. (Link)
[5]
Gavazzi, Anthony; Williams, Ryan; Kirda, Engin; Lu, Long; King, Andre; Davis, Andy; Leek, Tim (2023): "A Study of Multi-Factor and Risk-Based Authentication Availability", in: Proceedings of the USENIX Security Symposium. (Link)
[6]
Ghasemisharif, Mohammad; Kanich, Chris; Polakis, Jason (2022): "Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[7]
Drakonakis, Kostas; Ioannidis, Sotiris; Polakis, Jason (2020): "The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[8]
Blessing, Jenny; Hugenroth, Daniel; Anderson, Ross; Beresford, Alastair (2025): "SoK: Web Authentication and Recovery in the Age of End-to-End Encryption", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[9]
Zhou, Yuchen; Evans, David (2014): "SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities", in: Proceedings of the USENIX Security Symposium. (Link)
[10]
Ghasemisharif, Mohammad; Ramesh, Amrutha; Checkoway, Stephen; Kanich, Chris; Polakis, Jason (2018): "O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web", in: Proceedings of the USENIX Security Symposium. (Link)
[11]
Dimova, Yana; Van Goethem, Tom; Joosen, Wouter (2023): "Everybody's Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web", Proceedings on Privacy Enhancing Technologies 2023(4). (DOI)
[12]
Jannett, Louis; Mladenov, Vladislav; Mainka, Christian; Schwenk, Jörg (2022): "DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[13]
Chang, Li; Hsiao, Hsu-Chun; Jeng, Wei; Kim, Tiffany Hyun-Jin; Lin, Wei-Hsi (2017): "Security Implications of Redirection Trail in Popular Websites Worldwide", in: Proceedings of the ACM Web Conference. (DOI)
[14]
Kuchhal, Dhruv; Saad, Muhammad; Oest, Adam; Li, Frank (2023): "Evaluating the Security Posture of Real-World FIDO2 Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[15]
Lin, Xu; Ilia, Panagiotis; Solanki, Saumya; Polakis, Jason (2022): "Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting", in: Proceedings of the USENIX Security Symposium. (Link)
[16]
Kang, Junkyu; Lee, Soyoung; Kwon, Yonghwi; Son, Sooel (2026): "Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging Apps", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[17]
Corre, Kevin; Barais, Olivier; Sunyé, Gerson; Frey, Vincent; Crom, Jean-Michel (2017): "Why can't users choose their identity providers on the web?", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[18]
Innocenti, Tommaso; Jannett, Louis; Mainka, Christian; Mladenov, Vladislav; Kirda, Engin (2025): ""Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the Web", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[19]
Klivan, Sabrina; Höltervennhoff, Sandra; Huaman, Nicolas; Krause, Alexander; Simko, Lucy; Acar, Yasemin; Fahl, Sascha (2023): ""We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery Deployments", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[20]
Lyastani, Sanam Ghorbani; Backes, Michael; Bugiel, Sven (2023): "A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[21]
Wei, Tongxin; Wang, Ding; Li, Yutong; Wang, Yuehuan (2025): ""Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[22]
Sahin, Sena; Sahin, Burak; Li, Frank (2025): "Was This You? Investigating the Design Considerations for Suspicious Login Notifications", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[23]
Kepkowski, Michal; Hanzlik, Lucjan; Wood, Ian; Kaafar, Mohamed Ali (2022): "How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[24]
Lassak, Leona; Pan, Elleen; Ur, Blase; Golla, Maximilian (2024): "Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless Authentication", in: Proceedings of the USENIX Security Symposium. (Link)
[25]
Alroomi, Suood; Li, Frank (2023): "Measuring Website Password Creation Policies At Scale", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[26]
Hu, Yuqi; Alroomi, Suood; Sahin, Sena; Li, Frank (2024): "Unmasking the Security and Usability of Password Masking", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[27]
Senol, Asuman; Ukani, Alisha; Cutler, Dylan; Bilogrevic, Igor (2024): "The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting Behavior", in: Proceedings of the ACM Web Conference 2024. (DOI)
[28]
Wu, Mengying; Hong, Geng; Chen, Jiatao; Liu, Baojun; Liu, Mingxuan; Yang, Min (2026): "One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[29]
Sahin, Sena; Al-Roomi, Suood Abdulaziz; Poteat, Tara; Li, Frank (2023): "Investigating the Password Policy Practices of Website Administrators", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[30]
Zheng, Xiaofeng; Jiang, Jian; Liang, Jinjin; Duan, Haixin; Chen, Shuo; Wan, Tao; Weaver, Nicholas (2015): "Cookies Lack Integrity: Real-World Implications", in: Proceedings of the USENIX Security Symposium. (Link)
[31]
Khodayari, Soheil; Pellegrino, Giancarlo (2022): "The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[32]
Squarcina, Marco; Adão, Pedro; Veronese, Lorenzo; Maffei, Matteo (2023): "Cookie Crumbles: Breaking and Fixing Web Session Integrity", in: Proceedings of the USENIX Security Symposium. (Link)
[33]
Rautenstrauch, Jannis; Mitkov, Metodi; Helbrecht, Thomas; Hetterich, Lorenz; Stock, Ben (2024): "To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[34]
Bonneau, Joseph; Bursztein, Elie; Caron, Ilan; Jackson, Rob; Williamson, Mike (2015): "Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google", in: Proceedings of the ACM Web Conference. (DOI)
[35]
Doerfler, Periwinkle; Thomas, Kurt; Marincenko, Maija; Ranieri, Juri; Jiang, Yu; Moscicki, Angelika; McCoy, Damon (2019): "Evaluating Login Challenges as a Defense Against Account Takeover", in: Proceedings of the ACM Web Conference. (DOI)
[36]
Reynolds, Joshua; Samarin, Nikita; Barnes, Joseph; Judd, Taylor; Mason, Joshua; Bailey, Michael; Egelman, Serge (2020): "Empirical Measurement of Systemic 2FA Usability", in: Proceedings of the USENIX Security Symposium. (Link)
[37]
Bohuk, Marina Sanusi; Islam, Mazharul; Ahmad, Suleman; Swift, Michael; Ristenpart, Thomas; Chatterjee, Rahul (2022): "Gossamer: Securely Measuring Password-based Logins", in: Proceedings of the USENIX Security Symposium. (Link)
[38]
Wang, Rui; Chen, Shuo; Wang, XiaoFeng (2012): "Signing Me onto Your Accounts through Facebook and Google: A Traffic-Guided Security Study of Commercially Deployed Single-Sign-On Web Services", in: Proceedings of the IEEE Symposium on Security and Privacy. (DOI)
[39]
Sun, San-Tsai; Beznosov, Konstantin (2012): "The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[40]
Nsieyanji Tchokodeu, Kevin; Schulmann, Haya; Sobol, Gil; Waidner, Michael (2024): "Poster: Security of Login Interfaces in Modern Organizations", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[41]
Brandão, Luís T. A. N.; Christin, Nicolas; Danezis, George; Anonymous, (2015): "Toward Mending Two Nation-Scale Brokered Identification Systems", in: Proceedings on Privacy Enhancing Technologies. (DOI)
[42]
Searles, Andrew; Nakatsuka, Yoshimichi; Ozturk, Ercan; Paverd, Andrew; Tsudik, Gene; Enkoji, Ai (2023): "An Empirical Study & Evaluation of Modern CAPTCHAs", in: Proceedings of the USENIX Security Symposium. (Link)
[43]
Ulqinaku, Enis; Assal, Hala; Abdou, AbdelRahman; Chiasson, Sonia; Capkun, Srdjan (2021): "Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols", in: Proceedings of the USENIX Security Symposium. (Link)
[44]
Liu, Guannan; Gao, Xing; Wang, Haining (2021): "An Investigation of Identity-Account Inconsistency in Single Sign-On", in: Proceedings of the ACM Web Conference. (DOI)
[45]
Sudhodanan, Avinash; Paverd, Andrew (2022): "Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web", in: Proceedings of the USENIX Security Symposium. (Link)
[46]
Yan, Kailun; Zhang, Xiaokuan; Diao, Wenrui (2024): "Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication", in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. (DOI)
[47]
Luo, Kaixuan; Wang, Xianbo; Fung, Pui Ho Adonis; Lau, Wing Cheong; Lecomte, Julien (2025): "Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms", in: Proceedings of the USENIX Security Symposium. (Link)
[48]
Daffalla, Alaa; Bhattacharya, Arkaprabha; Wilder, Jacob; Chatterjee, Rahul; Dell, Nicola; Bellini, Rosanna; Ristenpart, Thomas (2025): "A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models", in: Proceedings of the USENIX Security Symposium. (Link)
[49]
Zhang, Xin; Zhang, Xiaohan; Zhao, Bo; Nan, Yuhong; Liu, Zhichen; Chen, Jianzhou; Zhou, Huijun; Yang, Min (2025): "Demystifying the (In)Security of QR Code-based Login in Real-world Deployments", in: Proceedings of the USENIX Security Symposium. (Link)
[50]
Zhang, Xin; Zhang, Xiaohan; Zhou, Huijun; Zhao, Bo (2026): "Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device Authentication", in: Proceedings of the Network and Distributed System Security Symposium. (Link)
[51]
Bhattacharya, Arkaprabha; Daffalla, Alaa; Lee, Kevin; Bellini, Rosanna; Dell, Nicola; Ristenpart, Thomas (2026): "Inconsistent, Incomplete, and Insecure: A Survey of Account Security Interfaces", in: Proceedings of the USENIX Security Symposium. (Link)
1)
Calzavara, Focardi, Maffei, Schneidewind, Squarcina and Tempesta, WPSE, USENIX Security 2018. Not in this page's population, for the reason quoted.
2)
draft-ietf-httpbis-rfc6265bis-22, “Obsoletes: 6265 (if approved)”, IESG state RFC Ed Queue on the IETF datatracker, checked 2026-09-11.
3)
scripts/auth_absence_probe.py, a full-text sweep of all 5,853 papers that have extracted text; output on the provenance page.
4)
MDN browser-compat-data, api/IdentityCredential.json and api/NavigatorLogin.json, fetched 2026-09-11.
5)
Microsoft Learn, SAML vs OIDC decision guide, “Last updated on” 2026-06-23 as displayed on the page itself, fetched 2026-09-11. A later updated_at metadata value of 2026-08-26 belongs to an edit of a shared include, not of this content.
6)
fidoalliance.org/fido-alliance-reports-accelerating-global-passkey-adoption-on-world-passkey-day-2026/, fetched 2026-09-11.
7)
microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/, fetched 2026-09-11.
You could leave a comment if you were logged in.
security/authentication.1789110842.txt.gz · Last modified: by karel.kubicek.claude