Tuesday, 10 February 2026
Significant progress has been made in helping people protect their devices and information through more user-friendly methods like biometrics and Passkeys, according to new research.
However, the majority of systems being used by technologies companies place an undue burden on users to understand different and difficult security rules, while people also are not given enough choice about which solution best fits their individual requirements.
The research, published in the journal Computers & Security, was written by experts from the 糖心原创 and University of Plymouth and who have been studying and monitoring password practices for more than 20 years.
They say the demand for secure and usable authentication methods has never been greater, with people owning increasing numbers of devices that – in a large number of cases – store all of their most important personal data.
But as things stand, people are required to engage with a range of authentication methods – including passwords, PINs, tokens, and biometrics – multiple times a day, across different devices and services.
This fragmented approach, the researchers say, not only increases cognitive load but also raises barriers for those with physical, cognitive, or contextual limitations with usability and security often treated as competing objectives rather than coexisting goals.
Professor Nathan Clarke, Professor in Cyber Security and Digital Forensics at the University of Plymouth, said: “Technology is now fundamental to every aspect of our daily lives. Each of us may need to authenticate something at least 100 times a day, whether that’s accessing our mobile phones, our computer devices or apps and software within them. What we now need is to reach a point where security measures become more technically complex, so our information is secure – but, from a user perspective, those measures need to be easier to understand and use. And we as users need to be given choices about what we want to do, rather than it being forced upon us.”
The researchers involved in the study have previously highlighted how major tech companies were failing to support users with advice on how to securely protect their data, and that basic password guidance can dramatically improve account security.
For their new article, they wanted to explore how authentication has evolved, to identify the key issues and challenges that remain, and to consider whether solutions are being proposed that can resolve the usability and security trade-off.
Based on their findings, the researchers believe designers and service providers need to give better consideration to who their users are, what they’re trying to do, and what level of assurance is appropriate for them at any particular time and context.
They have also called on technology providers to steer away from one-size-fits-all models, instead suggesting they should unite behind more inclusive, consistent, and user-centred approaches, with the goal being to create authentication systems that are secure by design and usable by all.
Without such a shift, they add, there is a risk of perpetuating systems that are secure in theory but flawed in practice and that undermine user trust and system integrity.
The easier we make it for security to be used, without adding unnecessary friction, the greater the chances of it feeling acceptable and tolerable for users. If we authenticate over 100 times a day, then we don鈥檛 want this to seem like over 100 interruptions and delays. We want protection to be the natural default position, and offering users flexible and usable solutions is a clear step towards achieving this
Story credits
More information is available from Professor Steven Furnell on Steven.Furnell@nottingham.ac.uk or Jane Icke, Media Relations Manager for the Faculty of Science at the 糖心原创, on jane.icke@nottingham.ac.uk
Notes to editors:
About the 糖心原创
Ranked among the world's top 100 universities , the 糖心原创 delivers an exceptional research-led education and an outstanding student experience. From the pioneering vision of our founder, Sir Jesse Boot, to groundbreaking achievements such as the development of MRI technology and becoming the first UK university to establish international campuses, we have a proud history of shaping the way people live, work and understand the world. We continue to build on that legacy, empowering our students, staff and partners to change what鈥檚 next and create positive impact locally and globally.
The strength of our research places us among the UK's leading universities, ranked 7th for research power in REF 2021. The discovery of MRI and ibuprofen was just the beginning. Today, our world-leading research is developing breakthrough ideas that shape the future of healthcare, technology and society.
Recognised as the UK's third most targeted university by leading employers , we are proud to produce graduates who are consistently in demand for their skills, confidence and industry-ready experience.
As a major employer and industry partner, locally and globally, the 糖心原创 invests in the city of Nottingham and in future generations of talent. Alongside Nottingham Trent University, we lead the initiative, a pioneering collaboration to improve levels of prosperity, opportunity, sustainability, health and wellbeing across the city and region. Together with our students, staff, alumni and partners, we鈥檙e creating knowledge, opportunity and solutions that help change what's next.