Security and Usability Evaluation of Text-Based Captchas on Mobile Interface


Merdanoğlu N., Onay Durdu P.

Human Factors and Ergonomics in Manufacturing and Service Industries, cilt.35, sa.3, 2025 (SCI-Expanded) identifier identifier

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 35 Sayı: 3
  • Basım Tarihi: 2025
  • Doi Numarası: 10.1002/hfm.70007
  • Dergi Adı: Human Factors and Ergonomics in Manufacturing and Service Industries
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Social Sciences Citation Index (SSCI), Scopus, Academic Search Premier, Compendex, Environment Index, INSPEC, Psycinfo
  • Anahtar Kelimeler: captcha, HIP, security, usability, usability evaluation, usability testing
  • Kocaeli Üniversitesi Adresli: Evet

Özet

Captchas are used as Human interaction proof mechanisms during the authentication process on software applications. They should provide resistance to various attacks to increase security but also be understood easily to ensure usability. Increasing the security generally reduces usability, so it is necessary to use captchas that will meet both the security and usability needs of users balanced. Within the scope of this study, a text-based captcha scheme that end-users commonly encounter during their daily interactions in mobile applications is selected and investigated to determine both a more robust and usable one for users. Six different text-based captcha types, which were distortion-based, non-distortion-based, dictionary-based, random-based, low contrast, and full contrast, were compared in terms of security and usability. Initially, security tests were applied. Afterwards, user tests were conducted with 30 participants. According to security test results, distortion, low contrast, and random-based captcha types were determined to be more robust, respectively. The most usable captcha type among the secure captcha types was determined as a random string captcha based on the user test results. Thus, it has been found that a balanced level of security and usability can be achieved when mobile application developers choose to use a random string captcha when designing interfaces. Recommendations to guide mobile interface developers were provided based on the findings obtained both from the user study and previous relevant literature.