UA SPECTRAL Lab — usable security and privacy research

AI Authentication Study

Please read this page before deciding whether to begin the task.

Data-saving notice: responses from this test session will not be stored.
Task time About 3 minutes
Activity Interactive task and follow-up survey
Participation Voluntary

You are invited to take part in a usable security and privacy research study about authentication and account permissions in the AI era. The study is led by an approved university research team. Being in this study is optional.

Please approach the task as you would an ordinary account-access request. Use only the study-provided account details shown on the page. Do not enter a personal email address, password, payment detail, or other credential.

Sign in to TaskFlow

Choose how you want to sign in

or

Continue with Provider A

TaskFlow wants to use your selected provider account to sign you in

You are signing in as student@gmail.com

Verify it's you

Approve the sign-in request to continue

Select the number shown in the phone notification, then approve.

9:41 LTE 100%
Phone notification
Provider notification
Sign-in request
Use this number to approve the TaskFlow sign-in.
--

One quick question

One more step before your code.

Thinking back to the screen you just saw, which of these did the TaskFlow AI Assistant ask permission to do? Select all that you remember.
What was the name of the AI assistant on the permission screen you just saw?
Did anything about the access it asked for seem broader than a TaskFlow AI Assistant should need?

Interactive task complete

Debrief: The account, sign-in, phone-notification, and AI permission screens were simulated and did not connect to a real provider, account, or payment method. This was disclosed after the task so that advance knowledge would not influence how participants reviewed the screens.

The study examines attention and decision-making across authentication steps. One permission was intentionally broader than TaskFlow needed: access to saved payment methods to make purchases. Your response is not a test of you, and no real access was granted regardless of which button you selected.

Next step: complete the Qualtrics survey. To finish the study, select the button below and submit the follow-up survey. Participation remains voluntary, and you may stop at any time.

Here is your participant code. The survey will receive it automatically when you select the button, but keep it available in case the survey asks for it.

P-XXXXXXXXXXXXXXXXXXXX

Your code

Saving task data...

Saving task data...

If you decide that you do not want your task data used, you may submit a removal request associated with your participant code. The research team will process the request under the approved study procedure.

Removal request recorded for this participant code.

If a new survey tab does not open, select “Continue to the Qualtrics survey” again. Keep this window open and use the participant code shown above if the survey asks for it.