Informing Google’s future sign-in, authentication,
and user account experiences
The Challenge.
Consumer Technology
〰️
Security & Trust
〰️
Future Visioning
〰️
Consumer Technology 〰️ Security & Trust 〰️ Future Visioning 〰️
Google's Cross-Device Authentication (XDA) team wanted to understand how people navigate authentication across increasingly connected ecosystems of phones, laptops, smart TVs, watches, speakers, and smart home devices.
The challenge was that authentication is largely invisible. Product teams think about authentication every day; users rarely think about it until something breaks. Google needed a behavioral understanding of how people make authentication decisions, how they perceive risk, and what future authentication experiences they would trust.
Methodologies &
My Role.
01
Remote Ethnography
Designed a 3 day diary study with 14 participants to capture authentication behaviors and map device ecosystems.
02
In-depth Interviews
Conducted 14 ninety-minute interviews exploring authentication behaviors, cross-device journeys, shared device experiences, and future-state concepts.
03
Project Management & Leadership
Managed client relationship, project scope, budget, work plan, and final deliverable development. Developed recruitment strategy, screener, and research materials.
04
Synthesis & Strategy
Translated behavioral patterns into product opportunities, design principles, and visual frameworks that aligned Product, UX, and Engineering teams.
05
Executive Storytelling
Led synthesis, opportunity framing, and narrative development, transforming research into actionable product strategy and executive presentations.
Key Insight #3: Physical Safety Creates a False Sense of Digital Safety
Users often assumed devices in their possession were inherently secure. If a device was:
In their hand
In their home
Nearby
Many users assumed additional authentication was unnecessary, even when significant personal information remained accessible.
Key Insight #1: Users Fall Along a Security-Convenience Spectrum
Rather than one universal mindset, users clustered around two distinct behavioral orientations:
Short-Cutters:
Prioritize speed and convenience
Use stronger authentication only for data they perceive as highly valuable
Prefer fewer accounts and simpler credentials
Guards:
Prioritize security
Actively seek stronger authentication methods
Maintain separate accounts and unique credentials for different purposes
Most users existed somewhere between these two poles.
Recommendation: Design for distinct user types.
Support both Short-Cutters and Guards by offering flexible authentication paths based on user preference and tolerance for risk.
Key Insight #2: Perceived Value Drives Security Behavior
Users didn't evaluate authentication based on actual risk. Instead, they evaluated it based on what they believed the underlying data was worth. People expected strong authentication for:
Financial information
Medical information
Personally identifiable information
But frequently underestimated risk on seemingly low-value accounts that still contained payment information or personal data.
Recommendation: Match security to context.
Tailor authentication methods to the perceived value of data, device type, and user context, not just system requirements.
Key Insight #4: People Want One Key to Their Digital Life
Across participants, a consistent future-state vision emerged:
People wanted authentication to disappear.
Near-term, users imagined their phone becoming a trusted key that unlocks all devices and services.
Long-term, users imagined becoming the key themselves, with devices automatically recognizing their identity and granting appropriate access.
Frameworks & Recommendations.
Recommendation: Support everyday management behaviors.
Acknowledge how users currently manage credentials and bridge the gap between informal strategies and secure solutions.
Recommendation: Centralize and simplify the future experience.
Work toward a seamless platform where the phone, or the user, acts as the universal, intelligent key to digital life.
Impact.
Provided foundational behavioral insights to inform future cross-device authentication strategy.
Helped shift product conversations from tech-driven to user-behavior-driven.
Enabled alignment across product, UX, and security stakeholders through clear visual frameworks.
Sparked follow-up projects exploring communal and ambient authentication.