We conducted a user study to compare a prototype image authentication system to traditional recall-based authentication systems (passwords and PINs). We compare two types of image portfolios, one using Random Art images and another which uses photographs. The user study consists of three phases: interviews, low-fidelity testing and formal prototype testing. In all phases participants were selected to be representative of the general population of computer users. An equal number of novice and expert users were selected, all of who were familiar with password authentication.