Breaking Mobile Notification-based Authentication with Concurrent Attacks Outside of Mobile Devices
Ahmed Tanvir Mahdad, Mohammed Jubur, Nitesh Saxena
Abstract
Notification-based authentication is an emerging Two-Factor Authentication (2FA) and passwordless solution that leverages interactive notifications on mobile devices to establish an additional layer of security beyond passwords. This method has gained popularity due to its convenience and ease of deployment in organizational settings. In this work, we aim to evaluate the effectiveness of notification-based authentication systems when a malicious entity is present on the user's computer, such as a keylogger or malicious extension, without compromising the mobile devices or communication channels. Furthermore, we investigate how the lack of information provided to users during the authentication workflow can lead to the approval of malicious authentication requests. Notably, we highlight the vulnerability of cross-service attacks, where an attacker authenticates to Service B while the user is attempting to authenticate to Service A. Our proof-of-concept attack program demonstrates the susceptibility of various notification-based authentication systems, and our user study reveals an alarming 82.2% cross-service attack success rate. These findings suggest a potential vulnerability in notification-based authentication systems, where the attacker compromise user account without compromising possession-factor device, such as smartphones.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bf66b885-32cc-4d24-a30a-b40f00a28b6eCited by top-tier papers3
- Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device AuthenticationXin Zhang, Xiaohan Zhang, Huijun Zhou, Bo ZhaoNDSS 2026
- SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic ProposalsMd Mojibur Rahman Redoy Akanda, Amanda Lacy, Nitesh SaxenaUSENIX Security 2025
- Broken Access: On the Challenges of Screen Reader Assisted Two-Factor and Passwordless AuthenticationMd Mojibur Rahman Redoy Akanda, Ahmed Tanvir Mahdad, Nitesh SaxenaWWW 2025
Related papers
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 3 citations
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
- Authenticating Drivers Using Automotive BatteriesLiang He, Yuanchao Shu, Youngmoon Lee, Dongyao Chen et al.UbiComp 2021 · 3 citations
