Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile Apps
Fannv He, Yan Jia, Jiayu Zhao, Yue Fang, Jice Wang, Mengyue Feng, Peng Liu, Yuqing Zhang
Abstract
—Authentication is one of the established practices to ensure user security. Personally identifiable information (PII), such as national identity card number (ID number) and bank card number, is used widely in China’s mobile apps as an additional secret to authenticate users, i.e., PII-as-Factor Au-thentication ( PaFA ). In this paper, we found a new threat that calls on the cautiousness of PaFA : the simultaneous usages and business-related interactions of apps make the authentication strength of a target app weaker than designed. An adversary, who knows fewer authentication factors (only SMS OTP) than a PaFA system required, can break the authentication by gathering information or abusing cross-app authorization from other apps. To systematically study the potential risks, we proposed a semi-automatic system, MAGGIE , to evaluate the security of PaFA in target apps. By measuring 234 real-world apps in Chinese app markets with the help of MAGGIE , we found 75.4% of apps that deployed PaFA can be bypassed, including the popular and sensitive ones (e.g., AliPay, WeChat, UnionPay), leading to severe consequences like hijack user accounts and making unauthorized purchases. Additionally, we conducted a survey to demonstrate the practical implications of the new risk on users. Finally, we reported our findings to the vendors and provided several mitigation measures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0da506d-cd23-4f38-9130-f5aeb0bf3c81Cited by top-tier papers2
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya et al.CCS 2026
- Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud ServicesYizhe Shi, Zhemin Yang, Dingyi Liu, Kangwei Zhong et al.NDSS 2026
Builds on14
- Composite Backdoor Attack for Deep Neural Network by Mixing Existing Benign FeaturesJunyu Lin, Lei Xu, Yingqi Liu, Xiangyu ZhangCCS 2020 · 197 citations
- PASTA: PASsword-based Threshold AuthenticationShashank Agrawal, Peihan Miao, Payman Mohassel, Pratyay MukherjeeCCS 2018 · 84 citations
- This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINsPhilipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth et al.S&P 2020 · 65 citations
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- Demystifying Hidden Privacy Settings in Mobile AppsYi Chen, Mingming Zha, Nan Zhang, Dandan Xu et al.S&P 2019 · 39 citations
Related papers
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou et al.CCS 2026
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 29 citations
- MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-ProgramsZidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao et al.CCS 2024 · 6 citations
- Lie to Me: Abusing the Mobile Content Sharing Service for Fun and ProfitGuosheng Xu, Siyi Li, Hao Zhou, Shucen Liu et al.WWW 2022 · 5 citations
- 'I Can't Even Buy Apples If I Don't Use Mobile Pay?': When Mobile Payments Become Infrastructural in ChinaHong Shen, Cori Faklaris, Haojian Jin, Laura Dabbish et al.CSCW 2020 · 27 citations
