Breaking Mobile Notification-based Authentication with Concurrent Attacks Outside of Mobile Devices
Ahmed Tanvir Mahdad, Mohammed Jubur, Nitesh Saxena
摘要
Notification-based authentication is an emerging Two-Factor Authentication (2FA) and passwordless solution that leverages interactive notifications on mobile devices to establish an additional layer of security beyond passwords. This method has gained popularity due to its convenience and ease of deployment in organizational settings. In this work, we aim to evaluate the effectiveness of notification-based authentication systems when a malicious entity is present on the user's computer, such as a keylogger or malicious extension, without compromising the mobile devices or communication channels. Furthermore, we investigate how the lack of information provided to users during the authentication workflow can lead to the approval of malicious authentication requests. Notably, we highlight the vulnerability of cross-service attacks, where an attacker authenticates to Service B while the user is attempting to authenticate to Service A. Our proof-of-concept attack program demonstrates the susceptibility of various notification-based authentication systems, and our user study reveals an alarming 82.2% cross-service attack success rate. These findings suggest a potential vulnerability in notification-based authentication systems, where the attacker compromise user account without compromising possession-factor device, such as smartphones.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- Anchors of Trust: A Usability Study on User Awareness, Consent, and Control in Cross-Device AuthenticationXin Zhang, Xiaohan Zhang, Huijun Zhou, Bo ZhaoNDSS 2026
- SoK: Inaccessible & Insecure: An Exposition of Authentication Challenges Faced by Blind and Visually Impaired Users in State-of-the-Art Academic ProposalsMd Mojibur Rahman Redoy Akanda, Amanda Lacy, Nitesh SaxenaUSENIX Security 2025
- Broken Access: On the Challenges of Screen Reader Assisted Two-Factor and Passwordless AuthenticationMd Mojibur Rahman Redoy Akanda, Ahmed Tanvir Mahdad, Nitesh SaxenaWWW 2025
相关 Paper
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 被引用 6 次
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 被引用 3 次
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
- Authenticating Drivers Using Automotive BatteriesLiang He, Yuanchao Shu, Youngmoon Lee, Dongyao Chen 等UbiComp 2021 · 被引用 3 次
