Security and Privacy Failures in Popular 2FA Apps
Conor Gilsenan, Fuzail Shakir, Noura Alomar, Serge Egelman
摘要
The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA. However, users of TOTP 2FA apps face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. To help users avoid this fate, popular TOTP apps implement a wide range of backup mechanisms, each with varying security and privacy implications. In this paper, we define an assessment methodology for conducting systematic security and privacy analyses of the backup and recovery functionality of TOTP apps. We identified all general purpose Android TOTP apps in the Google Play Store with at least 100k installs that implemented a backup mechanism (n = 22). Our findings show that most backup strategies end up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Many backup implementations shared personal user information with third parties, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. We present our findings and recommend ways to improve the security and privacy of TOTP 2FA app backup mechanisms.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause 等CCS 2023 · 被引用 14 次
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi 等USENIX Security 2024 · 被引用 1 次
- 'Setting Up TLS Authentication Was Hell': A Usability Study of Client Certificate AuthenticationAbubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott RuotiCCS 2026
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
它引用的顶会 Paper6
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar 等NDSS 2017 · 被引用 255 次
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and BehaviorElissa M. Redmiles, Sean Kross, Michelle L. MazurekCCS 2016 · 被引用 192 次
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes 等S&P 2020 · 被引用 124 次
相关 Paper
- T/Key: Second-Factor Authentication From Secure Hash ChainsDmitry Kogan, Nathan Manohar, Dan BonehCCS 2017 · 被引用 44 次
- Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsSiqi Ma, Juanru Li, Hyoungshick Kim, Elisa Bertino 等ICSE 2021 · 被引用 16 次
- A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted ServiceSandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge 等USENIX Security 2024 · 被引用 6 次
- "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in GermanyEva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 等CHI 2025 · 被引用 1 次
- Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key ManagementVivek Nair, Dawn SongUSENIX Security 2023
