The Sounds of the Phones: Dangers of Zero-Effort Second Factor Login based on Ambient Audio
Babins Shrestha, Maliheh Shirvanian, Prakash Shrestha, Nitesh Saxena
摘要
Reducing user burden underlying traditional two-factor authentication constitutes an important research effort. An interesting representative approach, Sound-Proof, leverages ambient sounds to detect the proximity between the second factor device (phone) and the login terminal (browser). Sound-Proof was shown to be secure against remote attackers and highly usable, and is now under early deployment phases.
In this paper, we identify a weakness of the Sound-Proof system, namely, the remote attacker does not have to predict the ambient sounds near the phone as assumed in the Sound-Proof paper, but rather can deliberately make-or wait for-the phone to produce predictable or previously known sounds (e.g., ringer, notification or alarm sounds). Exploiting this weakness, we build Sound-Danger, a full attack system that can successfully compromise the security of Sound-Proof. The attack involves buzzing the victim user's phone, or waiting for the phone to buzz, and feeding the corresponding sounds at the browser to login on behalf of the user. The attack works precisely under Sound-Proof's threat model.
Our contributions are three-fold. First, we design and develop the Sound-Danger attack system that exploits a wide range of a smartphone's functionality to break Sound-Proof, such as by actively making a phone or VoIP call, sending an SMS and creating an app-based notification, or by passively waiting for the phone to trigger an alarm. Second, we re-implement Sound-Proof's audio correlation algorithm and evaluate it against Sound-Danger under a large variety of attack settings. Our results show that many of our attacks succeed with a 100% chance such that the Sound-Proof correlation algorithm will accept the attacked audio samples as valid. Third, we collect general population statistics via an online survey to determine the phone usage habits relevant to our attacks. We then use these statistics to show how our different correlationbased attacks can be carefully executed to, for instance, compromise about 57% user accounts in just the first attempt and about 83% user accounts in less than a day. Finally, we provide some mitigation strategies and future directions that may help overcome some of our attacks and strengthen Sound-Proof.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Proximity-Echo: Secure Two Factor Authentication Using Active Sound SensingYanzhi Ren, Ping Wen, Hongbo Liu, Zhourong Zheng 等INFOCOM 2021 · 被引用 15 次
- Secure and Robust Two Factor Authentication via Acoustic FingerprintingYanzhi Ren, Tingyuan Yang, Zhiliang Xia, Hongbo Liu 等INFOCOM 2023 · 被引用 7 次
相关 Paper
- From One Form of Energy to Another: Laser-Induced Injection Attacks on Acoustic SensingLupeng Zhang, Minhao Cui, Wenwei Li, Xuefu Dong 等UbiComp 2026 · 被引用 1 次
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 被引用 3 次
- Remote Attacks on Speech Recognition Systems Using Sound from Power SupplyLanqing Yang, Xinqi Chen, Xiangyong Jian, Leping Yang 等USENIX Security 2023
- A Security and Usability Analysis of Local Attacks Against FIDO2Tarun Kumar Yadav, Kent E. SeamonsNDSS 2024
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
