본문

서브메뉴

Exploring the Security and Privacy Impacts of Using 2FA Apps
Exploring the Security and Privacy Impacts of Using 2FA Apps
Exploring the Security and Privacy Impacts of Using 2FA Apps

Detailed Information

자료유형  
 학위논문 서양
최종처리일시  
20260202103547
ISBN  
9798288863820
DDC  
004
저자명  
Gilsenan, Conor.
서명/저자  
Exploring the Security and Privacy Impacts of Using 2FA Apps
발행사항  
[Sl] : University of California, Berkeley, 2025
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2025
형태사항  
183 p
주기사항  
Source: Dissertations Abstracts International, Volume: 87-01, Section: A.
주기사항  
Advisor: Egelman, Serge;Wagner, David.
학위논문주기  
Thesis (Ph.D.)--University of California, Berkeley, 2025.
초록/해제  
요약The Time-based One-Time Password (TOTP) algorithm is a two-factor authentication (2FA) method that is widely deployed, but forces people to face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. Prior work has regularly confirmed that TOTP users are concerned about account lockout and, therefore, has called for improvements to backup and recovery mechanisms. However, the existing backup and recovery options for TOTP users were not well explored in the literature, which is a necessary starting point from which to design improvements. My work fills this gap and explores the functionality of existing backup mechanisms for TOTP users and how they get used in the real world.We reverse engineered the top 22 general purpose Android TOTP apps and found that many backup implementations allowed the developer or other third-parties to access personal user information, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. Most backup strategies also ended up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Next, we surveyed 330 current and former users of popular TOTP apps. A significant portion lacked basic awareness of account lockout risks. Two-thirds of current users had cloud backups enabled, exposing them to some of the security and privacy issues previously uncovered. Many of them did not know the feature existed nor that it was enabled, raising questions about whether they provided informed consent. The majority of current users were uncomfortable with anyone being able to read data from their cloud backups. About one-third had experienced account lockout, but most regained access quickly using alternative 2FA mechanisms (e.g., SMS 2FA). Notably, 13% of current users had no TOTP backup plan at all, putting 10+ million people at heightened risk of account lockout when extrapolated across the 100s of millions of TOTP app users.
일반주제명  
Computer science
일반주제명  
Web studies
일반주제명  
Information science
키워드  
Time-based One-Time Password
키워드  
Two-factor authentication
키워드  
Account lockout
기타저자  
University of California, Berkeley Electrical Engineering & Computer Sciences
기본자료저록  
Dissertations Abstracts International. 87-01A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008260126s2025        us                              c    eng  d
■001000017357691
■00520260202103547
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798288863820
■035    ▼a(MiAaPQ)AAI32041385
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a004
■1001  ▼aGilsenan,  Conor.
■24510▼aExploring  the  Security  and  Privacy  Impacts  of  Using  2FA  Apps
■260    ▼a[Sl]▼bUniversity  of  California,  Berkeley▼c2025
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2025
■300    ▼a183  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  87-01,  Section:  A.
■500    ▼aAdvisor:  Egelman,  Serge;Wagner,  David.
■5021  ▼aThesis  (Ph.D.)--University  of  California,  Berkeley,  2025.
■520    ▼aThe  Time-based  One-Time  Password  (TOTP)  algorithm  is  a  two-factor  authentication  (2FA)  method  that  is  widely  deployed,  but  forces  people  to  face  a  critical  usability  challenge:  maintain  access  to  the  secrets  stored  within  the  TOTP  app,  or  risk  getting  locked  out  of  their  accounts.  Prior  work  has  regularly  confirmed  that  TOTP  users  are  concerned  about  account  lockout  and,  therefore,  has  called  for  improvements  to  backup  and  recovery  mechanisms.  However,  the  existing  backup  and  recovery  options  for  TOTP  users  were  not  well  explored  in  the  literature,  which  is  a  necessary  starting  point  from  which  to  design  improvements.  My  work  fills  this  gap  and  explores  the  functionality  of  existing  backup  mechanisms  for  TOTP  users  and  how  they  get  used  in  the  real  world.We  reverse  engineered  the  top  22  general  purpose  Android  TOTP  apps  and  found  that  many  backup  implementations  allowed  the  developer  or  other  third-parties  to  access  personal  user  information,  had  serious  cryptographic  flaws,  and/or  allowed  the  app  developers  to  access  the  TOTP  secrets  in  plaintext.  Most  backup  strategies  also  ended  up  placing  trust  in  the  same  technologies  that  TOTP  2FA  is  meant  to  supersede:  passwords,  SMS,  and  email.  Next,  we  surveyed  330  current  and  former  users  of  popular  TOTP  apps.  A  significant  portion  lacked  basic  awareness  of  account  lockout  risks.  Two-thirds  of  current  users  had  cloud  backups  enabled,  exposing  them  to  some  of  the  security  and  privacy  issues  previously  uncovered.  Many  of  them  did  not  know  the  feature  existed  nor  that  it  was  enabled,  raising  questions  about  whether  they  provided  informed  consent.  The  majority  of  current  users  were  uncomfortable  with  anyone  being  able  to  read  data  from  their  cloud  backups.  About  one-third  had  experienced  account  lockout,  but  most  regained  access  quickly  using  alternative  2FA  mechanisms  (e.g.,  SMS  2FA).  Notably,  13%  of  current  users  had  no  TOTP  backup  plan  at  all,  putting  10+  million  people  at  heightened  risk  of  account  lockout  when  extrapolated  across  the  100s  of  millions  of  TOTP  app  users.
■590    ▼aSchool  code:  0028.
■650  4▼aComputer  science
■650  4▼aWeb  studies
■650  4▼aInformation  science
■653    ▼aTime-based  One-Time  Password
■653    ▼aTwo-factor  authentication
■653    ▼aAccount  lockout
■690    ▼a0984
■690    ▼a0646
■690    ▼a0723
■71020▼aUniversity  of  California,  Berkeley▼bElectrical  Engineering  &  Computer  Sciences.
■7730  ▼tDissertations  Abstracts  International▼g87-01A.
■790    ▼a0028
■791    ▼aPh.D.
■792    ▼a2025
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17357691▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

Preview

Export

ChatGPT Discussion

AI Recommended Related Books


    New Books MORE
    Statistics for the past 3 years. Go to brief

    Подробнее информация.

    • Бронирование
    • не существует
    • моя папка
    • Первый запрос зрения
    • Non-Book Loan Application
    • Nighttime Book Loan Application
    материал
    Reg No. Количество платежных Местоположение статус Ленд информации
    TF18840 전자도서 대출가능 My Folder 부재도서신고 비도서대출신청 야간 도서대출신청

    * Бронирование доступны в заимствований книги. Чтобы сделать предварительный заказ, пожалуйста, нажмите кнопку бронирование

    Books borrowed together with this book

    Related Popular Books

    Available after logging in.