서브메뉴
검색
Exploring the Security and Privacy Impacts of Using 2FA Apps
Exploring the Security and Privacy Impacts of Using 2FA Apps
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260202103547
- ISBN
- 9798288863820
- DDC
- 004
- 저자명
- Gilsenan, Conor.
- 서명/저자
- Exploring the Security and Privacy Impacts of Using 2FA Apps
- 발행사항
- [Sl] : University of California, Berkeley, 2025
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2025
- 형태사항
- 183 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-01, Section: A.
- 주기사항
- Advisor: Egelman, Serge;Wagner, David.
- 학위논문주기
- Thesis (Ph.D.)--University of California, Berkeley, 2025.
- 초록/해제
- 요약The Time-based One-Time Password (TOTP) algorithm is a two-factor authentication (2FA) method that is widely deployed, but forces people to face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. Prior work has regularly confirmed that TOTP users are concerned about account lockout and, therefore, has called for improvements to backup and recovery mechanisms. However, the existing backup and recovery options for TOTP users were not well explored in the literature, which is a necessary starting point from which to design improvements. My work fills this gap and explores the functionality of existing backup mechanisms for TOTP users and how they get used in the real world.We reverse engineered the top 22 general purpose Android TOTP apps and found that many backup implementations allowed the developer or other third-parties to access personal user information, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. Most backup strategies also ended up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Next, we surveyed 330 current and former users of popular TOTP apps. A significant portion lacked basic awareness of account lockout risks. Two-thirds of current users had cloud backups enabled, exposing them to some of the security and privacy issues previously uncovered. Many of them did not know the feature existed nor that it was enabled, raising questions about whether they provided informed consent. The majority of current users were uncomfortable with anyone being able to read data from their cloud backups. About one-third had experienced account lockout, but most regained access quickly using alternative 2FA mechanisms (e.g., SMS 2FA). Notably, 13% of current users had no TOTP backup plan at all, putting 10+ million people at heightened risk of account lockout when extrapolated across the 100s of millions of TOTP app users.
- 일반주제명
- Computer science
- 일반주제명
- Web studies
- 일반주제명
- Information science
- 키워드
- Account lockout
- 기타저자
- University of California, Berkeley Electrical Engineering & Computer Sciences
- 기본자료저록
- Dissertations Abstracts International. 87-01A.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260126s2025 us c eng d■001000017357691
■00520260202103547
■006m o d
■007cr#unu||||||||
■020 ▼a9798288863820
■035 ▼a(MiAaPQ)AAI32041385
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼aGilsenan, Conor.
■24510▼aExploring the Security and Privacy Impacts of Using 2FA Apps
■260 ▼a[Sl]▼bUniversity of California, Berkeley▼c2025
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2025
■300 ▼a183 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-01, Section: A.
■500 ▼aAdvisor: Egelman, Serge;Wagner, David.
■5021 ▼aThesis (Ph.D.)--University of California, Berkeley, 2025.
■520 ▼aThe Time-based One-Time Password (TOTP) algorithm is a two-factor authentication (2FA) method that is widely deployed, but forces people to face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. Prior work has regularly confirmed that TOTP users are concerned about account lockout and, therefore, has called for improvements to backup and recovery mechanisms. However, the existing backup and recovery options for TOTP users were not well explored in the literature, which is a necessary starting point from which to design improvements. My work fills this gap and explores the functionality of existing backup mechanisms for TOTP users and how they get used in the real world.We reverse engineered the top 22 general purpose Android TOTP apps and found that many backup implementations allowed the developer or other third-parties to access personal user information, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. Most backup strategies also ended up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Next, we surveyed 330 current and former users of popular TOTP apps. A significant portion lacked basic awareness of account lockout risks. Two-thirds of current users had cloud backups enabled, exposing them to some of the security and privacy issues previously uncovered. Many of them did not know the feature existed nor that it was enabled, raising questions about whether they provided informed consent. The majority of current users were uncomfortable with anyone being able to read data from their cloud backups. About one-third had experienced account lockout, but most regained access quickly using alternative 2FA mechanisms (e.g., SMS 2FA). Notably, 13% of current users had no TOTP backup plan at all, putting 10+ million people at heightened risk of account lockout when extrapolated across the 100s of millions of TOTP app users.
■590 ▼aSchool code: 0028.
■650 4▼aComputer science
■650 4▼aWeb studies
■650 4▼aInformation science
■653 ▼aTime-based One-Time Password
■653 ▼aTwo-factor authentication
■653 ▼aAccount lockout
■690 ▼a0984
■690 ▼a0646
■690 ▼a0723
■71020▼aUniversity of California, Berkeley▼bElectrical Engineering & Computer Sciences.
■7730 ▼tDissertations Abstracts International▼g87-01A.
■790 ▼a0028
■791 ▼aPh.D.
■792 ▼a2025
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17357691▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


