Lost and not Found: An Investigation of Recovery Methods for Multi-Factor Authentication

06/16/2023
by   Sabrina Amft, et al.
0

Multi-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps. However, this increased authentication security comes with potential drawbacks that can lead to account and asset loss. If users lose access to their additional authentication factors for any reason, they will be locked out of their accounts. Consequently, services that provide Multi-Factor Authentication should deploy procedures to allow their users to recover from losing access to their additional factor that are both secure and easy-to-use. To the best of our knowledge, we are the first to first-hand investigate the security and user experience of deployed Multi-Factor Authentication recovery procedures. We first evaluate the official help and support pages of 1,303 websites that provide Multi-Factor Authentication and collect documented information about their recovery procedures. Second, we select a subset of 71 websites, create accounts, set up Multi-Factor Authentication, and perform an in-depth investigation of their recovery procedure security and user experience. We find that many websites deploy insecure Multi-Factor Authentication recovery procedures and allowed us to circumvent and disable Multi-Factor Authentication when having access to the accounts' associated email addresses. Furthermore, we commonly observed discrepancies between our in-depth analysis and the official help and support pages, implying that information meant to aid users is often either incorrect or outdated.

READ FULL TEXT

page 19

page 20

research
05/26/2021

Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication

Threats to passwords are still very relevant due to attacks like phishin...
research
05/01/2023

How effective is multifactor authentication at deterring cyberattacks?

This study investigates the effectiveness of multifactor authentication ...
research
10/17/2022

A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites (Extended Version)

Heuristics for user experience state that users will transfer their expe...
research
08/10/2022

Multi-Factor Key Derivation Function (MFKDF)

We present the first general construction of a Multi-Factor Key Derivati...
research
04/17/2021

Towards Fortifying the Multi-Factor-Based Online Account Ecosystem

With the rapid growth of online services, the number of online accounts ...
research
12/16/2020

A novel Two-Factor HoneyToken Authentication Mechanism

The majority of systems rely on user authentication on passwords, but pa...
research
02/02/2023

A Transcontinental Analysis of Account Remediation Protocols of Popular Websites

Websites are used regularly in our day-today lives, yet research has sho...

Please sign up or login with your details

Forgot password? Click here to reset