Defeating the Secrets of OTP Apps

Autor: Michael Spreitzenbarth, Philip Polleit
Rok vydání: 2018
Předmět:
Zdroj: 2018 11th International Conference on IT Security Incident Management & IT Forensics (IMF).
DOI: 10.1109/imf.2018.00013
Popis: Despite the increasing number of cases of data theft (such as Equifax), the classic password is still in many places the sole security feature for user authentication. However, numerous possibilities for extending this now anachronistic form of access control already exist. One such option is the use of one-time passwords (OTP). These passwords are increasingly used for additional authentication (in addition to user name and password) of the respective user to service providers on the Internet and the applications that generate these are therefore referred to as so-called two-factor authentication apps (2FA apps). This paper investigates 16 such 2FA apps for the Android operating system and focuses on the extent to which these applications can offer a similar level of protection when compared to classical hardware tokens (e.g., YubiKey, SecurID-Authenticator).
Databáze: OpenAIRE