تجاوز إلى المحتوى الرئيسي
User Image

Noura Nassir AlOmar نوره بنت ناصر العمر

Lecturer

College of Computer and Information Sciences , Software Engineering Department.

علوم الحاسب والمعلومات
Building 6, 3rd floor, office# 22
المنشورات
ورقة مؤتمر

Security and Privacy Failures in Popular 2FA Apps

The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA. However, users of TOTP 2FA apps face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. To help users avoid this fate, popular TOTP apps implement a wide range of backup mechanisms, each with varying security and privacy implications. In this paper, we define an assessment methodology for conducting systematic security and privacy analyses of the backup and recovery functionality of TOTP apps. We identified all general purpose Android TOTP apps in the Google Play Store with at least 100k installs that implemented a backup mechanism (n = 22). Our findings show that most backup strategies end up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Many backup implementations shared personal user information with third parties, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. We present our findings and recommend ways to improve the security and privacy of TOTP 2FA app backup mechanisms.

اسم الناشر
USENIX Association
موقع المؤتمر
Anaheim, CA, United States
اسم المؤتمر
32nd USENIX Security Symposium
مزيد من المنشورات
publications
بواسطة Noura Alomar, Joel Reardon, Aniketh Girish, Narseo Vallina-Rodriguez, Serge Egelman
2025
تم النشر فى:
The 25th Privacy Enhancing Technologies Symposium
publications

The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA.

بواسطة Conor Gilsenan, Fuzail Shakir, Noura Alomar, Serge Egelman
تم النشر فى:
USENIX Association
publications

The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights.

بواسطة Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Hoofnagle, Serge Egelman
2023
تم النشر فى:
Proceedings on Privacy Enhancing Technologies