Skip to main content
User Image

Noura Nassir AlOmar نوره بنت ناصر العمر

Lecturer

College of Computer and Information Sciences , Software Engineering Department.

علوم الحاسب والمعلومات
Building 6, 3rd floor, office# 22
publication
Conference Paper

Security and Privacy Failures in Popular 2FA Apps

The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA. However, users of TOTP 2FA apps face a critical usability challenge: maintain access to the secrets stored within the TOTP app, or risk getting locked out of their accounts. To help users avoid this fate, popular TOTP apps implement a wide range of backup mechanisms, each with varying security and privacy implications. In this paper, we define an assessment methodology for conducting systematic security and privacy analyses of the backup and recovery functionality of TOTP apps. We identified all general purpose Android TOTP apps in the Google Play Store with at least 100k installs that implemented a backup mechanism (n = 22). Our findings show that most backup strategies end up placing trust in the same technologies that TOTP 2FA is meant to supersede: passwords, SMS, and email. Many backup implementations shared personal user information with third parties, had serious cryptographic flaws, and/or allowed the app developers to access the TOTP secrets in plaintext. We present our findings and recommend ways to improve the security and privacy of TOTP 2FA app backup mechanisms.

Publisher Name
USENIX Association
Conference Location
Anaheim, CA, United States
Conference Name
32nd USENIX Security Symposium
more of publication
publications
by Noura Alomar, Joel Reardon, Aniketh Girish, Narseo Vallina-Rodriguez, Serge Egelman
2025
Published in:
The 25th Privacy Enhancing Technologies Symposium
publications

The Time-based One-Time Password (TOTP) algorithm is a 2FA method that is widely deployed because of its relatively low implementation costs and purported security benefits over SMS 2FA.

by Conor Gilsenan, Fuzail Shakir, Noura Alomar, Serge Egelman
Published in:
USENIX Association
publications

The California Consumer Privacy Act (CCPA) provides California residents with a range of enhanced privacy protections and rights.

by Nikita Samarin, Shayna Kothari, Zaina Siyed, Oscar Bjorkman, Reena Yuan, Primal Wijesekera, Noura Alomar, Jordan Fischer, Chris Hoofnagle, Serge Egelman
2023
Published in:
Proceedings on Privacy Enhancing Technologies