Two-factor authentication: is the world ready?: quantifying 2FA adoption

Thanasis Petsas, Giorgos Tsirantonakis, E. Athanasopoulos, S. Ioannidis
{"title":"Two-factor authentication: is the world ready?: quantifying 2FA adoption","authors":"Thanasis Petsas, Giorgos Tsirantonakis, E. Athanasopoulos, S. Ioannidis","doi":"10.1145/2751323.2751327","DOIUrl":null,"url":null,"abstract":"As text-based passwords continue to be the dominant form for user identification today, services try to protect their costumers by offering enhanced, and more secure, technologies for authentication. One of the most promising is two-factor authentication (2FA). 2FA raises the bar for the attacker significantly, however, it is still questionable if the technology can be realistically adopted by the majority of Internet users. In this paper, we attempt a first study for quantifying the adoption of 2FA in probably the largest existing provider, namely Google. For achieving this, we leverage the password-reminder process in a novel way for discovering if 2FA is enabled for a particular account, without annoying or affecting the account's owner. Our technique has many challenges to overcome, since it requires issuing massively thousands of password reminders. In order to remain below the radar, and therefore avoid solving CAPTCHAs or having our hosts blocked, we leverage distributed systems, such as TOR and PlanetLab. After examining over 100,000 Google accounts, we conclude that 2FA has not yet been adopted by more than 6.4% of the users. Last but not least, as a side-effect of our technique, we are also able to exfiltrate private information, which can be potentially used for malicious purposes. Thus, in this paper we additionally present important findings for raising concerns about privacy risks in designing password reminders.","PeriodicalId":123258,"journal":{"name":"Proceedings of the Eighth European Workshop on System Security","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"92","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the Eighth European Workshop on System Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2751323.2751327","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 92

Abstract

As text-based passwords continue to be the dominant form for user identification today, services try to protect their costumers by offering enhanced, and more secure, technologies for authentication. One of the most promising is two-factor authentication (2FA). 2FA raises the bar for the attacker significantly, however, it is still questionable if the technology can be realistically adopted by the majority of Internet users. In this paper, we attempt a first study for quantifying the adoption of 2FA in probably the largest existing provider, namely Google. For achieving this, we leverage the password-reminder process in a novel way for discovering if 2FA is enabled for a particular account, without annoying or affecting the account's owner. Our technique has many challenges to overcome, since it requires issuing massively thousands of password reminders. In order to remain below the radar, and therefore avoid solving CAPTCHAs or having our hosts blocked, we leverage distributed systems, such as TOR and PlanetLab. After examining over 100,000 Google accounts, we conclude that 2FA has not yet been adopted by more than 6.4% of the users. Last but not least, as a side-effect of our technique, we are also able to exfiltrate private information, which can be potentially used for malicious purposes. Thus, in this paper we additionally present important findings for raising concerns about privacy risks in designing password reminders.
双因素认证:世界准备好了吗?:量化2FA的采用
由于基于文本的密码仍然是当今用户身份识别的主要形式,服务提供商试图通过提供增强的、更安全的身份验证技术来保护客户。其中最有前途的是双因素身份验证(2FA)。2FA大大提高了攻击者的门槛,然而,该技术是否能被大多数互联网用户实际采用仍然值得怀疑。在本文中,我们尝试对可能是最大的现有提供商(即Google)采用2FA进行量化研究。为了实现这一点,我们以一种新颖的方式利用密码提醒过程来发现是否为特定帐户启用了2FA,而不会惹恼或影响帐户的所有者。我们的技术有许多挑战需要克服,因为它需要发出大量成千上万的密码提醒。为了保持在雷达之下,从而避免解决captcha或阻止我们的主机,我们利用分布式系统,如TOR和PlanetLab。在检查了超过10万个谷歌账户后,我们得出结论,2FA尚未被超过6.4%的用户采用。最后但并非最不重要的是,作为我们技术的副作用,我们还能够泄露私人信息,这些信息可能被用于恶意目的。因此,在本文中,我们还提出了在设计密码提醒时提高对隐私风险的关注的重要发现。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信