Secondary Education: Measuring Secondary Uses of 2FA Phone Numbers - - PowerPoint PPT Presentation

secondary education
SMART_READER_LITE
LIVE PREVIEW

Secondary Education: Measuring Secondary Uses of 2FA Phone Numbers - - PowerPoint PPT Presentation

Secondary Education: Measuring Secondary Uses of 2FA Phone Numbers Min Hee Kim , Christina Yeung, Daniel Salsburg, Joseph A. Calandrino Office of Technology Research and Investigation Federal Trade Commission The views expressed are not


slide-1
SLIDE 1

Secondary Education:

Measuring Secondary Uses of 2FA Phone Numbers

Min Hee Kim, Christina Yeung, Daniel Salsburg, Joseph A. Calandrino

Office of Technology Research and Investigation Federal Trade Commission

The views expressed are not necessarily those of the Commission or any individual Commissioner.

slide-2
SLIDE 2

2FA! … & Something Else?

2 yay!

BUT THEN!

hey!

did you see? this

that

hey!

wait.

what?

why?

ALL THE THINGS!

… & Something Else?

slide-3
SLIDE 3

Could it be?

3

slide-4
SLIDE 4

4

Site Selection

Of the 45 …

slide-5
SLIDE 5

Account Creation and 2FA Enrollment

5

  • Case 1 (24 sites)
  • Case 2 (4 sites)
  • Case 3 (4 sites)
slide-6
SLIDE 6

2FA Phones

6

CLICK SUBMIT Third-Party Sharing at 2FA Enrollment?

  • LOOK. LISTEN.

Non-2FA Activity?

slide-7
SLIDE 7

Third-Party Sharing at 2FA Enrollment?

7

CLICK SUBMIT

  • No evidence of transmission
  • First-party with Base64 encoding
slide-8
SLIDE 8

Non-2FA Activity?

8

  • LOOK. LISTEN.

Non-2FA Activity?

  • No communication referenced the

website associated with a 2FA phone

  • 900 calls
  • 44 voicemail
  • 58 text messages
slide-9
SLIDE 9

Future Work

  • Go beyond:

– Other secondary uses – e.g., targeted uses – Monitor a larger number of accounts with greater user activity

  • ver a longer period of time – paid accounts, non-English sites
  • Explore:

– Mobile authentication applications – User attitudes, expectations, and behavior

9

slide-10
SLIDE 10

Thank You!

Min Hee Kim, Christina Yeung, Daniel Salsburg, Joseph A. Calandrino

Office of Technology Research and Investigation Federal Trade Commission

The views expressed are not necessarily those of the Commission or any individual Commissioner.

Who Are You?! Adventures in Authentication Workshop (WAY 2020) August 7, 2020