Philipp Markert, Florian Farke, and Markus Dürmuth
View The Email to Get Hacked: Attacking SMS-based Two-Factor Authentication
Santa Clara, California, USA | WAY 2019 | August 11, 2019
View The Email to Get Hacked: Attacking SMS-based Two-Factor - - PowerPoint PPT Presentation
View The Email to Get Hacked: Attacking SMS-based Two-Factor Authentication Philipp Markert, Florian Farke, and Markus Drmuth Santa Clara, California, USA | WAY 2019 | August 11, 2019 Two-Factor Authentication 1 1 2 1 Gmail 2FA
Philipp Markert, Florian Farke, and Markus Dürmuth
View The Email to Get Hacked: Attacking SMS-based Two-Factor Authentication
Santa Clara, California, USA | WAY 2019 | August 11, 2019
1
1
3
analyzed top 100 websites 75 left 57 left 31 offer 2FA 25
no login
18
duplicates
26
no 2FA
* Le Pochat et al. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. NDSS ’19
3
*
31 websites offer 2FA 25 (81%) 7 (23%)
4
24 (77%)
5
6
7
8
Tonight’s door code: long long short long
9
Link
Tonight’s door code: long long short long
https://confidential-mail.google.com/msg/... 10
Link
Tonight’s door code: long long short long
11
2FA Confidential Mode
12
alice@gmail.com pw: wonderland 12
13
13
https://confidential-mail.google.com/msg/… https://confidential-mail.oscar.com/msg/...
13
4.
13
2.
Confidential Mode
14
14
Confidential Mode
14
14
15
16
31 websites offer 2FA 25 (81%) 7 (23%) 24 (77%)
alice@gmail.com pw: wonderlandPhilipp Markert, Florian Farke, and Markus Dürmuth
View The Email to Get Hacked: Attacking SMS-based Two-Factor Authentication
Santa Clara, California, USA | WAY 2019 | August 11, 2019