On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices

On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
复制标题

DOI:
10.14722/ndss.2021.24212
复制
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
中科院分区:
其他
文献类型:
--
作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos

文献摘要

被引文献

相似文献

这个号码的代码。最后,要么用户被要求插入接收到的身份验证码,要么应用程序自动从传入的SMS中读取它,此时应用程序可以将代码发送回应用程序的后端。此程序证明了特定电话号码(以及相应的SIM卡)的所有权。我们注意到该协议如何有效地使用SMS通道作为唯一的“因素”来验证用户的帐户。
code to this number. Finally, either the user is asked to insert the received authentication code, or the app automatically reads it from the incoming SMS, at which point the app can send the code back to the app’s backend. This procedure proves ownership of a specific phone number (and of the corresponding SIM card). We note how this protocol effectively uses the SMS channel as the only “factor” to authenticate to a user’s account.