On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
On the Insecurity of SMS One-Time Password Messages against Local Attackers in Modern Mobile Devices
复制标题
DOI:
10.14722/ndss.2021.24212
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
中科院分区:
文献类型:
--
作者:
Zeyu Lei;Yuhong Nan;Y. Fratantonio;Antonio Bianchi;Cisco Talos
code to this number. Finally, either the user is asked to insert the received authentication code, or the app automatically reads it from the incoming SMS, at which point the app can send the code back to the app’s backend. This procedure proves ownership of a specific phone number (and of the corresponding SIM card). We note how this protocol effectively uses the SMS channel as the only “factor” to authenticate to a user’s account.