YoVDO

Security and Privacy Failures in Popular 2FA Apps

Offered By: USENIX via YouTube

Tags

USENIX Security Courses Cybersecurity Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a critical analysis of security and privacy vulnerabilities in popular Two-Factor Authentication (2FA) apps presented at USENIX Security '23. Delve into the research conducted by experts from UC Berkeley and ICSI on Time-based One-Time Password (TOTP) algorithms and their implementation in Android apps. Discover the challenges users face in maintaining access to TOTP secrets and the various backup mechanisms employed by popular apps. Learn about the systematic assessment methodology used to evaluate the security and privacy implications of these backup strategies. Uncover alarming findings, including the reliance on potentially insecure technologies, sharing of personal information with third parties, cryptographic flaws, and potential access to plaintext TOTP secrets by app developers. Gain insights into recommended improvements for enhancing the security and privacy of TOTP 2FA app backup mechanisms in this informative 15-minute conference talk.

Syllabus

USENIX Security '23 - Security and Privacy Failures in Popular 2FA Apps


Taught by

USENIX

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network