Multi-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps. However, this increased authentication security comes with potential drawbacks that can lead to account and asset loss. If users lose access to their additional authentication factors for any reason, they will be locked out of their accounts. Consequently, services that provide Multi-Factor Authentication should deploy procedures to allow their users to recover from losing access to their additional factor that are both secure and easy-to-use. To the best of our knowledge, we are the first to first-hand investigate the security and user experience of deployed Multi-Factor Authentication recovery procedures. We first evaluate the official help and support pages of 1,303 websites that provide Multi-Factor Authentication and collect documented information about their recovery procedures. Second, we select a subset of 71 websites, create accounts, set up Multi-Factor Authentication, and perform an in-depth investigation of their recovery procedure security and user experience. We find that many websites deploy insecure Multi-Factor Authentication recovery procedures and allowed us to circumvent and disable Multi-Factor Authentication when having access to the accounts' associated email addresses. Furthermore, we commonly observed discrepancies between our in-depth analysis and the official help and support pages, implying that information meant to aid users is often either incorrect or outdated.
翻译:多因素认证旨在通过增加额外认证因子(如硬件令牌或基于移动应用的一次性密码)来强化基于密码的认证安全性。然而,这种增强的认证安全性也带来了潜在风险,可能导致账户及资产的损失。一旦用户因任何原因失去对额外认证因子的访问权限,他们将无法登录账户。因此,提供多因素认证的服务应部署既安全又易于使用的恢复流程,帮助用户重新获得对额外因子的访问权限。据我们所知,我们是首个直接研究现有多因素认证恢复流程安全性与用户体验的团队。我们首先评估了1303个提供多因素认证网站的官方帮助与支持页面,收集了有关其恢复流程的文档化信息。其次,我们筛选了71个网站,创建账户并设置多因素认证,深入调查其恢复流程的安全性与用户体验。研究发现,许多网站部署了不安全的恢复机制,允许我们在获取账户关联邮箱后绕过并禁用多因素认证。此外,我们普遍观察到深度分析结果与官方帮助页面存在差异,这表明旨在辅助用户的信息往往不准确或已过时。