Multi-Factor Authentication is intended to strengthen the security of password-based authentication by adding another factor, such as hardware tokens or one-time passwords using mobile apps. However, this increased authentication security comes with potential drawbacks that can lead to account and asset loss. If users lose access to their additional authentication factors for any reason, they will be locked out of their accounts. Consequently, services that provide Multi-Factor Authentication should deploy procedures to allow their users to recover from losing access to their additional factor that are both secure and easy-to-use. In this work, we investigate the security and user experience of Multi-Factor Authentication recovery procedures, and compare their deployment to descriptions on help and support pages. We first evaluate the official help and support pages of 1,303 websites that provide Multi-Factor Authentication and collect documented information about their recovery procedures. Second, we select a subset of 71 websites, create accounts, set up Multi-Factor Authentication, and perform an in-depth investigation of their recovery procedure security and user experience. We find that many websites deploy insecure Multi-Factor Authentication recovery procedures and allowed us to circumvent and disable Multi-Factor Authentication when having access to the accounts' associated email addresses. Furthermore, we commonly observed discrepancies between our in-depth analysis and the official help and support pages, implying that information meant to aid users is often either incorrect or outdated. Based on our findings, we provide recommendations for best practices regarding Multi-Factor Authentication recovery.
翻译:多因素认证通过增加硬件令牌或移动应用一次性密码等额外因素,旨在增强基于密码认证的安全性。然而,这种增强的认证安全可能带来导致账户及资产损失的潜在弊端。若用户因任何原因无法访问额外认证因素,将被锁定在账户之外。因此,提供多因素认证的服务应部署既安全又易于使用的恢复流程,以便用户能够恢复对额外因素的访问权限。本研究调查多因素认证恢复流程的安全性与用户体验,并将其实际部署与帮助支持页面中的描述进行对比。我们首先评估了1303个提供多因素认证的网站的官方帮助支持页面,收集其恢复流程的文档化信息;其次,从其中选取71个网站的子集,创建账户、配置多因素认证,并深入调查恢复流程的安全性与用户体验。研究发现,许多网站部署了不安全的恢复流程,允许我们在仅具有账户关联邮箱访问权限的情况下绕过甚至禁用多因素认证。此外,我们普遍观察到实际深度分析与官方帮助支持页面之间存在差异,表明旨在辅助用户的信息常存在不准确或过时的问题。基于研究结果,我们为多因素认证恢复提出了最佳实践建议。