Online services are integral to modern life, supporting activities such as communication, commerce, and travel. These services typically require user authentication, traditionally relying on user ID and password combinations. However, this approach is increasingly vulnerable to attacks such as phishing. Many services have adopted stronger authentication mechanisms, including multi-factor authentication, risk-based authentication, and passkeys. Despite extensive research on login procedures, limited attention has been given to these post-login authentication processes. This paper presents a first study investigating the interplay between multi-factor authentication and context-specific authentication for ten popular online services. The results indicate that various authentication methods and behaviors can be observed across different scenarios and services.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Authentication Inconsistencies Across Online Services: A Multi-Scenario Security Analysis

  • Andre Büttner,
  • Nils Gruschka,
  • Sverre Stafsengen Broen,
  • Daniela Pöhn

摘要

Online services are integral to modern life, supporting activities such as communication, commerce, and travel. These services typically require user authentication, traditionally relying on user ID and password combinations. However, this approach is increasingly vulnerable to attacks such as phishing. Many services have adopted stronger authentication mechanisms, including multi-factor authentication, risk-based authentication, and passkeys. Despite extensive research on login procedures, limited attention has been given to these post-login authentication processes. This paper presents a first study investigating the interplay between multi-factor authentication and context-specific authentication for ten popular online services. The results indicate that various authentication methods and behaviors can be observed across different scenarios and services.