Is Second Factor Authentication Broken? an Analysis of 2FA Token Harvesting Techniques and the Transition to Universal Second Factor Authentication

dc.contributor.authorKing, Matthew
dc.date.accessioned2026-02-23T20:36:36Z
dc.date.available2026-02-23T20:36:36Z
dc.date.issued3/8/2019
dc.description.abstractSecond factor authentication (2FA) is the process of providing two different authentication factors to gain access to desired resources. 2FA involves combining something the user knows, most commonly a password, with something that they have. The “something they have” ranges from one-time passcodes sent through SMS or mobile applications, to biometrics and hardware tokens. While 2FA is better than simply using passwords to secure accounts, recently released tools reveal critical vulnerabilities for users attempting to secure accounts with SMS or authenticator app-based one-time passcodes (OTPs). This project details how one of those particular tools accomplishes the task of automatically harvesting user credentials and OTPs. Additionally, the project details how Universal 2nd Factor (U2F), an open source authentication protocol, can be used to provide more robust security for user accounts than 2FA. The project discusses features of the protocol’s security as well as issues associated with implementation.
dc.description.departmentUniversity of Tulsa
dc.identifier.otherMathematics and Science.Computer Science.06
dc.identifier.urihttps://shareok.org//handle/11244/342124
dc.relation.ispartofseriesMathematics and Science
dc.subject.keywordsComputer Science
dc.titleIs Second Factor Authentication Broken? an Analysis of 2FA Token Harvesting Techniques and the Transition to Universal Second Factor Authentication
dc.typeAbstract

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
AbstractOnly.png
Size:
437.62 KB
Format:
Portable Network Graphics