Skip to main content

The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild

Publication ,  Conference
Wang, KC; Arora, SS; Reiter, MK
Published in: Proceedings Annual Computer Security Applications Conference Acsac
January 1, 2025

Single-factor authentication (1FA) and two-factor authentication (2FA) for secure and reliable website account access have become everyday tasks for most users. However, the complexity of integrating 1FA, 2FA, and password reset mechanisms makes real-world deployments challenging to navigate, leaving key questions about their implications for account security and accessibility unanswered. In this paper, we present a comprehensive investigation into the deployment of 1FA, 2FA, and password reset mechanisms across 50 major websites in six industries. By formally modeling account access and password reset patterns and applying Karnaugh maps for logical optimization, we uncover surprising consequences of current integrations of authentication mechanisms. We present key findings on the implications of modern authentication integrations for account security and accessibility, highlighting both the overestimated strengths and overlooked weaknesses of current deployments. Our research aims to provide a valuable and practical understanding of real-world authentication deployments for advancing web authentication practices.

Duke Scholars

Published In

Proceedings Annual Computer Security Applications Conference Acsac

DOI

ISSN

1063-9527

Publication Date

January 1, 2025

Start / End Page

658 / 672
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Wang, K. C., Arora, S. S., & Reiter, M. K. (2025). The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild. In Proceedings Annual Computer Security Applications Conference Acsac (pp. 658–672). https://doi.org/10.1109/ACSAC67867.2025.00060
Wang, K. C., S. S. Arora, and M. K. Reiter. “The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild.” In Proceedings Annual Computer Security Applications Conference Acsac, 658–72, 2025. https://doi.org/10.1109/ACSAC67867.2025.00060.
Wang KC, Arora SS, Reiter MK. The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild. In: Proceedings Annual Computer Security Applications Conference Acsac. 2025. p. 658–72.
Wang, K. C., et al. “The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild.” Proceedings Annual Computer Security Applications Conference Acsac, 2025, pp. 658–72. Scopus, doi:10.1109/ACSAC67867.2025.00060.
Wang KC, Arora SS, Reiter MK. The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild. Proceedings Annual Computer Security Applications Conference Acsac. 2025. p. 658–672.

Published In

Proceedings Annual Computer Security Applications Conference Acsac

DOI

ISSN

1063-9527

Publication Date

January 1, 2025

Start / End Page

658 / 672