Skip to main navigation Skip to search Skip to main content

More than just a random number generator! Unveiling the security and privacy risks of mobile OTP authenticator apps

Muhammad Ikram*, I. Wayan Budi Sentana, Hassan Asghar, Mohamed Ali Kaafar, Michal Kepkowski

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

One-Time Passwords (OTPs) are a crucial component of multi-factor authentication (MFA) systems, providing additional security by requiring users to supply a dynamically generated code for authenticating to web services. The growth in smartphone usage has resulted in a shift from hardware tokens to mobile app-based OTP authenticators; however, these apps also present potential security and privacy threats. In this paper, we present a comprehensive analysis of 182 publicly available OTP apps on Google Play. Our analysis entails an array of passive and active measurements meticulously designed to assess the security and privacy attributes inherent to each OTP application. We investigate the presence of suspicious libraries, usage of binary protections, access to root privileges, secure backup and cryptographic mechanisms, and protection against traffic interception. Our experiments highlight several security and privacy weaknesses in instances of OTP apps. We observe that 28% of the analyzed apps are signed using a vulnerable version of the Android application signing mechanism. Over 40% of the OTP apps include third-party libraries leading to user information leakage to third-parties. 31.9% of the OTP applications are vulnerable to network interception, and only 13.2% possess the capability to detect devices that have been Jailbroken or rooted, which poses a significant concern. Our study highlights the need for better security and privacy guarantees in OTP apps and the importance of user awareness.

Original languageEnglish
Title of host publicationWeb Information Systems Engineering – WISE 2024
Subtitle of host publication25th International Conference, Doha, Qatar, December 2–5, 2024, proceedings, part V
EditorsMahmoud Barhamgi, Hua Wang, Xin Wang
Place of PublicationSingapore
PublisherSpringer, Springer Nature
Pages177-192
Number of pages16
ISBN (Electronic)9789819605767
ISBN (Print)9789819605750
DOIs
Publication statusPublished - 2025
Event25th International Conference on Web Information Systems Engineering, WISE 2024 - Doha, Qatar
Duration: 2 Dec 20245 Dec 2024

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume15440
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference25th International Conference on Web Information Systems Engineering, WISE 2024
Country/TerritoryQatar
CityDoha
Period2/12/245/12/24

Keywords

  • OTP apps
  • Security and privacy
  • Static and dynamic analysis

Fingerprint

Dive into the research topics of 'More than just a random number generator! Unveiling the security and privacy risks of mobile OTP authenticator apps'. Together they form a unique fingerprint.

Cite this