失物招领:无密码未来​​中账户恢复的隐患.pdf

编号:981868 PDF 55页 2.68MB 下载积分:VIP专享
下载报告请您先登录!

失物招领:无密码未来​​中账户恢复的隐患.pdf

1、Lost&FoundThe Hidden Risks of Account Recovery in a Passwordless FutureBlackhat USA 2025August 7,ThursdaySpeakers:Sid Rao,Gabriela SonkeriNote:This handout version of the slide deck has slightly different(and more)content than the presentation versionWho are we?Senior Security ResearcherDr.Sid Rao2S

2、ecurity EngineerGabriela Sonkeri*User and Impact ResearcherAmel Bourdoucen*Associate ProfessorProf.Janne Lindqvist*Contributions while working at Nokia Bell LabsContributions while working at Nokia Bell LabsNokia Bell Labs FinlandWolt FinlandF-Secure,Aalto UniversityFinlandAalto UniversityFinlandSpe

3、cial thanks:Prof.Tuomas Aura,Dr.Thanh Bui,and Dr.Markku AntikainenBackgroundUsers authentication credentials become unavailable#1:Authentication credentials are forgotten or mislaid by the user#2:Authentication credentials are inaccessible to the userPersonal device is lostLogging in from a new devi

4、ce or location 3Genuine scenarios in which a benign user wants to reclaim control over or recover their accountThe service provider needs to provision reclaiming control in such genuine scenariosGenuine-looking scenarios can be maliciousGenuineness cannot be verifiedFlaws in the recovery flowAccount

5、 Recovery OverviewAn automated process provisioned by the service provider for benign users to reclaim access4Recovery Method(independent communication channel)Step 1:Recover my accountStep 0:Establish Out-of-band trustRecovery Token(OTP or URL)Step 2:Generates recovery tokenStep 4:Retrieve the toke

6、nStep 3:Send the tokenStep 5:Submit the retrieved tokenStep 6:Allow recovery if token is validService ProviderUserRecovery Session(unauthenticated user session)Account Recovery Lifecycle5Password ChangeSet up a new password3Trigger recoveryUser clicks,e.g.,“Forgot password”Or“Unable to login”1 Verif

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(失物招领:无密码未来​​中账户恢复的隐患.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠