sms verification codes at risk of fraud abu dhabi study finds
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today
Almaghrib Today, almaghrib today
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today

SMS verification codes at risk of fraud, Abu Dhabi study finds

Almaghrib Today, almaghrib today

Almaghrib Today, almaghrib today SMS verification codes at risk of fraud, Abu Dhabi study finds

Prof Nasir Memon
Abu Dhabi - ArabToday

People’s use of authentication codes to regain access to their online accounts can be exploited by criminals. Researchers at New York University Abu Dhabi have released a study of how such attacks work and the ways to prevent them.
The proliferation of online services for banking, social media, shopping and just about everything else certainly makes life easier.
Buying things, checking account balances and staying in touch with friends involves little more than a few taps of a keyboard and the click of a mouse.
But remembering the passwords for our myriad online accounts can prove difficult, and often we need help to get into our accounts when our memory fails us.
With some accounts, users who forget their password can ask for a verification code to be sent to their mobile phone. The code can be used to regain access to the account.
However, a study by Prof Nasir Memon, who set up the Centre for Cyber Security at New York University Abu Dhabi, and his doctoral student Hossein Siadati has shown that this system is prone to abuse.
The work indicates that there is a significant risk of fraudsters obtaining verification codes – allowing them to gain access to accounts.
A fraudster looking to hack into an account can, relatively easily, activate the mechanism that leads to a verification code being sent to the mobile phone of the person to whom the account is registered. To do this, the fraudster needs to know only the email address associated with the account.
If they also know the user’s mobile phone number, and there are several ways of obtaining a person’s mobile number, they can contact them to try to get hold of the code. Doing this is known as a social engineering attack.
In their study, the researchers investigated what types of messages from fraudsters are most likely to get users to hand over a verification code.
Published in the Elsevier journal Computers and Security, their work also looked at how the messages that contain verification codes can be designed to minimise the risk of fraud.
"We wanted to explore this scientifically. What’s going on in the user’s mind. We sent them different messages," said Prof Memon.
To test what are the most effective "attack messages", the researchers recruited a team of adult participants.
So that the experiment mirrored as closely as possible what could happen in the real world, these volunteers did not know that they were going to be targeted in a simulated verification code forwarding attack.
The researchers sent, from their own mobile phones, a verification code to the mobile phones of the participants, none of whom had requested such a code. This first message was followed up with one of a number of "attack messages", such as, "We have received a complaint of abuse of your Gmail account. Please reply with the verification code we just sent you to receive the details privately", or, "You have a voicemail on Google Voice. To listen, please reply with the message code we just sent to you".
Sixteen attack messages were tested and the response rates compared. The attack message that was most effective at getting participants to send the verification code was: "Did you request a password reset for your Gmail account? Delete this message if you did. Otherwise, send "Cancel + the verification code we just sent to you".
Half of participants responded to this message by sending the verification code, an action which would have put their account at risk of being compromised had the attack been real.

Source: The National

almaghribtoday
almaghribtoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

sms verification codes at risk of fraud abu dhabi study finds sms verification codes at risk of fraud abu dhabi study finds

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

sms verification codes at risk of fraud abu dhabi study finds sms verification codes at risk of fraud abu dhabi study finds

 



Almaghrib Today, almaghrib today Skincare PR Performance Full Year 2017

GMT 09:22 2018 Monday ,22 January

Skincare PR Performance Full Year 2017
Almaghrib Today, almaghrib today New hunt for flight MH370 gets under way

GMT 11:03 2018 Wednesday ,24 January

New hunt for flight MH370 gets under way
Almaghrib Today, almaghrib today Modern colorful bedroom renovation

GMT 10:57 2017 Thursday ,21 December

Modern colorful bedroom renovation
Almaghrib Today, almaghrib today Puigdemont candidate for Catalan president

GMT 13:56 2018 Tuesday ,23 January

Puigdemont candidate for Catalan president
Almaghrib Today, almaghrib today Turkey detains dozens more

GMT 10:47 2018 Wednesday ,24 January

Turkey detains dozens more
Almaghrib Today, almaghrib today The Rake announces editorial updates

GMT 10:46 2018 Tuesday ,16 January

The Rake announces editorial updates
Almaghrib Today, almaghrib today Europe brings on charm and blue skies

GMT 11:51 2018 Tuesday ,23 January

Europe brings on charm and blue skies
Almaghrib Today, almaghrib today For the Variety of Interior Design Styles

GMT 10:46 2017 Tuesday ,19 December

For the Variety of Interior Design Styles
Almaghrib Today, almaghrib today US Christian tourists see deep meaning

GMT 13:44 2018 Monday ,22 January

US Christian tourists see deep meaning
Almaghrib Today, almaghrib today Amazon to open first cashierless shop

GMT 10:03 2018 Tuesday ,23 January

Amazon to open first cashierless shop

GMT 07:51 2017 Tuesday ,03 January

Police question Netanyahu

GMT 16:41 2012 Friday ,17 February

FAB 1

GMT 17:24 2011 Friday ,11 November

Ferrari GT Finally Caught Testing

GMT 15:20 2013 Friday ,20 September

Chinese visitors to London double in 3 years

GMT 16:04 2016 Saturday ,17 December

Drone attack kills 16 Daesh fighters in east Afghanistan

GMT 10:20 2013 Friday ,18 October

Philippine earthquake death toll at 171

GMT 22:22 2016 Wednesday ,23 March

Most Saudis think morals have fallen

GMT 10:27 2016 Monday ,26 December

Poor Memories Of China's Minority Groups

GMT 23:04 2014 Wednesday ,26 February

US new home sales hit 5-and-a-half year high in January

GMT 07:26 2017 Friday ,24 November

Several Houthi Leaders, Dozens of Insurgents Killed

GMT 11:14 2016 Friday ,25 March

AUS celebrates Global Day festival

GMT 10:25 2016 Tuesday ,06 September

Hanjin to spend $90mn

GMT 10:20 2012 Wednesday ,11 January

From screen to protest

GMT 09:37 2011 Tuesday ,26 July

Dubai airport posts 8.9%

GMT 11:22 2016 Thursday ,27 October

SICFF depicts heart-wrenching refugee saga

GMT 22:48 2016 Thursday ,28 January

Taiwan leader defies US, visits disputed island

GMT 05:16 2011 Wednesday ,20 July

DAE reaches new debt accord with lenders
Almaghrib Today, almaghrib today
 
 Almaghrib Today Facebook,almaghrib today facebook  Almaghrib Today Twitter,almaghrib today twitter Almaghrib Today Rss,almaghrib today rss  Almaghrib Today Youtube,almaghrib today youtube  Almaghrib Today Youtube,almaghrib today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

.almaghribtoday .almaghribtoday .almaghribtoday .almaghribtoday
almaghribtoday almaghribtoday almaghribtoday
almaghribtoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
almaghribtoday, Almaghribtoday, Almaghribtoday