{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,5]],"date-time":"2026-01-05T22:15:24Z","timestamp":1767651324421,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485910","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"482-496","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["2D-2FA: A New Dimension in Two-Factor Authentication"],"prefix":"10.1145","author":[{"given":"Maliheh","family":"Shirvanian","sequence":"first","affiliation":[{"name":"Visa Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shashank","family":"Agrawal","sequence":"additional","affiliation":[{"name":"Western Digital Research, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. Apple Developer: Notifications. https:\/\/developer.apple.com\/notifications\/."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Apple iOS Push Notifications: Security Implications Abuse Scenarios and Countermeasures. https:\/\/www.dhanjani.com\/blog\/2011\/02\/apple-ios-push-notifications-security-implications-abuse-scenarios-and-countermeasures.html."},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. Authy | Two Factor Authentication. https:\/\/authy.com."},{"key":"e_1_3_2_1_4_1","unstructured":"[n. d.]. dev.yubico | U2F Technical Overview. https:\/\/developers.yubico.com\/U2F\/Protocol_details\/Overview.html."},{"key":"e_1_3_2_1_5_1","unstructured":"[n. d.]. Duo | Duo Push. https:\/\/duo.com\/product\/trusted-users\/two-factor-authentication\/authentication-methods\/duo-push."},{"key":"e_1_3_2_1_6_1","unstructured":"[n. d.]. Duo Labs | NIST Shouted Who Listened? Analyzing User Response to NIST\u2019s Guidance on SMS 2FA Security. https:\/\/duo.com\/blog\/nist-shouted-who-listened-analyzing-user-response-to-nists-guidance-on-sms-2fa-security."},{"key":"e_1_3_2_1_7_1","unstructured":"[n. d.]. Duo Security Two-Factor Authentication. https:\/\/www.duosecurity.com\/."},{"key":"e_1_3_2_1_8_1","unstructured":"[n. d.]. Enrollment Guide. https:\/\/guide.duo.com\/enrollment."},{"key":"e_1_3_2_1_9_1","unstructured":"[n. d.]. FIDO Alliance Specifications Overview. https:\/\/fidoalliance.org\/specifications\/."},{"key":"e_1_3_2_1_10_1","unstructured":"[n. d.]. Firebase Cloud Messaging. https:\/\/firebase.google.com\/products\/cloud-messaging\/."},{"key":"e_1_3_2_1_11_1","unstructured":"[n. d.]. Google Authenticator: Generate 2-Step Verification codes on your phone. https:\/\/play.google.com\/store\/apps\/details?id=com.google.android.apps.authenticator2."},{"key":"e_1_3_2_1_12_1","unstructured":"[n. d.]. HID Advanced multi-factor authentication for enterprises. https:\/\/www.hidglobal.com\/products\/software\/activid\/digitalpersona."},{"key":"e_1_3_2_1_13_1","unstructured":"[n. d.]. HOTP: An HMAC-Based One-Time Password Algorithm. https:\/\/tools.ietf.org\/html\/rfc4226."},{"key":"e_1_3_2_1_14_1","unstructured":"[n. d.]. How to register a device for use with multi-factor authentication. https:\/\/docs.aws.amazon.com\/singlesignon\/latest\/userguide\/user-device-registration.html."},{"key":"e_1_3_2_1_15_1","unstructured":"[n. d.]. How was Google Firebase security bypassed?https:\/\/searchsecurity.techtarget.com\/answer\/How-was-Google-Firebase-security-bypassed."},{"key":"e_1_3_2_1_16_1","unstructured":"[n. d.]. InformationAge | Push to accept authentication: the dark side. https:\/\/www.information-age.com\/push-accept-authentication-dark-side-123464128\/."},{"key":"e_1_3_2_1_17_1","unstructured":"[n. d.]. Out-of-Band Authentication - Two-Factor Authentication - SMS. https:\/\/saaspass.com\/about\/out-of-band-authentication-SMS-two-factor-authentication\/."},{"key":"e_1_3_2_1_18_1","unstructured":"[n. d.]. Safenet MobilePASS - Mobile Software Authenticator. https:\/\/safenet.gemalto.com\/multi-factor-authentication\/authenticators\/software-authentication\/mobilepass-otp-authenticator\/."},{"key":"e_1_3_2_1_19_1","unstructured":"[n. d.]. Setting up and using two-factor authentication (2FA). https:\/\/support.zoom.us\/hc\/en-us\/articles\/360038247071-Setting-up-and-using-two-factor-authentication-2FA-."},{"key":"e_1_3_2_1_20_1","unstructured":"[n. d.]. Sign in faster with 2-Step Verification phone prompts. https:\/\/support.google.com\/accounts\/answer\/7026266."},{"key":"e_1_3_2_1_21_1","unstructured":"[n. d.]. The Daily Swig | U2F nowhere near ready for prime time. https:\/\/portswigger.net\/daily-swig\/u2f-nowhere-near-ready-for-prime-time."},{"key":"e_1_3_2_1_22_1","unstructured":"[n. d.]. This is the future of authentication according to security experts. https:\/\/thenextweb.com\/security\/2018\/12\/19\/this-is-the-future-of-authentication-according-to-security-experts\/."},{"key":"e_1_3_2_1_23_1","unstructured":"[n. d.]. TOTP: Time-Based One-Time Password Algorithm. https:\/\/tools.ietf.org\/html\/rfc6238."},{"key":"e_1_3_2_1_24_1","unstructured":"[n. d.]. Twilio | Push Authentication. https:\/\/www.twilio.com\/authy\/features\/push."},{"key":"e_1_3_2_1_25_1","unstructured":"[n. d.]. Two Factor Auth (2FA): List of websites and whether or not they support 2FA.https:\/\/twofactorauth.org\/."},{"key":"e_1_3_2_1_26_1","unstructured":"[n. d.]. Two Factor Authentication Java code implementing the Time-based One-time Password Algorithm. https:\/\/github.com\/j256\/two-factor-auth."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376457"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-01-2015-0001"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"volume-title":"Usability Scale.In Usability Evaluation in Industry, P.\u00a0W. Jordan, B.\u00a0Thomas, B.\u00a0A. Weerdmeester, and A.\u00a0L","author":"Brooke John","key":"e_1_3_2_1_30_1","unstructured":"John Brooke. 1996. SUS: a \u201cQuick and Dirty\u201d Usability Scale.In Usability Evaluation in Industry, P.\u00a0W. Jordan, B.\u00a0Thomas, B.\u00a0A. Weerdmeester, and A.\u00a0L. McClelland (Eds.). Taylor and Francis, London."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382240"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3025453.3025636"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2858036.2858267"},{"key":"e_1_3_2_1_34_1","unstructured":"STANISLAW JARECKI MOHAMMED JUBUR HUGO KRAWCZYK and NITESH SAXENA. [n. d.]. Two-Factor Password-Authenticated Key Exchange with End-to-End Security. ([n. d.])."},{"key":"e_1_3_2_1_35_1","volume-title":"Sound-proof: Usable two-factor authentication based on ambient sound. In 24th {USENIX} Security Symposium ({USENIX} Security 15). 483\u2013498.","author":"Karapanos Nikolaos","year":"2015","unstructured":"Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, and Srdjan Capkun. 2015. Sound-proof: Usable two-factor authentication based on ambient sound. In 24th {USENIX} Security Symposium ({USENIX} Security 15). 483\u2013498."},{"key":"e_1_3_2_1_36_1","volume-title":"HMAC: Keyed-Hashing for Message Authentication. IETF RFC 2104.","author":"Krawczyk H.","year":"1997","unstructured":"H. Krawczyk, M. Bellare, and R. Canetti. 1997. HMAC: Keyed-Hashing for Message Authentication. IETF RFC 2104."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660302"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/eurousec.2016.23001"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi10020013"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785830.2785835"},{"key":"e_1_3_2_1_41_1","unstructured":"Kyle\u00a0Lady Olabode\u00a0Abisem. 2017. State of the Auth. https:\/\/duo.com\/assets\/ebooks\/state-of-the-auth.pdf."},{"volume-title":"d.]","author":"RSA.","key":"e_1_3_2_1_42_1","unstructured":"RSA. [n. d.]. SecureID. http:\/\/www.rsa.com\/node.aspx?id=1156."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2428955.2429004"},{"key":"e_1_3_2_1_44_1","unstructured":"Bruce Schneier. [n. d.]. NIST is No Longer Recommending Two-Factor Authentication Using SMS. https:\/\/www.schneier.com\/blog\/archives\/2016\/08\/nist_is_no_long.html."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23167"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Maliheh Shirvanian Stanislaw Jarecki Nitesh Saxena and Naveen Nathan. 2014. Two-Factor Authentication Resilient to Server Compromise Using Mix-Bandwidth Devices.. In NDSS.","DOI":"10.14722\/ndss.2014.23167"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2014.10.009"},{"key":"e_1_3_2_1_48_1","series-title":"USEC","volume-title":"TinPal: An Enhanced Interface for Pattern Locks. In Workshop on Usable SecurityVol.\u00a018","author":"Tupsamudre Harshal","year":"2018","unstructured":"Harshal Tupsamudre, Sukanya Vaddepalli, Vijayanand Banahatti, and Sachin Lodha. 2018. TinPal: An Enhanced Interface for Pattern Locks. In Workshop on Usable Security, ser. USEC, Vol.\u00a018."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2493190.2493231"},{"key":"e_1_3_2_1_50_1","unstructured":"Zhi Xu and Sencun Zhu. 2012. Abusing Notification Services on Smartphones for Phishing and Spamming.. In WOOT. 1\u201311."}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","acronym":"ACSAC '21","location":"Virtual Event USA"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485910","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485910","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:15:13Z","timestamp":1755890113000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485910"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":50,"alternative-id":["10.1145\/3485832.3485910","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485910","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}