{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,17]],"date-time":"2026-01-17T03:57:43Z","timestamp":1768622263525,"version":"3.49.0"},"reference-count":62,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T00:00:00Z","timestamp":1704844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["OAC-2139358, CNS-2201465, and CNS-2152669"],"award-info":[{"award-number":["OAC-2139358, CNS-2201465, and CNS-2152669"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2024,2,29]]},"abstract":"<jats:p>\n            Reducing the level of user effort involved in traditional two-factor authentication (TFA) constitutes an important research topic. An interesting representative approach,\n            <jats:italic>Sound-Proof<\/jats:italic>\n            , leverages\n            <jats:italic>ambient sounds<\/jats:italic>\n            to detect the proximity between the second-factor device (phone) and the login terminal (browser), and it eliminates the need for the user to transfer PIN codes. In this article, we identify a weakness of the Sound-Proof system that makes it completely vulnerable to passive \u201cenvironment guessing\u201d and active \u201cenvironment manipulating\u201d\n            <jats:italic>remote<\/jats:italic>\n            attackers and\n            <jats:italic>proximity<\/jats:italic>\n            attackers. Addressing these security issues, we propose\n            <jats:italic>Listening-Watch<\/jats:italic>\n            , a new TFA mechanism based on a wearable device (watch\/bracelet) and active browser-generated random speech sounds. As the user attempts to log in, the browser populates a short random code encoded into speech, and the login succeeds if the watch\u2019s audio recording\n            <jats:italic>contains<\/jats:italic>\n            this code (decoded using\n            <jats:italic>speech recognition<\/jats:italic>\n            ) and is\n            <jats:italic>similar<\/jats:italic>\n            enough to the browser\u2019s audio recording. The remote attacker, who has guessed\/manipulated the user\u2019s environment, will be defeated, since authentication success relies upon the presence of the random code in watch\u2019s recordings. The proximity attacker will also be defeated unless it is extremely close (&lt;50 cm) to the watch, since the wearable microphones are usually designed to capture only nearby sounds (e.g., voice commands).\n          <\/jats:p>","DOI":"10.1145\/3632175","type":"journal-article","created":{"date-parts":[[2023,11,11]],"date-time":"2023-11-11T09:35:46Z","timestamp":1699695346000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Sound-based Two-factor Authentication: Vulnerabilities and Redesign"],"prefix":"10.1145","volume":"27","author":[{"given":"Prakash","family":"Shrestha","sequence":"first","affiliation":[{"name":"Equifax Inc. USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4136-7004","authenticated-orcid":false,"given":"Ahmed Tanvir","family":"Mahdad","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6083-104X","authenticated-orcid":false,"given":"Nitesh","family":"Saxena","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,1,10]]},"reference":[{"key":"e_1_3_2_2_2","article-title":"WACA: Wearable-assisted continuous authentication","author":"Acar Abbas","year":"2018","unstructured":"Abbas Acar, Hidayet Aksu, A. Selcuk Uluagac, and Kemal Akkaya. 2018. WACA: Wearable-assisted continuous authentication. Retrieved from https:\/\/arXiv:1802.10417","journal-title":"R"},{"key":"e_1_3_2_3_2","unstructured":"Authy Inc. 2021. Two-Factor Authentication\u2014Authy. Retrieved October 10 2021 from https:\/\/www.authy.com\/"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"issue":"194","key":"e_1_3_2_5_2","first-page":"4","article-title":"SUS-A quick and dirty usability scale","volume":"189","author":"Brooke John","year":"1996","unstructured":"John Brooke et\u00a0al. 1996. SUS-A quick and dirty usability scale. Usability Evaluation in Industry 189, 194 (1996), 4\u20137.","journal-title":"Usability Evaluation in Industry"},{"key":"e_1_3_2_6_2","article-title":"How to Play Music Through the Internal PC Speaker","year":"2017","unstructured":"CD3DTECH. 2017. How to Play Music Through the Internal PC Speaker. Retrieved from https:\/\/bit.ly\/2MJnXeo. Accessed: December 31, 2017.","journal-title":"R"},{"key":"e_1_3_2_7_2","unstructured":"Celestix. 2021. Celestix HOTPin Two Factor Authentication. Retrieved October 10 2021 from https:\/\/bit.ly\/2N5Cmko"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382240"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2011.2129508"},{"key":"e_1_3_2_10_2","unstructured":"Duo Inc.2021. Duo Mobile and Apple Watch\u2014Guide to Two-Factor Authentication. Retrieved October 10 2021 from https:\/\/guide.duo.com\/apple-watch"},{"key":"e_1_3_2_11_2","unstructured":"Duo Security Inc.2021. Easy Mobile Two-Factor Authentication. Retrieved October 10 2021 from https:\/\/duo.com\/solutions\/features\/user-experience\/easy-authentication"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/2335356.2335360"},{"key":"e_1_3_2_13_2","unstructured":"Ram\u00f3n Fern\u00e1ndez Astudillo. 2010. Integration of short-time fourier domain speech enhancement and observation uncertainty techniques for robust automatic speech recognition. https:\/\/api-depositonce.tu-berlin.de\/server\/api\/core\/bitstreams\/7dafa726-3d8e-41cf-b966-1f68aebf57c7\/content"},{"key":"e_1_3_2_14_2","article-title":"Introduction to MIDI and Computer Music: The MIDI Standard","author":"Gibson John","year":"2017","unstructured":"John Gibson. 2017. Introduction to MIDI and Computer Music: The MIDI Standard. Retrieved from https:\/\/bit.ly\/1J83S4X. Accessed: December 31, 2017.","journal-title":"R"},{"key":"e_1_3_2_15_2","unstructured":"Google Inc. 2017. Speech API\u2014Speech Recognition | Google Cloud Platform. Retrieved May 13 2017 from https:\/\/cloud.google.com\/speech\/"},{"key":"e_1_3_2_16_2","unstructured":"Google Inc.2021. Google 2-Step Verification. Retrieved October 10 2021 from https:\/\/bit.ly\/1AyTGig"},{"key":"e_1_3_2_17_2","unstructured":"Google Inc.2021. Sign in faster with 2-Step Verification phone prompts\u2014Android\u2014Google Account Help. Retrieved October 10 2021 from https:\/\/bit.ly\/2vRgT8l"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.12.001"},{"key":"e_1_3_2_19_2","unstructured":"Matt Gutman. 2015. Snapchat hacked: 4.6 million user names partial phone numbers leaked\u2014ABC15 Arizona. Retrieved October 10 2021 from https:\/\/bit.ly\/2vSSdKZ"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33167-1_22"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3241539.3241574"},{"key":"e_1_3_2_22_2","unstructured":"Apple Inc.2023. Lock or unlock Apple Watch. Retrieved August 22 2023 from https:\/\/tinyurl.com\/4e8fk8wy"},{"key":"e_1_3_2_23_2","unstructured":"Analog Devices Inc.2017. Understanding Microphone Sensitivity. Retrieved October 27 2017 from https:\/\/goo.gl\/WJhdCi"},{"key":"e_1_3_2_24_2","unstructured":"Google Inc.2019. Google Online Security Blog: A new version of Authenticator for Android. Retrieved October 11 2019 from https:\/\/bit.ly\/2OHukR0"},{"key":"e_1_3_2_25_2","unstructured":"Google Inc.2023. Lock your watch screen. Retrieved August 22 2023 from https:\/\/tinyurl.com\/bddwuawc"},{"key":"e_1_3_2_26_2","unstructured":"Mordor Intelligence. 2023. Wearable Technology Market\u2014Size Share and Manufacturers. Retrieved August 22 2023 from https:\/\/tinyurl.com\/37assm4d"},{"key":"e_1_3_2_27_2","volume-title":"Proceedings of the USENIX Security Symposium","author":"Karapanos Nikolaos","year":"2015","unstructured":"Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, and Srdjan Capkun. 2015. Sound-Proof: Usable two-factor authentication based on ambient sound. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_3_2_28_2","volume-title":"Proceedings of the CHiME Workshop on Machine Listening in Multisource Environments","author":"Koldovsk\u1ef3 Zbyn ek","year":"2011","unstructured":"Zbyn ek Koldovsk\u1ef3, Jir\u00ed M\u00e1lek, Jan Nouza, and Miroslav Bal\u00edk. 2011. CHiME data separation based on target signal cancellation and noise masking. In Proceedings of the CHiME Workshop on Machine Listening in Multisource Environments."},{"key":"e_1_3_2_29_2","unstructured":"Mohit Kumar. 2011. Coalition of Law Enforcement Hacked & Agents Information Leaked. Retrieved October 10 2021 from https:\/\/bit.ly\/2qHlHfp"},{"key":"e_1_3_2_30_2","unstructured":"Mohit Kumar. 2012. Anonymous leaks database from Israeli Musical Act Magazine site #OpIsrael. Retrieved from https:\/\/bit.ly\/2JjkC3J"},{"key":"e_1_3_2_31_2","unstructured":"Mohit Kumar. 2012. Bulgarian torrent tracker forum hacked and accused of collecting user IP. Retrieved October 10 2021 from https:\/\/bit.ly\/2VSqLvf"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274699"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASPAA.2001.969582"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2003.1228528"},{"key":"e_1_3_2_35_2","unstructured":"C. V. Lopes and P. M. Q. Aguiar. 2017. Digital Voices. Retrieved October 27 2017 from http:\/\/www.ics.uci.edu\/lopes\/dv\/dv.html"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.51"},{"key":"e_1_3_2_37_2","unstructured":"MathWorks. 2021. Butterworth filter design. Retrieved October 10 2021 from http:\/\/www.mathworks.com\/help\/signal\/ref\/butter.html"},{"key":"e_1_3_2_38_2","unstructured":"DPA Microphones. 2017. Large vs. small diagpragms in microphones. Retrieved October 27 2017 from https:\/\/goo.gl\/TGjcke"},{"key":"e_1_3_2_39_2","unstructured":"myNoise. 2018. Restaurant Ambience\u201410H Busy Coffee Shop Background Noise. Retrieved August 26 2023 from https:\/\/tinyurl.com\/5khuarct"},{"key":"e_1_3_2_40_2","unstructured":"Nymi. 2021. Nymi | Always On Authentication. Retrieved October 27 2017 from https:\/\/nymi.com\/"},{"key":"e_1_3_2_41_2","unstructured":"Omate. 2021. Omate TrueSmart. Retrieved October 10 2021 from https:\/\/www.omate.com\/"},{"key":"e_1_3_2_42_2","unstructured":"World Health Organization. 2017. Make Listening Safe. Retrieved October 28 2017 from https:\/\/goo.gl\/4hfd98"},{"key":"e_1_3_2_43_2","unstructured":"Precedence Research. 2023. Wearable Technology Market Size Trends Growth Report 2030. Retrieved August 22 2023 from https:\/\/tinyurl.com\/5n7vns22"},{"key":"e_1_3_2_44_2","unstructured":"RSA. 2021. SecurID|RSA Security Token-based Authentication. Retrieved October 10 2021 from https:\/\/www.rsa.com\/en-us\/products-services\/identity-access-management\/securid"},{"key":"e_1_3_2_45_2","unstructured":"Samsung. 2017. Samsung Gear S Smartwatch|Samsung. Retrieved from https:\/\/bit.ly\/1MPhF2w. Accessed: May 13 2017."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23167"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978328"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3212480.3212501"},{"key":"e_1_3_2_49_2","unstructured":"Nikhil Sonnad. 2015. What\u2019s in the Ashley Madison database that hackers released online\u2014Quartz. Retrieved October 10 2021 from https:\/\/bit.ly\/1WFcrP6"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","unstructured":"Claudio Soriente Gene Tsudik and Ersin Uzun. 2008. HAPADEP: Human-assisted pure audio device pairing. In Information Security Springer Berlin Heidelberg Berlin Heidelberg 385\u2013400.","DOI":"10.1007\/978-3-540-85886-7_27"},{"key":"e_1_3_2_51_2","unstructured":"Ryan De Souza. 2016. Hacker Leaks 250 GB of NASA Data Another Group Claims To Hijack NASA Drone. Retrieved October 10 2021 from https:\/\/bit.ly\/1mi8HVb"},{"key":"e_1_3_2_52_2","unstructured":"Study-Body-Language. 2017. Personal Distance\u2014Zones. Retrieved October 27 2017 from http:\/\/www.study-body-language.com\/Personal-distance.html"},{"key":"e_1_3_2_53_2","first-page":"399","volume-title":"Proceedings of the USENIX Security Symposium","author":"Sunshine Joshua","year":"2009","unstructured":"Joshua Sunshine, Serge Egelman, Hazim Almuhimedi, Neha Atri, and Lorrie Faith Cranor. 2009. Crying wolf: An empirical study of ssl warning effectiveness. In Proceedings of the USENIX Security Symposium. 399\u2013416."},{"key":"e_1_3_2_54_2","unstructured":"The Seattle Times. 2019. How to work from a coffee shop without being a jerk. Retrieved August 26 2023 from https:\/\/tinyurl.com\/3tenzd6x."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/PerCom.2014.6813957"},{"key":"e_1_3_2_56_2","unstructured":"Western Michigan University. 2017. Solfa Cipher. Retrieved from http:\/\/www.wmich.edu\/mus-theo\/solfa-cipher\/. Accessed: December 31 2017."},{"key":"e_1_3_2_57_2","unstructured":"Usability.gov. 2017. System Usability Scale (SUS)|Usability.gov. Retrieved December 31 2017 from https:\/\/goo.gl\/6SmFie"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2011.5947378"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.intcom.2009.10.001"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2012.6288963"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2008.4518538"},{"key":"e_1_3_2_62_2","unstructured":"Chester Wisniewski. 2011. Sony Europe hacked by Lebanese hacker... Again\u2014Naked Security. Retrieved October 10 2021 from https:\/\/bit.ly\/2J6Vu1P"},{"key":"e_1_3_2_63_2","unstructured":"Yubico AB. [n.d.]. Trust the Net with YubiKey Strong Two-Factor Authentication. Retrieved from https:\/\/www.yubico.com\/"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3632175","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3632175","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:49:55Z","timestamp":1750286995000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3632175"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,10]]},"references-count":62,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,2,29]]}},"alternative-id":["10.1145\/3632175"],"URL":"https:\/\/doi.org\/10.1145\/3632175","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,10]]},"assertion":[{"value":"2021-11-24","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-01-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}