{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:39:01Z","timestamp":1780634341256,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["OAC-2139358, CNS-2201465 and CNS-2154507"],"award-info":[{"award-number":["OAC-2139358, CNS-2201465 and CNS-2154507"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690286","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"1686-1700","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display Authenticators"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-4136-7004","authenticated-orcid":false,"given":"Ahmed Tanvir","family":"Mahdad","sequence":"first","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9398-3875","authenticated-orcid":false,"given":"Mohammed","family":"Jubur","sequence":"additional","affiliation":[{"name":"Jazan University, Jazan, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6083-104X","authenticated-orcid":false,"given":"Nitesh","family":"Saxena","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2021. Outlook- Free personal email and calender from Microsoft. https:\/\/outlook.live.com\/owa\/."},{"key":"e_1_3_2_1_2_1","unstructured":"AO Kaspersky Lab. 2021. Kaspersky Security Cloud - Free. https:\/\/www.kaspersky.com\/free-cloud-antivirus."},{"key":"e_1_3_2_1_3_1","unstructured":"Avast Foundation. 2021. Avast Free Antivirus. https:\/\/www.avast.com\/en-us."},{"key":"e_1_3_2_1_4_1","unstructured":"Avast Software s.r.o. 2021. AVG Free Antivirus. https:\/\/www.avg.com\/en-us\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Avira Operations GmbH & Co. KG. 2021. Avira Antivirus. https:\/\/www.avira.com\/."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-84252-9_5"},{"key":"e_1_3_2_1_7_1","volume-title":"Annual international cryptology conference","author":"Bellare Mihir","unstructured":"Mihir Bellare and Phillip Rogaway. 1993. Entity authentication and key distribution. In Annual international cryptology conference. Springer, 232--249."},{"key":"e_1_3_2_1_8_1","unstructured":"BleepingComputer LLC. 2022. Malicious browser extensions targeted almost 7 million people. https:\/\/www.bleepingcomputer.com\/news\/security\/malicious-browser-extensions-targeted-almost-7-million-people\/."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_1_10_1","volume-title":"Markku Antikainen, Viswanathan Manihatty Bojan, and Tuomas Aura.","author":"Bui Thanh","year":"2018","unstructured":"Thanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan, and Tuomas Aura. 2018. Man-in-the-machine: exploiting ill-secured communication inside the computer. In 27th {USENIX} Security Symposium ({USENIX} Security 18). 1511--1525."},{"key":"e_1_3_2_1_11_1","unstructured":"Checkpoint Software Technologies Limited. 2022. May 2022s Most Wanted Malware: Snake Keylogger Returns to the Top Ten after a long absense. https:\/\/www.checkpoint.com\/press-releases\/may-2022s-most-wanted-malware-snake-keylogger-returns-to-the-top-ten-after-a-long-absence\/."},{"key":"e_1_3_2_1_12_1","unstructured":"Chromium Project. 2021. ChromeDriver- WebDriver For Chrome. https:\/\/chromedriver.chromium.org."},{"key":"e_1_3_2_1_13_1","unstructured":"Cisco. 2022. Guide to Web Authentication. https:\/\/webauthn.guide\/."},{"key":"e_1_3_2_1_14_1","unstructured":"Comodo Group Inc. 2020. What is Zeus Trojan | How the Zeus Virus infects the computers https:\/\/enterprise.comodo.com\/blog\/what-is-zeus-trojan\/."},{"key":"e_1_3_2_1_15_1","unstructured":"Facebook. 2021. Facebook. https:\/\/www.facebook.com\/."},{"key":"e_1_3_2_1_16_1","volume-title":"Sixteenth Symposium on Usable Privacy and Security (SOUPS","author":"Farke Florian M","year":"2020","unstructured":"Florian M Farke, Lennart Lorenz, Theodor Schnitzler, Philipp Markert, and Markus D\u00fcrmuth. 2020. {You} still use the password after {all}--Exploring {FIDO2} Security Keys in a Small Company. In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). 19--35."},{"key":"e_1_3_2_1_17_1","unstructured":"FIDO Alliance . 2022. FIDO2: WebAuthn & CTAP. https:\/\/fidoalliance.org\/fido2\/."},{"key":"e_1_3_2_1_18_1","volume-title":"FIDO Security Reference (FIDO Alliance Review Draft","author":"Alliance FIDO","year":"2021","unstructured":"FIDO Alliance. 2021. FIDO Security Reference (FIDO Alliance Review Draft 25 May 2021). https:\/\/fidoalliance.org\/specs\/common-specs\/fido-security-ref-v2.1-rd-20210525.html."},{"key":"e_1_3_2_1_19_1","unstructured":"FIDO Alliance. 2022. Client-to-Authenticator protocol (CTAP2). https:\/\/fidoalliance.org\/specs\/fido-v2.0-ps-20190130\/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html."},{"key":"e_1_3_2_1_20_1","unstructured":"FIDO Alliance. 2022. FIDO Alliance- Open Authentication Standards. https:\/\/fidoalliance.org\/."},{"key":"e_1_3_2_1_21_1","unstructured":"Google. 2021. Google Accounts. https:\/\/accounts.google.com."},{"key":"e_1_3_2_1_22_1","unstructured":"Google Cloud. 2021. Titan Security Key. https:\/\/cloud.google.com\/titan-security-key."},{"key":"e_1_3_2_1_23_1","volume-title":"Headless Chrome: DevOps Love It, So Do Hackers, Heres Why. https:\/\/www.imperva.com\/blog\/headless-chrome-devops-love-it-so-do-hackers-heres-why\/.","year":"2021","unstructured":"Imparva. 2021. Headless Chrome: DevOps Love It, So Do Hackers, Heres Why. https:\/\/www.imperva.com\/blog\/headless-chrome-devops-love-it-so-do-hackers-heres-why\/."},{"key":"e_1_3_2_1_24_1","volume-title":"Headless Chrome: DevOps Love It, So Do Hackers, Heres Why. https:\/\/www.imperva.com\/blog\/headless-chrome-devops-love-it-so-do-hackers-heres-why\/.","year":"2018","unstructured":"Imperva. 2018. Headless Chrome: DevOps Love It, So Do Hackers, Heres Why. https:\/\/www.imperva.com\/blog\/headless-chrome-devops-love-it-so-do-hackers-heres-why\/."},{"key":"e_1_3_2_1_25_1","unstructured":"InfoSecurity Magazine. 2018. Attackers keen on Automated Browsers. https:\/\/www.infosecurity-magazine.com\/news\/attackers-keen-on-automated\/."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3440712"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453084"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Dhruv Kuchhal Muhammad Saad Adam Oest and Frank Li. 2023. Evaluating the Security Posture of Real-World FIDO2 Deployments. (2023).","DOI":"10.1145\/3576915.3623063"},{"key":"e_1_3_2_1_29_1","volume-title":"International Conference on Financial Cryptography and Data Security. Springer, 422--440","author":"Lang Juan","year":"2016","unstructured":"Juan Lang, Alexei Czeskis, Dirk Balfanz, Marius Schilder, and Sampath Srinivas. 2016. Security keys: Practical cryptographic second factors for the modern web. In International Conference on Financial Cryptography and Data Security. Springer, 422--440."},{"key":"e_1_3_2_1_30_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Lassak Leona","year":"2021","unstructured":"Leona Lassak, Annika Hildebrandt, Maximilian Golla, and Blase Ur. 2021. \" Its Stored, Hopefully, on an Encrypted Server: Mitigating Users Misconceptions About {FIDO2} Biometric {WebAuthn}. In 30th USENIX Security Symposium (USENIX Security 21). 91--108."},{"key":"e_1_3_2_1_31_1","volume-title":"IEEE Symposium on Security and Privacy. 268--285","author":"Lyastani Sanam Ghorbani","year":"2020","unstructured":"Sanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes, and Sven Bugiel. 2020. Is FIDO2 the Kingslayer of User Authentication A Comparative Usability Study of FIDO2 Passwordless Authentication.. In IEEE Symposium on Security and Privacy. 268--285."},{"key":"e_1_3_2_1_32_1","unstructured":"MalwareBytes. 2021. MalwareBytes Cybersecurity for Home and Business. https:\/\/www.malwarebytes.com\/."},{"key":"e_1_3_2_1_33_1","unstructured":"McAfee. 2021. McAfee Total Protection. https:\/\/www.mcafee.com\/en-us\/antivirus\/free.html."},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"McCune Jonathan M","year":"2009","unstructured":"Jonathan M McCune. 2009. Safe passage for passwords and other sensitive data. In Proceedings of the Network and Distributed System Security Symposium, 2009."},{"key":"e_1_3_2_1_35_1","volume-title":"Windows Defender Antivirus","author":"Security Windows","unstructured":"Microsoft. 2021. Windows 10 Security, Windows Defender Antivirus, Windows Defender Security Centre. https:\/\/www.microsoft.com\/en-us\/windows\/comprehensive-security."},{"key":"e_1_3_2_1_36_1","unstructured":"NIST. 2022. Authenticator Assurance Level (AAL). https:\/\/csrc.nist.gov\/glossary\/term\/authenticator_assurance_level."},{"key":"e_1_3_2_1_37_1","unstructured":"Software Freedom Conservancy- Selenium Project. 2021. Selenium WebDriver. https:\/\/www.selenium.dev\/projects\/."},{"key":"e_1_3_2_1_38_1","unstructured":"Sophos Ltd. 2021. Sophos Home - Cybersecurity made simple. https:\/\/home.sophos.com\/en-us.aspx."},{"key":"e_1_3_2_1_39_1","unstructured":"StatCounter. 2021. Browser Market Share Worldwide. https:\/\/gs.statcounter.com\/browser-market-share."},{"key":"e_1_3_2_1_40_1","volume-title":"Desktop Operating System Market Share Worldwide-October","year":"2023","unstructured":"StatCounter. 2023. Desktop Operating System Market Share Worldwide-October 2023. https:\/\/gs.statcounter.com\/os-market-share\/desktop\/worldwide."},{"key":"e_1_3_2_1_41_1","volume-title":"Operating System Market Share Worldwide-","year":"2022","unstructured":"StatCounter. 2023. Operating System Market Share Worldwide- September 2022. https:\/\/gs.statcounter.com\/os-market-share."},{"key":"e_1_3_2_1_42_1","volume-title":"Global market share held by operating systems for desktop PCs, from","year":"2013","unstructured":"Statista. 2024. Global market share held by operating systems for desktop PCs, from January 2013 to February 2024. https:\/\/www.statista.com\/statistics\/218089\/global-market-share-of-windows-7\/."},{"key":"e_1_3_2_1_43_1","unstructured":"ThreatPost. 2021. 500 Malicious Chrome Extensions Impact Millions of Users. https:\/\/threatpost.com\/500-malicious-chrome-extensions-millions\/152918\/."},{"key":"e_1_3_2_1_44_1","unstructured":"Twitter Inc. 2021. Explore Twitter. https:\/\/twitter.com\/explore."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2021.06.034"},{"key":"e_1_3_2_1_46_1","unstructured":"Yubico. 2021. Security Key by Yubico. https:\/\/www.yubico.com\/product\/security-key-by-yubico."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176946"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690286","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690286","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:18:19Z","timestamp":1755843499000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690286"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":47,"alternative-id":["10.1145\/3658644.3690286","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690286","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}