Collected research
Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting
Risk-based login systems decide whether to demand a second factor by comparing browser fingerprints, so a phishing page harvesting exactly the attributes a target site measures lets an attacker replay the victim's fingerprint from another device and skip two-factor authentication. The authors automate building matching fingerprinting vectors and measure how many live phishing kits collect enough.
Record
- Researcher
- Xu Lin, Panagiotis Ilia, Saumya Solanki and Jason Polakis
- Published by
- usenix.org
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Xu Lin, Panagiotis Ilia, Saumya Solanki and Jason Polakis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .