Sunil, Don (2025) Security Analysis & Mitigation Strategies for Multi-Factor Authenticator Apps. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (587kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (532kB) | Preview |
Abstract
The growing dependence on Time-based One-Time Password (TOTP) authenticator apps such as Google Authenticator, Microsoft Authenticator, and Authy for multi-factor authentication (MFA) has made people more concerned with regard to their cryptographic robustness specifically in transport and backup layers. This study critically investigates whether widely used authenticator applications are susceptible to data leakage through insecure backup exports along with transport-layer exposures, in addition to whether such vulnerabilities can be reduced without any compromising of usability.
For development of this simulation-based framework, a lightweight emulator-less environment under Ubuntu WSL2 was used. For vulnerabilities, replication occurred when synthetic TOTP seeds exported in plaintext JSON format were utilized, also when traffic was captured via mitmproxy and was analyzed using custom parsing scripts. Mobile Security Framework or MobSF was used in order to conduct static analysis for the purpose of detecting missing cryptographic safeguards and insecure implementations. The captured data confirmed that secret seeds could be intercepted within certain configurations, so this revealed meaningful privacy risks.
In response, there was a mitigation strategy that was implemented via designing of a wrapper because it encrypts exported backup files through using Argon2id-based key derivation plus the XChaCha20-Poly1305 authenticated encryption scheme. The resulting .sec files preserved data integrity and also confidentiality while encryption times averaged to under 250 ms per file, and also the files incurred minimal overhead. They integrated further a validation mechanism, and SHA-256 hashing and hexdump inspection confirmed complete obfuscation of original contents. Secret leakage risk can drop greatly with application-layer encryption, as shown by the framework’s results. Users remain endangered though by common dependence on open backups and certain apps' missing certificate pinning. Furthermore, usability remains preserved within the proposed approach. This preservation indicates that the strong security controls can coexist along with user accessibility.
This work offers a script-driven reproducible prototype regarding secure backup handling within TOTP apps stressing a key need for firm cryptographic conduct within MFA ecosystems. Developers are also given a pathway to adopt secure design patterns that advances academic discourse as well as practical security engineering in mobile authentication without sacrificing performance or usability.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Monaghan, Mark UNSPECIFIED |
| Uncontrolled Keywords: | Multi-Factor Authentication (MFA); Time-based One-Time Password (TOTP); Authenticator Apps; Backup Security; End-to-End Encryption |
| Subjects: | Q Science > QA Mathematics > Electronic computers. Computer science T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 19 Aug 2026 15:31 |
| Last Modified: | 19 Aug 2026 15:31 |
| URI: | https://norma.ncirl.ie/id/eprint/9554 |
Actions (login required)
![]() |
View Item |
Tools
Tools