Authentication Inconsistencies Across Online Services: A Multi-Scenario Security Analysis
摘要
Online services are integral to modern life, supporting activities such as communication, commerce, and travel. These services typically require user authentication, traditionally relying on user ID and password combinations. However, this approach is increasingly vulnerable to attacks such as phishing. Many services have adopted stronger authentication mechanisms, including multi-factor authentication, risk-based authentication, and passkeys. Despite extensive research on login procedures, limited attention has been given to these post-login authentication processes. This paper presents a first study investigating the interplay between multi-factor authentication and context-specific authentication for ten popular online services. The results indicate that various authentication methods and behaviors can be observed across different scenarios and services.