Overview
Syllabus
Intro
Facts and Figures about Airlock & Ergon
OWASP Top 10
Upfront Web Application Security
Upfront Authentication
Strong Authentication Examples: OTP
Strong Authentication Examples: C/R
Trivial: Feedback Messages
Trivial Remedy: Generic Feedback Message
How About 2-Factor Authentication?
Requirements
Step 1: Simulate 2nd Factor with OTP
Step 1: Simulate 2nd Factor with MTAN
Account Locked Information
Simulate for unknown users
Step 3: Unknown users with different 2nd factors
What we implemented
Some Implementation Details
Configuration
Usability Considerations
Prevent other hidden channels
Conclusion
Taught by
OWASP Foundation