Automating Multi-Factor Authentication | Or Polaczek

  Рет қаралды 11,626

Selenium Conference

Selenium Conference

Күн бұрын

The use of Multi-Factor Authentication is becoming more and more common online, especially in E-commerce. I believe that a true end-to-end monitoring system should be able to cover MFA steps without special tweaks.
This talk will describe the 3 most common methods used today to implement MFA:
- SMS code verification
- Automated phone-call that either reads a X-digits code or requires you to dial one yourself
- Time-based One Time Password (TOTP) algorithm using dedicated apps such as Google Authenticator / 1Password / Okta /etc.
After understanding the differences between the above methods, we'll walk through one way to automate each form of MFA. While SMS and TOTP are relatively easy to automate, automating phone calls and speech-to-text is more complicated. In order to address that challenge, this talk will introduce a new technology: Asterisk - an open-source telecommunications engine.
The talk will feature 3 live demos, one for automating each MFA form:
- How to use Twillio's API to automate the reception of SMS with verification code
- How to use a Python library and a pre-configured user account to automate TOTP
- How to use Asterisk and Amazon's ASR (automatic speech recognition) to automate the reception OR typing of a verification code of an automated phone call
All the demos and code-samples (including a dedicated Asterisk Dockerfile with the relevant configuration) will be open-sourced before the conference will start.

Пікірлер: 8
@MarcelVerkerk
@MarcelVerkerk 6 жыл бұрын
Well done Or! Liked the demos and the backup video to cover the failed demo :D - will keep this video in mind in case i ever need to deal with MFA!
@hemchanderrao338
@hemchanderrao338 4 жыл бұрын
Could you please share the github link for the code
@pottimurthyharshini3702
@pottimurthyharshini3702 2 жыл бұрын
Figured out ways to automate FaceID, Fingerprints and other Biometrics by now? Please post your insights about these as well.
@PratikGhodsad7
@PratikGhodsad7 2 жыл бұрын
Super awesome
@Sherloklol
@Sherloklol 4 жыл бұрын
Do you have any code examples to share on a code repo like github?
@cmrd
@cmrd 3 жыл бұрын
github.com/orpolaczek/seconf-2017-demo/blob/master/totp/facebook_login.py
@osaynlatongchongya1582
@osaynlatongchongya1582 2 жыл бұрын
Nice app
@osaynlatongchongya1582
@osaynlatongchongya1582 2 жыл бұрын
Nice video
Automating Multi-factor auth (MFA) based application with Katalon Studio
16:08
Clowns abuse children#Short #Officer Rabbit #angel
00:51
兔子警官
Рет қаралды 78 МЛН
Little girl's dream of a giant teddy bear is about to come true #shorts
00:32
How Many Balloons Does It Take To Fly?
00:18
MrBeast
Рет қаралды 191 МЛН
Hacking Two Factor Authentication: Four Methods for Bypassing 2FA and MFA
10:16
Distributed Automation Using Selenium Grid / AWS / Autoscaling
39:13
Selenium Conference
Рет қаралды 16 М.
MFA Can Be Easily Bypassed - Here's How
9:22
Grant Collins
Рет қаралды 89 М.
How to Automate Windows Based Application using Winium and Selenium
26:41
How to automate OTP number in Selenium and API || Using Twilio SMS APIs
38:43
Naveen AutomationLabs
Рет қаралды 73 М.
Automate TOTP 2-Factor Authentication (2FA) with Playwright
10:17
AutomateTogether
Рет қаралды 13 М.
Getting started with MFA - Using Google Authenticator for authentication
2:22
Xero Accounting Software
Рет қаралды 33 М.
Запрещенный Гаджет для Авто с aliexpress 2
0:50
Тимур Сидельников
Рет қаралды 684 М.
#samsung #retrophone #nostalgia #x100
0:14
mobijunk
Рет қаралды 11 МЛН
Что делать если в телефон попала вода?
0:17
Лена Тропоцел
Рет қаралды 2,9 МЛН
Looks very comfortable. #leddisplay #ledscreen #ledwall #eagerled
0:19
LED Screen Factory-EagerLED
Рет қаралды 4,9 МЛН
Как распознать поддельный iPhone
0:44
PEREKUPILO
Рет қаралды 2,2 МЛН