Black Hat
,
Events
,
Governance & Risk Management
Bell Labs’ Siddharth Rao on the Need for Stronger Safeguards in Account Recovery
Service providers often sacrifice security in account recovery to keep users on their platforms. Siddharth Rao, senior security research scientist at Nokia Bell Labs, said this approach leaves systems vulnerable because usability is prioritized over robust safeguards. The trade-off may help retain customers but creates weak points for exploitation.
See Also: AI, Zero Trust and SASE: Modernizing Security
One major risk comes from relying on out-of-band channels such as email or SMS for recovery. These are outside the provider’s control and can be compromised without detection. Rao said providers often fail to apply the same strict password policies to recovery as they do during account creation, leaving recovery flows easier to exploit.
“There are two aspects to this. One is overly strict security policies, and the other aspect is the design problems … there are also inconsistencies in practice. The problem is the whole approach,” Rao said.
In this video interview with Information Security Media Group at Black Hat USA 2025, Rao also discussed:
- How physical access and stealth tactics enable adversaries to exploit vulnerabilities;
- Why fully automated account recovery fails to address critical edge cases;
- The need for multifactor authentication tools, such as YubiKeys, in recovery flows.
Rao’s research spans the security analysis of networked systems and the human factors in security, privacy and AI. His work bridges theory and real-world application through an interdisciplinary, hands-on approach. His efforts have contributed to shaping public policy and raising awareness around cybersecurity issues. Rao also currently advises various startups focusing on novel technological interventions.

