+ All Categories
Home > Documents > Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management...

Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management...

Date post: 31-Mar-2015
Category:
Upload: alondra-barret
View: 215 times
Download: 0 times
Share this document with a friend
Popular Tags:
21
Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal
Transcript
Page 1: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Bootstrapping Mobile PINs Using Passwords

Markus JakobssonDebin Liu

Information Risk ManagementPayPal

Page 2: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

A Bit about Authentication

2

1 2 3 4 5

Short battery life

Slow Web connection

Lack of coverage

Poor voice quality

Small screen

size

Difficulty customizing

settings

Difficulty authenticating

Page 3: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Commercial Four-Letter Word

“Friction”

Page 4: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

A Bit About Human Memory

Not so amazing

Page 5: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Common PIN

Your spouse’s birthday

Page 6: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Love/Hate

PINs

Page 7: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

What will users see

Page 8: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Example User Mapping

“Blu2thRules” “2582”

Page 9: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Opportunistic Derivation

Access; Truncate; Map; Store

Page 10: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Special Characters

~1.5%

Can be reduced

Page 11: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Special Phones

Need numeric pad

Page 12: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Strong password, weak PIN

“1234Brew$g”, “1begHELP”

Page 13: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Password change?

Dual Universes

Page 14: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Measuring Security

Raided Dropboxes

Page 15: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Entropy of Derived PINs

FSP (8359) SNP (2873) Malware (16192)0

2

4

6

8

10

12

14

12

10.59.7

10.910

9.2

1.10.5 0.5

pwd4 EntropyPIN EntropyInformation Loss by Mapping

Data Sources (Size)

Info

rmat

ion

En

trop

ies

Page 16: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Special Characters

FSP (8359) SNP (2873) Malware (16192)0.00%

5.00%

10.00%

15.00%

20.00%

25.00%

30.00%

35.00% 32.16%

11.14%

26.96%

1.44% 1.95%

6.16%

Percentage of Passwords using Upper Case Letters

Percentage of Passwords using Special Characters

Data Sources (Size)

Per

cen

tage

Page 17: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Imagine PIN Theft

0

2

4

6

8

10

12

14

16

18

20

Page 18: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Experiment

What is Joe’s PIN?

Joe uses a PIN to access his PayPal account from his phone. But he does not want to have to remember another number, and he does not want to reuse his banking PIN. So he uses PayPal’s new “password to PIN” feature so that he only has to remember his password. Joe’s password is “Blu2thrules”. Look at the screen-shot below and let us know what PIN he should enter.

Page 19: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Usability of Derived PINs25-subject Qualitative study

Successful but Slow 24%

Failed12%

Successful and Fas

t64%

Page 20: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Usability of Derived PINs100-subject Quantitative study

Likely Successful22%

Failed10%

Successful68%

Page 21: Bootstrapping Mobile PINs Using Passwords Markus Jakobsson Debin Liu Information Risk Management PayPal.

Other things I pitch

Address web/app spoofing: www.SpoofKiller.com

Mobile-friendly passwords: www.fastword.me

Mobile malware detection: www.fatskunk.com

Etc: www.markus-jakobsson.com


Recommended