+ All Categories
Home > Documents > THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf ·...

THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf ·...

Date post: 23-Jul-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
23
THE PASSWORD THICKET By: Joseph Bonneau Sören Preibusch technical and market failures in human authentication on the web Reviewed by: Komal Sachdeva MT10007
Transcript
Page 1: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

THE PASSWORD THICKET

By:

Joseph Bonneau

Sören Preibusch

technical and market failures in human authentication on the web

Reviewed by:

Komal SachdevaMT10007

Page 2: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Some Definitions:

PASSWORD:

A secret word or phrase known only to a restricted group.

THICKET:

A dense growth of shrubs or underbrush.

2

Page 3: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Recent Examples

Twitter

hack.

2009

3http://en.webrazzi.com/

Page 4: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Motivation and Related Work.HUMAN ASPECT

Easily guessable passwords.

password cracking

Writing down.

social engineering attack

Reuse.

the average web user was found to maintain 25 separate password accounts, with just 6.5 passwords.

4

Page 5: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

HUMAN ASPECT

Sharing password.

sharing password increases intimacy between couples.

teenagers share them casually.

5

Motivation and Related Work.

Page 6: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

INDUSTRY ASPECT

Improved storage

salted and hashed password

Password entry.

cued recall system

mnemonic password

graphic password

6

Motivation and Related Work.

Page 7: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Single sign on system.

OpenID

Facebook Connect

Password Standardization

ISO27001

TLS implementation

Falk et al.’s study were that most banking websites (76%) suffered at least one noticeable design flaw of the 5 checked for,including 30% of banks failing to use TLS

7

Motivation and Related Work.

Page 8: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Work Done.

Selection of sites. Their study included 150 websites which offer free user accounts for a variety of purposes, including the most popular destinations on the web and a random sample of e-commerce, news, and communication websites

8

Websites

● Identity

● Content

● E-commerce

Page 9: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

9

Work Done.

http://preibusch.de/publ/password-market

Page 10: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Evaluation Basis.

Enrollment.

strong password, requesting email

Login/Logout.

password transmitted safely ?

Password Updates

length and content of the password

Password Reset/Recovery

clear text mail, random onetime password

Possible attacks

user probing

password guessing

10

Page 11: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Analysis

Varied User Experience

advice for password protection.

78% of sites provided no advice or guidance on what a password is, demonstrating that users are expected to have internalised the concept of webbased password login.

11

Page 12: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

varied amount of data collected

12

Analysis

http://preibusch.de/publ/password-market

Page 13: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

13

Security weakness Lack of standardization

Password recovery• Email based – 48%• Temporary password - 27%• Cleartext password – 25%

Analysis

Page 14: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

14

Lack of standardization: Password length

Analysis

http://preibusch.de/publ/password-market

Page 15: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Security weakness

Password guessing

Time out- only permitted to make 4 login attempts a minute.

CAPTCHA

No limit- more than 100 passwords are tried and in more than 100 sites there was no notification till then.

15

Analysis

Page 16: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

16

Clusters of websites

Analysis

http://preibusch.de/publ/password-market

Page 17: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Site’s security implementation

17

Analysis

http://preibusch.de/publ/password-market

Page 18: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

18

Most popular deploy better password security

Analysis

http://preibusch.de/publ/password-market

Page 19: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Site’s security requirement

Content sites require less rigorous password security measures than e-commerece website.

Payment sites were also more likely to block users from sharing passwords through BugMeNot with very strong significance, with 85% doing so compared to just 20% of non payment-processing sites

19

Analysis

Page 20: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Password collection

20

Analysis

http://preibusch.de/publ/password-market

Page 21: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Economic model

Password security as a tragedy of common.

To prevent depletion of their password memory, consumers must either reduce the burden for each individual password by choosing weaker passwords or reduce the cumulative burden by re-using passwords.

Password insecurity as a negative externality.

web sites with poor password security impose a strong negative externality on sites which have implemented more security, as they dissipate a security cost without accountability in the market.

21

Page 22: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Proposed Solution

Password Tax.

Restricting password re-use by password segmentation

Liability

Technical standards

22

Page 23: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords.

Thank you…

23


Recommended