23
THE PASSWORD THICKET By: Joseph Bonneau Sören Preibusch technical and market failures in human authentication on the web Reviewed by: Komal Sachdeva MT10007

THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

THE PASSWORD THICKET

By:

Joseph Bonneau

Sören Preibusch

technical and market failures in human authentication on the web

Reviewed by:

Komal SachdevaMT10007

Page 2: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Some Definitions:

PASSWORD:

A secret word or phrase known only to a restricted group.

THICKET:

A dense growth of shrubs or underbrush.

2

Page 3: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Recent Examples

Twitter

hack.

2009

3http://en.webrazzi.com/

Page 4: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Motivation and Related Work.HUMAN ASPECT

Easily guessable passwords.

password cracking

Writing down.

social engineering attack

Reuse.

the average web user was found to maintain 25 separate password accounts, with just 6.5 passwords.

4

Page 5: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

HUMAN ASPECT

Sharing password.

sharing password increases intimacy between couples.

teenagers share them casually.

5

Motivation and Related Work.

Page 6: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

INDUSTRY ASPECT

Improved storage

salted and hashed password

Password entry.

cued recall system

mnemonic password

graphic password

6

Motivation and Related Work.

Page 7: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Single sign on system.

OpenID

Facebook Connect

Password Standardization

ISO27001

TLS implementation

Falk et al.’s study were that most banking websites (76%) suffered at least one noticeable design flaw of the 5 checked for,including 30% of banks failing to use TLS

7

Motivation and Related Work.

Page 8: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Work Done.

Selection of sites. Their study included 150 websites which offer free user accounts for a variety of purposes, including the most popular destinations on the web and a random sample of e-commerce, news, and communication websites

8

Websites

● Identity

● Content

● E-commerce

Page 9: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

9

Work Done.

http://preibusch.de/publ/password-market

Page 10: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Evaluation Basis.

Enrollment.

strong password, requesting email

Login/Logout.

password transmitted safely ?

Password Updates

length and content of the password

Password Reset/Recovery

clear text mail, random onetime password

Possible attacks

user probing

password guessing

10

Page 11: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Analysis

Varied User Experience

advice for password protection.

78% of sites provided no advice or guidance on what a password is, demonstrating that users are expected to have internalised the concept of webbased password login.

11

Page 12: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

varied amount of data collected

12

Analysis

http://preibusch.de/publ/password-market

Page 13: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

13

Security weakness Lack of standardization

Password recovery• Email based – 48%• Temporary password - 27%• Cleartext password – 25%

Analysis

Page 14: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

14

Lack of standardization: Password length

Analysis

http://preibusch.de/publ/password-market

Page 15: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Security weakness

Password guessing

Time out- only permitted to make 4 login attempts a minute.

CAPTCHA

No limit- more than 100 passwords are tried and in more than 100 sites there was no notification till then.

15

Analysis

Page 16: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

16

Clusters of websites

Analysis

http://preibusch.de/publ/password-market

Page 17: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Site’s security implementation

17

Analysis

http://preibusch.de/publ/password-market

Page 18: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

18

Most popular deploy better password security

Analysis

http://preibusch.de/publ/password-market

Page 19: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Site’s security requirement

Content sites require less rigorous password security measures than e-commerece website.

Payment sites were also more likely to block users from sharing passwords through BugMeNot with very strong significance, with 85% doing so compared to just 20% of non payment-processing sites

19

Analysis

Page 20: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Password collection

20

Analysis

http://preibusch.de/publ/password-market

Page 21: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Economic model

Password security as a tragedy of common.

To prevent depletion of their password memory, consumers must either reduce the burden for each individual password by choosing weaker passwords or reduce the cumulative burden by re-using passwords.

Password insecurity as a negative externality.

web sites with poor password security impose a strong negative externality on sites which have implemented more security, as they dissipate a security cost without accountability in the market.

21

Page 22: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Proposed Solution

Password Tax.

Restricting password re-use by password segmentation

Liability

Technical standards

22

Page 23: THE PASSWORD THICKET - Personalpersonal.strath.ac.uk/.../komalsachdeva_password_thicket.pdf · 2018-04-05 · Motivation and Related Work. HUMAN ASPECT Easily guessable passwords

Thank you…

23