A spark is enough in a straw world: a study of websites password management in the wild

04/19/2018
by   Simone Raponi, et al.
0

With the entry into force of the General Data Protection Regulation (GDPR), in the May 25th 2018, the European Parliament, together with the Council of the European Union and the European Commission, aim to strengthen the data protection for all the European citizens. The organizations or individuals that collect, process, or analyze data of European Union citizens, in case of non-compliance with the regulation, are subject to heavy penalties ranging from 10-20M euros to 2-4 year (in case of an enterprise). In this paper we first provide a survey of both user authentication mechanisms implemented by websites and password recovery mechanisms currently adopted. Subsequently, we provide a thorough analysis of the password management of the Alexa's top 200 websites in different countries, including England, Germany, and Italy, by pointing out that almost 43 users' identities on the web. Then we model an attacker with different capabilities and we show how websites' vulnerabilities can be exploited to carry on many attacks; finally we propose several effective countermeasures and we point out that most of websites are far from being ready for the compliance with the regulation and may incur in the aforementioned unsustainable penalties.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/22/2019

Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework

As a result of the GDPR and the ePrivacy Directive, European users encou...
research
01/08/2020

Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence

New consent management platforms (CMPs) have been introduced to the web ...
research
08/29/2023

Needle in the Haystack: Analyzing the Right of Access According to GDPR Article 15 Five Years after the Implementation

The General Data Protection Regulation (GDPR) was implemented in 2018 to...
research
02/02/2022

Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?

Data protection regulations, such as GDPR and CCPA, require websites and...
research
10/19/2021

The Impact of User Location on Cookie Notices (Inside and Outside of the European Union)

The web is global, but privacy laws differ by country. Which set of priv...
research
08/27/2019

Multiple Purposes, Multiple Problems: A User Study of Consent Dialogs after GDPR

The European Union's General Data Protection Regulation (GDPR) requires ...
research
03/11/2021

On Medical Device Cybersecurity Compliance in EU

The medical device products at the European Union market must be safe an...

Please sign up or login with your details

Forgot password? Click here to reset