How to end password reuse on the web

05/01/2018
by   Ke Coby Wang, et al.
0

We present a framework by which websites can coordinate to make it difficult for users to set similar passwords at these websites, in an effort to break the culture of password reuse on the web today. Though the design of such a framework is fraught with risks to users' security and privacy, we show that these risks can be effectively mitigated through careful scoping of the goals for such a framework and through principled design. At the core of our framework is a private set-membership-test protocol that enables one website to determine, upon a user setting a password for use at it, whether that user has already set a similar password at another website, but with neither side disclosing to the other the password(s) it employs in the protocol. Our framework then layers over this protocol a collection of techniques to mitigate the leakage necessitated by such a test. These mechanisms are consistent with common user experience today, and so our framework should be unobtrusive to users who do not reuse similar passwords across websites (e.g., due to having adopted a password manager). Through a working implementation of our framework and optimization of its parameters based on insights of how passwords tend to be reused, we show that our design can meet the scalability challenges facing such a service.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/22/2018

To Extend or not to Extend: on the Uniqueness of Browser Extensions and Web Logins

Recent works showed that websites can detect browser extensions that use...
research
12/23/2019

Detecting stuffing of a user's credentials at her own accounts

We propose a framework by which websites can coordinate to detect creden...
research
01/10/2020

Understanding and Mitigating the Security Risks of Content Inclusion in Web Browsers

Thanks to the wide range of features offered by web browsers, modern web...
research
08/19/2020

Automatic Generation of Chatbots for Conversational Web Browsing

In this paper, we describe the foundations for generating a chatbot out ...
research
07/15/2019

Tracking sex: The implications of widespread sexual data leakage and tracking on porn websites

This paper explores tracking and privacy risks on pornography websites. ...
research
11/18/2021

Reining in Mobile Web Performance with Document and Permission Policies

The quality of experience with the mobile web remains poor, partially as...
research
04/08/2022

CookieEnforcer: Automated Cookie Notice Analysis and Enforcement

Online websites use cookie notices to elicit consent from the users, as ...

Please sign up or login with your details

Forgot password? Click here to reset