Measuring Website Password Creation Policies At Scale

09/06/2023
by   Suood Alroomi, et al.
0

Researchers have extensively explored how password creation policies influence the security and usability of user-chosen passwords, producing evidence-based policy guidelines. However, for web authentication to improve in practice, websites must actually implement these recommendations. To date, there has been limited investigation into what password creation policies are actually deployed by sites. Existing works are mostly dated and all studies relied on manual evaluations, assessing a small set of sites (at most 150, skewed towards top sites). Thus, we lack a broad understanding of the password policies used today. In this paper, we develop an automated technique for inferring a website's password creation policy, and apply it at scale to measure the policies of over 20K sites, over two orders of magnitude (135x) more sites than prior work. Our findings identify the common policies deployed, potential causes of weak policies, and directions for improving authentication in practice. Ultimately, our study provides the first large-scale understanding of password creation policies on the web.

READ FULL TEXT
research
08/02/2018

Shepherd: Enabling Automatic and Large-Scale Login Security Studies

More and more parts of the internet are hidden behind a login field. Thi...
research
10/18/2021

Long Passphrases: Potentials and Limits

Passphrases offer an alternative to traditional passwords which aim to b...
research
03/12/2020

Lost in Disclosure: On The Inference of Password Composition Policies

Large-scale password data breaches are becoming increasingly commonplace...
research
08/21/2019

Case Study: Disclosure of Indirect Device Fingerprinting in Privacy Policies

Recent developments in online tracking make it harder for individuals to...
research
05/03/2018

An Automated Approach to Auditing Disclosure of Third-Party Data Collection in Website Privacy Policies

A dominant regulatory model for web privacy is "notice and choice". In t...
research
12/11/2017

Usability of Humanly Computable Passwords

Reusing passwords across multiple websites is a common practice that com...
research
11/18/2021

Reining in Mobile Web Performance with Document and Permission Policies

The quality of experience with the mobile web remains poor, partially as...

Please sign up or login with your details

Forgot password? Click here to reset