Web password recovery --- a necessary evil?

01/20/2018
by   Fatma Al Maqbali, et al.
0

Web password recovery, enabling a user who forgets their password to re-establish a shared secret with a website, is very widely implemented. However, use of such a fall-back system brings with it additional vulnerabilities to user authentication. This paper provides a framework within which such systems can be analysed systematically, and uses this to help gain a better understanding of how such systems are best implemented. To this end, a model for web password recovery is given, and existing techniques are documented and analysed within the context of this model. This leads naturally to a set of recommendations governing how such systems should be implemented to maximise security. A range of issues for further research are also highlighted.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/17/2020

Understanding The Top 10 OWASP Vulnerabilities

Understanding the common vulnerabilities in web applications help busine...
research
11/17/2019

Web-sites password management (in)security: Evidence and remedies

Single-factor password-based authentication is generally the norm to acc...
research
11/17/2019

A Longitudinal Study on Web-sites Password Management (in)Security: Evidence and Remedies

Single-factor password-based authentication is generally the norm to acc...
research
09/01/2021

Let Your Camera See for You: A Novel Two-Factor Authentication Method against Real-Time Phishing Attacks

Today, two-factor authentication (2FA) is a widely implemented mechanism...
research
12/02/2020

Smarter Password Guessing Techniques Leveraging Contextual Information and OSINT

In recent decades, criminals have increasingly used the web to research,...
research
05/26/2021

Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication

Threats to passwords are still very relevant due to attacks like phishin...
research
01/18/2021

Leveraging AI to optimize website structure discovery during Penetration Testing

Dirbusting is a technique used to brute force directories and file names...

Please sign up or login with your details

Forgot password? Click here to reset