Computer Security – ESORICS 2015
Volume 9327 of the series Lecture Notes in Computer Science pp 456-477
The Emperor’s New Password Creation Policies: An Evaluation of Leading Web Services and the Effect of Role in Resisting Against Online Guessing
- Ding WangAffiliated withSchool of EECS, Peking UniversityNational Engineering Research Center for Software Engineering
- , Ping WangAffiliated withNational Engineering Research Center for Software EngineeringSchool of Software and Microelectronics, Peking University
Abstract
While much has changed in Internet security over the past decades, textual passwords remain as the dominant method to secure user web accounts and they are proliferating in nearly every new web services. Nearly every web services, no matter new or aged, now enforce some form of password creation policy. In this work, we conduct an extensive empirical study of 50 password creation policies that are currently imposed on high-profile web services, including 20 policies mainly from US and 30 ones from mainland China. We observe that no two sites enforce the same password creation policy, there is little rationale under their choices of policies when changing policies, and Chinese sites generally enforce more lenient policies than their English counterparts.
We proceed to investigate the effectiveness of these 50 policies in resisting against the primary threat to password accounts (i.e. online guessing) by testing each policy against two types of weak passwords which represent two types of online guessing. Our results show that among the total 800 test instances, 541 ones are accepted: 218 ones come from trawling online guessing attempts and 323 ones come from targeted online guessing attempts. This implies that, currently, the policies enforced in leading sites largely fail to serve their purposes, especially vulnerable to targeted online guessing attacks.
Keywords
User authentication Password creation policy Password cracking Online trawling guessing Online targeted guessing- Title
- The Emperor’s New Password Creation Policies: An Evaluation of Leading Web Services and the Effect of Role in Resisting Against Online Guessing
- Book Title
- Computer Security – ESORICS 2015
- Book Subtitle
- 20th European Symposium on Research in Computer Security, Vienna, Austria, September 21–25, 2015, Proceedings, Part II
- Pages
- pp 456-477
- Copyright
- 2015
- DOI
- 10.1007/978-3-319-24177-7_23
- Print ISBN
- 978-3-319-24176-0
- Online ISBN
- 978-3-319-24177-7
- Series Title
- Lecture Notes in Computer Science
- Series Volume
- 9327
- Series ISSN
- 0302-9743
- Publisher
- Springer International Publishing
- Copyright Holder
- Springer International Publishing Switzerland
- Additional Links
- Topics
- Keywords
-
- User authentication
- Password creation policy
- Password cracking
- Online trawling guessing
- Online targeted guessing
- Industry Sectors
- eBook Packages
- Editors
-
- Günther Pernul (15)
- Peter Y A Ryan (16)
- Edgar Weippl (17)
- Editor Affiliations
-
- 15. University of Regensburg
- 16. University of Luxembourg
- 17. SBA Research
- Authors
- Author Affiliations
-
- 18. School of EECS, Peking University, Beijing, 100871, China
- 19. National Engineering Research Center for Software Engineering, Beijing, China
- 20. School of Software and Microelectronics, Peking University, Beijing, 100260, China
Continue reading...
To view the rest of this content please follow the download PDF link above.
