Passpet Convenient Password Management and Phishing Protection - - PowerPoint PPT Presentation

passpet
SMART_READER_LITE
LIVE PREVIEW

Passpet Convenient Password Management and Phishing Protection - - PowerPoint PPT Presentation

Passpet Convenient Password Management and Phishing Protection Ka-Ping Yee Kragen Sitaker ping@zesty.ca kragen@pobox.com problems: design: solutions: practical matters: evaluation: problems: the big 5 problems: the big 5 1 many


slide-1
SLIDE 1

Passpet

Convenient Password Management and Phishing Protection Ka-Ping Yee ping@zesty.ca Kragen Sitaker kragen@pobox.com

slide-2
SLIDE 2

problems: design: solutions: practical matters: evaluation:

slide-3
SLIDE 3

problems: the big 5

slide-4
SLIDE 4

problems: the big 5

1 many passwords

slide-5
SLIDE 5

problems: the big 5

1 many passwords 2 dictionary attack

slide-6
SLIDE 6

problems: the big 5

1 many passwords 2 dictionary attack 3 password entry in webpages

slide-7
SLIDE 7
slide-8
SLIDE 8

problems: the big 5

1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation

slide-9
SLIDE 9
slide-10
SLIDE 10
slide-11
SLIDE 11
slide-12
SLIDE 12

problems: the big 5

1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

slide-13
SLIDE 13
slide-14
SLIDE 14

problems: the big 5

1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

slide-15
SLIDE 15

design:

slide-16
SLIDE 16

design:

logging in setting up a new password setting up Passpet

slide-17
SLIDE 17

solutions:

slide-18
SLIDE 18

solutions:

1 many passwords

slide-19
SLIDE 19

master secret site name site-specific password

slide-20
SLIDE 20

master secret site name site-specific password

slide-21
SLIDE 21

master secret site name site-specific password

slide-22
SLIDE 22

solutions:

1 many passwords 2 dictionary attack

slide-23
SLIDE 23

master secret site name site-specific password

slide-24
SLIDE 24

? site name site-specific password

slide-25
SLIDE 25

? site name site-specific password

+

slide-26
SLIDE 26

master secret site-specific password

+

site name

slide-27
SLIDE 27

master secret site-specific password

+

site name

+

slide-28
SLIDE 28

master secret site name site-specific password

+ +

master secret user name

Password Multiplier (Halderman, 2005)

slide-29
SLIDE 29

Passpet: variable-strength password hash

slide-30
SLIDE 30

Give responsive feedback

  • n password strength.
slide-31
SLIDE 31

solutions:

1 many passwords 2 dictionary attack 3 password entry in webpages

slide-32
SLIDE 32
slide-33
SLIDE 33

solutions:

1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation

slide-34
SLIDE 34

Petname Tool (Close, 2005)

slide-35
SLIDE 35

Passpet: use site label for hashing

slide-36
SLIDE 36

Help users rely on information from the user, not an attacker.

slide-37
SLIDE 37

solutions:

1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

slide-38
SLIDE 38

Dynamic Security Skins (Dhamija, 2005)

slide-39
SLIDE 39

Passpet: interact directly with custom icon

slide-40
SLIDE 40

Passpet: interact directly with custom icon

slide-41
SLIDE 41

Get the user to interact with something personalized.

slide-42
SLIDE 42

contributions:

1 variable-strength hashing 2 password strength feedback 3 use user-assigned labels for hashing 4 personalized security agent 5 direct interaction with customized UI

slide-43
SLIDE 43

practical matters:

slide-44
SLIDE 44

practical matters:

What if you want to use another computer?

slide-45
SLIDE 45

practical matters:

What if someone gets your password file?

slide-46
SLIDE 46

practical matters:

What if you want to use another computer?

Firefox Passpet

encrypted site labels

Passpet Server

encrypted site labels

slide-47
SLIDE 47

practical matters:

What if you want to use existing websites?

slide-48
SLIDE 48

practical matters:

What if you need to change a password?

slide-49
SLIDE 49

evaluation:

slide-50
SLIDE 50

evaluation:

Passpet for Internet Explorer: tested at HP labs with 15 users main complaint: want to use other computers Passpet for Firefox: not yet usability-tested

slide-51
SLIDE 51

thanks:

Tyler Close (Petname Tool) Alan Karp (Passpet user study) David Wagner (design and cryptography)

  • J. Alex Halderman (Password Multiplier)

Rachna Dhamija (Dynamic Security Skins)

http://passpet.org/