THE TANGLED WEB OF PASSWORD REUSE
DAS, BONNEAU, CAESAR, BORISOV, AND WANG PRESENTED BY: CODY FRENZEL AND JP WHEELER
THE TANGLED WEB OF PASSWORD REUSE DAS, BONNEAU, CAESAR, BORISOV, - - PowerPoint PPT Presentation
THE TANGLED WEB OF PASSWORD REUSE DAS, BONNEAU, CAESAR, BORISOV, AND WANG PRESENTED BY: CODY FRENZEL AND JP WHEELER INTRODUCTION Easy to guess passwords undermine security Many online services offer password composition policies and
DAS, BONNEAU, CAESAR, BORISOV, AND WANG PRESENTED BY: CODY FRENZEL AND JP WHEELER
and meters
password reuse more prevalent
same user over different websites based on the largest data set yet collected
different online accounts
across different online accounts
at one site to produce guesses for passwords potentially used at other sites for the same user
but such passwords are considered too complex to remember
these categories:
attack by using a training set to obtain probabilities of candidate substrings
passwords over 3.9 different sites
when forced to change. They created a generic algorithm that could guess future passwords.
password attacks by deploying password management tools like PwdHash.
processes when creating passwords for different websites
universities
passwords
transformation rules, such as adding a few random extra characters or adding emoticons
incorporate the interesting rules in order to preserve simplicity
should determine the user’s password for other sites with a low number of guesses
pattern sequences
apply the corresponding transformation sequentially
transformations iteratively from the following set: {Digit, Symbol, Uppercase letter, Lowercase letter}
symbols at the front or end
the front, then the back, then combinations of both
reverses the input password
transformations
substrings where the delimiter character belongs to the set {Digit, Symbol, Uppercase Letter}
capitalizes the first letter of each
to crack target password
that this is a significant security vulnerability
and many users share the same method of modification
passwords in less than 10 attempts
pairs