USABLE SECURITY GRAD SEC SEP 28 2017 USER AUTHENTICATION What - - PowerPoint PPT Presentation

usable security
SMART_READER_LITE
LIVE PREVIEW

USABLE SECURITY GRAD SEC SEP 28 2017 USER AUTHENTICATION What - - PowerPoint PPT Presentation

USABLE SECURITY GRAD SEC SEP 28 2017 USER AUTHENTICATION What we know (passwords) What we have (tokens) What we are (iris, fingerprint) [Accuracy vs. cost trade-off] Other USER AUTHENTICATION INKBLOT AUTHENTICATION Come up with


slide-1
SLIDE 1

USABLE
 SECURITY

GRAD SEC

SEP 28 2017

slide-2
SLIDE 2

USER AUTHENTICATION

What we know (passwords) What we have (tokens) Other What we are (iris, fingerprint)
 [Accuracy vs. cost trade-off]

slide-3
SLIDE 3

USER AUTHENTICATION

slide-4
SLIDE 4

INKBLOT AUTHENTICATION

Come up with two characters per image

slide-5
SLIDE 5

DO WE NEED STRONG PASSWORDS?

What’s the threat model? How should we store passwords? Is the attack online or offline? Is the attack targeted or seeking any user?

slide-6
SLIDE 6

DO WE NEED STRONG PASSWORDS?

Let’s consider offline attacks 6-digit passwords + 3-strikes-you’re-out Let’s give the attacker 10 years to guess 10 years = ~10^4 passwords = ~1%

slide-7
SLIDE 7

TODAY’S PAPERS

slide-8
SLIDE 8

BONUS PAPER

slide-9
SLIDE 9

EXPERIMENT SETUP

297 USB drives dropped around campus Varied location, time of day, and appearance: Periodically went to the locations to see what was taken/when

slide-10
SLIDE 10

All files are .html page informing them they’re part of a study <img> hits the measurement server + Survey

EXPERIMENT SETUP

slide-11
SLIDE 11

45% of the drives
 had a file open 98% of the drives
 were removed

Might have plugged it in
 but not opened a file

Median 6.9h

FINDINGS

slide-12
SLIDE 12

WHY DID THEY DO IT?

Fewer opened files Perhaps they opened it altruistically to return it?

slide-13
SLIDE 13

WHY DID THEY DO IT?

slide-14
SLIDE 14

WHY DID THEY DO IT?

Altruism? Reality
 (50% with
 return label)

slide-15
SLIDE 15

WHY TAKE THE RISK?

slide-16
SLIDE 16

WHY TAKE THE RISK?

Domain-specific risk taking (DOSPERT) scale
 Test for risk aversion (higher = riskier), different categories

slide-17
SLIDE 17

WHY TAKE THE RISK?

Domain-specific risk taking (DOSPERT) scale
 Test for risk aversion (higher = riskier), different categories

slide-18
SLIDE 18

WHO DID IT?

Representative of the university setting

slide-19
SLIDE 19

DID THEY KNOW WHAT THEY WERE DOING?

Security Behavior Intentions Scale (SeBIS) Original study: Mechanical Turks. Not representative of UIUC

slide-20
SLIDE 20

TODAY’S PAPERS