User authentication on the web
Joseph Bonneau jcb82@cl.cam.ac.uk
Computer Laboratory
SOCIALNETS workshop November 18, 2010
- J. Bonneau (U. of Cambridge)
SOCIALNETS November 18, 2010 1 / 10
User authentication on the web Joseph Bonneau jcb82@cl.cam.ac.uk - - PowerPoint PPT Presentation
User authentication on the web Joseph Bonneau jcb82@cl.cam.ac.uk Computer Laboratory SOCIALNETS workshop November 18, 2010 J. Bonneau (U. of Cambridge) SOCIALNETS November 18, 2010 1 / 10 Looming authentication challenges The old world 1
Computer Laboratory
SOCIALNETS November 18, 2010 1 / 10
1
2
SOCIALNETS November 18, 2010 1 / 10
SOCIALNETS November 18, 2010 2 / 10
SOCIALNETS November 18, 2010 2 / 10
SOCIALNETS November 18, 2010 2 / 10
SOCIALNETS November 18, 2010 2 / 10
feature scoring enrolment Password selection advice given +1 pt Minimum password length required +1 pt Dictionary words prohibited +1 pt Numbers or symbols required +1 pt User list protected from probing +1 pt Cleartext password sent in email after enrolment −1 pt login Password hashed in-browser before POST +1 pt Limits placed on password guessing +1 pt User list protected from probing +1 pt Federated identity login accepted +1 pt password update Password re-entry required to authorise update +1 pt Notification email sent after password reset +1 pt password recovery Password update required after recovery +1 pt Cleartext password sent in email upon request −1 pt User list protected from probing +1 pt encryption Full TLS for all password submission +2 pts POST only TLS for password submission +1 pt
SOCIALNETS November 18, 2010 2 / 10
100 200 300 400 500 Traffic rank 0.0 0.2 0.4 0.6 0.8 1.0 Proportion of sites collecting passwords
SOCIALNETS November 18, 2010 2 / 10
SOCIALNETS November 18, 2010 3 / 10
SOCIALNETS November 18, 2010 4 / 10
SOCIALNETS November 18, 2010 4 / 10
SOCIALNETS November 18, 2010 4 / 10
Ask
SOCIALNETS November 18, 2010 4 / 10
SOCIALNETS November 18, 2010 4 / 10
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Password [RockYou] Password [Klein] Password [Spafford] Password [Schneier]
SOCIALNETS November 18, 2010 4 / 10
SOCIALNETS November 18, 2010 4 / 10
SOCIALNETS November 18, 2010 4 / 10
1 2 3 4 5 6 7 8 9 10
No TLS, no password requirements, cleartext passwords emailed, no guessing or user probing restrictions, email addresses verified No TLS, no password requirements or advice, emailed temp. passwords for reset, no password advice, no guessing or user probing restrictions, email addresses verified TLS deployed, 6 char. min. password, emailed reset links, no password advice, no guessing or user probing restrictions, email addresses not verified No TLS, 6 char. min. password, personal knowledge questions for reset, no password advice, no guessing or user probing restrictions, email addresses verified TLS deployed, 6 char. min. password, emailed reset links, no password advice, guessing restrictions in place, email addresses verifiedphilly.com
Victoria’s S. $ Macy’s $ eBooks
USA Today Ask Jeeves TalkBizNow EmailAccount Topeka C.-J. PhotoBucket $ Mail2World Canada.com Mail.com StumbleUpon Football Fan. Indian Express Fertility Fr. CD Wow Milwaukee J. S. Florida-Times U. The Pirate Bay SoftHome The Guardian TCPalm SF Chronicle LiveMocha Last.fm The Drum NY Times Forbes Truthdig The Tennessean The Courier-J. PhillyBurbs Lincoln J. S. AOL Children’s Place $ Xanga ESPN Ticket Web $ TicketMaster $ Gap $ Barnes & Noble $ IMDB Art Beads
Seattle Weekly New York Post
Spiegel $ Shoplet Blick Weather Und.
$ Dallas M. N. Reddit CBS Sports Bodybuilding $ 3Dup Two Peas in a B. Weather Channel Post-Tribune Orlando Sent. Miami.com LA Times Houston Chron. Chicago Trib. Wasabi Sonico hi5 Gawab Rand McNally Oriental Trad. Hermes Frederick’s $ Anthropologie $ The Economist SJ Mercury News CNN CNET Bill O’Reilly ResearchGate aNobii Sierra T. P. $ Lucky Vitamin efollet.com Eddie Bauer Costco $
Times Online Press-Telegram Bloomberg Swiss Mail Plaxo Zappos! $ REI $ Overstock $ Home Depot $ DVD Empire $ Build-A-Bear W. Best Buy $ Bath & Body W. Reuters $ Walmart $ Things Rem. Target $ ShopBop $ Sephora $ Sears $ NewEgg $ Horchow $ Amazon $ ZZ Network TigerDirect $ rediff Times of India On The Snow Topix
LinkedIn Digg Craigslist Deviant Art $ Hushmail Fairfax Dig. Cafe Press $ MS Live Wordpress
Yahoo! Ebay $ Mixx Wikipedia LiveJournal $ CNBC Facebook $ Gamespot AliBaba $ Google $ MySpace IKEA Godmail JCPenney $ Buy.com $ The Golf World Legend Identity site E-commerce site Content site Payment $ Cluster of sites
score
SOCIALNETS November 18, 2010 5 / 10
10 1E-2 1E-1 1E+0 1E+1 1E+2 1E+3 1E+4 1E+5 password score page views per million E-commerce News/Customization User interaction
SOCIALNETS November 18, 2010 6 / 10
SOCIALNETS November 18, 2010 7 / 10
SOCIALNETS November 18, 2010 7 / 10
SOCIALNETS November 18, 2010 7 / 10
1
2
SOCIALNETS November 18, 2010 7 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
Yahoo!
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 8 / 10
SOCIALNETS November 18, 2010 9 / 10
1
2
3
4
SOCIALNETS November 18, 2010 9 / 10
1
2
3
4
SOCIALNETS November 18, 2010 9 / 10
1
2
3
4
SOCIALNETS November 18, 2010 8 / 10
1
2
3
4
SOCIALNETS November 18, 2010 7 / 10
1
2
3
4
SOCIALNETS November 18, 2010 6 / 10
1
2
3
4
SOCIALNETS November 18, 2010 6 / 10
SOCIALNETS November 18, 2010 7 / 10
Bortz et al. 2007
SOCIALNETS November 18, 2010 8 / 10
Narayanan 2009
SOCIALNETS November 18, 2010 8 / 10
Narayanan 2009
SOCIALNETS November 18, 2010 8 / 10
Reaching a head with OSNs
Griffith et. al: 30% of individual’s mother’s maiden names
Schecter et. al: ∼ 25% of questions guessed by friends, family
SOCIALNETS November 18, 2010 9 / 10
0.0 0.2 0.4 0.6 0.8 1.0 success rate α 5 10 15 20 25 30 35 40 marginal guesswork ˜ µα
Forename Surname Password [RockYou] Password [Klein] Password [Spafford] Password [Schneier]
Personal knowledge worse than passwords (Bonneau et al. 2010)
SOCIALNETS November 18, 2010 9 / 10
SOCIALNETS November 18, 2010 9 / 10
Schecther et al. 2008
SOCIALNETS November 18, 2010 9 / 10
Schecther et al. 2008
SOCIALNETS November 18, 2010 9 / 10
SOCIALNETS November 18, 2010 9 / 10
SOCIALNETS November 18, 2010 9 / 10
SOCIALNETS November 18, 2010 10 / 10