login
|
join
professional documents
home
Profile
docsters
request
Blogs
Upload
all docs
legal
business
financial
technology
educational
creative
BUZZ
Stronger Password Authentication Using Browser Extensions
Categories
educational
>
Alternative
Tags
Serious
be first to review
Mythri
Stronger Password Authentication Using Browser ExtensionsBlake Ross, Collin Jackson, Nick Miyake, Dan Boneh, John MitchellStanford Universityhttp://crypto.stanford.edu/PwdHash2Password Phishing ProblemBank AFake SiteUser cannot reliably identify fake sitesCaptured password can be used at target sitepwdApwdA3Common Password ProblemBank Avulnerable sitehigh security sitepwdApwdB=pwdAPhishing attack or break-in at site B reveals pwd at A•Server-side solutions will not keep pwd safe•Solution: Strengthen with client-side supportSite B4Our Solution: PwdHashLightweight browser extensionImpedes password theft Invisible to serverInvisible to user Pwd PrefixPwd Hashing5Password HashingBank Ahash(pwdB, SiteB)hash(pwdA, BankA)Site BGenerate a unique password per site•HMACfido:123(banka.com) Q7a+0ekEXb•HMACfido:123(siteb.com) OzX2+ICiqcpwdApwdB=6Password Hashing: past attemptsHash pwd with realm provided by remote site:•HTTP 1.1 Digest Authentication•Kerberos 5•Does not prevent phishing, common pwdHash pwd with network service name:•Abadi, Bharat, Marais [PTO ‟97] Standalone.•Gabber, Gibbons, Mattias, Mayer [FC ‟97]. Proxy.•Relies on intercepting traffic can‟t handle https7Password Hashing: a popular ideaRecent password hashing projects:Similar hashing algorithmsOnly PwdHash defends against spoofingand is invisible to the userSite PasswordPassword MakerGenpassPasswdletPassword ComposerMagic Password GeneratorPwdHashPassword Generator Extension8The Spoofing ProblemJavaScript can display password fields or dialogs:Unhashed password sent to attacker in clear9Password PrefixOriginal pwdshould never be visibleto web pageOzX2+ICiqcSite B@@fido:123@@123@@abcdefgh10Password Prefix: How it worksNormal operation:Prefix in password fieldAbnormal operation:Prefix in non-password field•Can just ignore the prefix and not hash•Remind user not to enter password@@fido:123 @@abcdefgh **********abcdefgh fido:123HMACfido:123(siteb.com) Q7a+0ekEXb11Why use Password Prefix?Protection mechanism “built in” to passwordDoes not rely on user to make a decisionSame prefix works for everyoneDistinguishes secure passwords from•normal passwords•social security numbers•PINsOnly use it when you want to12Other Trusted Pwd InterfacesPassword prefixSecure attention sequenceTrusted image or phrase:•Passmark•DSSStarts with @@13Other ChallengesPassword ResetInternet CafesDictionary AttacksSpyware, DNS poisoning (no protection)Other issues (described in the paper)•Choosing salt for hash•Encoding hashed password•Additional attacks and defenses14After install, PwdHash can‟t protect existing pwds•Only passwords starting with @@are secure•User can choose where to use PwdHash•User must enter old password unhashed into password reset pagePwd Prefix makes it easy •Old passwords won‟t be accidentally hashed•New, secure passwords are automatically hashedPasswordResetStarts with @@15Internet CafesUsers cannot install software at Internet Cafes.Would not be a problem if PwdHash were universally availableInterim solution: A secure web site for remote hashing, e.g.https://www.pwdhash.comHash is computed usingJavaScript•Server never sees password•Resulting hash is copied into clipboard•Can also be used as a standalone password generatorInternet ExplorerFirefox16Dictionary attacksAfter phishing attack or break-in to low security site,attacker can repeatedly guess password and check hash. •Succeeds on 15% of passwords (unlike 100% today)•Less effective on longer, stronger passwordsSolution: better authentication protocol (SPEKE, SRP, etc.)•Requires server-side changesDefense: user specifies a global pwd to strengthen all pwd hashes•Creates a new pwd management problem for shared machinesDefense: slow hash function (Halderman, Waters, Felten „05)•Increases time of dictionary attackaardvark, aback, abacus, abandon…17PwdHash: Try it outPrototype for Internet Explorer and Mozilla Firefox Defends against spoofingInvisible to userInvisible to serverComplementary to other anti-phishing solutionsOnly use it when you want towww.pwdhash.com
Public Domain
views:
99
downloads:
1
rating:
not rated
reviews:
0
posted:
1/22/2008
language:
English
search term
page on Google
times searched
Using Firefox with Extensions
shared by:
MissPowerPoint
on:
4/26/2008
|
views:
78
|
downloads:
1
|
comments:
0
|
category:
technology
Authentication and Authorization Using Entangled Photons
shared by:
NIST
on:
7/2/2008
|
views:
8
|
downloads:
0
|
comments:
0
|
category:
legal
password
shared by:
honeytech
on:
11/12/2007
|
views:
103
|
downloads:
3
|
comments:
0
|
category:
business
password
shared by:
StarBoy
on:
11/14/2007
|
views:
106
|
downloads:
3
|
comments:
0
|
category:
educational
Authentication
shared by:
honeytech
on:
11/12/2007
|
views:
525
|
downloads:
15
|
comments:
0
|
category:
technology
Sender Authentication Whitepaper
shared by:
D27
on:
12/29/2007
|
views:
156
|
downloads:
1
|
comments:
0
|
category:
technology
sensitivity analysis using financial inputs
shared by:
Mythri
on:
1/23/2008
|
views:
143
|
downloads:
15
|
comments:
0
|
category:
financial
sensitivity analysis using financial inputs[1]
shared by:
Mythri
on:
1/23/2008
|
views:
37
|
downloads:
1
|
comments:
0
|
category:
financial
Working for a Stronger Economy
shared by:
Reps
on:
6/18/2008
|
views:
5
|
downloads:
0
|
comments:
0
|
category:
legal
Password Audit
shared by:
ocak
on:
1/10/2008
|
views:
294
|
downloads:
43
|
comments:
0
|
category:
technology
PTC CAT Strong Authentication case study
shared by:
arnneisp
on:
4/30/2008
|
views:
44
|
downloads:
0
|
comments:
0
|
category:
technology
Requesting a MAGIC Password
shared by:
NASSdocs
on:
6/17/2008
|
views:
1
|
downloads:
0
|
comments:
0
|
category:
legal
Shadow-Password-HOWTO
shared by:
msaleem
on:
11/14/2007
|
views:
107
|
downloads:
3
|
comments:
0
|
category:
technology
View this message in a browser
shared by:
DAU
on:
6/24/2008
|
views:
15
|
downloads:
0
|
comments:
0
|
category:
legal
The Federal Crime Victims Division - 1999
shared by:
Mythri
on:
3/3/2008
|
views:
368
|
downloads:
4
|
comments:
0
|
category:
educational
The Detroit Handgun Intervention Program A Court Based Program for Youthful Handgun Offenders - November 1998
shared by:
Mythri
on:
3/3/2008
|
views:
301
|
downloads:
3
|
comments:
0
|
category:
educational
The Decline of Intimate Partner Homicide - July 2005
shared by:
Mythri
on:
3/3/2008
|
views:
187
|
downloads:
0
|
comments:
0
|
category:
educational
The Crime of Staling How Big is the Problem - 1997
shared by:
Mythri
on:
3/3/2008
|
views:
283
|
downloads:
1
|
comments:
0
|
category:
legal
The Career Academy Concept - May 2001
shared by:
Mythri
on:
3/3/2008
|
views:
268
|
downloads:
5
|
comments:
1
|
category:
educational
The Campbell Collaboration Helping To Understand What Works - July 2004
shared by:
Mythri
on:
3/3/2008
|
views:
206
|
downloads:
1
|
comments:
0
|
category:
educational
The Bulletproof Vest Partnership - March 2002
shared by:
Mythri
on:
3/3/2008
|
views:
247
|
downloads:
0
|
comments:
0
|
category:
educational
Of Fragmentation and Ferment The Impact of State Sentencing Policies on Incarceration Rates 1975-2002 - August 2005
shared by:
Mythri
on:
3/3/2008
|
views:
200
|
downloads:
0
|
comments:
0
|
category:
educational
La Cosa Nostra in the Unites States - 2000
shared by:
Mythri
on:
3/3/2008
|
views:
406
|
downloads:
1
|
comments:
0
|
category:
educational
Guide for the Selection of Chemical and Biological Decontamination Equipment for Emergency First Responders Guide Volume II Intro - October 2001
shared by:
Mythri
on:
3/3/2008
|
views:
301
|
downloads:
4
|
comments:
0
|
category:
educational
password authentication algoritms
1
1