pith. sign in

arxiv: 1801.06730 · v2 · pith:2ZAS2MLAnew · submitted 2018-01-20 · 💻 cs.CR

Web password recovery --- a necessary evil?

classification 💻 cs.CR
keywords passwordimplementedrecoverysystemsanalysedmodeluseradditional
0
0 comments X
read the original abstract

Web password recovery, enabling a user who forgets their password to re-establish a shared secret with a website, is very widely implemented. However, use of such a fall-back system brings with it additional vulnerabilities to user authentication. This paper provides a framework within which such systems can be analysed systematically, and uses this to help gain a better understanding of how such systems are best implemented. To this end, a model for web password recovery is given, and existing techniques are documented and analysed within the context of this model. This leads naturally to a set of recommendations governing how such systems should be implemented to maximise security. A range of issues for further research are also highlighted.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.