2020
DOI: 10.1109/access.2020.2981207
|View full text |Cite
|
Sign up to set email alerts
|

A Longitudinal Study on Web-Sites Password Management (in)Security: Evidence and Remedies

Abstract: Single-factor password-based authentication is generally the norm to access online Web-sites. While single-factor authentication is well known to be a weak form of authentication, a further concern arises when considering the possibility for an attacker to recover the user passwords by leveraging the loopholes in the password recovery mechanisms. Indeed, the adoption by a Web-site of a poor password management system makes useless even the most robust password chosen by the registered users. In this paper, bui… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
2

Citation Types

0
6
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
3
1

Relationship

0
7

Authors

Journals

citations
Cited by 13 publications
(6 citation statements)
references
References 20 publications
0
6
0
Order By: Relevance
“…The cost of using FCWs has been investigated in [17,18,20,28]. The correlation between FCW security and the use of a specific content management system has been introduced in [10], while other studies performed a correlation analysis on website security, such as [13,15,21,22,27]. Taking into consideration the number of studies and the lack of space, we concentrate solely on a subset of relevant studies to this work and their results.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…The cost of using FCWs has been investigated in [17,18,20,28]. The correlation between FCW security and the use of a specific content management system has been introduced in [10], while other studies performed a correlation analysis on website security, such as [13,15,21,22,27]. Taking into consideration the number of studies and the lack of space, we concentrate solely on a subset of relevant studies to this work and their results.…”
Section: Related Workmentioning
confidence: 99%
“…Goethem et al [15] presents a large-scale security analysis of 22,851 websites originating in 28 European countries. Furthermore, Raponi and Di Pietro [27] analyzed the password recovery management mechanism of Alexa's top 200 websites, with domains registered in certain European countries. They found that more than 54% of the websites in France, 36% in Italy, 47% in Spain, and 33% in the UK were vulnerable in December 2017.…”
Section: Related Workmentioning
confidence: 99%
“…However, they come with many security problems: Users tend to choose easily guessable passwords and re-use them for multiple accounts [18,69,87,89,90], or suffer from insecure or hard-to-use password policies [35,52,84]. Additionally, service providers may implement insecure and inadequate password storage, leaving millions of passwords unprotected due to data breaches [17,29,32,70,72,95]. Multi-Factor Authentication (MFA) adds an extra factor and additional security to passwordbased authentication schemes, and has become important in many authentication deployments on the web.…”
Section: Introductionmentioning
confidence: 99%
“…Password-based authentication is in use for a long time and the popular among wide user bases. However, as we are meeting rapid adoption of new technologies such as cloud applications, social networking sites, we often need to remember quite a few usernames and passwords daily, which is not always easy [2]. A recent study revealed that on average, a user maintains 25 online accounts [3].…”
Section: Introductionmentioning
confidence: 99%