作者
Daniel McCarney, David Barrera, Jeremy Clark, Sonia Chiasson, Paul C Van Oorschot
发表日期
2012/12/3
图书
Proceedings of the 28th annual computer security applications conference
页码范围
89-98
简介
Passwords continue to prevail on the web as the primary method for user authentication despite their well-known security and usability drawbacks. Password managers offer some improvement without requiring server-side changes. In this paper, we evaluate the security of dual-possession authentication, an authentication approach offering encrypted storage of passwords and theft-resistance without the use of a master password. We further introduce Tapas, a concrete implementation of dual-possession authentication leveraging a desktop computer and a smartphone. Tapas requires no server-side changes to websites, no master password, and protects all the stored passwords in the event either the primary or secondary device (e.g., computer or phone) is stolen. To evaluate the viability of Tapas as an alternative to traditional password managers, we perform a 30 participant user study comparing Tapas to two …
引用总数
20122013201420152016201720182019202020212022202320241378119181047361
学术搜索中的文章
D McCarney, D Barrera, J Clark, S Chiasson… - Proceedings of the 28th annual computer security …, 2012