It's no secret Measuring the security and reliability of authentication via 'secret' questions

被引:71
作者
Schechter, Stuart
Brush, A. J. Bernheim
Egelman, Serge
机构
来源
PROCEEDINGS OF THE 2009 30TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY | 2009年
关键词
D O I
10.1109/SP.2009.11
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
All four of the most popular webmail providers - AOL, Google, Microsoft, and Yahoo! - rely on personal questions as the secondary authentication secrets used to reset account passwords. The security of these questions has received limited formal scrutiny, almost all of which predates webmail. We ran a user stud), to measure the reliability and security of the questions used by all four webmail providers. We asked participants to answer these questions and then asked their acquaintances to guess their answers. Acquaintances with whom participants reported being unwilling to share their webmail passwords were able to guess 17% of their answers. Participants forgot 20% of their own answers within six months. What's more, 13% of answers could be guessed within five attempts by guessing the most popular answers of other participants, though this weakness is partially attributable to the geographic homogeneity of our participant pool.
引用
收藏
页码:375 / 390
页数:16
相关论文
共 17 条
[1]  
BRAINARD J, 2006, CCS 06, P168
[2]  
BRIDIS T, 2008, E COMMUNICATION 0918
[3]  
*COMMONWEALTHBANK, 2008, NETBANK NETCODE SMS
[4]  
*H P LTD, 2008, TOP 20 WEBS
[5]  
Jakobsson M, 2008, CHI 2008: 26TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS VOLS 1 AND 2, CONFERENCE PROCEEDINGS, P197
[6]  
Just Mike., 2005, SECURITY USABILITY, P143
[7]  
KEIZER G, 2008, COMPUTERWORLD 0919
[8]  
KREMER J, 2007, YAHOO MAIL OCT
[9]  
*MICR CORP, 2007, WIND LIV HOTM FACT S
[10]  
PODD J, 1996, OZCHI 96, P304