Pushing on String: The 'Don't Care' Region of Password Strength

被引:24
|
作者
Florencio, Dinei [1 ]
Herley, Cormac [2 ]
Van Oorschot, Paul C. [3 ,4 ]
机构
[1] Microsoft Res, Multimedia & Interact Experiences Grp, Redmond, WA 98052 USA
[2] Microsoft Res, Redmond, WA USA
[3] Carleton Univ, Comp Sci, Ottawa, ON, Canada
[4] Carleton Univ, Authenticat & Comp Secur, Ottawa, ON, Canada
关键词
D O I
10.1145/2934663
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Harder-to-guess passwords do not always reduce the likelihood of successful guessing attacks; in fact, in a large portion of the attack space, they make no difference at all. Enterprises should focus on users with the most easily guessed passwords; an attacker probably gets all the access needed just by compromising them, so improving other passwords denies the attacker very little. There is a saturation point where the network is so thoroughly penetrated that additional passwords gain the attacker very little; resistance to guessing beyond that point is wasted since it denies the attacker nothing. The justifiably recommended practice of storing passwords as salted hashes means the password distribution is obscured, as are any improvements caused by policies. Composition policies are also unfocused in that they affect all users rather than being directed specifically where they may matter most. A policy may greatly affect user password choice and still have little effect on outcome. The best investments to defend against offline attacks appear to involve measures transparent to users.
引用
收藏
页码:66 / 74
页数:9
相关论文
共 50 条
  • [2] Don't know, don't care?
    Johnson King, Zoe A.
    PHILOSOPHICAL STUDIES, 2020, 177 (02) : 413 - 431
  • [3] Don’t know, don’t care?
    Zoë A. Johnson King
    Philosophical Studies, 2020, 177 : 413 - 431
  • [4] Why Older Adults (Don't) Use Password Managers
    Ray, Hirak
    Wolf, Flynn
    Kuber, Ravi
    Aviv, Adam J.
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 73 - 90
  • [5] String Kernels Based on Variable-Length-Don't-Care Patterns
    Narisawa, Kazuyuki
    Bannai, Hideo
    Hatano, Kohei
    Inenaga, Shunsuke
    Takeda, Masayuki
    DISCOVERY SCIENCE, PROCEEDINGS, 2008, 5255 : 308 - +
  • [6] Why people (don't) use password managers effectively
    Pearman, Sarah
    Zhang, Shikun Aerin
    Bauer, Lujo
    Christin, Nicolas
    Cranor, Lorrie Faith
    PROCEEDINGS OF THE FIFTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY (SOUPS 2019), 2019, : 319 - 338
  • [7] Don't Listen! I Am Dictating My Password!
    Zhu, Shaojian
    Ma, Yao
    Feng, Jinjuan
    Sears, Andrew
    ASSETS'09: PROCEEDINGS OF THE 11TH INTERNATIONAL ACM SIGACCESS CONFERENCE ON COMPUTERS AND ACCESSIBILITY, 2009, : 229 - 230
  • [8] A password so secret even you don't know it
    Giles, Jim
    NEW SCIENTIST, 2012, 215 (2874) : 14 - 14
  • [9] Don't know, don't care III
    Swan, KG
    Anderson, ER
    Fowler, J
    Swan, KG
    Liman, JP
    Lajewski, WM
    MILITARY MEDICINE, 1999, 164 (11) : 758 - 763
  • [10] You don't know they don't care
    Armour, Martha
    VETERINARY ECONOMICS, 2007, 48 (03): : 112 - 112