Email-based password recovery - risking or rescuing users?

被引:0
|
作者
Al Maqbali, Fatma [1 ]
Mitchell, Chris J. [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, London, England
关键词
password recovery; email-based password recovery; content and design of email-based password recovery;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Secret passwords are very widely used for user authentication to websites, despite their known shortcomings. Most websites using passwords also implement password recovery to allow users to re-establish a shared secret if the existing value is forgotten; many such systems involve sending a password recovery email to the user, e.g. containing a secret link. The security of password recovery, and hence the entire user-website relationship, depends on the email being acted upon correctly; unfortunately, as we show, such emails are not always designed to maximise security and can introduce vulnerabilities into recovery. To understand better this serious practical security problem, we surveyed password recovery emails for 50 of the top English language websites. We investigated a range of security and usability issues for such emails, covering their design, structure and content (including the nature of the user instructions), the techniques used to recover the password, and variations in email content from one web service to another. Many well-known web services, including Facebook, Dropbox, and Microsoft, suffer from recovery email design, structure and content issues. This is, to our knowledge, the first study of its type reported in the literature. This study has enabled us to formulate a set of recommendations for the design of such emails.
引用
收藏
页码:16 / 20
页数:5
相关论文
共 50 条
  • [21] Email-based epidemiological surveys on restless legs syndrome in Japan
    Takashi Nomura
    Yuichi Inoue
    Masayoshi Kusumi
    Yasunori Oka
    Kenji Nakashima
    Sleep and Biological Rhythms, 2008, 6 : 139 - 145
  • [22] Consultation time in email-based, store-and-forward telemedicine
    Caffery, Liam
    Smith, Anthony C.
    JOURNAL OF TELEMEDICINE AND TELECARE, 2007, 13 : 27 - 28
  • [23] Acceptability of a theory of planned behaviour email-based nutrition intervention
    Kothe, E. J.
    Mullan, B. A.
    HEALTH PROMOTION INTERNATIONAL, 2014, 29 (01) : 81 - 90
  • [24] MEME*: An adaptive email-based information sharing system for educational institutions
    Dain, M
    Brzezinski, J
    12TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2001, : 449 - 453
  • [25] A systematic review of email-based reminder interventions to increase vaccine uptake
    Odone, A.
    Frascella, B.
    Balzarini, F.
    Alacreu, A. Oradini
    Signorelli, C.
    EUROPEAN JOURNAL OF PUBLIC HEALTH, 2019, 29
  • [26] An email-based high capacity text steganography using repeating characters
    Fateh, Mansoor
    Rezvani, Mohsen
    International Journal of Computers and Applications, 2021, 43 (03) : 226 - 232
  • [27] Effectiveness of email-based reminders to increase vaccine uptake: a systematic review
    Frascella, Beatrice
    Oradini-Alacreu, Aurea
    Balzarini, Federica
    Signorelli, Carlo
    Lopalco, Pier Luigi
    Odone, Anna
    VACCINE, 2020, 38 (03) : 433 - 443
  • [28] MEME: An adaptive email-based knowledge sharing system for educational institutions
    Brzezinski, J
    Dain, M
    ADVANCED COMPUTER SYSTEMS, PROCEEDINGS, 2002, 664 : 171 - 179
  • [29] Theory of Planned Behavior: Implications for an email-based physical activity intervention
    Parrott, Matthew W.
    Tennant, Leo Keith
    Olejnik, Stephen
    Poudevigne, Melanie S.
    PSYCHOLOGY OF SPORT AND EXERCISE, 2008, 9 (04) : 511 - 526
  • [30] Piloting an email-based resource package for job seekers with multiple sclerosis
    Dorstyn, Diana
    Roberts, Rachel
    Murphy, Gregory
    Kneebone, Ian
    Migliorini, Christine
    Craig, Ashley
    Hutchinson, Claire
    Field, Deborah
    DISABILITY AND REHABILITATION, 2017, 39 (09) : 867 - 873