Email-based password recovery - risking or rescuing users?

被引:0
|
作者
Al Maqbali, Fatma [1 ]
Mitchell, Chris J. [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, London, England
关键词
password recovery; email-based password recovery; content and design of email-based password recovery;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Secret passwords are very widely used for user authentication to websites, despite their known shortcomings. Most websites using passwords also implement password recovery to allow users to re-establish a shared secret if the existing value is forgotten; many such systems involve sending a password recovery email to the user, e.g. containing a secret link. The security of password recovery, and hence the entire user-website relationship, depends on the email being acted upon correctly; unfortunately, as we show, such emails are not always designed to maximise security and can introduce vulnerabilities into recovery. To understand better this serious practical security problem, we surveyed password recovery emails for 50 of the top English language websites. We investigated a range of security and usability issues for such emails, covering their design, structure and content (including the nature of the user instructions), the techniques used to recover the password, and variations in email content from one web service to another. Many well-known web services, including Facebook, Dropbox, and Microsoft, suffer from recovery email design, structure and content issues. This is, to our knowledge, the first study of its type reported in the literature. This study has enabled us to formulate a set of recommendations for the design of such emails.
引用
收藏
页码:16 / 20
页数:5
相关论文
共 50 条
  • [31] Factors affecting acceptability of an email-based intervention to increase fruit and vegetable consumption
    Emily J Kothe
    Barbara A Mullan
    BMC Public Health, 14
  • [32] A Learning Evasive Email-Based P2P-Like Botnet
    Wang, Zhi
    Qin, Meilin
    Chen, Mengqi
    Jia, Chunfu
    Ma, Yong
    CHINA COMMUNICATIONS, 2018, 15 (02) : 15 - 24
  • [33] Factors affecting acceptability of an email-based intervention to increase fruit and vegetable consumption
    Kothe, Emily J.
    Mullan, Barbara A.
    BMC PUBLIC HEALTH, 2014, 14
  • [34] A Learning Evasive Email-Based P2P-Like Botnet
    Zhi Wang
    Meilin Qin
    Mengqi Chen
    Chunfu Jia
    Yong Ma
    中国通信, 2018, 15 (02) : 15 - 24
  • [35] EMARE: An Email-based Mobile Agent Runtime Environment for information retrieval on the Internet
    Ho, MH
    Chang, YS
    Yuan, SM
    2ND IEEE INTERNATIONAL WORKSHOP ON WIRELESS AND MOBILE TECHNOLOGIES IN EDUCATION, 2004, : 93 - 97
  • [36] An economic analysis of email-based telemedicine: A cost minimisation study of two service models
    Liam Caffery
    Anthony C Smith
    Paul A Scuffham
    BMC Health Services Research, 8
  • [37] Do Exonerees Face Housing Discrimination? An Email-Based Field Experiment and Content Analysis
    Kukucka, Jeff
    Clow, Kimberley A.
    Horodyski, Ashley M.
    Deegan, Kelly
    Gayleard, Nina M.
    PSYCHOLOGY PUBLIC POLICY AND LAW, 2021, 27 (04) : 570 - 580
  • [38] An economic analysis of email-based telemedicine: A cost minimisation study of two service models
    Caffery, Liam
    Smith, Anthony C.
    Scuffham, Paul A.
    BMC HEALTH SERVICES RESEARCH, 2008, 8 (1)
  • [39] An Email-Based Delphi Approach to Tourism Program Evaluation: Involving Stakeholders in Research Design
    Northcote, Jeremy
    Lee, Diane
    Chok, Stephanie
    Wegner, Aggie
    CURRENT ISSUES IN TOURISM, 2008, 11 (03) : 269 - 279
  • [40] Low-cost, email-based system for self blood pressure monitoring at home
    Nakajima, Kazuki
    Nambu, Masayuki
    Kiryu, Tohru
    Tamura, Toshiyo
    Sasaki, Kazuo
    JOURNAL OF TELEMEDICINE AND TELECARE, 2006, 12 (04) : 203 - 207