Email-based password recovery - risking or rescuing users?

被引:0
|
作者
Al Maqbali, Fatma [1 ]
Mitchell, Chris J. [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, London, England
关键词
password recovery; email-based password recovery; content and design of email-based password recovery;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Secret passwords are very widely used for user authentication to websites, despite their known shortcomings. Most websites using passwords also implement password recovery to allow users to re-establish a shared secret if the existing value is forgotten; many such systems involve sending a password recovery email to the user, e.g. containing a secret link. The security of password recovery, and hence the entire user-website relationship, depends on the email being acted upon correctly; unfortunately, as we show, such emails are not always designed to maximise security and can introduce vulnerabilities into recovery. To understand better this serious practical security problem, we surveyed password recovery emails for 50 of the top English language websites. We investigated a range of security and usability issues for such emails, covering their design, structure and content (including the nature of the user instructions), the techniques used to recover the password, and variations in email content from one web service to another. Many well-known web services, including Facebook, Dropbox, and Microsoft, suffer from recovery email design, structure and content issues. This is, to our knowledge, the first study of its type reported in the literature. This study has enabled us to formulate a set of recommendations for the design of such emails.
引用
收藏
页码:16 / 20
页数:5
相关论文
共 50 条
  • [41] Email-Based Recruitment Into the Health eHeart Study: Cohort Analysis of Invited Eligible Patients
    Ng, Madelena Y.
    Olgin, Jeffrey E.
    Marcus, Gregory M.
    Lyles, Courtney R.
    Pletcher, Mark J.
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2023, 25
  • [42] An analysis of the images attached to referral messages in an email-based telemedicine system for developing countries
    Jakowenko, Janelle
    Wootton, Richard
    JOURNAL OF TELEMEDICINE AND TELECARE, 2006, 12 : 49 - 53
  • [43] An email-based survey of practice regarding hemodynamic monitoring and management in children with septic shock in China
    Wang, Ying
    Qian, Juan
    Qian, Suyun
    Liu, Chunfeng
    Chen, Yibing
    Lu, Guoping
    Zhang, Yucai
    Ren, Xiaoxu
    TRANSLATIONAL PEDIATRICS, 2021, 10 (03) : 587 - +
  • [44] Nationwide Implementation of Hello World: A Dutch Email-Based Health Promotion Program for Pregnant Women
    Bot, Mariska
    Milder, Ivon E. J.
    Bemelmans, Wanda J. E.
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2009, 11 (03)
  • [45] LEDA: a Large-Organization Email-Based Decision-Dialogue-Act Analysis Dataset
    Karan, Vanja Mladen
    Khare, Prashant
    Shekhar, Ravi
    McQuistin, Stephen
    Perkins, Colin
    Castro, Ignacio
    Tyson, Gareth
    Healey, Patrick G. T.
    Purver, Matthew
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, ACL 2023, 2023, : 6080 - 6089
  • [46] Patient-reported complications related to colonoscopy: a prospective feasibility study of an email-based survey
    Steffenssen, Mia W.
    Al-Najami, Issam
    Zimmermann-Nielsen, Erik
    Baatrup, Gunnar
    ACTA ONCOLOGICA, 2019, 58 : S65 - S70
  • [47] Using deep reasoning questions to improve an email-based sexually transmitted infection prevention intervention
    Okwumabua, Theresa M.
    Peasant, Courtney
    Anderson, Mollie B.
    Barnes, Ebony
    Craig, Scotty D.
    AMERICAN JOURNAL OF SEXUALITY EDUCATION, 2018, 13 (04) : 452 - 469
  • [48] Effect of Personalized Email-Based Reminders on Participants' Timeliness in an Online Education Program: Randomized Controlled Trial
    Balter, Olle
    Jemstedt, Andreas
    Abraham, Feben Javan
    Osowski, Christine Persson
    Mugisha, Reuben
    Balter, Katarina
    JMIR FORMATIVE RESEARCH, 2023, 7
  • [49] Password-based authentication and the experiences of end users
    Ezugwu, Assumpta
    Ukwandu, Elochukwu
    Ugwu, Celestine
    Ezema, Modesta
    Olebara, Comfort
    Ndunagu, Juliana
    Ofusori, Lizzy
    Ome, Uchenna
    SCIENTIFIC AFRICAN, 2023, 21
  • [50] Breaking habits with mindful snacking? An email-based intervention targeting unwanted snacking habits in an Australian sample
    Dibb-Smith, Amanda
    Chapman, Janine
    Brindal, Emily
    EATING BEHAVIORS, 2019, 32 : 37 - 43