Quantifying User Password Exposure to Third-Party CDNs
نویسندگان
چکیده
Web services commonly employ Content Distribution Networks (CDNs) for performance and security. As web traffic is becoming 100% HTTPS, more websites allow CDNs to terminate their HTTPS connections. This practice may expose a website’s user sensitive information such as user’s login password third-party CDN. In this paper, we measure quantify the extent of exposure CDNs. We find that among Alexa top 50K websites, at least 12,451 them use contain entrances. Among those 33% users’ passwords CDNs, popular CDN observe from than 40% its customers. result suggests if infrastructure has vulnerability or an insider attack, many accounts will be risk. If assume attacker passive eavesdropper, website can avoid by encrypting in Our measurement shows less 17% adopt countermeasure.
منابع مشابه
Orienting to third-party conversations.
Children as young as two years of age are able to learn novel object labels through overhearing, even when distracted by an attractive toy (Akhtar, 2005). The present studies varied the information provided about novel objects and examined which elements (i.e. novel versus neutral information and labels versus facts) toddlers chose to monitor, and what type of information they were more likely ...
متن کاملThird Party User Interaction Control in SIP Networks
A lot of attractive applications in addition to manipulation of session related signaling involve specific processing at media level such as playing media, prompting and collecting media from the user, mixing media streams etc. One of the ways of provisioning applications in managed all IP-based multimedia networks, is based on Open Service Access (OSA) service platform. The paper investigates ...
متن کاملPSV (Password Security Visualizer): From Password Checking to User Education
This paper presents the Password Security Visualizer (PSV), an interactive visualization system specifically designed for password security education. PSV can be seen as a reconfigurable “box” containing different proactive password checkers (PPCs) and visualizers of password security information, allowing it to be used like a “many in one” or “hybrid” PPC. PSV can provide many new features tha...
متن کاملParty Pooper: Third-Party Libraries in Android
Third-party libraries (3PLs), such as advertising networks, gaming networks, and analytics engines, are an integral part of modern mobile platforms. If Android developers want to integrate functionality provided by 3PLs, they must bundle opaque binary code into their applications. Unfortunately, developers must in essence overprivilege their Android applications by requesting dangerous permissi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Lecture Notes in Computer Science
سال: 2023
ISSN: ['1611-3349', '0302-9743']
DOI: https://doi.org/10.1007/978-3-031-28486-1_27