<input Type="password"> Must Die!

نویسندگان

  • Daniel Sandler
  • Dan S. Wallach
چکیده

We propose that the HTML password input widget is harmful to user security, as it draws attention away from relevant security indicators, exposes a password’s keystrokes to hidden client-side code, and generally conditions users to supply sensitive information in insensitive places. In this paper we advocate private password entry: a mandatory, common authentication user experience that allows the user to enter a password for any site in private, free from snooping JavaScript. We describe a UI design for private password entry called the password booth that is backward-compatible with HTML login forms on most existing websites. It can be used to provide timely and relevant security indicators, as well as potentially unify and enhance other advances in authentication on the web. We hope that the password booth approach will, like a voting booth or a bank-card PIN pad, become a security feature that users come to expect for their own peace of mind.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Password Visualization beyond Password Masking

When entering a password (or other secrets) the typed input is most commonly masked, i.e. the characters are hidden behind bullets or asterisks. This, however, complicates the input and highly decreases the user’s confident causing several issues such as login failure attempts. On the other hand, password masking is an important security requirement for a lot of applications and contexts to pre...

متن کامل

Passwords for both Mobile and Desktop Computers: ObPwd for Firefox and Android

Many users now access password-protected accounts and websites alternately from desktop machines, and mobile devices (e.g., smartphones, tablets). The input mechanisms of the mobile devices are often miniature physical or virtual on-screen keyboards, posing challenges for users trying to type passwords with mixed-case and special-characters expected by websites and more easily entered on deskto...

متن کامل

Authentication Using Graphical Passwords: Basic Results

Access to computer systems is most often based on the use of alphanumeric passwords. However, users have difficulty remembering a password that is long and random-appearing. Instead, they create short, simple, and insecure passwords. Graphical passwords have been designed to try to make passwords more memorable and easier for people to use and, therefore, more secure. Using a graphical password...

متن کامل

Oblivious PAKE: Efficient Handling of Password Trials

In this work we introduce the notion of Oblivious Password based Authenticated Key Exchange (O-PAKE) and a compiler to transform a large class of PAKE into O-PAKE protocols. O-PAKE allows a client that shares one password with a server to use a subset of passwords within one PAKE session. It succeeds if and only if one of those input passwords matches the one stored on the server side. The term...

متن کامل

A Text based Authentication Scheme for Improving Security of Textual Passwords

User authentication through textual passwords is very common in computer systems due to its ease of use. However textual passwords are vulnerable to different kinds of security attacks, such as spyware and dictionary attacks. In order to overcome the deficiencies of textual password scheme, many graphical password schemes have been proposed. The proposed schemes could not fully replace textual ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008