Stronger Password Authentication Using Browser Extensions
نویسندگان
چکیده
We describe a browser extension, PwdHash, that transparently produces a different password for each site, improving web password security and defending against password phishing and other attacks. Since the browser extension applies a cryptographic hash function to a combination of the plaintext password entered by the user, data associated with the web site, and (optionally) a private salt stored on the client machine, theft of the password received at one site will not yield a password that is useful at another site. While the scheme requires no changes on the server side, implementing this password method securely and transparently in a web browser extension turns out to be quite difficult. We describe the challenges we faced in implementing PwdHash and some techniques that may be useful to anyone facing similar security issues in a browser environment.
منابع مشابه
Snap2Pass: Consumer-Friendly Challenge-Response Authentication with a Phone
This paper proposes a challenge-response authentication system for web applications called Snap2Pass that is easy to use, provides strong security guarantees, and requires no browser extensions. The system uses QR codes which are small two-dimensional pictures that encode digital data. When logging in to a site, the web server sends the PC browser a QR code that encodes a cryptographic challeng...
متن کاملA Survey on Security Solutions of Top e-Banking Providers from an Eastern European Market
We analyse the security of e-banking services from top e-banking providers on the Romanian market. This location is relevant from at least two reasons: it’s a dynamic and diverse market situated at the crossroads between central and eastern Europe and half of the providers come from foreign markets (CitiBank, ING, Raiffeisen, etc.) or are acquired by Western European providers (Societe Generale...
متن کاملA PAKE – SRP 6 BROWSER EXTENSION Alexandru
The username/password paradigm is a well-known authentication mechanism. Probably the most common version in use is the password authentication via an HTML form. The user has to type his/her password directly into a web page from the site to which he/she wishes to authenticate himself/herself. The problem with using this approach is that it relies on the user to determine when it is safe to ent...
متن کاملSecure, Consumer-Friendly Web Authentication and Payments with a Phone
This paper proposes a challenge-response authentication system for web applications called Snap2Pass that is easy to use, provides strong security guarantees, and requires no browser extensions. The system uses QR codes which are small two-dimensional pictures that encode digital data. When logging in to a site, the web server sends the PC browser a QR code that encodes a cryptographic challeng...
متن کاملSecure Passwords Through Enhanced Hashing
Passwords play a critical role in online authentication. Unfortunately, passwords suffer from two seemingly intractable problems: password cracking and password theft. In this paper, we propose PasswordAgent, a new password hashing mechanism that utilizes both a salt repository and a browser plug-in to secure web logins with strong passwords. Password hashing is a technique that allows users to...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005