Evaluating Password Composition Policy and Password Meters of Popular Websites

Kyungchan Lim, Joshua H. Kang,Matthew Dixson, Hyungjoon Koo,Doowon Kim

SP Workshops(2023)

引用 0|浏览6
暂无评分
摘要
Password-based authentication is one of the most commonly adopted mechanisms for online security. Choosing strong passwords is crucial for protecting ones' digital identities and assets, as weak passwords can be readily guessable, resulting in a compromise such as unauthorized access. To promote the use of strong passwords on the Web, the National Institute of Standards and Technology (NIST) provides website administrators with password composition policy (PCP) guidelines. We manually inspect popular websites to check if their password policies conform to NIST's PCP guidelines by generating passwords that meet each criterion and testing the 100 popular websites. Our findings reveal that a considerable number of websites (on average, 53.5%) do not comply with the guidelines, which could result in password breaches.
更多
查看译文
关键词
National Institute of Standards and Technology,NIST PCP guidelines,online security,password breaches,password composition policy guidelines,password policies,password-based authentication,unauthorized access,Website administrators
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要