作者
Dinei Florêncio, Cormac Herley, Paul C Van Oorschot
发表日期
2014
研讨会论文
28th large installation system administration conference (LISA14)
页码范围
44-61
简介
The research literature on passwords is rich but little of it directly aids those charged with securing web-facing services or setting policies. With a view to improving this situation we examine questions of implementation choices, policy and administration using a combination of literature survey and first-principles reasoning to identify what works, what does not work, and what remains unknown. Some of our results are surprising. We find that offline attacks, the justification for great demands of user effort, occur in much more limited circumstances than is generally believed (and in only a minority of recently-reported breaches). We find that an enormous gap exists between the effort needed to withstand online and offline attacks, with probable safety occurring when a password can survive 10 6 and 10 14 guesses respectively. In this gap, eight orders of magnitude wide, there is little return on user effort: exceeding the online threshold but falling short of the offline one represents wasted effort. We find that guessing resistance above the online threshold is also wasted at sites that store passwords in plaintext or reversibly encrypted: there is no attack scenario where the extra effort protects the account.
引用总数
2014201520162017201820192020202120222023202442630223023202628138
学术搜索中的文章
D Florêncio, C Herley, PC Van Oorschot - 28th large installation system administration …, 2014