passpet
play

Passpet Convenient Password Management and Phishing Protection - PowerPoint PPT Presentation

Passpet Convenient Password Management and Phishing Protection Ka-Ping Yee Kragen Sitaker ping@zesty.ca kragen@pobox.com problems: design: solutions: practical matters: evaluation: problems: the big 5 problems: the big 5 1 many


  1. Passpet Convenient Password Management and Phishing Protection Ka-Ping Yee Kragen Sitaker ping@zesty.ca kragen@pobox.com

  2. problems: design: solutions: practical matters: evaluation:

  3. problems: the big 5

  4. problems: the big 5 1 many passwords

  5. problems: the big 5 1 many passwords 2 dictionary attack

  6. problems: the big 5 1 many passwords 2 dictionary attack 3 password entry in webpages

  7. problems: the big 5 1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation

  8. problems: the big 5 1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

  9. problems: the big 5 1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

  10. design:

  11. design: logging in setting up a new password setting up Passpet

  12. solutions:

  13. solutions: 1 many passwords

  14. master secret site-specific ⊕ password site name

  15. master secret site-specific ⊕ password site name

  16. master secret site-specific ⊕ password site name

  17. solutions: 1 many passwords 2 dictionary attack

  18. master secret site-specific ⊕ password site name

  19. ? site-specific ⊕ password site name

  20. ? site-specific + password site name

  21. master secret site-specific + password site name

  22. master secret site-specific + + password site name

  23. Password Multiplier (Halderman, 2005) master secret master secret site-specific + + password user name site name

  24. Passpet: variable-strength password hash

  25. Give responsive feedback on password strength.

  26. solutions: 1 many passwords 2 dictionary attack 3 password entry in webpages

  27. solutions: 1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation

  28. Petname Tool (Close, 2005)

  29. Passpet: use site label for hashing

  30. Help users rely on information from the user, not an attacker.

  31. solutions: 1 many passwords 2 dictionary attack 3 password entry in webpages 4 site impersonation 5 UI spoofing

  32. Dynamic Security Skins (Dhamija, 2005)

  33. Passpet: interact directly with custom icon

  34. Passpet: interact directly with custom icon

  35. Get the user to interact with something personalized.

  36. contributions: 1 variable-strength hashing 2 password strength feedback 3 use user-assigned labels for hashing 4 personalized security agent 5 direct interaction with customized UI

  37. practical matters:

  38. practical matters: What if you want to use another computer?

  39. practical matters: What if someone gets your password file?

  40. practical matters: What if you want to use another computer? Firefox Passpet Server Passpet encrypted encrypted site labels site labels

  41. practical matters: What if you want to use existing websites?

  42. practical matters: What if you need to change a password?

  43. evaluation:

  44. evaluation: Passpet for Internet Explorer: tested at HP labs with 15 users main complaint: want to use other computers Passpet for Firefox: not yet usability-tested

  45. thanks: Tyler Close (Petname Tool) Alan Karp (Passpet user study) David Wagner (design and cryptography) J. Alex Halderman (Password Multiplier) Rachna Dhamija (Dynamic Security Skins) http://passpet.org/

Recommend


More recommend