The Experts below are selected from a list of 66 Experts worldwide ranked by ideXlab platform

Samson Zhou - One of the best experts on this subject based on the ideXlab platform.

  • On the Economics of Offline Password Cracking
    arXiv: Cryptography and Security, 2020
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with $10^5$ hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker -- if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of $500$ million cracked Passwords is less than $100$ times the total value of $5$ million Passwords). See paper for full abstract.

  • on the economics of offline Password cracking
    IEEE Symposium on Security and Privacy, 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

  • IEEE Symposium on Security and Privacy - On the Economics of Offline Password Cracking
    2018 IEEE Symposium on Security and Privacy (SP), 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

Jeremiah Blocki - One of the best experts on this subject based on the ideXlab platform.

  • On the Economics of Offline Password Cracking
    arXiv: Cryptography and Security, 2020
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with $10^5$ hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker -- if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of $500$ million cracked Passwords is less than $100$ times the total value of $5$ million Passwords). See paper for full abstract.

  • IEEE Symposium on Security and Privacy - On the Economics of Offline Password Cracking
    2018 IEEE Symposium on Security and Privacy (SP), 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

  • on the economics of offline Password cracking
    IEEE Symposium on Security and Privacy, 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

  • GOTCHA Password hackers!
    Proceedings of the 2013 ACM workshop on Artificial intelligence and security - AISec '13, 2013
    Co-Authors: Jeremiah Blocki, Manuel Blum, Anupam Datta
    Abstract:

    We introduce GOTCHAs (Generating panOptic Turing Tests to Tell Computers and Humans Apart) as a way of preventing automated offline dictionary attacks against user selected Passwords. A GOTCHA is a randomized puzzle generation protocol, which involves interaction between a computer and a human. Informally, a GOTCHA should satisfy two key properties: (1) The puzzles are easy for the human to solve. (2) The puzzles are hard for a computer to solve even if it has the random bits used by the computer to generate the final puzzle --- unlike a CAPTCHA. Our main theorem demonstrates that GOTCHAs can be used to mitigate the threat of offline dictionary attacks against Passwords by ensuring that a Password Cracker must receive constant feedback from a human being while mounting an attack. Finally, we provide a candidate construction of GOTCHAs based on Inkblot images. Our construction relies on the usability assumption that users can recognize the phrases that they originally used to describe each Inkblot image --- a much weaker usability assumption than previous Password systems based on Inkblots which required users to recall their phrase exactly. We conduct a user study to evaluate the usability of our GOTCHA construction. We also generate a GOTCHA challenge where we encourage artificial intelligence and security researchers to try to crack several Passwords protected with our scheme.

Weijun Hong - One of the best experts on this subject based on the ideXlab platform.

  • UIC/ATC/ScalCom - A Weak Password Cracker of UHF RFID Tags
    2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th I, 2015
    Co-Authors: Zhentao Zhao, Jiankai Li, Shengguang Li, Shufang Li, Yang Kang, Weijun Hong
    Abstract:

    Under the ISO/IEC 18000-6C protocol of UHF RFID an electronic tag's information security is based on Password protection, but its natural defect is unable to reject brute tests which can be exhaustive. By the protocol analysis, this article theoretically proves that tags' weak Passwords can be cracked. Combined with a concrete Tag-Interrogator module a method for improving the cracking efficiency is given out with a special concise Password library. Furthermore this paper implements the Password Cracker has carried on the exploration of distributed detection. By this method most electronic tags' Passwords can be cracked within one week. The ultimate goal of this paper is to remind that UHF RFID industry projects should enhance the security level of tag's Password practically.

  • A Weak Password Cracker of UHF RFID Tags
    2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th I, 2015
    Co-Authors: Zhentao Zhao, Jiankai Li, Shengguang Li, Shufang Li, Yang Kang, Weijun Hong
    Abstract:

    Under the ISO/IEC 18000-6C protocol of UHF RFID an electronic tag's information security is based on Password protection, but its natural defect is unable to reject brute tests which can be exhaustive. By the protocol analysis, this article theoretically proves that tags' weak Passwords can be cracked. Combined with a concrete Tag-Interrogator module a method for improving the cracking efficiency is given out with a special concise Password library. Furthermore this paper implements the Password Cracker has carried on the exploration of distributed detection. By this method most electronic tags' Passwords can be cracked within one week. The ultimate goal of this paper is to remind that UHF RFID industry projects should enhance the security level of tag's Password practically.

Benjamin Harsha - One of the best experts on this subject based on the ideXlab platform.

  • On the Economics of Offline Password Cracking
    arXiv: Cryptography and Security, 2020
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with $10^5$ hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker -- if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of $500$ million cracked Passwords is less than $100$ times the total value of $5$ million Passwords). See paper for full abstract.

  • on the economics of offline Password cracking
    IEEE Symposium on Security and Privacy, 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

  • IEEE Symposium on Security and Privacy - On the Economics of Offline Password Cracking
    2018 IEEE Symposium on Security and Privacy (SP), 2018
    Co-Authors: Jeremiah Blocki, Benjamin Harsha, Samson Zhou
    Abstract:

    We develop an economic model of an offline Password Cracker which allows us to make quantitative predictions about the fraction of accounts that a rational Password attacker would crack in the event of an authentication server breach. We apply our economic model to analyze recent massive Password breaches at Yahoo!, Dropbox, LastPass and AshleyMadison. All four organizations were using key-stretching to protect user Passwords. In fact, LastPass' use of PBKDF2-SHA256 with 10^5 hash iterations exceeds 2017 NIST minimum recommendation by an order of magnitude. Nevertheless, our analysis paints a bleak picture: the adopted key-stretching levels provide insufficient protection for user Passwords. In particular, we present strong evidence that most user Passwords follow a Zipf's law distribution, and characterize the behavior of a rational attacker when user Passwords are selected from a Zipf's law distribution. We show that there is a finite threshold which depends on the Zipf's law parameters that characterizes the behavior of a rational attacker — if the value of a cracked Password (normalized by the cost of computing the Password hash function) exceeds this threshold then the adversary's optimal strategy is always to continue attacking until each user Password has been cracked. In all cases (Yahoo!, Dropbox, LastPass and AshleyMadison) we find that the value of a cracked Password almost certainly exceeds this threshold meaning that a rational attacker would crack all Passwords that are selected from the Zipf's law distribution (i.e., most user Passwords). This prediction holds even if we incorporate an aggressive model of diminishing returns for the attacker (e.g., the total value of 500 million cracked Passwords is less than 100 times the total value of 5 million Passwords). On a positive note our analysis demonstrates that memory hard functions (MHFs) such as SCRYPT or Argon2i can significantly reduce the damage of an offline attack. In particular, we find that because MHFs substantially increase guessing costs a rational attacker will give up well before he cracks most user Passwords and this prediction holds even if the attacker does not encounter diminishing returns for additional cracked Passwords. Based on our analysis we advocate that Password hashing standards should be updated to require the use of memory hard functions for Password hashing and disallow the use of non-memory hard functions such as BCRYPT or PBKDF2.

Zhentao Zhao - One of the best experts on this subject based on the ideXlab platform.

  • UIC/ATC/ScalCom - A Weak Password Cracker of UHF RFID Tags
    2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th I, 2015
    Co-Authors: Zhentao Zhao, Jiankai Li, Shengguang Li, Shufang Li, Yang Kang, Weijun Hong
    Abstract:

    Under the ISO/IEC 18000-6C protocol of UHF RFID an electronic tag's information security is based on Password protection, but its natural defect is unable to reject brute tests which can be exhaustive. By the protocol analysis, this article theoretically proves that tags' weak Passwords can be cracked. Combined with a concrete Tag-Interrogator module a method for improving the cracking efficiency is given out with a special concise Password library. Furthermore this paper implements the Password Cracker has carried on the exploration of distributed detection. By this method most electronic tags' Passwords can be cracked within one week. The ultimate goal of this paper is to remind that UHF RFID industry projects should enhance the security level of tag's Password practically.

  • A Weak Password Cracker of UHF RFID Tags
    2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th I, 2015
    Co-Authors: Zhentao Zhao, Jiankai Li, Shengguang Li, Shufang Li, Yang Kang, Weijun Hong
    Abstract:

    Under the ISO/IEC 18000-6C protocol of UHF RFID an electronic tag's information security is based on Password protection, but its natural defect is unable to reject brute tests which can be exhaustive. By the protocol analysis, this article theoretically proves that tags' weak Passwords can be cracked. Combined with a concrete Tag-Interrogator module a method for improving the cracking efficiency is given out with a special concise Password library. Furthermore this paper implements the Password Cracker has carried on the exploration of distributed detection. By this method most electronic tags' Passwords can be cracked within one week. The ultimate goal of this paper is to remind that UHF RFID industry projects should enhance the security level of tag's Password practically.