The Experts below are selected from a list of 57 Experts worldwide ranked by ideXlab platform
Lorrie Faith Cranor - One of the best experts on this subject based on the ideXlab platform.
-
SOUPS - Human selection of mnemonic phrase-based Passwords
Proceedings of the second symposium on Usable privacy and security - SOUPS '06, 2006Co-Authors: Sasha Romanosky, Lorrie Faith CranorAbstract:Textual Passwords are often the only mechanism used to authenticate users of a networked system. Unfortunately, many Passwords are easily guessed or cracked. In an attempt to strengthen Passwords, some systems instruct users to create mnemonic phrase-based Passwords. A mnemonic Password is one where a user chooses a memorable phrase and uses a character (often the first letter) to represent each word in the phrase.In this paper, we hypothesize that users will select mnemonic phrases that are commonly available on the Internet, and that it is possible to build a Dictionary to crack mnemonic phrase-based Passwords. We conduct a survey to gather user-generated Passwords. We show the majority of survey respondents based their mnemonic Passwords on phrases that can be found on the Internet, and we generate a mnemonic Password Dictionary as a proof of concept. Our 400,000-entry Dictionary cracked 4% of mnemonic Passwords; in comparison, a standard Dictionary with 1.2 million entries cracked 11% of control Passwords. The user-generated mnemonic Passwords were also slightly more resistant to brute force attacks than control Passwords. These results suggest that mnemonic Passwords may be appropriate for some uses today. However, mnemonic Passwords could become more vulnerable in the future and should not be treated as a panacea.
-
Human selection of mnemonic phrase-based Passwords
SOUPS '06: Proceedings of the second symposium on Usable privacy and security, 2006Co-Authors: Cynthia Kuo, Sasha Romanosky, Lorrie Faith CranorAbstract:Textual Passwords are often the only mechanism used to authenticate users of a networked system. Unfortunately, many Passwords are easily guessed or cracked. In an attempt to strengthen Passwords, some systems instruct users to create mnemonic phrase-based Passwords. A mnemonic Password is one where a user chooses a memorable phrase and uses a character (often the first letter) to represent each word in the phrase. In this paper, we hypothesize that users will select mnemonic phrases that are commonly available on the Internet, and that it is possible to build a Dictionary to crack mnemonic phrase-based Passwords. We conduct a survey to gather user-generated Passwords. We show the majority of survey respondents based their mnemonic Passwords on phrases that can be found on the Internet, and we generate a mnemonic Password Dictionary as a proof of concept. Our 400,000-entry Dictionary cracked 4% of mnemonic Passwords; in comparison, a standard Dictionary with 1.2 million entries cracked 11% of control Passwords. The usergenerated mnemonic Passwords were also slightly more resistant to brute force attacks than control Passwords. These results suggest that mnemonic Passwords may be appropriate for some uses today. However, mnemonic Passwords could become more vulnerable in the future and should not be treated as a panacea.
Cynthia Kuo - One of the best experts on this subject based on the ideXlab platform.
-
Human selection of mnemonic phrase-based Passwords
SOUPS '06: Proceedings of the second symposium on Usable privacy and security, 2006Co-Authors: Cynthia Kuo, Sasha Romanosky, Lorrie Faith CranorAbstract:Textual Passwords are often the only mechanism used to authenticate users of a networked system. Unfortunately, many Passwords are easily guessed or cracked. In an attempt to strengthen Passwords, some systems instruct users to create mnemonic phrase-based Passwords. A mnemonic Password is one where a user chooses a memorable phrase and uses a character (often the first letter) to represent each word in the phrase. In this paper, we hypothesize that users will select mnemonic phrases that are commonly available on the Internet, and that it is possible to build a Dictionary to crack mnemonic phrase-based Passwords. We conduct a survey to gather user-generated Passwords. We show the majority of survey respondents based their mnemonic Passwords on phrases that can be found on the Internet, and we generate a mnemonic Password Dictionary as a proof of concept. Our 400,000-entry Dictionary cracked 4% of mnemonic Passwords; in comparison, a standard Dictionary with 1.2 million entries cracked 11% of control Passwords. The usergenerated mnemonic Passwords were also slightly more resistant to brute force attacks than control Passwords. These results suggest that mnemonic Passwords may be appropriate for some uses today. However, mnemonic Passwords could become more vulnerable in the future and should not be treated as a panacea.
Sasha Romanosky - One of the best experts on this subject based on the ideXlab platform.
-
SOUPS - Human selection of mnemonic phrase-based Passwords
Proceedings of the second symposium on Usable privacy and security - SOUPS '06, 2006Co-Authors: Sasha Romanosky, Lorrie Faith CranorAbstract:Textual Passwords are often the only mechanism used to authenticate users of a networked system. Unfortunately, many Passwords are easily guessed or cracked. In an attempt to strengthen Passwords, some systems instruct users to create mnemonic phrase-based Passwords. A mnemonic Password is one where a user chooses a memorable phrase and uses a character (often the first letter) to represent each word in the phrase.In this paper, we hypothesize that users will select mnemonic phrases that are commonly available on the Internet, and that it is possible to build a Dictionary to crack mnemonic phrase-based Passwords. We conduct a survey to gather user-generated Passwords. We show the majority of survey respondents based their mnemonic Passwords on phrases that can be found on the Internet, and we generate a mnemonic Password Dictionary as a proof of concept. Our 400,000-entry Dictionary cracked 4% of mnemonic Passwords; in comparison, a standard Dictionary with 1.2 million entries cracked 11% of control Passwords. The user-generated mnemonic Passwords were also slightly more resistant to brute force attacks than control Passwords. These results suggest that mnemonic Passwords may be appropriate for some uses today. However, mnemonic Passwords could become more vulnerable in the future and should not be treated as a panacea.
-
Human selection of mnemonic phrase-based Passwords
SOUPS '06: Proceedings of the second symposium on Usable privacy and security, 2006Co-Authors: Cynthia Kuo, Sasha Romanosky, Lorrie Faith CranorAbstract:Textual Passwords are often the only mechanism used to authenticate users of a networked system. Unfortunately, many Passwords are easily guessed or cracked. In an attempt to strengthen Passwords, some systems instruct users to create mnemonic phrase-based Passwords. A mnemonic Password is one where a user chooses a memorable phrase and uses a character (often the first letter) to represent each word in the phrase. In this paper, we hypothesize that users will select mnemonic phrases that are commonly available on the Internet, and that it is possible to build a Dictionary to crack mnemonic phrase-based Passwords. We conduct a survey to gather user-generated Passwords. We show the majority of survey respondents based their mnemonic Passwords on phrases that can be found on the Internet, and we generate a mnemonic Password Dictionary as a proof of concept. Our 400,000-entry Dictionary cracked 4% of mnemonic Passwords; in comparison, a standard Dictionary with 1.2 million entries cracked 11% of control Passwords. The usergenerated mnemonic Passwords were also slightly more resistant to brute force attacks than control Passwords. These results suggest that mnemonic Passwords may be appropriate for some uses today. However, mnemonic Passwords could become more vulnerable in the future and should not be treated as a panacea.
Manfred Schimmler - One of the best experts on this subject based on the ideXlab platform.
-
ICPADS - An efficient implementation of PBKDF2 with RIPEMD-160 on multiple FPGAs
2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014Co-Authors: Ayman Abbas, Rian Voß, Lars Wienbrandt, Manfred SchimmlerAbstract:A weakness of many security systems is the strength of the chosen Password or key derivation function. We show how FPGA technology can be used to effectively attack cryptographic applications with a Password Dictionary. We have implemented two independent PBKDF2 cores each using four HMAC cores with pipelines calculating a RIPEMD-160 hash to derive encryption keys together with one resource optimized AES-256 XTS core for direct decryption on a Xilinx Spartan6-LX150 FPGA. Our design targets TRUECRYPT containers, but may be applied to similar encryption tools with little adaption. In order to save resources and maximize speed, we have further optimized the RIPEMD-160 hash function for this purpose. Our design executed on the multi-FPGA system RIVYERA S6-LX150 containing 128 S6-LX150 FPGAs, finally reaches a peak performance of about 245,000 Passwords per second.
-
An efficient implementation of PBKDF2 with RIPEMD-160 on multiple FPGAs
2014 20th IEEE International Conference on Parallel and Distributed Systems (ICPADS), 2014Co-Authors: Ayman Abbas, Rian Voß, Lars Wienbrandt, Manfred SchimmlerAbstract:A weakness of many security systems is the strength of the chosen Password or key derivation function. We show how FPGA technology can be used to effectively attack cryptographic applications with a Password Dictionary. We have implemented two independent PBKDF2 cores each using four HMAC cores with pipelines calculating a RIPEMD-160 hash to derive encryption keys together with one resource optimized AES-256 XTS core for direct decryption on a Xilinx Spartan6-LX150 FPGA. Our design targets TRUECRYPT containers, but may be applied to similar encryption tools with little adaption. In order to save resources and maximize speed, we have further optimized the RIPEMD-160 hash function for this purpose. Our design executed on the multi-FPGA system RIVYERA S6-LX150 containing 128 S6-LX150 FPGAs, finally reaches a peak performance of about 245,000 Passwords per second.
Paul C. Van Oorschot - One of the best experts on this subject based on the ideXlab platform.
-
What lies beneath? Analyzing automated SSH bruteforce attacks
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2016Co-Authors: Abdel Rahman Abdou, Paul C. Van Oorschot, David Barrera, Paul C. Van OorschotAbstract:We report on what we believe to be the largest dataset (to date) of automated secure shell (SSH) bruteforce attacks. The dataset includes plaintext Password guesses in addition to timing, source, and username details, which allows us to analyze attacker behaviour and dynamics (e.g., coordinated attacks and Password Dictionary sharing). Our methodology involves hosting six instrumented SSH servers in six cities. Over the course of a year, we recorded a total of $$~$$17M login attempts originating from 112 different countries and over 6 K distinct source IP addresses. We shed light on attacker behaviour, and based on our findings provide recommendations for SSH users and administrators.
-
PasswordS - What Lies Beneath? Analyzing Automated SSH Bruteforce Attacks
Technology and Practice of Passwords, 2015Co-Authors: Abdel Rahman Abdou, David Barrera, Paul C. Van OorschotAbstract:We report on what we believe to be the largest dataset (to date) of automated secure shell (SSH) bruteforce attacks. The dataset includes plaintext Password guesses in addition to timing, source, and username details, which allows us to analyze attacker behaviour and dynamics (e.g., coordinated attacks and Password Dictionary sharing). Our methodology involves hosting six instrumented SSH servers in six cities. Over the course of a year, we recorded a total of 17M login attempts originating from 112 dierent countries and over 6K distinct source IP addresses. We shed light on attacker behaviour, and based on our ndings provide recommendations for SSH users and administrators.