The Experts below are selected from a list of 24 Experts worldwide ranked by ideXlab platform
Simon Weiler - One of the best experts on this subject based on the ideXlab platform.
-
ACM Conference on Computer and Communications Security - POSTER: Password Entering and Transmission Security
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014Co-Authors: Gamze Canova, Melanie Volkamer, Simon WeilerAbstract:The most popular form of user authentication on websites is the use of Passwords. When entering a Password, it is crucial that the website uses HTTPS (for the entire content). However, this is often not the case. We propose PassSec - a Firefox Add-On to support users to detect Password Fields on which their Password might be endangered. In addition, PassSec displays a non-blocking warning next to the Password Field, once users click into the Password Field. The user is provided with possible consequences of entering a Password, recommendations and further information if wanted.
Gamze Canova - One of the best experts on this subject based on the ideXlab platform.
-
ACM Conference on Computer and Communications Security - POSTER: Password Entering and Transmission Security
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014Co-Authors: Gamze Canova, Melanie Volkamer, Simon WeilerAbstract:The most popular form of user authentication on websites is the use of Passwords. When entering a Password, it is crucial that the website uses HTTPS (for the entire content). However, this is often not the case. We propose PassSec - a Firefox Add-On to support users to detect Password Fields on which their Password might be endangered. In addition, PassSec displays a non-blocking warning next to the Password Field, once users click into the Password Field. The user is provided with possible consequences of entering a Password, recommendations and further information if wanted.
Melanie Volkamer - One of the best experts on this subject based on the ideXlab platform.
-
ACM Conference on Computer and Communications Security - POSTER: Password Entering and Transmission Security
Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, 2014Co-Authors: Gamze Canova, Melanie Volkamer, Simon WeilerAbstract:The most popular form of user authentication on websites is the use of Passwords. When entering a Password, it is crucial that the website uses HTTPS (for the entire content). However, this is often not the case. We propose PassSec - a Firefox Add-On to support users to detect Password Fields on which their Password might be endangered. In addition, PassSec displays a non-blocking warning next to the Password Field, once users click into the Password Field. The user is provided with possible consequences of entering a Password, recommendations and further information if wanted.
Nilsson Erik - One of the best experts on this subject based on the ideXlab platform.
-
Användarvänlighet och säkerhet - Ett lyckligt äktenskap eller snabb skilsmässa? : En rapport om hur användarvänlighet och säkerhet bör kombineras vid autentisering.
Linnéuniversitetet Institutionen för datavetenskap fysik och matematik DFM, 2012Co-Authors: Nilsson ErikAbstract:Säkerhet är ett måste på Internet, men det gäller också att skapa webbsidor som är trevliga att besöka och lätta att använda. Detta är inte alltid det enklaste att kombinera. Rapporten innehåller grundläggande fakta om användarvänlighet och vilka säkerhetshot det finns på Internet idag. Dessutom finns sammanfattningar från tidigare forskning om hur användarvänlighet och säkerhet bör kombineras. Denna forskning innefattar presentation av lösenordsfält, lösenfraser och captcha. Undersökningen baseras på testning av hur ett lösenordsfält bör presenteras, för att vara säkert och samtidigt användarvänligt. Testfallen gav användbara svar på om utbyte av lösenord mot lösenfraser skulle kunna öka både säkerheten och förmågan att komma ihåg lösenordet. Dessutom visar undersökningsresultaten hur säkerhetstekniken captcha påverkar användaren och om den är lämplig att använda i alla lägen. Resultat och effekter av detta kompletteras av en jämförelse mellan tio av de vanligaste captcha-teknikerna. Arbetets slutsats kring frågan om det går att öka säkerheten genom förbättrad användarvänlighet, är att detta är möjligt med hjälp av kommunikation och information till användaren. Förhoppningen är därmed att valda teorier, med stöd av undersökningsresultatet, kommer att få genomslag i framtidens standarder på Internet. Nyckelord i rapporten: Säkerhet, användarvänlighet, lösenfras, lösenordsfält, captcha.Security is a must on the Internet but websites must also be nice to visit and easy to use. To combine security with usability is not always that simple. This report contains basic facts about usability and security threats on Internet today. Besides that there is summary of earlier researches about how usability and security should be combined. This research covers how Password input Fields should be presented, passphrases and captcha. The study is based on testing of how a Password input Field should be presented, to be secure and still usable. The testcases gave useful answers about how a change from Passwords to passphrases could improve the security and in the same time improve the memorability. The test also shows how the security technique affect the user and if it’s appropriate to use it on all websites. Results and effects of this is complemented with a comparison of ten of the most common captchas. The report’s conclusion about the question if it’s possible to increase security through usability, is that this is possible with communication and information to the user. The expectation is that chosen theories, with support from the study results, will get penetration in Internets future standards. Keywords in the report: Security, usability, passphrase, Password Field, captcha
Karen A. Forcht - One of the best experts on this subject based on the ideXlab platform.
-
New concepts in Password management
The Journal of International Information Management, 2001Co-Authors: S. E. Kruck, John R. Sciandra, Karen A. ForchtAbstract:Passwords have been used for many years in the security of computer systems. The pass word mechanism has not changed in recent years and has several inherent security problems. This paper examines several Password problems including sniffers, dictionary and brute force attacks. A specific Department of Defense incident is cited to illustrate a method to thwart sniffers followed by several suggestions intended to increase the security of the Password process. INTRODUCTION Passwords are used throughout computing today as they provide a simple means of access control and authentication, thus helping to ensure that a person accessing a particular system is authorized to do so. As technology has advanced, increasingly more complicated computer sys tems contain more and more mission-critical infonnation. Unfortunately the implementation of basic Password control has not changed much over the last several years. Since it is still unlikely that the basic Password mechanism can and will change very quickly across large corporations or other large entities such as the Department of Defense (DOD), it may be more useful to examine the way in which these large organizations manage those Passwords and develop methodologies to work within existing strucmres. Hopefully, by using some techniques in which the DOD infor mation specialists may already have expertise, new ways may be suggested to manage Passwords and address a few of the problems. First, we must examine the basic Password mechanism and understand some of the prob lems associated with it. Second, the DOD specific problem will be evaluated. Human behavior is illustrated followed by suggested Password authentication schemes and Password protection tech niques. Password PROBLEMS Passwords are generally a single group of characters that are uc^d with a login name to allow access to computer resources. The Password Field is specially designed to hide the charac ters as they are typed. The computer screen typically displays asterisks in order to hide the