首页> 外文会议>IEEE Symposium on Security and Privacy >They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and Websites
【24h】

They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and Websites

机译:如果他们一起工作,他们会做得更好:密码经理和网站之间交互问题的情况

获取原文

摘要

Password managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2,947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research.
机译:密码管理器是支持用户安全生成和存储在线帐户中使用的凭据和登录的工具。以前的工作说明了构建密码管理器意味着面临各种安全性和可用性挑战。对于强大的安全性和良好的可用性,密码管理人员和网站之间的互动需要顺利且不毫不努力。但是,对流行密码管理器的用户评论建议某些网站的交互问题。因此,据我们所知,这项工作是第一个系统地识别这些互动问题并调查15个桌面密码管理员,包括十个最受欢迎的人员的互动问题受到影响。我们使用定性分析方法来确定来自2,947名用户评论的39个互动问题,以及30个密码经理的372个GitHub问题。接下来,我们为585个测试用例中找到的所有密码管理器中找到的所有相互作用问题的最小工作示例(MWE)实现了最小的工作示例(MWE)。我们的结果说明了一个)密码管理人员努力正确实现HTTP基本身份验证和现代标准等认证功能例如自动填充属性和b)网站无法实现干净且结构良好的身份验证表单。我们得出结论,我们通过遵守现有的标准,建议和最佳实践,我们可以通过PWM提供商或网络开发商解决一些发现,而其他案件目前几乎不可能安全地实施并需要进一步的研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号