ACM Home Page
Please provide us with feedback. Feedback
Delayed password disclosure
Full text PdfPdf (270 KB)
Source
Workshop On Digital Identity Management archive
Proceedings of the 2007 ACM workshop on Digital identity management table of contents
Fairfax, Virginia, USA
SESSION: Usability and authentication table of contents
Pages: 17 - 26  
Year of Publication: 2007
ISBN:978-1-59593-889-3
Authors
Markus Jakobsson  Indiana University, Bloomington, IN
Steven Myers  Indiana University, Bloomington, IN
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 5,   Downloads (12 Months): 91,   Citation Count: 2
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1314403.1314407
What is a DOI?

ABSTRACT

We present a new authentication protocol called Delayed Password Disclosure. Based on the traditional user name and password paradigm, the protocol's goal is aimed at reducing the effectiveness of phishing/spoofing attacks that are becoming increasingly problematic for Internet users. This is done by providing the user with dynamic feedback while password entry occurs. While this is a process that would normally be frowned upon by the cryptographic community, we argue that it may result in more effective security than that offered by currently proposed "cryptographically acceptable" alternatives. While the protocol cannot prevent partial disclosure of one's password to the phisher, it does provide a user with the tools necessary to recognizean on going phishing attack, and prevent the disclosure of his/her entire password, providing graceful security degradation.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
M. Bellare, A. Boldyreva, and A. Palacio. An uninstantiable random-oracle-model scheme for a hybrid-encryption problem. In CCanchin and JCamenisch, editors, Advances in Cryptology-EUROCRYPT'04, pages 171--188. Springer, 2004.
 
2
 
3
M. Bellare, D. Pointcheval, and P. Rogaway. Authenticated key exchange secure against dictionary attacks. EUROCRYPT-Lecture Notes in Computer Science, 1807:139--155, 2000.
 
4
5
 
6
D. R. L. Brown and R. P. Gallant. The static Diffie-Hellman problem. Cryptology ePrint Archive, Report 2004/306, 2004. http://eprint.iacr.org/.
7
 
8
N. Chou, R. Ledesma, Y. Teraguchi, D. Boneh, and J. C. Mitchell. Client-side defense against web-based identity theft, Apr. 2004.
9
10
 
11
A. Emigh. Online identity theft: Technology, chokepoints and countermeasures. In DHS Report, 2005.
 
12
 
13
14
 
15
 
16
A. Herzberg and A. Gbara. Trustbar: Protecting (even naive). web users from spoofing and phishing attacks, 2004.
17
 
18
 
19
 
20
 
21
B. Parno, C. Kuo, and A. Perrig. Phoolproof phishing prevention. In G. D. Crescenzo and A. Rubin, editors, Financial Cryptography, volume 4107 of Lecture Notes in Computer Science, pages 1--19. Springer, 2006.
 
22


Collaborative Colleagues:
Markus Jakobsson: colleagues
Steven Myers: colleagues