The TypTop System: Personalized Typo-Tolerant Password Checking
Rahul Chatterjee, Joanne Woodage, Yuval Pnueli, Anusha Chowdhury, Thomas Ristenpart
Abstract
Password checking systems traditionally allow login only if the correct password is submitted. Recent work on typo-tolerant password checking suggests that usability can be improved, with negligible security loss, by allowing a small number of typographical errors. Existing systems, however, can only correct a handful of errors, such as accidentally leaving caps lock on or incorrect capitalization of the first letter in a password. This leaves out numerous kinds of typos made by users, such as transposition errors, substitutions, or capitalization errors elsewhere in a password. Some users therefore receive no benefit from existing typo-tolerance mechanisms.
We introduce personalized typo-tolerant password checking. In our approach, the authentication system learns over time the typos made by a specific user. In experiments using Mechanical Turk, we show that 45% of users would benefit from personalization. Therefore, we design a system, called TypTop, that securely implements personalized typo-tolerance. Underlying TypTop is a new stateful password-based encryption scheme that can be used to store recent failed login attempts. Our formal analysis shows that security in the face of an attacker that obtains the state of the system reduces to the difficulty of a brute-force dictionary attack against the real password. We implement TypTop for Linux and Mac OS login and report on a proof-of-concept deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 328ced95-0c54-4db5-91aa-e6108a17d011Cited by top-tier papers5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationSena Sahin, Frank LiCCS 2021 · 13 citations
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan et al.USENIX Security 2022
- Conditional Encryption with Applications to Secure Personalized Password Typo CorrectionMohammad Hassan Ameri, Jeremiah BlockiCCS 2024
- Towards a Rigorous Statistical Analysis of Empirical Password DatasetsJeremiah Blocki, Peiyuan LiuS&P 2023
Builds on2
Related papers
- How to Tolerate Typos in Strong Asymmetric PAKEIan McQuoid, Mike Rosulek, Jiayu XuCRYPTO 2025 · 3 citations
- Exploring the Effect of Music on User Typing and Identification through Keystroke DynamicsLukas Mecke, Assem Mahmoud, Simon Marat, Florian AltCHI 2025 · 1 citation
- Security and Privacy Failures in Popular 2FA AppsConor Gilsenan, Fuzail Shakir, Noura Alomar, Serge EgelmanUSENIX Security 2023
- AirtypeLogger: How Short Keystrokes in Virtual Space Can Expose Your Semantic Input to Nearby CamerasTongyu Zhang, Yiran Shen, Ning Chen, Guoming Zhang et al.IEEE VR 2025 · 1 citation
- PhraseFlow: Designs and Empirical Studies of Phrase-Level InputMingrui Ray Zhang, Shumin ZhaiCHI 2021 · 12 citations
