USENIX Security2022Top-tier venue
Gossamer: Securely Measuring Password-based Logins
Marina Sanusi Bohuk, Mazharul Islam, Suleman Ahmad, Michael M. Swift, Thomas Ristenpart, Rahul Chatterjee
Abstract
Passwords remain the primary way to authenticate users online. Yet little is known about the characteristics of login requests submitted to login systems due to the sensitivity of monitoring submitted passwords. This means we don't have answers to basic questions, such as how often users submit a password similar to their actual password, whether users often resubmit the same incorrect password, how many users utilize passwords known to be in a public breach, and more. Whether we can build and deploy measurement infrastructure to safely answer such questions is, itself, an open question. We offer a system, called Gossamer, that enables securely logging information about login attempts, including carefully chosen statistics about submitted passwords. We provide a simulation-based approach for tuning the security-utility trade-offs for storing different password-derived statistics. This enables us to gather useful measurements while reducing risk even in the unlikely case of complete compromise of the measurement system. We worked closely with two large universities and deployed Gossamer to perform a measurement study that observed 34 million login requests over a seven month period. The measurements we gather provide insight into the use of breached credentials, password usability, and other characteristics of the submitted login requests.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop ThemSachin Kumar Singh, Shreeman Gautam, Cameron Cartier, Sameer Patil et al.NSDI 2024 · 15 citations
- Speranza: Usable, Privacy-friendly Software SigningKelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen R. SollinsCCS 2023 · 5 citations
- A Two-Decade Retrospective Analysis of a University's Vulnerability to Attacks Exploiting Reused PasswordsAlexandra Nisenoff, Maximilian Golla, Miranda Wei, Juliette Hainline et al.USENIX Security 2023
- Araña: Discovering and Characterizing Password Guessing Attacks in PracticeMazharul Islam, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart et al.USENIX Security 2023
Builds on7
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
Related papers
- Using Amnesia to Detect Credential Database BreachesKe Coby Wang, Michael K. ReiterUSENIX Security 2021 · 18 citations
- Understanding Users' Interaction with Login NotificationsPhilipp Markert, Leona Lassak, Maximilian Golla, Markus DürmuthCHI 2024 · 6 citations
- "What was that site doing with my Facebook password?": Designing Password-Reuse NotificationsMaximilian Golla, Miranda Wei, Juliette Hainline, Lydia Filipe et al.CCS 2018 · 68 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- A Large-Scale Measurement of Website Login PoliciesSuood Abdulaziz Al-Roomi, Frank LiUSENIX Security 2023
