A Large-Scale Measurement of Website Login Policies
Suood Abdulaziz Al-Roomi, Frank Li
摘要
Authenticating on a website using a password involves a multistage login process, where each stage entails critical policy and implementation decisions that impact login security and usability. While the security community has identified best practices for each stage of the login workflow, we currently lack a broad understanding of website login policies in practice. Prior work relied upon manual inspection of websites, producing evaluations of only a small population of sites skewed towards the most popular ones. In this work, we seek to provide a more comprehensive and systematic picture of real-world website login policies. We develop an automated method for inferring website login policies and apply it to domains across the Google CrUX Top 1 Million. We successfully evaluate the login policies on between 18K and 359K sites (varying depending on the login stage considered), providing characterization of a population two to three orders of magnitude larger than previous studies. Our findings reveal the extent to which insecure login policies exist and identify some underlying causes. Ultimately, our study provides the most comprehensive empirical grounding to date on the state of website login security, shedding light on directions for improving online authentication.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting BehaviorAsuman Senol, Alisha Ukani, Dylan Cutler, Igor BilogrevicWWW 2024 · 被引用 14 次
- PointerGuess: Targeted Password Guessing Model Using Pointer MechanismKedong Xiu, Ding WangUSENIX Security 2024 · 被引用 12 次
- SINBAD: Saliency-informed detection of breakage caused by ad blockingSaiid El Hajj Chehade, Sandra Deepthy Siby, Carmela TroncosoS&P 2024 · 被引用 3 次
- PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery NetworksShihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu 等NSDI 2025 · 被引用 2 次
- Unmasking the Security and Usability of Password MaskingYuqi Hu, Suood Alroomi, Sena Sahin, Frank LiCCS 2024 · 被引用 1 次
它引用的顶会 Paper5
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 被引用 56 次
- Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and SupportMax Maass, Alina Stöver, Henning Pridöhl, Sebastian Bretthauer 等USENIX Security 2021 · 被引用 35 次
- Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationSena Sahin, Frank LiCCS 2021 · 被引用 13 次
- Leaky Forms: A Study of Email and Password Exfiltration Before Form SubmissionAsuman Senol, Gunes Acar, Mathias Humbert, Frederik J. Zuiderveen BorgesiusUSENIX Security 2022
相关 Paper
- Measuring Website Password Creation Policies At ScaleSuood Alroomi, Frank LiCCS 2023 · 被引用 15 次
- Investigating the Password Policy Practices of Website AdministratorsSena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank LiS&P 2023
- To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security LandscapeJannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich 等S&P 2024 · 被引用 6 次
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan 等USENIX Security 2025
- pASSWORD tYPOS and How to Correct Them SecurelyRahul Chatterjee, Anish Athayle, Devdatta Akhawe, Ari Juels 等S&P 2016 · 被引用 68 次
