Protecting accounts from credential stuffing with password breach alerting
Kurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan, Patrick Gage Kelley, Luca Invernizzi, Borbala Benko, Tadek Pietraszek, Sarvar Patel, Dan Boneh, Elie Bursztein
摘要
Protecting accounts from credential stuffing attacks remains burdensome due to an asymmetry of knowledge: attackers have wide-scale access to billions of stolen usernames and passwords, while users and identity providers remain in the dark as to which accounts require remediation. In this paper, we propose a privacy-preserving protocol whereby a client can query a centralized breach repository to determine whether a specific username and password combination is publicly exposed, but without revealing the information queried. Here, a client can be an end user, a password manager, or an identity provider. To demonstrate the feasibility of our protocol, we implement a cloud service that mediates access to over 4 billion credentials found in breaches and a Chrome extension serving as an initial client. Based on anonymous telemetry from nearly 670,000 users and 21 million logins, we find that 1.5% of logins on the web involve breached credentials. By alerting users to this breach status, 26% of our warnings result in users migrating to a new password, at least as strong as the original. Our study illustrates how secure, democratized access to password breach alerting can help mitigate one dimension of account hijacking. Client Server CreateRequest(u,p) LS CreateResponse(S, Req) Verdict(Resp, LS) true, false Req Resp
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper42
- Communication-Computation Trade-offs in PIRAsra Ali, Tancrède Lepoint, Sarvar Patel, Mariana Raykova 等USENIX Security 2021 · 被引用 126 次
- Private Blocklist Lookups with ChecklistDmitry Kogan, Henry Corrigan-GibbsUSENIX Security 2021 · 被引用 104 次
- Identifying Harmful Media in End-to-End Encrypted Communication: Efficient Private Membership ComputationAnunay Kulshrestha, Jonathan R. MayerUSENIX Security 2021 · 被引用 50 次
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 被引用 48 次
- Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design PatternsMaximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri 等USENIX Security 2021 · 被引用 48 次
它引用的顶会 Paper8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens 等USENIX Security 2017 · 被引用 316 次
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
相关 Paper
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan 等USENIX Security 2022
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan 等CCS 2019 · 被引用 80 次
- Breach Extraction Attacks: Exposing and Addressing the Leakage in Second Generation Compromised Credential Checking ServicesDario Pasquini, Danilo Francati, Giuseppe Ateniese, Evgenios M. KornaropoulosS&P 2024 · 被引用 3 次
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang, Yutong LiS&P 2026 · 被引用 1 次
- Checking Passwords on Leaky Computers: A Side Channel Analysis of Chrome's Password Leak Detect ProtocolAndrew Kwong, Walter Wang, Jason Kim, Jonathan Berger 等USENIX Security 2023
