Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web Browsers
Anuj Gautam, Tarun Kumar Yadav, Garrett Smith, Kent E. Seamons, Scott Ruoti
摘要
Password managers provide significant security benefits to users. However, malicious client-side scripts and browser extensions can steal passwords after the manager has autofilled them into the web page. In this paper, we extend prior work by Stock and Johns, showing how password autofill can be hardened to prevent these local attacks. We implement our design in the Firefox browser and conduct experiments demonstrating that our defense successfully protects passwords from XSS attacks and malicious extensions. We also show that our implementation is compatible with 97% of the Alexa top 1000 websites. Next, we generalize our design, creating a second defense that prevents recently discovered local attacks against the FIDO2 protocols. We implement this second defense into Firefox, demonstrating that it protects the FIDO2 protocol against XSS attacks and malicious extensions. This defense is compatible with all websites, though it does require a small change (2-3 lines) to web servers implementing FIDO2.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes 等USENIX Security 2018 · 被引用 63 次
- They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesNicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar 等S&P 2021 · 被引用 37 次
- You've Changed: Detecting Malicious Browser Extensions through their Update DeltasNikolaos Pantelaios, Nick Nikiforakis, Alexandros KapravelosCCS 2020 · 被引用 34 次
- "It Basically Started Using Me: " An Observational Study of Password Manager UsageSean Oesch, Scott Ruoti, James Simmons, Anuj GautamCHI 2022 · 被引用 21 次
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 被引用 3 次
相关 Paper
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 被引用 1 次
- A Security and Usability Analysis of Local Attacks Against FIDO2Tarun Kumar Yadav, Kent E. SeamonsNDSS 2024
- Phishing Attacks against Password Manager Browser ExtensionsClaudio Anliker, Daniele Lain, Srdjan CapkunUSENIX Security 2025
- That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Browser-Based Password ManagersSean Oesch, Scott RuotiUSENIX Security 2020
- Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsAsmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem FawazWWW 2024 · 被引用 12 次
