zxcvbn: Low-Budget Password Strength Estimation
Daniel Lowe Wheeler
摘要
For over 30 years, password requirements and feedback have largely remained a product of LUDS: counts of lowerand uppercase letters, digits and symbols. LUDS remains ubiquitous despite being a conclusively burdensome and ineffective security practice.
zxcvbn is an alternative password strength estimator that is small, fast, and crucially no harder than LUDS to adopt. Using leaked passwords, we compare its estimations to the best of four modern guessing attacks and show it to be accurate and conservative at low magnitudes, suitable for mitigating online attacks. We find 1.5 MB of compressed storage is sufficient to accurately estimate the best-known guessing attacks up to 10 5 guesses, or 10 4 and 10 3 guesses, respectively, given 245 kB and 29 kB. zxcvbn can be adopted with 4 lines of code and downloaded in seconds. It runs in milliseconds and works as-is on web, iOS and Android.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper32
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan 等USENIX Security 2019 · 被引用 154 次
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 被引用 100 次
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 被引用 100 次
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan 等CCS 2019 · 被引用 80 次
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes 等USENIX Security 2018 · 被引用 63 次
它引用的顶会 Paper1
相关 Paper
- No Single Silver Bullet: Measuring the Accuracy of Password Strength MetersDing Wang, Xuan Shan, Qiying Dong, Yaosheng Shen 等USENIX Security 2023
- Confident Monte Carlo: Rigorous Analysis of Guessing Curves for Probabilistic Password ModelsPeiyuan Liu, Jeremiah Blocki, Wenjie BaiS&P 2023
- Reasoning Analytically about Password-Cracking SoftwareEnze Liu, Amanda Nakanishi, Maximilian Golla, David Cash 等S&P 2019 · 被引用 33 次
- Distinguishing Attacks from Legitimate Authentication Traffic at ScaleCormac Herley, Stuart E. SchechterNDSS 2019 · 被引用 15 次
- Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsMing Xu, Chuanwang Wang, Jitao Yu, Junjie Zhang 等CCS 2021 · 被引用 32 次
