skip to main content
10.1145/2660267.2662387acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
poster

POSTER: Password Entering and Transmission Security

Authors Info & Claims
Published:03 November 2014Publication History

ABSTRACT

The most popular form of user authentication on websites is the use of passwords. When entering a password, it is crucial that the website uses HTTPS (for the entire content). However, this is often not the case. We propose PassSec - a Firefox Add-On to support users to detect password fields on which their password might be endangered. In addition, PassSec displays a non-blocking warning next to the password field, once users click into the password field. The user is provided with possible consequences of entering a password, recommendations and further information if wanted.

References

  1. C. Bravo-Lillo, L. Cranor, J. Downs, and S. Komanduri. Bridging the gap in computer security warnings: A mental model approach. Security Privacy, IEEE, 9(2):18--26, March 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. N. Kolb, S. Bartsch, M. Volkamer, and J. Vogt. Capturing attention for warnings about insecure password fields--systematic development of a passive security intervention. In Human Aspects of Information Security, Privacy, and Trust, pages 172--182. Springer, 2014.Google ScholarGoogle Scholar
  3. M.-E. Maurer, A. De Luca, and H. Hussmann. Data type based security alert dialogs. In CHI'11 Extended Abstracts on Human Factors in Computing Systems, pages 2359--2364. ACM, 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. M.-E. Maurer, A. De Luca, and S. Kempe. Using data type based security alert dialogs to raise online security awareness. In Proceedings of the Seventh Symposium on Usable Privacy and Security, page 2. ACM, 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. H.-M. Sun, Y.-H. Chen, and Y.-H. Lin. opass: A user authentication protocol resistant to password stealing and password reuse attacks. Information Forensics and Security, IEEE Transactions on, 7(2):651--663, 2012.Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. R. West. The psychology of security. Communications of the ACM, 51(4):34--40, 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. POSTER: Password Entering and Transmission Security

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          CCS '14: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
          November 2014
          1592 pages
          ISBN:9781450329576
          DOI:10.1145/2660267

          Copyright © 2014 Owner/Author

          Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 3 November 2014

          Check for updates

          Qualifiers

          • poster

          Acceptance Rates

          CCS '14 Paper Acceptance Rate114of585submissions,19%Overall Acceptance Rate1,261of6,999submissions,18%

          Upcoming Conference

          CCS '24
          ACM SIGSAC Conference on Computer and Communications Security
          October 14 - 18, 2024
          Salt Lake City , UT , USA
        • Article Metrics

          • Downloads (Last 12 months)2
          • Downloads (Last 6 weeks)0

          Other Metrics

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader