谷歌浏览器插件
订阅小程序
在清言上使用

Tapas: design, implementation, and usability evaluation of a password manager

ACSAC '12: Proceedings of the 28th Annual Computer Security Applications Conference(2012)

引用 83|浏览0
暂无评分
摘要
Passwords continue to prevail on the web as the primary method for user authentication despite their well-known security and usability drawbacks. Password managers offer some improvement without requiring server-side changes. In this paper, we evaluate the security of dual-possession authentication, an authentication approach offering encrypted storage of passwords and theft-resistance without the use of a master password. We further introduce Tapas, a concrete implementation of dual-possession authentication leveraging a desktop computer and a smartphone. Tapas requires no server-side changes to websites, no master password, and protects all the stored passwords in the event either the primary or secondary device (e.g., computer or phone) is stolen. To evaluate the viability of Tapas as an alternative to traditional password managers, we perform a 30 participant user study comparing Tapas to two configurations of Firefox's built-in password manager. We found users significantly preferred Tapas. We then improve Tapas by incorporating feedback from this study, and reevaluate it with an additional 10 participants.
更多
查看译文
关键词
authentication approach,participant user study,built-in password manager,desktop computer,master password,usability evaluation,preferred tapas,dual-possession authentication,user authentication,traditional password manager,server-side change
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要