2020/12/03 by Adil Ahmed Chowdhury, Chowdhury, Adil Ahmed, Farida Chowdhury +3
Computer Science · Social Sciences · #Computer science #Computer security #Credential #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Internet privacy #One-time password #Password #Password policy #Privacy, Security, and Data Protection #User Authentication and Security Systems
paper · pdf · doi:10.48550/arxiv.2012.01765
openalex publication_date 2020/12/03 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
The Government of Bangladesh is aggressively transforming its public service\nlandscape by transforming public services into online services via a number of\nwebsites. The motivation is that this would be a catalyst for a transformative\nchange in every aspect of citizen life. Some web services must be protected\nfrom any unauthorised usages and passwords remain the most widely used\ncredential mechanism for this purpose. However, if passwords are not adopted\nproperly, they can be a cause for security breach. That is why it is important\nto study different aspects of password security on different websites. In this\npaper, we present a study of password security among 36 different Bangladeshi\ngovernment websites against six carefully chosen password security heuristics.\nThis study is the first of its kind in this domain and offers interesting\ninsights. For example, many websites have not adopted proper security measures\nwith respect to security. There is no password construction guideline adopted\nby many websites, thus creating a barrier for users to select a strong\npassword. Some of them allow supposedly weak passwords and still do not utilise\na secure HTTPS channel to transmit information over the Internet.\n