2018/01/20 by Fatma Al Maqbali, Chris J Mitchell, Maqbali, Fatma Al +1
Computer Science · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #cs.CR
paper · pdf · doi:10.48550/arxiv.1801.06730
v2. Revised version
arxiv created 2018/01/30 · arxiv updated 2018/01/31
Web password recovery, enabling a user who forgets their password to re-establish a shared secret with a website, is very widely implemented. However, use of such a fall-back system brings with it additional vulnerabilities to user authentication. This paper provides a framework within which such systems can be analysed systematically, and uses this to help gain a better understanding of how such systems are best implemented. To this end, a model for web password recovery is given, and existing techniques are documented and analysed within the context of this model. This leads naturally to a set of recommendations governing how such systems should be implemented to maximise security. A range of issues for further research are also highlighted.