2016/08/04 by Mordechai Guri, Eyal Shemer, Guri, Mordechai +5
Computer Science · Social Sciences · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Privacy, Security, and Data Protection #User Authentication and Security Systems #cs.CR
paper · pdf · doi:10.48550/arxiv.1608.01492
arxiv created 2016/08/04 · openalex publication_date 2016/08/04 · arxiv updated 2016/08/05 · openalex created_date 2022/10/01 · openalex updated_date 2026/07/28
In this paper we examine the standard password recovery process of large Internet services such as Gmail, Facebook, and Twitter. Although most of these services try to maintain user privacy, with regard to registration information and other personal information provided by the user, we demonstrate that personal information can still be obtained by unauthorized individuals or attackers. This information includes the full (or partial) email address, phone number, friends list, address, etc. We examine different scenarios and demonstrate how the details revealed in the password recovery process can be used to deduct more focused information about users.