Authors
Frank Stajano, Max Spencer, Graeme Jenkinson, Quentin Stafford-Fraser
Publication date
2015
Conference
Technology and Practice of Passwords: International Conference on Passwords, PASSWORDS'14, Trondheim, Norway, December 8-10, 2014, Revised Selected Papers 7
Pages
61-73
Publisher
Springer International Publishing
Description
Subtle and sometimes baffling variations in the implementation of password-based authentication are widespread on the web. Despite being imperceptible to end users, such variations often require that password managers implement complex heuristics in order to act on the user’s behalf. These heuristics are inherently brittle. As a result, password managers are unnecessarily complex and yet they still occasionally fail to work properly on some websites. In this paper we propose PMF, a specification of simple semantic labels for password-related web forms. These semantic labels allow a software agent such as a password manager to extract meaning, such as which site the login form is for and what field in the form corresponds to the username. Our spec also allows the agent to generate a strong password on the user’s behalf. PMF reduces a password manager’s dependency on complex heuristics …
Total citations
20152016201720182019202020212022202320242531122332
Scholar articles
F Stajano, M Spencer, G Jenkinson, Q Stafford-Fraser - Technology and Practice of Passwords: International …, 2015