DocumentCode :
168981
Title :
Do you think your passwords are secure?
Author :
Ziegler, Dominik ; Rauter, Mattias ; Stromberger, Christof ; Teufl, Peter ; Hein, Daniel
Author_Institution :
Inst. for Appl. Inf. Process. & Commun., Graz Univ. of Technol., Graz, Austria
fYear :
2014
fDate :
11-14 May 2014
Firstpage :
1
Lastpage :
8
Abstract :
Many systems rely on passwords for authentication. Due to numerous accounts for different services, users have to choose and remember a significant number of passwords. Password-Manager applications address this issue by storing the user´s passwords. They are especially useful on mobile devices, because of the ubiquitous access to the account passwords. Password-Managers often use key derivation functions to convert a master password into a cryptographic key suitable for encrypting the list of passwords, thus protecting the passwords against unauthorized, off-line access. Therefore, design and implementation flaws in the key derivation function impact password security significantly. Design and implementation problems in the key derivation function can render the encryption on the password list useless, by for example allowing efficient bruteforce attacks, or - even worse - direct decryption of the stored passwords. In this paper, we analyze the key derivation functions of popular Android Password-Managers with often startling results. With this analysis, we want to raise the awareness of developers of security critical apps for security, and provide an overview about the current state of implementation security of security-critical applications.
Keywords :
authorisation; cryptography; message authentication; ubiquitous computing; Android password-manager; authentication; bruteforce attack; cryptographic key; direct decryption; encryption; key derivation function; mobile device; password security; security-critical application; ubiquitous access; Androids; Databases; Encryption; Humanoid robots; Usability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy and Security in Mobile Systems (PRISMS), 2014 International Conference on
Conference_Location :
Aalborg
Print_ISBN :
978-1-4799-4630-3
Type :
conf
DOI :
10.1109/PRISMS.2014.6970600
Filename :
6970600
Link To Document :
بازگشت