Passwords and the Evolution of Imperfect Authentication.

The article emphasizes the need to critically revisit authentication as a whole and the password's role therein to understand the current situation in computer security. Topics discussed include the simplistic models of user and attacker behaviors that have led researchers to emphasize on the wrong...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 58; no. 7; pp. 78 - 88
Autores principales: BONNEAU, JOSEPH, HERLEY, CORMAC, VAN OORSCHOT, PAUL C., STAJANO, FRANK
Formato: Artículo
Publicado: Association for Computing Machinery Jul2015
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=103441792&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 103441792
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Jul2015
      vid: 58
      iid: 7
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        103441792
        10.1145/2699390
      ppf: 78
      ppct: 10
      formats:
      tig:
        atl: Passwords and the Evolution of Imperfect Authentication.
      aug:
        au:
          BONNEAU, JOSEPH
          HERLEY, CORMAC
          VAN OORSCHOT, PAUL C.
          STAJANO, FRANK
        affil:
          Postdoctoral research fellow, Stanford University, Stanford, CA
          Technology fellow, Electronic Frontier Foundation, San Francisco, CA
          Principal researcher, Microsoft Research, Redmond, WA
          Professor of computer science and Canada Research Chair in Authentication and Computer Security, School of Computer Science, Carleton University, Ottawa, Ontario, Canada
          Reader in Security and Privacy, University of Cambridge, Cambridge, U.K.
          Head, Academic Centre of Excellence in Cyber Security Research, University of Cambridge, Cambridge, U.K.
          Fellow of Trinity College, University of Cambridge, Cambridge, U.K.
      su:
        Computer access control
        Computer passwords
        Electronic authentication
        Computer security
        Computer science
        Machine learning
      sug:
        subj:
          Computer access control
          Computer passwords
          Electronic authentication
          Computer security
          Computer science
          Machine learning
      ab: The article emphasizes the need to critically revisit authentication as a whole and the password's role therein to understand the current situation in computer security. Topics discussed include the simplistic models of user and attacker behaviors that have led researchers to emphasize on the wrong threats, authentication as a classification problem amenable to machine learning, and the continued use of passwords to reduce harm at acceptable cost. Also mentioned are the history of passwords, two outdated models that underlie much of the current password literature, and the need to protect user accounts and sensitive data.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2015
    holdings:
      @attributes:
        islocal: N