• DocumentCode
    168981
  • Title

    Do you think your passwords are secure?

  • Author

    Ziegler, Dominik ; Rauter, Mattias ; Stromberger, Christof ; Teufl, Peter ; Hein, Daniel

  • Author_Institution
    Inst. for Appl. Inf. Process. & Commun., Graz Univ. of Technol., Graz, Austria
  • fYear
    2014
  • fDate
    11-14 May 2014
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Many systems rely on passwords for authentication. Due to numerous accounts for different services, users have to choose and remember a significant number of passwords. Password-Manager applications address this issue by storing the user´s passwords. They are especially useful on mobile devices, because of the ubiquitous access to the account passwords. Password-Managers often use key derivation functions to convert a master password into a cryptographic key suitable for encrypting the list of passwords, thus protecting the passwords against unauthorized, off-line access. Therefore, design and implementation flaws in the key derivation function impact password security significantly. Design and implementation problems in the key derivation function can render the encryption on the password list useless, by for example allowing efficient bruteforce attacks, or - even worse - direct decryption of the stored passwords. In this paper, we analyze the key derivation functions of popular Android Password-Managers with often startling results. With this analysis, we want to raise the awareness of developers of security critical apps for security, and provide an overview about the current state of implementation security of security-critical applications.
  • Keywords
    authorisation; cryptography; message authentication; ubiquitous computing; Android password-manager; authentication; bruteforce attack; cryptographic key; direct decryption; encryption; key derivation function; mobile device; password security; security-critical application; ubiquitous access; Androids; Databases; Encryption; Humanoid robots; Usability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Privacy and Security in Mobile Systems (PRISMS), 2014 International Conference on
  • Conference_Location
    Aalborg
  • Print_ISBN
    978-1-4799-4630-3
  • Type

    conf

  • DOI
    10.1109/PRISMS.2014.6970600
  • Filename
    6970600