A Longitudinal Study on Web-sites Password Management (in)Security: Evidence and Remedies
Simone Raponi, Roberto Di Pietro

TL;DR
This study analyzes the security flaws in online password recovery systems of popular websites, highlighting poor practices and proposing an open-source module to enhance user protection against mail service provider attacks.
Contribution
It provides an updated analysis of top websites' password recovery mechanisms, revises attacker models, and introduces extsc{sol}, a practical open-source solution for improved security.
Findings
Many websites lack GDPR compliance in password management.
Current recovery mechanisms are vulnerable to mail service provider attacks.
The proposed extsc{sol} module can be adopted broadly to improve security.
Abstract
Single-factor password-based authentication is generally the norm to access on-line Web-sites. While single-factor authentication is well known to be a weak form of authentication, a further concern arises when considering the possibility for an attacker to recover the user passwords by leveraging the loopholes in the password recovery mechanisms. Indeed, the adoption by a Web-site of a poor password management system makes useless even the most robust password chosen by the registered users. In this paper, building on the results of our previous work, we study the possible attacks to on-line password recovery systems analyzing the mechanisms implemented by some of the most popular Web-sites. In detail, we provide several contributions: (i) we revise and detail the attacker model; (ii) we provide an updated analysis with respect to a preliminary study we carried out in December 2017;…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
