The Emperor is Now Clothed: A Secure Governance Framework for Web User Authentication through Password Managers
Ali Cherry, Konstantinos Barmpis, Siamak F. Shahandashti

TL;DR
This paper introduces Berytus, a browser-based governance framework that enhances web user authentication by securely mediating interactions between password managers and web applications, effectively mitigating common security threats.
Contribution
The paper presents Berytus, a novel browser-based API framework that improves security and functionality of password management and web authentication processes.
Findings
Berytus effectively mitigates phishing and XSS attacks.
The framework supports multi-factor and custom authentication schemes.
Implementation in Firefox demonstrates practical security improvements.
Abstract
Existing approaches to facilitate the interaction between password managers and web applications fall short of providing adequate functionality and mitigation strategies against prominent attacks. HTML Autofill is not sufficiently expressive, Credential Management API does not support browser extension password managers, and other proposed solutions do not conform to established user mental models. In this paper, we propose Berytus, a browser-based governance framework that mediates the interaction between password managers and web applications. Two APIs are designed to support Berytus acting as an orchestrator between password managers and web applications. An implementation of the framework in Firefox is developed that fully supports registration and authentication processes. As an orchestrator, Berytus is able to authenticate web applications and facilitate authenticated key exchange…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Privacy, Security, and Data Protection · Spam and Phishing Detection
