A Longitudinal Study on Web-sites Password Management (in)Security: Evidence and Remedies

Single-factor password-based authentication is generally the norm to access\non-line Web-sites. While single-factor authentication is well known to be a\nweak form of authentication, a further concern arises when considering the\npossibility for an attacker to recover the user passwords by leveraging the\nloopholes in the password recovery mechanisms. Indeed, the adoption by a\nWeb-site of a poor password management system makes useless even the most\nrobust password chosen by the registered users. In this paper, building on the\nresults of our previous work, we study the possible attacks to on-line password\nrecovery systems analyzing the mechanisms implemented by some of the most\npopular Web-sites. In detail, we provide several contributions: (i) we revise\nand detail the attacker model; (ii) we provide an updated analysis with respect\nto a preliminary study we carried out in December 2017; (iii) we perform a\nbrand new analysis of the current top 200 Alexa's Web-sites of five major EU\ncountries; and, (iv) we propose \\sol, a working open-source module that could\nbe adopted by any Web-site to provide registered users with a password recovery\nmechanism to prevent mail service provider-level attacks. Overall, it is\nstriking to notice how the analyzed Web-sites have made little (if any) effort\nto become compliant with the GDPR regulation, showing that the objective to\nhave basic user protection mechanisms in place---despite the fines threatened\nby GDPR---is still far, mainly because of sub-standard security management\npractices. Finally, it is worth noting that while this study has been focused\non EU registered Web-sites, the proposed solution has, instead, general\napplicability.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC