They would do better if they worked together: The case of interaction problems between password managers and websites

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Autoren

  • Nicolas Huaman
  • Sabrina Amft
  • Marten Oltrogge
  • Yasemin Acar
  • Sascha Fahl

Organisationseinheiten

Externe Organisationen

  • Helmholtz-Zentrum für Informationssicherheit (CISPA)
  • Max-Planck-Institut für Sicherheit und Privatsphäre
Forschungs-netzwerk anzeigen

Details

OriginalspracheEnglisch
Titel des SammelwerksProceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021
Herausgeber (Verlag)Institute of Electrical and Electronics Engineers Inc.
Seiten1367-1381
Seitenumfang15
ISBN (elektronisch)9781728189345
ISBN (Print)978-1-7281-8935-2
PublikationsstatusVeröffentlicht - Mai 2021
Veranstaltung42nd IEEE Symposium on Security and Privacy, SP 2021 - Virtual, San Francisco, USA / Vereinigte Staaten
Dauer: 24 Mai 202127 Mai 2021

Publikationsreihe

NameProceedings - IEEE Symposium on Security and Privacy
Band2021-May
ISSN (Print)1081-6011
ISSN (elektronisch)2375-1207

Abstract

Password managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2, 947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research.

ASJC Scopus Sachgebiete

Zitieren

They would do better if they worked together: The case of interaction problems between password managers and websites. / Huaman, Nicolas; Amft, Sabrina; Oltrogge, Marten et al.
Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021. Institute of Electrical and Electronics Engineers Inc., 2021. S. 1367-1381 (Proceedings - IEEE Symposium on Security and Privacy; Band 2021-May).

Publikation: Beitrag in Buch/Bericht/Sammelwerk/KonferenzbandAufsatz in KonferenzbandForschungPeer-Review

Huaman, N, Amft, S, Oltrogge, M, Acar, Y & Fahl, S 2021, They would do better if they worked together: The case of interaction problems between password managers and websites. in Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021. Proceedings - IEEE Symposium on Security and Privacy, Bd. 2021-May, Institute of Electrical and Electronics Engineers Inc., S. 1367-1381, 42nd IEEE Symposium on Security and Privacy, SP 2021, Virtual, San Francisco, USA / Vereinigte Staaten, 24 Mai 2021. https://doi.org/10.1109/SP40001.2021.00094
Huaman, N., Amft, S., Oltrogge, M., Acar, Y., & Fahl, S. (2021). They would do better if they worked together: The case of interaction problems between password managers and websites. In Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021 (S. 1367-1381). (Proceedings - IEEE Symposium on Security and Privacy; Band 2021-May). Institute of Electrical and Electronics Engineers Inc.. https://doi.org/10.1109/SP40001.2021.00094
Huaman N, Amft S, Oltrogge M, Acar Y, Fahl S. They would do better if they worked together: The case of interaction problems between password managers and websites. in Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021. Institute of Electrical and Electronics Engineers Inc. 2021. S. 1367-1381. (Proceedings - IEEE Symposium on Security and Privacy). doi: 10.1109/SP40001.2021.00094
Huaman, Nicolas ; Amft, Sabrina ; Oltrogge, Marten et al. / They would do better if they worked together : The case of interaction problems between password managers and websites. Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021. Institute of Electrical and Electronics Engineers Inc., 2021. S. 1367-1381 (Proceedings - IEEE Symposium on Security and Privacy).
Download
@inproceedings{a032653ae773410281adee45d07fb11e,
title = "They would do better if they worked together: The case of interaction problems between password managers and websites",
abstract = "Password managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2, 947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research.",
keywords = "Web-Security",
author = "Nicolas Huaman and Sabrina Amft and Marten Oltrogge and Yasemin Acar and Sascha Fahl",
year = "2021",
month = may,
doi = "10.1109/SP40001.2021.00094",
language = "English",
isbn = "978-1-7281-8935-2",
series = "Proceedings - IEEE Symposium on Security and Privacy",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
pages = "1367--1381",
booktitle = "Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021",
address = "United States",
note = "42nd IEEE Symposium on Security and Privacy, SP 2021 ; Conference date: 24-05-2021 Through 27-05-2021",

}

Download

TY - GEN

T1 - They would do better if they worked together

T2 - 42nd IEEE Symposium on Security and Privacy, SP 2021

AU - Huaman, Nicolas

AU - Amft, Sabrina

AU - Oltrogge, Marten

AU - Acar, Yasemin

AU - Fahl, Sascha

PY - 2021/5

Y1 - 2021/5

N2 - Password managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2, 947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research.

AB - Password managers are tools to support users with the secure generation and storage of credentials and logins used in online accounts. Previous work illustrated that building password managers means facing various security and usability challenges. For strong security and good usability, the interaction between password managers and websites needs to be smooth and effortless. However, user reviews for popular password managers suggest interaction problems for some websites. Therefore, to the best of our knowledge, this work is the first to systematically identify these interaction problems and investigate how 15 desktop password managers, including the ten most popular ones, are affected. We use a qualitative analysis approach to identify 39 interaction problems from 2, 947 user reviews and 372 GitHub issues for 30 password managers. Next, we implement minimal working examples (MWEs) for all interaction problems we found and evaluate them for all password managers in 585 test cases.Our results illustrate that a) password managers struggle to correctly implement authentication features such as HTTP Basic Authentication and modern standards such as the autocomplete-attribute and b) websites fail to implement clean and well-structured authentication forms. We conclude that some of our findings can be addressed by either PWM providers or web-developers by adhering to already existing standards, recommendations and best practices, while other cases are currently almost impossible to implement securely and require further research.

KW - Web-Security

UR - http://www.scopus.com/inward/record.url?scp=85115055467&partnerID=8YFLogxK

U2 - 10.1109/SP40001.2021.00094

DO - 10.1109/SP40001.2021.00094

M3 - Conference contribution

AN - SCOPUS:85115055467

SN - 978-1-7281-8935-2

T3 - Proceedings - IEEE Symposium on Security and Privacy

SP - 1367

EP - 1381

BT - Proceedings - 2021 IEEE Symposium on Security and Privacy, SP 2021

PB - Institute of Electrical and Electronics Engineers Inc.

Y2 - 24 May 2021 through 27 May 2021

ER -