PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 4, 200718 citations

Evaluating a trial deployment of password re-use for phishing prevention

View Full Paper
DFDinei FlorêncioCHCormac Herley

Key Points

Key points are not available for this paper at this time.

Abstract

We propose a scheme that exploits scale to prevent phishing. We show that while stopping phishers from obtaining passwords is very hard, detecting the fact that a password has been entered at an unfamiliar site is simple. Our solution involves a client that reports Password Re-Use (PRU) events at unfamiliar sites, and a server that accumulates these reports and detects an attack. We show that it is simple to then mitigate the damage by communicating the identities of phished accounts to the institution under attack. Thus, we make no attempt to prevent information leakage, but we try to detect and then rescue users from the consequences of bad trust decisions.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Florêncio et al. (2007) studied this question.

synapsesocial.com/papers/6a1bef04ea84844e355f3112https://doi.org/10.1145/1299015.1299018
Ask AI
Helpful
Bookmark
Share
View Full Paper