Increasing real-world security of user IDs and passwords

Larry Holt · 2011

While there are many highly secure authentication systems, the user ID and password credential pair remains the most commonly used means of authentication even though it is one of the easiest to break. It is vulnerable to technical and social attacks but proper application of people, process and technical controls in the selection, use and monitoring of passwords can decrease the likelihood of compromise. This paper investigates the technical and social uses, weaknesses, vulnerabilities, attacks and defenses of the user ID and password combination. This reviews existing technology, use and attacks of user IDs and passwords; it will consider what can be done as well as suggest what should be done. Academic research and industry practice are addressed.

Read the paper · More papers on PaperTik