Password Managers: Comparative Evaluation, Design, Implementation and Empirical Analysis

Daniel McCarney · 2013

Passwords continue to prevail on the web as the primary method for user authentication, despite well-known security and usability drawbacks.Password managers are known to offer some improvement without the deployment barrier of server-side changes.This thesis examines password managers to alleviate some of the security and usability deficits of password authentication, while retaining the deployability advantages of passwords In order to provide more fine-grained comparative evaluation of password managers, we extend the Usability-Deployability-Security (UDS) framework of Bonneau et al. (IEEE Symposium on Security and Privacy, 2012), by adding additional evaluation properties which allow differentiation of password managers by important characteristics not measured by the more general UDS.We introduce and evaluate the security of dual-possession authentication, an authentication approach offering encrypted storage of passwords and theft-resistance without the use of a master password.We further introduce Tapas as a concrete implementation of dual-possession authentication leveraging a desktop computer and a smartphone.Tapas requires no server-side changes to websites, no master password, and protects all the stored passwords in the event either the primary or secondary device (e.g., computer or phone) is stolen.To empirically evaluate the viability of Tapas as an alternative to traditional password managers, we perform a 30 participant user study comparing Tapas to two configurations of Firefox's built-in password manager.We found users significantly preferred Tapas.We then improve Tapas by incorporating feedback from this study, and reevaluate it with an additional 10 participants.

Read the paper · More papers on PaperTik