Panic passwords: authenticating under duress
Jeremy Edmund Clark, Urs Hengartner · 2008
Panic passwords allow a user to signal duress during authentication. We show that the well-known model of giving a user two passwords, a ‘regular ’ and a ‘panic ’ password, is susceptible to iteration and forced-randomization attacks, and is secure only within a very narrow threat model. We expand this threat model significantly, making explicit assumptions and tracking four parameters. We also introduce several new panic password systems to address new categories of scenarios. 1. INTRODUCTORY REMARKS As important services and sensitive data congregate online, attackers have an increasing incentive to obtain the passwords that protect these services and data. Panic passwords are a mechanism to allow a user to use a special type