05 Stephan Wiefling - On the Security and Privacy of Risk-based Authentication
Автор: Per Thorsheim
Загружено: 2021-11-23
Просмотров: 317
Описание:
Risk-based Authentication (RBA) is recommended by NIST (USA) and NCSC (UK) to strengthen password-based authentication against attacks involving stolen passwords, like credential stuffing or password spraying. Large online services already deployed RBA to protect their user base (1). Beyond that, users find RBA more usable than 2FA, and equally secure (2).
But what about its usability, security, and privacy in practice? We studied RBA on a real-world online service for almost two years to find out more. And yes, we can create a strong, usable, and still more privacy-friendly RBA that complies with the GDPR and CCPA.
Website: https://riskbasedauthentication.org
(1) Talk from PasswordsCon 2019: • 06 - Stephan Wiefling - Is This Really You...
(2) Talk from PasswordsCon 2020: • 02 - Stephan Wiefling - On The Usability O...
----
Stephan Wiefling is a PhD student in Sankt Augustin, Germany (Data- and Application Security Group, H-BRS). His current research spans areas of Authentication and Usability.
Twitter: @SWiefling
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: