YoVDO

Protecting Accounts from Credential Stuffing with Password Breach Alerting

Offered By: USENIX via YouTube

Tags

USENIX Security Courses Cybersecurity Courses Cloud Services Courses Password Security Courses Protocol Design Courses Chrome Extensions Courses Credential Stuffing Courses

Course Description

Overview

Explore a Distinguished Paper Award-winning conference talk from USENIX Security '19 that delves into a privacy-preserving protocol for protecting accounts from credential stuffing attacks. Learn about the asymmetry of knowledge between attackers and users, and discover how a centralized breach repository can be queried without compromising sensitive information. Examine the implementation of a cloud service accessing over 4 billion breached credentials and a Chrome extension client. Analyze findings from anonymous telemetry involving 670,000 users and 21 million logins, revealing that 1.5% of web logins use breached credentials. Understand the impact of breach alerts on user behavior, with 26% of warnings resulting in password changes. Explore the ethical considerations, principles, and challenges in designing this protocol, including private set intersection and denial of service prevention. Gain insights into Google's strategy, password security state, and the prevalence of credential stuffing threats across the internet.

Syllabus

Introduction
Motivation
Challenge
Research
Googles strategy
Asymmetry of knowledge
Ethics
Principles
User retention
Most predominant threat
How we designed this protocol
Proof of work
Private 10 intersection
Challenges
Private Center
Denial of Service
Data Source
How we do this
Password Checkup
Breach Response
Warning
Chrome Web Store
Anonymous telemetry
In practice
State of password security
Where is this threat most prominent
The long tail of the Internet
Password strength


Taught by

USENIX

Related Courses

Application Analysis with ModSecurity
Pluralsight
PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse - 2024
IEEE via YouTube
A Cure for Botnets? Fighting Credential Stuffing at Adobe
DefCamp via YouTube
Securing Third Party Applications at Scale - AppSecCali 2019
OWASP Foundation via YouTube
Blue Team Fundamentals
Security BSides San Francisco via YouTube