University of Minnesota
Security and Privacy in Computing
index.php
CSci 8271 readings on user authentication

Readings on: user authentication (including passwords)

Candidate main reading: Tara Whalen, Thibault Meunier, Mrudula Kodali, Alex Davidson, Marwan Fayed, Armando Faz-Hernández, Watson Ladd, Deepak Maram, Nick Sullivan, Benedikt Christoph Wolters, Maxime Guerreiro, and Andrew Galloni. “Let The Right One In: Attestation as a Usable CAPTCHA Alternative”. In Symposium on Usable Privacy and Security, August 2022.
[USENIX]

Main reading for Tuesday, January 30th: Kevin Lee, Sten Sjöberg, and Arvind Narayanan. “Password policies of most top websites fail to follow best practices”. In Symposium on Usable Privacy and Security, August 2022.
[USENIX]

Candidate main reading: Eva Gerlitz, Maximilian Häring, Charlotte Theresa Mädler, Matthew Smith, and Christian Tiefenau. “Adventures in Recovery Land: Testing the Account Recovery of Popular Websites When the Second Factor is Lost”. In Symposium on Usable Privacy and Security, August 2023.
[USENIX]

Candidate main reading: Ding Wang, Yunkai Zou, Yuan-An Xiao, Siqi Ma, and Xiaofeng Chen. “Pass2Edit: A Multi-Step Generative Model for Guessing Edited Passwords”. In USENIX Security Symposium, August 2023.
[USENIX]

Main reading for Thursday, February 1st: Ding Wang, Yunkai Zou, Zijian Zhang, and Kedong Xiu. “Password Guessing Using Random Forest”. In USENIX Security Symposium, August 2023.
[USENIX]

Candidate main reading: Fangyi Yu and Miguel Vargas Martin. “Honey, I Chunked the Passwords: Generating Semantic Honeywords Resistant to Targeted Attacks Using Pre-trained Language Models”. In Detection of Intrusions and Malware, and Vulnerability Assessment, July 2023.
[Springer]