Главная
Study mode:
on
1
Intro
2
Verizon Wireless: Password Requirements
3
Password Policy: Frozen in 1979
4
Inconsistent Requirements
5
Inconsistent Feedback Input: correcthorsebatterystaple
6
Threat Model
7
Core estimator: minimum rank over top lists Input wheeler
8
Word transformations
9
Keyboard patterns
10
Sequence Patterns
11
Outline for today
12
Gold standard: PGS
13
Training data
14
Test data
15
Estimator size?
16
Minimum rank only?
17
Runtime Performance
18
Conclusion
19
Give it a try!
20
Proposal: keep UI simple
Description:
Explore a groundbreaking approach to password strength estimation in this 32-minute USENIX Security '16 conference talk. Delve into the limitations of traditional LUDS-based password requirements and discover zxcvbn, a more effective and user-friendly alternative. Learn how this small, fast, and easily adoptable estimator accurately predicts password strength using leaked password data and modern guessing attacks. Understand the technical aspects of zxcvbn's implementation, including its compressed storage capabilities, cross-platform compatibility, and millisecond-level performance. Gain insights into the estimator's effectiveness in mitigating online attacks and its potential to revolutionize password security practices across various platforms.

zxcvbn - Low-Budget Password Strength Estimation

USENIX
Add to list