All the latest UK technology news, reviews and analysis

Weak web account ID tools undermining security

by Dave Neal

09 Mar 2010

Comments: 2

  • Tweet this
Password page
Personal knowledge questions are often easy to guess

The security mechanisms used to protect online accounts are inherently flawed, according to a new paper by researchers at Cambridge and Edinburgh universities.

Joseph Bonneau, Mike Just and Greg Matthews argue in a paper entitled What's in a name? (PDF) that security questions used to verify an account can often be beaten by simple guesswork or through some personal knowledge of the account holder.

"Despite their ubiquity, personal knowledge questions have received relatively little attention from the security community until recently," the paper said.

"User studies have demonstrated the ability of friends, family and acquaintances to guess answers correctly, while other research has found that some questions used have a tiny set of possible answers.

"Many common questions have also been shown to have answers readily available in public databases or online social networks."

The researchers looked at the type of security questions asked using data from a range of online service providers, including banks and financial institutions, as well as webmail services such as Hotmail, Gmail and Yahoo Mail.

One in three asked for a person's name, and one in five asked for a place name. The researchers said that, when faced with these questions and given three guesses, an attacker can compromise roughly one in 80 accounts.

The use of names is unwise because it is possible to identify and focus on the most common names in any given location. The name Smith is popular in the Western world, for example, while Kim is very common in Korea.

"Given names are a matter of fashion and vary in several interesting dimensions. In the countries studied, female names seem to provide slightly higher resistance to guessing than male names," said the paper.

"The diversity of forenames has been increasing slowly but steadily over the past six decades in the US. Curiously, pet names are slightly harder to guess than human names."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

33%

1%

11%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Web Development Manager / Team Leader / PHP / MySQL

Development Manager / PHP Developer / MySQL / LAMP...

Process Expert for Information/Content Management

Process Expert for Information/Content Management...

SSIS Developer / Implementation Specialist

SQL Server / SSIS / ETL / T-SQL Data Migration A...

Linux Systems Administrator / Network Systems Admin

Linux Systems Administrator / Linux CentOS / Network...

To send to more than one email address, simply separate each address with a comma.