For this #ThrowbackThursday, we will look at #ACSAC2024's Passwords and Authentication session. The links in this thread will lead you to the paper pdfs and the slide decks, so be sure to check them out! 1/6
Opening the session was Fu & Wang's "Leaky Autofill: An Empirical Study on the #PrivacyThreat of #PasswordManager Autofill Functionality," revealing key privacy risks in PM autofill. (https://www.acsac.org/2024/program/final/s438.html) 2/6
#Cybersecurity #Authentication
Second up was Huaman et al.'s "Passwords To-Go: Investigating Multifaceted Challenges for Password Managers in the Android Ecosystem" highlighting challenges in using APIs for better security & usability. (https://www.acsac.org/2024/program/final/s443.html) 3/6
#PasswordManager #MobileSecurity
Then followed Westers et al.'s "Single Sign-On Privacy: We Still Know What You Did Last Summer", exposing critical #SSO #privacy leaks and introducing a robust Chrome extension to combat them. (https://www.acsac.org/2024/program/final/s318.html) 4/6
#Cybersecurity #IdentityProviders #InternetSecurity
Following that was Fang et al.'s "FreeAuth: #Privacy Preserving Email Ownership Authentication with Verification-Email-Free", presenting a novel scheme to authenticate email ownership without conventional verification emails. (https://www.acsac.org/2024/program/final/s465.html) 5/6
#EmailSecurity #Phishing
Ending the session, we saw Ferens et al.'s "Securing PUFs via a Predictive Adversarial ML System by Modeling of Attackers" highlighting advances in defending #IoT devices against ML-based #PUF attacks. (https://www.acsac.org/2024/program/final/s179.html) 6/6
#Cybersecurity #MLSecurity