A Survey of Alerting Websites: Risks and Solutions - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2015

A Survey of Alerting Websites: Risks and Solutions

Résumé

In the recent years an incredible amount of data has been leaked from major websites such as Adobe, Snapchat and LinkedIn. There are hundreds of millions of usernames, email addresses, passwords, telephone numbers and credit card details in the wild. The aftermath of these breaches is the rise of alerting websites such as haveibeenpwned.com, which let users verify if their accounts have been compromised. Unfortunately, these seemingly innocuous websites can be easily turned into phishing tools. In this work, we provide a comprehensive study of the most popular ones. Our study exposes the associated privacy risks and evaluates existing solutions towards designing privacy-friendly alerting websites. In particular, we study three solutions: private set intersection, private set intersection cardinality and private information retrieval adapted to membership testing. Finally, we investigate the practicality of these solutions with respect to real world database leakages.
Fichier principal
Vignette du fichier
ifipsec15.pdf (341.77 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01199703 , version 1 (15-09-2015)

Identifiants

Citer

Amrit Kumar, Cédric Lauradoux. A Survey of Alerting Websites: Risks and Solutions. IFIP SEC, May 2015, Hamburg, Germany. pp.126-141, ⟨10.1007/978-3-319-18467-8_9⟩. ⟨hal-01199703⟩
208 Consultations
309 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More