We introduce Kamouflage: a new architecture for building theft-resistant password managers. An attacker who steals a laptop or cell phone with a Kamouflage-based password manager is forced to carry out a considerable amount of online work before obtaining any user credentials. We implemented our proposal as a replacement for the built-in Firefox password manager, and provide performance measurements and the results of user studies to evaluate the effectiveness of our approach. We expect Kamouflage to become the standard architecture for password managers on mobile devices.
Kamouflage loss-resistant password management
Available Media | Publication (Pdf) Slides (pdf) |
Conference | European Symposium On Research In Computer Security (ESORICS) - 2010 |
Authors | Hristo Bojinov , Elie Bursztein , Dan Boneh , |
Citation |