{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:06:12Z","timestamp":1783008372239,"version":"3.54.5"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030808242","type":"print"},{"value":"9783030808259","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-80825-9_1","type":"book-chapter","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T23:38:40Z","timestamp":1625787520000},"page":"1-20","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["You\u2019ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures"],"prefix":"10.1007","author":[{"given":"Tommaso","family":"Innocenti","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Seyed Ali","family":"Mirheidari","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amin","family":"Kharraz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bruno","family":"Crispo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,7,9]]},"reference":[{"key":"1_CR1","doi-asserted-by":"crossref","unstructured":"Al Maqbali, F., Mitchell, C.J.: Email-based password recovery-risking or rescuing users? In: 2018 International Carnahan Conference on Security Technology (ICCST), pp. 1\u20135. IEEE (2018)","DOI":"10.1109\/CCST.2018.8585576"},{"key":"1_CR2","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"324","DOI":"10.1007\/978-3-030-02683-7_23","volume-title":"Proceedings of the Future Technologies Conference (FTC) 2018","author":"FA Maqbali","year":"2019","unstructured":"Maqbali, F.A., Mitchell, C.J.: Web password recovery: a necessary evil? In: Arai, K., Bhatia, R., Kapoor, S. (eds.) FTC 2018. AISC, vol. 881, pp. 324\u2013341. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-02683-7_23"},{"key":"1_CR3","doi-asserted-by":"crossref","unstructured":"Bonneau, J., Bursztein, E., Caron, I., Jackson, R., Williamson, M.: Secrets, lies, and account recovery: lessons from the use of personal knowledge questions at google. In: Proceedings of the 24th International Conference on World Wide Web, pp. 141\u2013150 (2015)","DOI":"10.1145\/2736277.2741691"},{"key":"1_CR4","unstructured":"Bonneau, J., Preibusch, S.: The password thicket: technical and market failures in human authentication on the web. In: WEIS (2010)"},{"key":"1_CR5","doi-asserted-by":"crossref","unstructured":"Cao, Y., Chen, Z., Li, S., Wu, S.: Deterministic browser. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 163\u2013178 (2017)","DOI":"10.1145\/3133956.3133996"},{"key":"1_CR6","doi-asserted-by":"crossref","unstructured":"Chen, S., Wang, R., Wang, X., Zhang, K.: Side-channel leaks in web applications: a reality today, a challenge tomorrow. In: 2010 IEEE Symposium on Security and Privacy, pp. 191\u2013206. IEEE (2010)","DOI":"10.1109\/SP.2010.20"},{"key":"1_CR7","unstructured":"Conikee, C.: Case study: exploiting a business logic flaw with github\u2019s forgot password workflow, December 2019. https:\/\/medium.com\/@chetan_conikee\/case-study-exploiting-a-business-logic-flaw-with-githubs-forgot-password-workflow-discovered-d4d36ee3dd16"},{"key":"1_CR8","unstructured":"Corporation, T.M.: CWE-640: weak password recovery mechanism for forgotten password. https:\/\/cwe.mitre.org\/data\/definitions\/640.html"},{"key":"1_CR9","unstructured":"Disclose.io: Open-source tools to help hackers and organizations make the internet safer, together. https:\/\/disclose.io. Accessed 20 Feb 2021"},{"key":"1_CR10","doi-asserted-by":"crossref","unstructured":"Dmitrienko, A., Liebchen, C., Rossow, C., Sadeghi, A.R.: Security analysis of mobile two-factor authentication schemes. Intel Technol. J. 18(4) (2014)","DOI":"10.1007\/978-3-662-45472-5_24"},{"key":"1_CR11","unstructured":"Gracey, J.: Hacking github with unicode\u2019s dotless \u2018i\u2019, November 2019. https:\/\/eng.getwisdom.io\/hacking-github-with-unicode-dotless-i\/"},{"key":"1_CR12","doi-asserted-by":"crossref","unstructured":"Hanamsagar, A., Woo, S.S., Kanich, C., Mirkovic, J.: Leveraging semantic transformation to investigate password habits and their causes. In: Proceedings of the 2018 CHI Conference on Human Factors in Computing Systems, pp. 1\u201312 (2018)","DOI":"10.1145\/3173574.3174144"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Jakobsson, M., Stolterman, E., Wetzel, S., Yang, L.: Love and authentication. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 197\u2013200 (2008)","DOI":"10.1145\/1357054.1357087"},{"issue":"5","key":"1_CR14","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2004.80","volume":"2","author":"M Just","year":"2004","unstructured":"Just, M.: Designing and evaluating challenge-question systems. IEEE Secur. Priv. 2(5), 32\u201339 (2004)","journal-title":"IEEE Secur. Priv."},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Karlof, C., Tygar, J.D., Wagner, D.A.: Conditioned-safe ceremonies and a user study of an application to web authentication. In: NDSS (2009)","DOI":"10.1145\/1572532.1572578"},{"key":"1_CR16","unstructured":"Kettle, J.: Practical http host header attacks, May 2013. https:\/\/www.skeletonscribe.net\/2013\/05\/practical-http-host-header-attacks.html"},{"key":"1_CR17","unstructured":"Kettle, J.: Cracking the lens: targeting http\u2019s hidden attack-surface, July 2017. https:\/\/portswigger.net\/research\/cracking-the-lens-targeting-https-hidden-attack-surface"},{"key":"1_CR18","unstructured":"Kettle, J.: Collaborator everywhere, May 2018. https:\/\/github.com\/PortSwigger\/collaborator-everywhere"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Lei, Z., Nan, Y., Fratantonio, Y., Bianchi, A.: On the insecurity of SMS one-time password messages against local attackers in modern mobile devices. In: Proceedings of the 2021 Network and Distributed System Security (NDSS) Symposium (2021)","DOI":"10.14722\/ndss.2021.24212"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Li, Y., Wang, H., Sun, K.: Email as a master key: analyzing account recovery in the wild. In: IEEE INFOCOM 2018-IEEE Conference on Computer Communications, pp. 1646\u20131654. IEEE (2018)","DOI":"10.1109\/INFOCOM.2018.8486017"},{"key":"1_CR21","unstructured":"Lovisotto, G., Malik, R., Sluganovic, I., Roeschlin, M., Trueman, P., Martinovic, I.: Mobile biometrics in financial services: a five factor framework. University of Oxford, Oxford, UK (2017)"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Ma, S., et al.: An empirical study of SMS one-time password authentication in android apps. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp. 339\u2013354 (2019)","DOI":"10.1145\/3359789.3359828"},{"key":"1_CR23","unstructured":"Mirheidari, S.A., Arshad, S., Onarlioglu, K., Crispo, B., Kirda, E., Robertson, W.: Cached and confused: web cache deception in the wild. In: 29th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 2020), pp. 665\u2013682 (2020)"},{"key":"1_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/978-3-642-39235-1_9","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"C Mulliner","year":"2013","unstructured":"Mulliner, C., Borgaonkar, R., Stewin, P., Seifert, J.-P.: SMS-based one-time passwords: attacks and defense. In: Rieck, K., Stewin, P., Seifert, J.-P. (eds.) DIMVA 2013. LNCS, vol. 7967, pp. 150\u2013159. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-39235-1_9"},{"key":"1_CR25","unstructured":"Oesch, S., Ruoti, S.: That was then, this is now: a security evaluation of password generation, storage, and autofill in browser-based password managers. In: USENIX Security Symposium (2020)"},{"key":"1_CR26","unstructured":"OWASP: Forgot password cheat sheet. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/ForgotPasswordCheatSheet.html"},{"key":"1_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/978-3-642-17197-0_13","volume-title":"Decision and Game Theory for Security","author":"S Preibusch","year":"2010","unstructured":"Preibusch, S., Bonneau, J.: The password game: negative externalities from weak password practices. In: Alpcan, T., Butty\u00e1n, L., Baras, J.S. (eds.) GameSec 2010. LNCS, vol. 6442, pp. 192\u2013207. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-17197-0_13"},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"Rabkin, A.: Personal knowledge questions for fallback authentication: security questions in the era of Facebook. In: Proceedings of the 4th Symposium on Usable Privacy and Security, pp. 13\u201323 (2008)","DOI":"10.1145\/1408664.1408667"},{"key":"1_CR29","doi-asserted-by":"publisher","first-page":"52075","DOI":"10.1109\/ACCESS.2020.2981207","volume":"8","author":"S Raponi","year":"2020","unstructured":"Raponi, S., Di Pietro, R.: A longitudinal study on web-sites password management (in) security: evidence and remedies. IEEE Access 8, 52075\u201352090 (2020)","journal-title":"IEEE Access"},{"key":"1_CR30","doi-asserted-by":"crossref","unstructured":"Schechter, S., Brush, A.B., Egelman, S.: It\u2019s no secret. Measuring the security and reliability of authentication via \u201csecret\u201d questions. In: 2009 30th IEEE Symposium on Security and Privacy, pp. 375\u2013390. IEEE (2009)","DOI":"10.1109\/SP.2009.11"},{"key":"1_CR31","doi-asserted-by":"crossref","unstructured":"Stock, B., Pellegrino, G., Li, F., Backes, M., Rossow, C.: Didn\u2019t you hear me? - Towards more successful web vulnerability notifications. In: Proceedings of the 2018 Network and Distributed System Security (NDSS) Symposium (2018)","DOI":"10.14722\/ndss.2018.23171"},{"key":"1_CR32","unstructured":"Stock, B., Pellegrino, G., Rossow, C., Johns, M., Backes, M.: Hey, you have a problem: on the feasibility of large-scale web vulnerability notification. In: 25th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 2016), pp. 1015\u20131032 (2016)"},{"issue":"10","key":"1_CR33","doi-asserted-by":"publisher","first-page":"3289","DOI":"10.1007\/s11042-014-1888-3","volume":"74","author":"C Yoo","year":"2015","unstructured":"Yoo, C., Kang, B.T., Kim, H.K.: Case study of the vulnerability of OTP implemented in internet banking systems of South Korea. Multimedia Tools Appl. 74(10), 3289\u20133303 (2015)","journal-title":"Multimedia Tools Appl."},{"key":"1_CR34","doi-asserted-by":"publisher","unstructured":"Zhang, Y., Gao, H., Pei, G., Luo, S., Chang, G., Cheng, N.: A survey of research on captcha designing and breaking techniques. In: 2019 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/13th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE), pp. 75\u201384 (2019). https:\/\/doi.org\/10.1109\/TrustCom\/BigDataSE.2019.00020","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00020"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-80825-9_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,5]],"date-time":"2021-08-05T09:07:21Z","timestamp":1628154441000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-80825-9_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030808242","9783030808259"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-80825-9_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"9 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2021.campus.ciencias.ulisboa.pt\/cfp.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"65","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}