{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T04:53:46Z","timestamp":1755838426369,"version":"3.41.0"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319175324"},{"type":"electronic","value":"9783319175331"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-17533-1_18","type":"book-chapter","created":{"date-parts":[[2015,4,8]],"date-time":"2015-04-08T12:50:20Z","timestamp":1428497420000},"page":"253-267","source":"Crossref","is-referenced-by-count":9,"title":["Half a Century of Practice: Who Is Still Storing Plaintext Passwords?"],"prefix":"10.1007","author":[{"given":"Erick","family":"Bauman","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yafeng","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"18_CR1","unstructured":"Easychair home page, http:\/\/www.easychair.org\/"},{"key":"18_CR2","unstructured":"Edas, https:\/\/www.edas.info\/index.php"},{"key":"18_CR3","unstructured":"Hotcrp begin work on safe password storage, https:\/\/github.com\/kohler\/hotcrp\/commit\/127613bfbee196c06b6e799bbc4705b7be37cc06"},{"key":"18_CR4","unstructured":"Microsoft\u2019s conference management toolkit, https:\/\/cmt.research.microsoft.com\/"},{"key":"18_CR5","unstructured":"Plain text offenders, http:\/\/plaintextoffenders.com\/"},{"key":"18_CR6","unstructured":"Security - keepass, http:\/\/keepass.info\/help\/base\/security.html"},{"key":"18_CR7","unstructured":"Softconf start v2 conferencemanager, http:\/\/www.softconf.com\/"},{"key":"18_CR8","unstructured":"uclassify, http:\/\/www.uclassify.com\/"},{"key":"18_CR9","unstructured":"Hackers released the passwords of over 70 million chinese internet accounts (2011), https:\/\/dazzlepod.com\/rootkit\/"},{"key":"18_CR10","unstructured":"Ieee data breach: 100k passwords leak in plain text (2011), http:\/\/www.neowin.net\/news\/ieee-data-breach-100k-passwords-leak-in-plain-text"},{"key":"18_CR11","unstructured":"rootkit.com cleartext passwords (2011), https:\/\/dazzlepod.com\/rootkit\/"},{"key":"18_CR12","unstructured":"Linkedin password hack: Check to see if yours was one of the 6.5 million leaked (2012), http:\/\/www.huffingtonpost.com\/2012\/06\/07\/linkedin-password-hack-check_n_1577184.html"},{"key":"18_CR13","unstructured":"Militarysingles.com hack exposes over 160,000 users information (2012), http:\/\/www.databreaches.net\/militarysingles-com-hack-exposes-over-160000-users-information\/"},{"key":"18_CR14","unstructured":"Yahoo hack leaks 453,000 voice passwords. http:\/\/www.darkreading.com\/attacks-and-breaches\/yahoo-hack-leaks-453000-voice-passwords\/d\/d-id\/1105289? , 2012."},{"key":"18_CR15","unstructured":"Youporn passwords available for download, thousands of users exposed (2012), http:\/\/nakedsecurity.sophos.com\/2012\/02\/22\/youporn-password-download\/"},{"issue":"12","key":"18_CR16","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/322796.322806","volume":"42","author":"A. Adams","year":"1999","unstructured":"Adams, A., Sasse, M.A.: Users are not the enemy. Commun. ACM\u00a042(12), 40\u201346 (1999)","journal-title":"Commun. ACM"},{"key":"18_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"286","DOI":"10.1007\/978-3-642-15497-3_18","volume-title":"Computer Security \u2013 ESORICS 2010","author":"H. Bojinov","year":"2010","unstructured":"Bojinov, H., Bursztein, E., Boyen, X., Boneh, D.: Kamouflage: Loss-resistant password management. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol.\u00a06345, pp. 286\u2013302. Springer, Heidelberg (2010)"},{"key":"18_CR18","first-page":"553","volume-title":"SP 2012","author":"J. Bonneau","year":"2012","unstructured":"Bonneau, J., Herley, C., Oorschot, P.C.V., Stajano, F.: v. Oorschot, and F.\u00a0Stajano. The quest to replace passwords: A framework for comparative evaluation of web authentication schemes. In: SP 2012, pp. 553\u2013567. IEEE Computer Society, Washington, DC (2012)"},{"key":"18_CR19","unstructured":"Bonneau, J., Preibusch, S.: The password thicket: Technical and market failures in human authentication on the web. In: WEIS (2010)"},{"key":"18_CR20","unstructured":"Calin, B.: Statistics from 10,000 leaked hotmail passwords (2009), http:\/\/www.acunetix.com\/blog\/news\/statistics-from-10000-leaked-hotmail-passwords\/"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Das, A., Bonneau, J., Caesar, M., Borisov, N., Wang, X.: The Tangled Web of Password Reuse. In: NDSS (February 2014)","DOI":"10.14722\/ndss.2014.23357"},{"key":"18_CR22","first-page":"983","volume-title":"INFOCOM 2010","author":"M. Dell\u2019Amico","year":"2010","unstructured":"Dell\u2019Amico, M., Michiardi, P., Roudier, Y.: Password strength: An empirical analysis. In: INFOCOM 2010, pp. 983\u2013991. IEEE Press, Piscataway (2010)"},{"key":"18_CR23","first-page":"657","volume-title":"WWW 2007","author":"D. Florencio","year":"2007","unstructured":"Florencio, D., Herley, C.: A large-scale study of web password habits. In: WWW 2007, pp. 657\u2013666. ACM, New York (2007)"},{"key":"18_CR24","first-page":"44","volume-title":"SOUPS 2006","author":"S. Gaw","year":"2006","unstructured":"Gaw, S., Felten, E.W.: Password management strategies for online accounts. In: SOUPS 2006, pp. 44\u201355. ACM, New York (2006)"},{"key":"18_CR25","unstructured":"Grimes, R.A.: Myspace password exploit: Crunching the numbers"},{"key":"18_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1007\/978-3-642-12368-9_17","volume-title":"Information Security Theory and Practices. Security and Privacy of Pervasive Systems and Smart Devices","author":"J. Hart","year":"2010","unstructured":"Hart, J., Markantonakis, K., Mayes, K.: Website credential storage and two-factor web authentication with a java SIM. In: Samarati, P., Tunstall, M., Posegga, J., Markantonakis, K., Sauveron, D. (eds.) WISTP 2010. LNCS, vol.\u00a06033, pp. 229\u2013236. Springer, Heidelberg (2010)"},{"key":"18_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-04444-1_1","volume-title":"Computer Security \u2013 ESORICS 2009","author":"T. Holz","year":"2009","unstructured":"Holz, T., Engelberth, M., Freiling, F.: Learning more about the underground economy: A case-study of keyloggers and dropzones. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol.\u00a05789, pp. 1\u201318. Springer, Heidelberg (2009)"},{"issue":"4","key":"18_CR28","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/975817.975820","volume":"47","author":"B. Ives","year":"2004","unstructured":"Ives, B., Walsh, K.R., Schneider, H.: The domino effect of password reuse. Commun. ACM\u00a047(4), 75\u201378 (2004)","journal-title":"Commun. ACM"},{"key":"18_CR29","unstructured":"Kohler, E.: Hotcrp conference management software (2014), http:\/\/read.seas.harvard.edu\/~kohler\/hotcrp\/"},{"key":"18_CR30","doi-asserted-by":"crossref","unstructured":"Komanduri, S., Shay, R., Kelley, P.G., Mazurek, M.L., Bauer, L., Christin, N., Cranor, L.F., Egelman, S.: CHI 2011, pp. 2595\u20132604. ACM, New York (2011)","DOI":"10.1145\/1978942.1979321"},{"key":"18_CR31","unstructured":"McIlroy, M.D.: A research unix reader: Annotated excerpts from the programmers manual (1971)"},{"issue":"11","key":"18_CR32","doi-asserted-by":"publisher","first-page":"594","DOI":"10.1145\/359168.359172","volume":"22","author":"R. Morris","year":"1979","unstructured":"Morris, R., Thompson, K.: Password security: A case history. Communications of the ACM\u00a022(11), 594\u2013597 (1979)","journal-title":"Communications of the ACM"},{"key":"18_CR33","first-page":"364","volume-title":"CCS 2005","author":"A. Narayanan","year":"2005","unstructured":"Narayanan, A., Shmatikov, V.: Fast dictionary attacks on passwords using time-space tradeoff. In: CCS 2005, pp. 364\u2013372. ACM, New York (2005)"},{"issue":"5","key":"18_CR34","doi-asserted-by":"publisher","first-page":"466","DOI":"10.1016\/S0167-4048(00)05032-X","volume":"19","author":"M. Peyravian","year":"2000","unstructured":"Peyravian, M., Zunic, N.: Methods for protecting password transmission. Computers& Security\u00a019(5), 466\u2013469 (2000)","journal-title":"Computers& Security"},{"key":"18_CR35","unstructured":"Raphael, J.: Gawker hack exposes ridiculous password habits (2010), http:\/\/www.pcworld.com\/article\/213679\/Gawker_Hack_Exposes_Ridiculous_Password_Habits.html"},{"key":"18_CR36","unstructured":"Ross, B., Jackson, C., Miyake, N., Boneh, D., Mitchell, J.C.: Stronger password authentication using browser extensions. In: Proceedings of the 14th Usenix Security Symposium, vol.\u00a031 (2005)"},{"issue":"7","key":"18_CR37","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1145\/361011.361067","volume":"17","author":"J.H. Saltzer","year":"1974","unstructured":"Saltzer, J.H.: Protection and the control of information sharing in multics. Commun. ACM\u00a017(7), 388\u2013402 (1974)","journal-title":"Commun. ACM"},{"key":"18_CR38","doi-asserted-by":"crossref","unstructured":"Shay, R., Komanduri, S., Kelley, P.G., Leon, P.G., Mazurek, M.L., Bauer, L., Christin, N., Cranor, L.F.: Encountering stronger password requirements: User attitudes and behaviors. In: SOUPS 2010, pp. 2:1\u20132:20. ACM, New York (2010)","DOI":"10.1145\/1837110.1837113"},{"key":"18_CR39","unstructured":"Siegler, M.: One of the 32 million with a rockyou account? you may want to change all your passwords (2009), http:\/\/techcrunch.com\/2009\/12\/14\/rockyou-hacked\/"},{"key":"18_CR40","doi-asserted-by":"crossref","unstructured":"Wang, R., Chen, S., Wang, X.: Signing me onto your accounts through facebook and google: A traffic-guided security study of commercially deployed single-sign-on web services. In: SP 2012, pp. 365\u2013379. IEEE (2012)","DOI":"10.1109\/SP.2012.30"},{"key":"18_CR41","first-page":"162","volume-title":"CCS 2010","author":"M. Weir","year":"2010","unstructured":"Weir, M., Aggarwal, S., Collins, M., Stern, H.: Testing metrics for password creation policies by attacking large sets of revealed passwords. In: CCS 2010, pp. 162\u2013175. ACM, New York (2010)"},{"key":"18_CR42","first-page":"391","volume-title":"SP 2009","author":"M. Weir","year":"2009","unstructured":"Weir, M., Aggarwal, S., de Medeiros, B., Glodek, B.: Password cracking using probabilistic context-free grammars. In: SP 2009, pp. 391\u2013405. IEEE Computer Society, Washington, DC (2009)"},{"key":"18_CR43","unstructured":"White, C.: Adobe leaks 150 million passwords; facebook and others impacted (2013), http:\/\/www.neowin.net\/news\/adobe-leaks-150-million-passwords-facebook-and-others-impacted"},{"issue":"4","key":"18_CR44","doi-asserted-by":"crossref","first-page":"551","DOI":"10.15388\/Informatica.2003.041","volume":"14","author":"C.-C. Yang","year":"2003","unstructured":"Yang, C.-C., Chang, T.-Y., Hwang, M.-S.: Security of improvement on methods for protecting password transmission. Informatica\u00a014(4), 551\u2013558 (2003)","journal-title":"Informatica"},{"key":"18_CR45","first-page":"32","volume-title":"SOUPS 2006","author":"K.-P. Yee","year":"2006","unstructured":"Yee, K.-P., Sitaker, K.: Passpet: Convenient password management and phishing protection. In: SOUPS 2006, pp. 32\u201343. ACM, New York (2006)"},{"key":"18_CR46","first-page":"176","volume-title":"CCS 2010","author":"Y. Zhang","year":"2010","unstructured":"Zhang, Y., Monrose, F., Reiter, M.K.: The security of modern password expiration: An algorithmic framework and empirical analysis. In: CCS 2010, pp. 176\u2013186. ACM, New York (2010)"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-17533-1_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,22]],"date-time":"2025-05-22T00:20:31Z","timestamp":1747873231000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-17533-1_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319175324","9783319175331"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-17533-1_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]}}}