{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T04:31:56Z","timestamp":1773117116090,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":44,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642258664","type":"print"},{"value":"9783642258671","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-25867-1_6","type":"book-chapter","created":{"date-parts":[[2012,1,10]],"date-time":"2012-01-10T03:04:26Z","timestamp":1326164666000},"page":"49-81","source":"Crossref","is-referenced-by-count":59,"title":["Pico: No More Passwords!"],"prefix":"10.1007","author":[{"given":"Frank","family":"Stajano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"12","key":"6_CR1","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/322796.322806","volume":"42","author":"A. Adams","year":"1999","unstructured":"Adams, A., Angela Sasse, M.: Users are not the enemy. Communications of the ACM\u00a042(12), 40\u201346 (1999), http:\/\/hornbeam.cs.ucl.ac.uk\/hcs\/people\/documents\/Angela%20Publications\/1999\/p40-adams.pdf","journal-title":"Communications of the ACM"},{"key":"6_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/978-3-642-04904-0_20","volume-title":"Security Protocols","author":"R. Anderson","year":"2009","unstructured":"Anderson, R., Bond, M.: The Man-in-the-Middle Defence. In: Christianson, B., Crispo, B., Malcolm, J.A., Roe, M. (eds.) Security Protocols. LNCS, vol.\u00a05087, pp. 153\u2013156. Springer, Heidelberg (2009), http:\/\/www.cl.cam.ac.uk\/~mkb23\/research\/Man-in-the-Middle-Defence.pdf"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Beautement, A., Angela Sasse, M., Wonham, M.: The compliance budget: managing security behaviour in organisation. In: Proc. New Security Paradigms Workshop 2008, pp. 47\u201358. ACM (2008), http:\/\/hornbeam.cs.ucl.ac.uk\/hcs\/people\/documents\/Adam%27s%20Publications\/Compliance%20Budget%20final.pdf","DOI":"10.1145\/1595676.1595684"},{"key":"6_CR4","unstructured":"Bonneau, J., Preibusch, S.: The password thicket: technical and market failures in human authentication on the web. In: Proc.\u00a09th Workshop on the Economics of Information Security (June 2010), http:\/\/preibusch.de\/publications\/Bonneau_Preibusch__password_thicket.pdf"},{"key":"6_CR5","unstructured":"Choudary, O.: The Smart Card Detective: a hand-held EMV interceptor. Master\u2019s thesis, University of Cambridge (2010), http:\/\/www.cl.cam.ac.uk\/~osc22\/docs\/mphil_acs_osc22.pdf"},{"key":"6_CR6","unstructured":"Corner, M.D., Noble, B.D.: Zero-interaction authentication. In: Proc.\u00a0ACM MobiCom 2002, pp. 1\u201311 (2002), http:\/\/www.sigmobile.org\/awards\/mobicom2002-student.pdf"},{"key":"6_CR7","unstructured":"Desmedt, Y., Burmester, M., Safavi-Naini, R., Wang, H.: Threshold Things That Think (T4): Security Requirements to Cope with Theft of Handheld\/Handless Internet Devices. In: Proc. Symposium on Requirements Engineering for Information Security (2001)"},{"key":"6_CR8","unstructured":"Desmedt, Y., Jajodia, S.: Redistributing Secret Shares to New Access Structures and Its Applications. Tech. Rep. ISSE-TR-97-01, George Mason University (July 1997), ftp:\/\/isse.gmu.edu\/pub\/techrep\/9701jajodia.ps.gz"},{"key":"6_CR9","unstructured":"Drimer, S., Murdoch, S.J.: Keep your enemies close: distance bounding against smartcard relay attacks. In: Proc. USENIX Security Symposium, pp. 87\u2013102 (August 2007), http:\/\/www.cl.cam.ac.uk\/~sd410\/papers\/sc_relay.pdf"},{"key":"6_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1007\/978-3-540-85886-7_28","volume-title":"Information Security","author":"D. Flor\u00eancio","year":"2008","unstructured":"Flor\u00eancio, D., Herley, C.: One-Time Password Access to Any Server without Changing the Server. In: Wu, T.-C., Lei, C.-L., Rijmen, V., Lee, D.-T. (eds.) ISC 2008. LNCS, vol.\u00a05222, pp. 401\u2013420. Springer, Heidelberg (2008), http:\/\/research.microsoft.com\/~cormac\/Papers\/otpaccessanyserver.pdf"},{"key":"6_CR11","doi-asserted-by":"crossref","unstructured":"Flor\u00eancio, D., Herley, C.: Where do security policies come from? In: Proc.\u00a0SOUPS 2010, pp. 10:1\u201310:14. ACM (2010), http:\/\/research.microsoft.com\/pubs\/132623\/WhereDoSecurityPoliciesComeFrom.pdf","DOI":"10.1145\/1837110.1837124"},{"key":"6_CR12","unstructured":"Flor\u00eancio, D., Herley, C., Coskun, B.: Do strong web passwords accomplish anything? In: Proc. USENIX HOTSEC 2007, pp. 10:1\u201310:6 (2007), http:\/\/research.microsoft.com\/pubs\/74162\/hotsec07.pdf"},{"key":"6_CR13","doi-asserted-by":"crossref","unstructured":"Hancke, G.P., Kuhn, M.G.: An RFID Distance Bounding Protocol. In: Proc. IEEE SECURECOMM 2005, pp. 67\u201373 (2005), http:\/\/www.cl.cam.ac.uk\/~mgk25\/sc2005-distance.pdf","DOI":"10.1109\/SECURECOMM.2005.56"},{"issue":"9","key":"6_CR14","doi-asserted-by":"publisher","first-page":"1081","DOI":"10.1109\/TC.2006.138","volume":"55","author":"F. Hao","year":"2006","unstructured":"Hao, F., Anderson, R., Daugman, J.: Combining Crypto with Biometrics Effectively. IEEE Transactions on Computers\u00a055(9), 1081\u20131088 (2006), http:\/\/sites.google.com\/site\/haofeng662\/biocrypt_TC.pdf","journal-title":"IEEE Transactions on Computers"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Herley, C.: So Long, and No Thanks for the Externalities: the Rational Rejection of Security Advice by Users. In: Proc. New Security Paradigms Workshop 2009. ACM (2009), http:\/\/research.microsoft.com\/users\/cormac\/papers\/2009\/SoLongAndNoThanks.pdf","DOI":"10.1145\/1719030.1719050"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Herley, C., van Oorschot, P.C.: A Research Agenda Acknowledging the Persistence of Passwords (in submission, 2011)","DOI":"10.1109\/MSP.2011.150"},{"key":"6_CR17","unstructured":"Jakobsson, M., Akavipat, R.: Rethinking Passwords to Adapt to Constrained Keyboards (2011) (in submission), http:\/\/www.markus-jakobsson.com\/fastwords.pdf"},{"key":"6_CR18","unstructured":"Johnson, M., Moore, S.: A New Approach to E-Banking. In: Erlingsson, \u00da., et al. (eds.) Proc. 12th Nordic Workshop on Secure IT Systems (NORDSEC 2007), pp. 127\u2013138 (October 2007), http:\/\/www.matthew.ath.cx\/publications\/2007-Johnson-ebanking.pdf"},{"key":"6_CR19","unstructured":"Kristol, D.M., Gabber, E., Gibbons, P.B., Matias, Y., Mayer, A.: Design and implementation of the Lucent Personalized Web Assistant (LPWA). Tech. rep., Bell Labs (1998)"},{"key":"6_CR20","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1109\/CSAC.1997.646200","volume-title":"Proceedings of the 13th Annual Computer Security Applications Conference","author":"C.E. Landwehr","year":"1997","unstructured":"Landwehr, C.E.: Protecting unattended computers without software. In: Proceedings of the 13th Annual Computer Security Applications Conference, pp. 274\u2013283. IEEE Computer Society, Washington, DC, USA (December 1997), ISBN O-8186-8274-4, http:\/\/www.dtic.mil\/cgi-bin\/GetTRDoc?Location=U2&doc=GetTRDoc.pdf&AD=ADA465472"},{"key":"6_CR21","unstructured":"Landwehr, C.E., Latham, D.L.: Secure Identification System. US Patent 5,892,901, filed 1997-06-10, granted 1999-04-06 (1999)"},{"key":"6_CR22","doi-asserted-by":"crossref","unstructured":"Laurie, B., Singer, A.: Choose the red pill and the blue pill: a position paper. In: Proc. New Security Paradigms Workshop 2008, pp. 127\u2013133. ACM (2008), http:\/\/www.links.org\/files\/nspw36.pdf","DOI":"10.1145\/1595676.1595695"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Matsumoto, T., Matsumoto, H., Yamada, K., Hoshino, S.: Impact of Artificial Gummy Fingers on Fingerprint Systems. In: Proc. SPIE, Optical Security and Counterfeit Deterrence Techniques IV, vol. 4677 (2002), http:\/\/cryptome.org\/gummy.htm","DOI":"10.1117\/12.462719"},{"key":"#cr-split#-6_CR24.1","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Perrig, A., Reiter, M.K.: Seeing-Is-Believing: Using Camera Phones for Human-Verifiable Authentication. In: Proc. IEEE Symposium on Security and Privacy 2005, pp. 110-124 (2005), http:\/\/sparrow.ece.cmu.edu\/group\/pub\/mccunej_believing.pdf","DOI":"10.21236\/ADA457868"},{"key":"#cr-split#-6_CR24.2","unstructured":"updated version in Int.\u00a0J.\u00a0Security and Networks 4(1-2), 43-56 (2009), http:\/\/sparrow.ece.cmu.edu\/group\/pub\/mccunej_ijsn4_1-2_2009.pdf"},{"issue":"11","key":"6_CR25","doi-asserted-by":"publisher","first-page":"1489","DOI":"10.1109\/TMC.2006.169","volume":"5","author":"A. Nicholson","year":"2006","unstructured":"Nicholson, A., Corner, M.D., Noble, B.D.: Mobile Device Security using Transient Authentication. IEEE Transactions on Mobile Computing\u00a05(11), 1489\u20131502 (2006), http:\/\/prisms.cs.umass.edu\/mcorner\/papers\/tmc_2005.pdf","journal-title":"IEEE Transactions on Mobile Computing"},{"key":"6_CR26","unstructured":"Norman, D.A.: The Psychology of Everyday Things. Basic Books (1988) ISBN 0-385-26774-6, also published as The Design of Everyday Things (paperback)"},{"key":"6_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11889663_1","volume-title":"Financial Cryptography and Data Security","author":"B. Parno","year":"2006","unstructured":"Parno, B., Kuo, C., Perrig, A.: Phoolproof Phishing Prevention. In: Di Crescenzo, G., Rubin, A. (eds.) FC 2006. LNCS, vol.\u00a04107, pp. 1\u201319. Springer, Heidelberg (2006), http:\/\/sparrow.ece.cmu.edu\/group\/pub\/parno_kuo_perrig_phoolproof.pdf"},{"key":"6_CR28","doi-asserted-by":"crossref","unstructured":"Pashalidis, A.: Accessing Password-Protected Resources without the Password. In: Burgin, M., et al. (eds.) Proc.\u00a0CSIE 2009, pp. 66\u201370. IEEE Computer Society (2009), http:\/\/kyps.net\/xrtc\/cv\/kyps.pdf","DOI":"10.1109\/CSIE.2009.910"},{"key":"6_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/3-540-45067-X_22","volume-title":"Information Security and Privacy","author":"A. Pashalidis","year":"2003","unstructured":"Pashalidis, A., Mitchell, C.J.: A Taxonomy of Single Sign-On Systems. In: Safavi-Naini, R., Seberry, J., et al. (eds.) ACISP 2003. LNCS, vol.\u00a02727, pp. 249\u2013264. Springer, Heidelberg (2003), http:\/\/www.isg.rhul.ac.uk\/cjm\/atosso.pdf"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"Pashalidis, A., Mitchell, C.J.: Impostor: a single sign-on system for use from untrusted devices. In: Proc.\u00a0IEEE GLOBECOM 2004, vol.\u00a04, pp. 2191\u20132195 (2004), http:\/\/www.isg.rhul.ac.uk\/cjm\/iassos2.pdf","DOI":"10.1109\/GLOCOM.2004.1378398"},{"key":"6_CR31","series-title":"IFIP AICT","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-05437-2_11","volume-title":"iNetSec 2009 \u2013 Open Research Problems in Network Security","author":"R. Peeters","year":"2009","unstructured":"Peeters, R., Kohlweiss, M., Preneel, B.: Threshold Things That Think: Authorisation for Resharing. In: Camenisch, J., Kesdogan, D. (eds.) iNetSec 2009. IFIP AICT, vol.\u00a0309, pp. 111\u2013124. Springer, Heidelberg (2009), http:\/\/www.cosic.esat.kuleuven.be\/publications\/article-1223.pdf"},{"key":"6_CR32","first-page":"1","volume-title":"Proceedings of the 5th Symposium on Usable Privacy and Security, SOUPS 2009","author":"R. Peeters","year":"2009","unstructured":"Peeters, R., Kohlweiss, M., Preneel, B., Sulmon, N.: Threshold things that think: usable authorization for resharing. In: Proceedings of the 5th Symposium on Usable Privacy and Security, SOUPS 2009, p. 18:1. ACM, New York (2009) ISBN 978-1-60558-736-3, http:\/\/cups.cs.cmu.edu\/soups\/2009\/posters\/p1-peeters.pdf"},{"key":"6_CR33","unstructured":"Ross, B., Jackson, C., Miyake, N., Boneh, D., Mitchell, J.C.: Stronger Password Authentication Using Browser Extensions. In: Proc.\u00a0Usenix Security, pp. 17\u201332 (2005), http:\/\/crypto.stanford.edu\/PwdHash\/pwdhash.pdf"},{"key":"6_CR34","doi-asserted-by":"crossref","unstructured":"Schechter, S., Egelman, S., Reeder, R.W.: It\u2019s not what you know, but who you know: a social approach to last-resort authentication. In: Proc. CHI 2009, pp. 1983\u20131992 (2009), http:\/\/research.microsoft.com\/pubs\/79349\/paper1459-schechter.pdf","DOI":"10.1145\/1518701.1519003"},{"issue":"11","key":"6_CR35","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1145\/359168.359176","volume":"22","author":"A. Shamir","year":"1979","unstructured":"Shamir, A.: How to Share a Secret. Communications of the ACM\u00a022(11), 612\u2013613 (1979), http:\/\/securespeech.cs.cmu.edu\/reports\/shamirturing.pdf","journal-title":"Communications of the ACM"},{"key":"6_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"204","DOI":"10.1007\/3-540-44810-1_27","volume-title":"Security Protocols","author":"F. Stajano","year":"2001","unstructured":"Stajano, F.: The Resurrecting Duckling \u2013 What Next? In: Christianson, B., Crispo, B., Malcolm, J.A., Roe, M. (eds.) Security Protocols 2000. LNCS, vol.\u00a02133, pp. 204\u2013214. Springer, Heidelberg (2001), http:\/\/www.cl.cam.ac.uk\/~fms27\/papers\/2000-Stajano-duckling.pdf"},{"key":"6_CR37","unstructured":"Stajano, F.: Security for Ubiquitous Computing. Wiley (2002) ISBN 0-470-84493-0, Contains the most complete treatment of the Resurrecting Duckling [38]"},{"key":"6_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/10720107_24","volume-title":"Security Protocols","author":"F. Stajano","year":"2000","unstructured":"Stajano, F., Anderson, R.: The Resurrecting Duckling: Security Issues in Ad-Hoc Wireless Networks. In: Malcolm, J.A., Christianson, B., Crispo, B., Roe, M. (eds.) Security Protocols 1999. LNCS, vol.\u00a01796, pp. 172\u2013182. Springer, Heidelberg (2000), http:\/\/www.cl.cam.ac.uk\/~fms27\/papers\/1999-StajanoAnd-duckling.pdf"},{"key":"6_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1007\/978-3-642-14577-3_4","volume-title":"Financial Cryptography and Data Security","author":"F. Stajano","year":"2010","unstructured":"Stajano, F., Wong, F.-L., Christianson, B.: Multichannel Protocols to Prevent Relay Attacks. In: Sion, R. (ed.) FC 2010. LNCS, vol.\u00a06052, pp. 4\u201319. Springer, Heidelberg (2010), http:\/\/www.cl.cam.ac.uk\/~fms27\/papers\/2009-StajanoWonChr-relay.pdf"},{"issue":"1","key":"6_CR40","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1109\/30.125076","volume":"38","author":"R. Want","year":"1992","unstructured":"Want, R., Hopper, A.: Active Badges and Personal Interactive Computing Objects. IEEE Transactions on Consumer Electronics\u00a038(1), 10\u201320 (1992), http:\/\/nano.xerox.com\/want\/papers\/pico-itce92.pdf","journal-title":"IEEE Transactions on Consumer Electronics"},{"key":"#cr-split#-6_CR41.1","doi-asserted-by":"crossref","unstructured":"Wong, F.-L., Stajano, F.: Multi-channel protocols. In: Christianson, B., Crispo, B., Malcolm, J.A., Roe, M. (eds.) Security Protocols 2005. LNCS, vol.\u00a04631, pp. 112-127. Springer, Heidelberg (2007), http:\/\/www.cl.cam.ac.uk\/~fms27\/papers\/2005-WongSta-multichannel.pdf","DOI":"10.1007\/978-3-540-77156-2_14"},{"key":"#cr-split#-6_CR41.2","doi-asserted-by":"crossref","unstructured":"updated version in IEEE Pervasive Computing 6(4), 31-39 (2007), http:\/\/www.cl.cam.ac.uk\/~fms27\/papers\/2007-WongSta-multichannel.pdf","DOI":"10.1109\/MPRV.2007.76"},{"key":"6_CR42","doi-asserted-by":"crossref","unstructured":"Wong, T.M., Wang, C., Wing, J.M.: Verifiable Secret Redistribution for Archive System. In: IEEE Security in Storage Workshop 2002, pp. 94\u2013105 (2002), http:\/\/www.cs.cmu.edu\/~wing\/publications\/Wong-Winga02.pdf","DOI":"10.21236\/ADA461227"}],"container-title":["Lecture Notes in Computer Science","Security Protocols XIX"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-25867-1_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,18]],"date-time":"2025-03-18T17:11:57Z","timestamp":1742317917000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-25867-1_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642258664","9783642258671"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-25867-1_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011]]}}}