Website Security & Threat Management
Research Directions in Password Security

Research Directions in Password Security

10/14/2021 · Ian McQuoid, Marina Sanusi, Tara Whalen

What this post added

This post details Cloudflare Research's exploration into advanced authentication methods to combat password reuse and credential stuffing attacks. It introduces Password Authenticated Key Exchanges (PAKEs), specifically focusing on Strong Asymmetric PAKEs (saPAKEs) like OPAQUE, which aim to establish secure keys without revealing plaintext passwords to the server. It also highlights the rollout of the Exposed Credential Checks feature in the WAF, powered by the Might I Get Pwned (MIGP) protocol, which detects compromised credentials and variants by using a private membership test protocol and generating password variants.

Read the original post ↗