A study of password security factors among Bangladeshi government websites
File(s)2012.01765v1.pdf (911.42 KB)
Accepted version
Author(s)
Chowdhury, Adil Ahmed
Chowdhury, Farida
Ferdous, Md Sadek
Type
Conference Paper
Abstract
The Government of Bangladesh is aggressively transforming its public service landscape by transforming public services into online services via a number of websites. The motivation is that this would be a catalyst for a transformative change in every aspect of citizen life. Some web services must be protected from any unauthorised usages and passwords remain the most widely used credential mechanism for this purpose. However, if passwords are not adopted properly, they can be a cause for security breach. That is why it is important to study different aspects of password security on different websites. In this paper, we present a study of password security among 36 different Bangladeshi government websites against six carefullychosen password security heuristics. This study is the first of its kind in this domain and offers interesting insights. For example, many websites have not adopted proper security measures with respect to security. There is no password construction guideline adopted by many websites, thus creating a barrier for users to select a strong password. Some of them allow supposedly weak passwords and still do not utilise a secure HTTPS channel to transmit information over the Internet.
Date Issued
2021-04-06
Date Acceptance
2020-12-01
Citation
2020 23rd International Conference on Computer and Information Technology (ICCIT), 2021
Publisher
IEEE
Journal / Book Title
2020 23rd International Conference on Computer and Information Technology (ICCIT)
Copyright Statement
© 2021 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. See http://www.ieee.org/publications_standards/publications/rights/index.html for more information.
Identifier
http://arxiv.org/abs/2012.01765v1
Source
The 23rd International Conference on Computer and Information Technology (ICCIT), 2020
Subjects
cs.CR
cs.CR
Notes
Accepted for publication in the 23rd International Conference on Computer and Information Technology (ICCIT), 19-21 December, 2020
Publication Status
Published
Start Date
2020-12-19
Finish Date
2020-12-21
Coverage Spatial
Sylhet, Bangladesh