The Government of Bangladesh is aggressively transforming its public service landscape by transforming public services into online services via a number of websites. The motivation is that this would be a catalyst for a transformative change in every aspect of citizen life. Some web services must be protected from any unauthorised usages and passwords remain the most widely used credential mechanism for this purpose. However, if passwords are not adopted properly, they can be a cause for security breach. That is why it is important to study different aspects of password security on different websites. In this paper, we present a study of password security among 36 different Bangladeshi government websites against six carefully chosen password security heuristics. This study is the first of its kind in this domain and offers interesting insights. For example, many websites have not adopted proper security measures with respect to security. There is no password construction guideline adopted by many websites, thus creating a barrier for users to select a strong password. Some of them allow supposedly weak passwords and still do not utilise a secure HTTPS channel to transmit information over the Internet.
翻译:孟加拉国政府正在通过一些网站将公共服务转变为在线服务,从而积极改变其公共服务格局。其动机是,这将推动公民生活各个方面的变革。一些网络服务必须受到保护,免遭任何未经授权的使用,密码仍然是为此最广泛使用的证明机制。然而,如果密码没有得到正确采用,它们可能成为破坏安全的原因。这就是为什么必须研究不同网站密码安全的不同方面。在本文中,我们对36个不同的孟加拉国政府网站的密码安全性进行了研究,而不是6个精心选择的密码安全喜剧。本研究是该领域的首个此类研究,并提供了有趣的见解。例如,许多网站在安全方面没有采取适当的安全措施,许多网站没有采用密码构建准则,因此给用户选择强有力的密码设置障碍。其中一些网站允许所谓薄弱的密码,仍然不使用安全的 HTTPS 频道在互联网上传递信息。