In this paper we examine the standard password recovery process of large Internet services such as Gmail, Facebook, and Twitter. Although most of these services try to maintain user privacy, with regard to registration information and other personal information provided by the user, we demonstrate that personal information can still be obtained by unauthorized individuals or attackers. This information includes the full (or partial) email address, phone number, friends list, address, etc. We examine different scenarios and demonstrate how the details revealed in the password recovery process can be used to deduct more focused information about users.
翻译:在本文中,我们研究了大型互联网服务(如Gmail、Facebook和Twitter)的标准密码检索程序,尽管大多数这类服务都试图维护用户隐私,但就登记信息以及用户提供的其他个人信息而言,我们证明个人信息仍可由未经授权的个人或袭击者获取,包括完整的(或部分的)电子邮件地址、电话号码、朋友名单、地址等。我们审视了不同的情景,并展示了如何利用密码检索过程中披露的细节来减少关于用户的更有针对性的信息。