BEGIN:VCALENDAR
VERSION:2.0
CALSCALE:GREGORIAN
BEGIN:VTIMEZONE
TZID:Europe/Berlin
LAST-MODIFIED:20201011T015911Z
TZURL:http://tzurl.org/zoneinfo-outlook/Europe/Berlin
X-LIC-LOCATION:Europe/Berlin
BEGIN:DAYLIGHT
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
DTSTART:19700329T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=-1SU
END:DAYLIGHT
BEGIN:STANDARD
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
DTSTART:19701025T030000
RRULE:FREQ=YEARLY;BYMONTH=10;BYDAY=-1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20220516T134523Z
UID:1652708595596-30792@ical.cispa.de
DTSTART;TZID=Europe/Berlin:20220802T100000
DTEND;TZID=Europe/Berlin:20220802T110000
SUMMARY:CISPA DLS / Thomas Ristenpart – "Improving Password-based Authentication" 
DESCRIPTION:Passwords remain the most widely used authentication mechanism, despite  being a primary vector for compromise of people's digital assets. Underlying this fact is the billions of login credentials (username and password pairs) that have been exposed due to breaches. These fuel credential stuffing attacks in which breached credentials are submitted to login services.\n\nIn this talk I will describe our work on mitigating credential stuffing and other remote password guessing attacks. Through measurement studies at two large universities and analysis of public breach data, our work provides the most granular understanding to date of remote password guessing attack efficacy. We also explore the potential for more advanced credential  tweaking attacks, which learn from breach data variants of breached passwords  likely to be selected by users, and show that submitting these as guesses can be increase attacker success rates.\n\nTo combat such threats, we propose password breach alerting protocols that perform a kind of cryptographic private set intersection to help  individuals or services determine if a user's password--or a variant of it--appears in some known breach. Our resulting service design, called Might I Get Pwned, was deployed at Cloudflare and is actively used now to help their customers  detect breached credentials.\n\nI will discuss works done in collaboration with Suleman Ahmad, Junade Ali, Marina Sanusi Bohuk, Sofı́a Celi, Rahul Chatterjee, Mazharul Islam, Lucy Li, Bijeeta Pal, Nick Sullivan, Michael Swift, Stefano Tessaro, Nirvan Tyagi, Lukec Valenta, Tara Whalen, and Christopher Wood.

LOCATION:https://cispa-de.zoom.us/j/96190179483?pwd=WHFqejVSUTVHU0dxbFkrK1lsLzBIZz09
END:VEVENT
END:VCALENDAR