5 citations · 13 across the 9 of their papers we have counts for
Showing 2018Show all
3 papers · 1 filter
cs.CR2018
The Hsu-Harn-Mu-Zhang-Zhu group key establishment protocol is insecure
Chris J Mitchell
A significant security vulnerability in a recently published group key establishment protocol is described. This vulnerability allows a malicious insider to fraudulently establish…
cs.CR2018★ 1 cited
Web password recovery --- a necessary evil?
Fatma Al Maqbali, Chris J Mitchell
Web password recovery, enabling a user who forgets their password to re-establish a shared secret with a website, is very widely implemented. However, use of such a fall-back syste…
cs.CR2018★ 5 cited
Mitigating CSRF attacks on OAuth 2.0 and OpenID Connect
Wanpeng Li, Chris J Mitchell, Thomas Chen
Many millions of users routinely use their Google, Facebook and Microsoft accounts to log in to websites supporting OAuth 2.0 and/or OpenID Connect-based single sign on. The securi…