Ke Coby Wang

dblp:220/3081 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
5since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 first-author · 5 since 2021
YearPublicationVenuePosition
2025 The 2FA Illusion: Uncovering Weak Links of Web Account Access in the Wild
abstract
Single-factor authentication (1FA) and two-factor authentication (2FA) for secure and reliable website account access have become everyday tasks for most users. However, the complexity of integrating 1FA, 2FA, and password reset mechanisms makes real-world deployments challenging to navigate, leaving key questions about their implications for account security and accessibility unanswered. In this paper, we present a comprehensive investigation into the deployment of 1FA, 2FA, and password reset mechanisms across 50 major websites in six industries. By formally modeling account access and password reset patterns and applying Karnaugh maps for logical optimization, we uncover surprising consequences of current integrations of authentication mechanisms. We present key findings on the implications of modern authentication integrations for account security and accessibility, highlighting both the overestimated strengths and overlooked weaknesses of current deployments. Our research aims to provide a valuable and practical understanding of real-world authentication deployments for advancing web authentication practices.
Ke Coby Wang, Sunpreet S. Arora, Michael K. Reiter
ACSAC1
2025 A Composability Analysis Framework for Web3 Wallet Recovery Mechanisms
abstract
Modern Web3 wallets offer hybrid recovery solutions that combine multiple key recovery methods to balance security, availability, and usability. These methods include secret sharing of wallet private keys, encrypted cloud storage, and smart contract-based advanced recovery functionalities. However, such combined approaches can introduce new attack vectors that are not present in standalone recovery solutions. In this work, we propose a formal security analysis frame-work for blockchain/Web3 wallet designs with key or asset recovery functionalities. To assess whether a wallet design is secure, our framework considers several factors, including user availability and responsiveness to malicious actions, co-custodianship with external parties, the total value of assets managed by the wallet, and the reputation of the entities chosen by the user to facilitate spending or recovery functionalities. Through probabilistic model checking, our framework identifies the conditions under which a wallet design remains secure. We also include two examples of Web3 wallet designs with composite recovery mechanisms (inspired by existing designs) to demonstrate the effectiveness of our framework.
Panagiotis Chatzigiannis, Ke Coby Wang, Sunpreet S. Arora, Mohsen Minaei
SP2
2025 Detecting Compromise of Passkey Storage on the Cloud
Mazharul Islam 0002, Sunpreet S. Arora, Rahul Chatterjee 0001, Ke Coby Wang
USENIX Security Symposium4
2024 Bernoulli Honeywords
Ke Coby Wang, Michael K. Reiter
NDSS1
2021 Using Amnesia to Detect Credential Database Breaches
Ke Coby Wang, Michael K. Reiter
USENIX Security Symposium1
2020 Detecting Stuffing of a User's Credentials at Her Own Accounts
Ke Coby Wang, Michael K. Reiter
USENIX Security Symposium1
2019 How to End Password Reuse on the Web
Ke Coby Wang, Michael K. Reiter
NDSS1