TITLE:
Why Credentials Are Not Hard to Hunt: A Critical Review of Credential Gathering Attacks
AUTHORS:
Jiya Patel, Peng Liu
KEYWORDS:
Credential Theft, FIDO2, Browser Attestation, Shamir Secret Sharing
JOURNAL NAME:
Journal of Software Engineering and Applications,
Vol.19 No.7,
July
24,
2026
ABSTRACT: Credential theft remains one of the most persistent vectors of cyberattack because credentials are heterogeneous: different types are stored, stolen, and exploited through distinct mechanisms, yet most defenses are applied uniformly across them. This paper combines a critical review with a targeted design proposal. We first examine how major credential types, including passwords, hashes, Kerberos tickets, cookies, payment-card data, and cryptographic keys, are stored and extracted from memory, disk, and network traffic, and how attackers exploit them once stolen. We then survey existing protection mechanisms, from hardware isolation to FIDO2/WebAuthn, and identify two unresolved gaps in FIDO2: its reliance on a trustworthy browser, and the absence of a cryptographically sound account-recovery mechanism. To address these, we propose an extension combining zero-knowledge browser attestation, built on Direct Anonymous Attestation and TPM-measured platform state, with a Shamir Secret Sharing-based recovery architecture distributed across trusted contacts. We argue, and illustrate through this extension, that credential-specific defenses are more tractable and effective than general-purpose ones.