An Empirical Analysis on the Usability and Security of Passwords

被引:5
|
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [1] Balancing Usability and Security of Graphical Passwords
    Lapin, Kristina
    Siurkus, Manfredas
    DIGITAL INTERACTION AND MACHINE INTELLIGENCE, MIDI 2021, 2022, 440 : 153 - 160
  • [2] Usability and Security of Text Passwords on Mobile Devices
    Melicher, William
    Kurilova, Darya
    Segreti, Sean M.
    Kalvani, Pranshu
    Shay, Richard
    Ur, Blase
    Bauer, Lujo
    Christin, Nicolas
    Cranor, Lorrie Faith
    Mazurek, Michelle L.
    34TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2016, 2016, : 527 - 539
  • [3] An Empirical Analysis of Passwords
    Pushpa, S. K.
    Manjunath, T. N.
    Babu, Gireesh C. N.
    Azeez, Syed Furqan
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND INTERNET OF THINGS (ICGCIOT 2018), 2018, : 89 - 92
  • [4] Usability and Security of Gaze-Based Graphical Grid Passwords
    Arianezhad, Majid
    Stebila, Douglas
    Mozaffari, Behzad
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY: FC 2013 WORKSHOPS, 2013, 7862 : 17 - 33
  • [5] Empirical keystroke analysis in passwords
    Montalvao, Jugurta
    Freire, Eduardo O.
    Bezerra, Murilo A., Jr.
    Garcia, Rodolfo
    5TH ISSNIP-IEEE BIOSIGNALS AND BIOROBOTICS CONFERENCE (2014): BIOSIGNALS AND ROBOTICS FOR BETTER AND SAFER LIVING, 2014, : 167 - 172
  • [6] The Impact of Image Choices on the Usability and Security of Click Based Graphical Passwords
    Suo, Xiaoyuan
    Zhu, Ying
    Owen, G. Scott
    ADVANCES IN VISUAL COMPUTING, PT 2, PROCEEDINGS, 2009, 5876 : 889 - +
  • [7] Prioritizing security over usability: Strategies for how people choose passwords
    Wash, Rick
    Rader, Emilee
    JOURNAL OF CYBERSECURITY, 2021, 7 (01): : 1 - 17
  • [8] Composition Policies for Gesture Passwords: User Choice, Security, Usability and Memorability
    Clark, Gradeigh D.
    Lindqvist, Janne
    Oulasvirta, Antti
    2017 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2017, : 344 - 352
  • [9] Exploring Usability Effects of Increasing Security in Click-based Graphical Passwords
    Stobert, Elizabeth
    Forget, Alain
    Chiasson, Sonia
    van Oorschot, P. C.
    Biddle, Robert
    26TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2010), 2010, : 79 - 88
  • [10] Empirical Studies on the Security and Usability Impact of Immutability
    Weber, Sam
    Coblenz, Michael
    Myers, Brad
    Aldrich, Jonathan
    Sunshine, Joshua
    2017 IEEE CYBERSECURITY DEVELOPMENT (SECDEV), 2017, : 50 - 53