An Empirical Analysis on the Usability and Security of Passwords

被引:5
|
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [21] Passwords: Philology, Security, Authentication
    Dillon, Michael
    SYMPLOKE, 2020, 28 (1-2) : 596 - 598
  • [22] Concerns and Security for Hashing Passwords
    Herrera, Jonathan
    Ali, Md Liakat
    2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 861 - 865
  • [23] Passwords: Philology, Security, Authentication
    Huskey, Samuel J.
    TECHNOLOGY AND CULTURE, 2019, 60 (04) : 1126 - 1127
  • [24] Passwords: Philology, Security, Authentication
    Vadde, Aarthi
    AMERICAN LITERATURE, 2020, 92 (04) : 820 - 824
  • [25] A Large-Scale Empirical Analysis of Chinese Web Passwords
    Li, Zhigong
    Han, Weili
    Xu, Wenyuan
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 559 - 574
  • [26] Usability and Security Analysis of the KeepKey Wallet
    Almutairi, Emad
    Al-Megren, Shiroq
    2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2019, : 149 - 153
  • [27] Graphical Passwords as Browser Extension: Implementation and Usability Study
    Bicakci, Kemal
    Yuceel, Mustafa
    Erdeniz, Burak
    Gurbaslar, Hakan
    Atalay, Nart Bedin
    TRUST MANAGEMENT III, 2009, 300 : 15 - +
  • [28] Pictures at the ATM: Exploring the usability of multiple graphical passwords
    Moncur, Wendy
    Leplatre, Gregory
    CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, VOLS 1 AND 2, 2007, : 887 - 894
  • [29] An Empirical Investigation: Health Care Employee Passwords and Their Crack Times in Relationship to HIPAA Security Standards
    Medlin, B. Dawn
    Cazier, Joseph A.
    INTERNATIONAL JOURNAL OF HEALTHCARE INFORMATION SYSTEMS AND INFORMATICS, 2007, 2 (03) : 39 - 48
  • [30] Security technologies on image information (5); the security of passwords
    Kanaoka, Akira
    Kyokai Joho Imeji Zasshi/Journal of the Institute of Image Information and Television Engineers, 2015, 69 (05): : 437 - 441