An Empirical Analysis on the Usability and Security of Passwords

被引:5
|
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [31] User Study, Analysis, and Usable Security of Passwords Based on Digital Objects
    Biddle, Robert
    Mannan, Mohammad
    van Oorschot, Paul C.
    Whalen, Tara
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2011, 6 (03) : 970 - 979
  • [32] Using cognitive dimensions to evaluate the usability of security APIs: An empirical investigation
    Wijayarathna, Chamila
    Arachchilage, Nalin Asanka Gamagedara
    INFORMATION AND SOFTWARE TECHNOLOGY, 2019, 115 : 5 - 19
  • [33] Empirical Investigations on Usability of Security Warning Dialogs: End Users Experience
    Ahmad, Farah Nor Aliah
    Zaaba, Zarul Fitri
    Aminuddin, Mohamad Amar Irsyad Mohd
    Abdullah, Nasuha Lee
    ADVANCES IN CYBER SECURITY (ACES 2019), 2020, 1132 : 335 - 349
  • [34] On the Semantic Patterns of Passwords and their Security Impact
    Veras, Rafael
    Collins, Christopher
    Thorpe, Julie
    21ST ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2014), 2014,
  • [35] Smart Contract Programming Languages on Blockchains: An Empirical Evaluation of Usability and Security
    Parizi, Reza M.
    Amritraj
    Dehghantanha, Ali
    BLOCKCHAIN - ICBC 2018, 2018, 10974 : 75 - 91
  • [36] Passwords: Philology, Security, Authentication.
    Slater, Avery
    CRITICAL INQUIRY, 2021, 47 (02) : 422 - 423
  • [37] Choosing passwords: Security and human factors
    Gehringer, EF
    SOCIAL IMPLICATIONS OF INFORMATION AND COMMUNICATION TECHNOLOGY, PROCEEDINGS, 2002, : 369 - 373
  • [38] Passwords a Lesson in Cyber Security Failure?
    Furnell S.
    Furnell, Steven, 1600, Oxford University Press (62): : 26 - 27
  • [39] Security Evaluation of Passwords Used on Internet
    Hub, Miloslav
    Capek, Jan
    JOURNAL OF ALGORITHMS & COMPUTATIONAL TECHNOLOGY, 2011, 5 (03) : 437 - 450
  • [40] USABILITY ANALYSIS OF MESSAGES FROM A SECURITY SYSTEM
    MOSTELLER, WS
    BALLAS, J
    PROCEEDINGS OF THE HUMAN FACTORS SOCIETY 33RD ANNUAL MEETING, VOL 1: PERSPECTIVES, 1989, : 399 - 403