The Next Domino to Fall: Empirical Analysis of User Passwords across Online Services

被引:28
|
作者
Wang, Chun [1 ]
Jan, Steve T. K. [1 ]
Hu, Hang [1 ]
Bossart, Douglas [1 ]
Wang, Gang [1 ]
机构
[1] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24060 USA
关键词
D O I
10.1145/3176258.3176332
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Leaked passwords from data breaches can pose a serious threat if users reuse or slightly modify the passwords for other services. With more services getting breached today, there is still a lack of a quantitative understanding of this risk. In this paper, we perform the first large-scale empirical analysis of password reuse and modification patterns using a ground-truth dataset of 28.8 million users and their 61.5 million passwords in 107 services over 8 years. We find that password reuse and modification is very common (observed on 52% of the users). Sensitive online services such as shopping websites and email services received the most reused and modified passwords. We also observe that users would still reuse the already-leaked passwords for other online services for years after the initial data breach. Finally, to quantify the security risks, we develop a new training-based guessing algorithm. We show that more than 16 million password pairs (including 30% of the modified passwords) can be cracked within just 10 guesses.
引用
收藏
页码:196 / 203
页数:8
相关论文
共 29 条
  • [1] Analysis of various Authentication Schemes for Passwords using Images to enhance Network Security through Online Services
    Princes, P. Sahaya Suganya
    Andrews, J.
    2017 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2017,
  • [2] An empirical analysis of the demand for physician services across the European Union
    Sergi Jiménez-Martín
    José M. Labeaga
    Maite Martínez-Granado
    The European Journal of Health Economics, formerly: HEPAC , 2004, 5 (2): : 150 - 165
  • [3] EMPIRICAL STUDY ON USER ACCEPTANCE TESTING e-HEALTH SERVICES ACROSS DELHI - NCR
    Sharma, Rahul
    SURANAREE JOURNAL OF SCIENCE AND TECHNOLOGY, 2022, 29 (06):
  • [4] The measurement of end-user computing satisfaction of online banking services: empirical evidence from Finland
    Pikkarainen, Kari
    Pikkarainen, Tero
    Karjaluoto, Heikki
    Pahnila, Seppo
    INTERNATIONAL JOURNAL OF BANK MARKETING, 2006, 24 (03) : 158 - 172
  • [5] Digital Public Services in Smart Cities – an Empirical Analysis of Lead User Preferences
    Bernd W. Wirtz
    Wilhelm M. Müller
    Florian W. Schmidt
    Public Organization Review, 2021, 21 : 299 - 315
  • [6] Digital Public Services in Smart Cities - an Empirical Analysis of Lead User Preferences
    Wirtz, Bernd W.
    Mueller, Wilhelm M.
    Schmidt, Florian W.
    PUBLIC ORGANIZATION REVIEW, 2021, 21 (02) : 299 - 315
  • [7] An empirical analysis of the antecedents of adoption of online services A prototype-based framework
    Seneler, Cagla Ozen
    Basoglu, Nuri
    Daim, Tugrul U.
    JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2010, 23 (04) : 417 - +
  • [8] Which ideas are more likely to be implemented in online user innovation communities? An empirical analysis
    Li, Mingguo
    Kankanhalli, Atreyi
    Kim, Seung Hyun
    DECISION SUPPORT SYSTEMS, 2016, 84 : 28 - 40
  • [9] Distinct kratom user populations across the United States: A regional analysis based on an online survey
    Nicewonder, Jessica A.
    Buros, Amy F.
    Veltri, Charles A.
    Grundmann, Oliver
    HUMAN PSYCHOPHARMACOLOGY-CLINICAL AND EXPERIMENTAL, 2019, 34 (05)
  • [10] Research on the Characteristics and Usefulness of User Reviews of Online Mental Health Consultation Services: A Content Analysis
    Liu, Jingfang
    Gao, Lu
    HEALTHCARE, 2021, 9 (09)