An Empirical Analysis on the Usability and Security of Passwords

被引:5
|
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
来源
2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020) | 2020年
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [1] Usability and Security of Text Passwords on Mobile Devices
    Melicher, William
    Kurilova, Darya
    Segreti, Sean M.
    Kalvani, Pranshu
    Shay, Richard
    Ur, Blase
    Bauer, Lujo
    Christin, Nicolas
    Cranor, Lorrie Faith
    Mazurek, Michelle L.
    34TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2016, 2016, : 527 - 539
  • [2] Prioritizing security over usability: Strategies for how people choose passwords
    Wash, Rick
    Rader, Emilee
    JOURNAL OF CYBERSECURITY, 2021, 7 (01): : 1 - 17
  • [3] Empirical keystroke analysis in passwords
    Montalvao, Jugurta
    Freire, Eduardo O.
    Bezerra, Murilo A., Jr.
    Garcia, Rodolfo
    5TH ISSNIP-IEEE BIOSIGNALS AND BIOROBOTICS CONFERENCE (2014): BIOSIGNALS AND ROBOTICS FOR BETTER AND SAFER LIVING, 2014, : 167 - 172
  • [4] The Impact of Image Choices on the Usability and Security of Click Based Graphical Passwords
    Suo, Xiaoyuan
    Zhu, Ying
    Owen, G. Scott
    ADVANCES IN VISUAL COMPUTING, PT 2, PROCEEDINGS, 2009, 5876 : 889 - +
  • [5] Security and Usability: Analysis and Evaluation
    Kainda, Ronald
    Flechais, Ivan
    Roscoe, A. W.
    FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 275 - 282
  • [6] The usability of passphrases for authentication: An empirical field study
    Keith, Mark
    Shao, Benjamin
    Steinbart, Paul John
    INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2007, 65 (01) : 17 - 28
  • [7] Concerns and Security for Hashing Passwords
    Herrera, Jonathan
    Ali, Md Liakat
    2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 861 - 865
  • [8] Contributions to empirical analysis of keystroke dynamics in passwords
    Montalvao, Jugurta
    Freire, Eduardo O.
    Bezerra, Murilo A., Jr.
    Garcia, Rodolfo
    PATTERN RECOGNITION LETTERS, 2015, 52 : 80 - 86
  • [9] Empirical Investigations on Usability of Security Warning Dialogs: End Users Experience
    Ahmad, Farah Nor Aliah
    Zaaba, Zarul Fitri
    Aminuddin, Mohamad Amar Irsyad Mohd
    Abdullah, Nasuha Lee
    ADVANCES IN CYBER SECURITY (ACES 2019), 2020, 1132 : 335 - 349
  • [10] Usability versus security of authentication
    Hub, Miloslav
    Capek, Jan
    Myskova, Renata
    Roudny, Radim
    COMMUNICATION AND MANAGEMENT IN TECHNOLOGICAL INNOVATION AND ACADEMIC GLOBALIZATION, 2010, : 34 - 38