An Empirical Analysis on the Usability and Security of Passwords

被引:5
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
来源
2020 IEEE 21ST INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2020) | 2020年
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [21] Graphical Passwords as Browser Extension: Implementation and Usability Study
    Bicakci, Kemal
    Yuceel, Mustafa
    Erdeniz, Burak
    Gurbaslar, Hakan
    Atalay, Nart Bedin
    TRUST MANAGEMENT III, 2009, 300 : 15 - +
  • [22] An Empirical Investigation: Health Care Employee Passwords and Their Crack Times in Relationship to HIPAA Security Standards
    Medlin, B. Dawn
    Cazier, Joseph A.
    INTERNATIONAL JOURNAL OF HEALTHCARE INFORMATION SYSTEMS AND INFORMATICS, 2007, 2 (03) : 39 - 48
  • [23] Better Together: Usability and Security Go Hand in Hand
    Cranor, Lorrie Faith
    Buchler, Norbou
    IEEE SECURITY & PRIVACY, 2014, 12 (06) : 89 - 93
  • [24] A Comparative Study of Authentication Schemes with Security and Usability of IPAS
    Almuairfi, Sadiq
    Veeraraghavan, Prakash
    Chilamkurti, Naveen
    JOURNAL OF INTERNET TECHNOLOGY, 2014, 15 (04): : 615 - 624
  • [25] The Effect of Length on Key Fingerprint Verification Security and Usability
    Turner, Dan
    Shahandashti, Siamak F.
    Petrie, Helen
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [26] Biometric authentication -: Security and usability
    Matyas, V
    Ríha, Z
    ADVANCED COMMUNICATIONS AND MULTIMEDIA SECURITY, 2002, 100 : 227 - 239
  • [27] Passwords a Lesson in Cyber Security Failure?
    Furnell S.
    Furnell, Steven, 1600, Oxford University Press (62): : 26 - 27
  • [28] An Empirical Usability Analysis of the Google Authentication API
    Wijayarathna, Chamila
    Arachchilage, Nalin A. G.
    PROCEEDINGS OF EASE 2019 - EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, 2019, : 268 - 274
  • [29] Analysis of an eHealth app: Privacy, Security and Usability
    Alturki, Ryan
    AlGhamdi, Mohammed J.
    Awan, Nabeela
    Kundi, Mehwish
    Gay, Valerie
    Alshehri, Mohammad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (04) : 209 - 214
  • [30] Analysis of an ehealth app: Privacy, security and usability
    Alturki R.
    AlGhamdi M.J.
    Gay V.
    Awan N.
    Kundi M.
    Alshehri M.
    International Journal of Advanced Computer Science and Applications, 2020, 11 (04): : 209 - 214