Authors
Blase Ur, Jonathan Bees, Sean M. Segreti, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor
Publication date
2016
Publisher
Proceedings of the 34th Annual ACM Conference on Human Factors in Computing Systems (CHI)
Description
Although many users create predictable passwords, the extent to which users realize these passwords are predictable is not well understood. We investigate the relationship between users' perceptions of the strength of specific passwords and their actual strength. In this 165-participant online study, we ask participants to rate the comparative security of carefully juxtaposed pairs of passwords, as well as the security and memorability of both existing passwords and common password-creation strategies. Participants had serious misconceptions about the impact of basing passwords on common phrases and including digits and keyboard patterns in passwords. However, in most other cases, participants' perceptions of what characteristics make a password secure were consistent with the performance of current password-cracking tools. We find large variance in participants' understanding of how passwords may be …
Total citations
2015201620172018201920202021202220232024110283426313331269
Scholar articles
B Ur, J Bees, SM Segreti, L Bauer, N Christin… - Proceedings of the 2016 CHI conference on human …, 2016