An Empirical Analysis on the Usability and Security of Passwords

被引:5
|
作者
Walia, Kanwardeep Singh [1 ]
Shenoy, Shweta [2 ]
Cheng, Yuan [1 ]
机构
[1] Calif State Univ Sacramento, Dept Comp Sci, Sacramento, CA 95819 USA
[2] KLA Corp, Milpitas, CA USA
关键词
authentication; passwords; phonemes; usability; security;
D O I
10.1109/IRI49571.2020.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize - an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the user-generated passwords are secure. Moreover, we convert the user-generated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [41] An Empirical Usability Analysis of the Google Authentication API
    Wijayarathna, Chamila
    Arachchilage, Nalin A. G.
    PROCEEDINGS OF EASE 2019 - EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, 2019, : 268 - 274
  • [42] Analysis of an eHealth app: Privacy, Security and Usability
    Alturki, Ryan
    AlGhamdi, Mohammed J.
    Awan, Nabeela
    Kundi, Mehwish
    Gay, Valerie
    Alshehri, Mohammad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (04) : 209 - 214
  • [43] Analysis of an ehealth app: Privacy, security and usability
    Alturki R.
    AlGhamdi M.J.
    Gay V.
    Awan N.
    Kundi M.
    Alshehri M.
    International Journal of Advanced Computer Science and Applications, 2020, 11 (04): : 209 - 214
  • [44] ALETHEIA: Improving the Usability of Static Security Analysis
    Tripp, Omer
    Guarnieri, Salvatore
    Pistoia, Marco
    Aravkin, Aleksandr
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 762 - 774
  • [45] Security and usability
    Camp, L. Jean
    IEEE TECHNOLOGY AND SOCIETY MAGAZINE, 2007, 26 (01) : 3 - +
  • [46] Security usability
    Gutmann, P
    Grigg, I
    IEEE SECURITY & PRIVACY, 2005, 3 (04) : 56 - 58
  • [47] The Next Domino to Fall: Empirical Analysis of User Passwords across Online Services
    Wang, Chun
    Jan, Steve T. K.
    Hu, Hang
    Bossart, Douglas
    Wang, Gang
    PROCEEDINGS OF THE EIGHTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY'18), 2018, : 196 - 203
  • [48] Usability and user authentication: Pictorial passwords vs. pin
    De Angeli, A
    Coventry, L
    Johnson, G
    Coutts, M
    CONTEMPORARY ERGONOMICS 2003, 2003, : 253 - 258
  • [49] Pass-Go: A proposal to improve the usability of graphical passwords
    School of Information Technology and Engineering, University of Ottawa, 800 King Edward Avenue, P. O. Box 450, Station A, Ottawa, ON K1N 6N5, Canada
    Int. J. Netw. Secur., 2008, 2 (273-292): : 273 - 292
  • [50] Usability and security an appraisal of usability issues in information security methods
    Schultz, EE
    Proctor, RW
    Lien, MC
    Salvendy, G
    COMPUTERS & SECURITY, 2001, 20 (07) : 620 - 634