2015
DOI: 10.1145/2739044
|View full text |Cite
|
Sign up to set email alerts
|

A Large-Scale Evaluation of High-Impact Password Strength Meters

Abstract: Passwords are ubiquitous in our daily digital lives. They protect various types of assets ranging from a simple account on an online newspaper website to our health information on government websites. However, due to the inherent value they protect, attackers have developed insights into cracking/guessing passwords both offline and online. In many cases, users are forced to choose stronger passwords to comply with password policies; such policies are known to alienate users and do not significantly improve pas… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
31
0

Year Published

2016
2016
2021
2021

Publication Types

Select...
6
1
1

Relationship

0
8

Authors

Journals

citations
Cited by 59 publications
(31 citation statements)
references
References 17 publications
0
31
0
Order By: Relevance
“…In all, targeted online guessing is a much more damaging threat to password security than trawling guessing and than the community (see [8,18]) might have expected. Our models will facilitate better evaluation of existing and future password policies (e.g., [9,24,28]), and they will also be helpful for forensic investigators to recover passwords in an offline manner.…”
Section: Evaluation Resultsmentioning
confidence: 99%
“…In all, targeted online guessing is a much more damaging threat to password security than trawling guessing and than the community (see [8,18]) might have expected. Our models will facilitate better evaluation of existing and future password policies (e.g., [9,24,28]), and they will also be helpful for forensic investigators to recover passwords in an offline manner.…”
Section: Evaluation Resultsmentioning
confidence: 99%
“…This is also echoed by Loge et al's work on a PPC for Android unlock patterns [14], in which they observed that the password strength could be influenced by individual features such as age and gender. (2) to highlight the complexity of password security by externalizing inconsistencies between different PPCs and more advanced attacks on passwords; (3) to engage users actively so that the process of learning is enjoyable, (4) to produce an open system that can be easily executed and customized by users on different platforms. To achieve those design goals, we decided to follow some well-established design principles to design and implement PSV.…”
Section: Related Workmentioning
confidence: 99%
“…Insights learned from research work on PPCs and PSMs [4,5,[25][26][27] have suggested that educating users about password security and attacks is an important aspect to make PPCs more effective, but very few tools have been developed and evaluated for this purpose.…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…For example, it is widely acknowledged that the password strength meter, which is deployed to help users generate stronger passwords, operates as a black-box and has inconsistent design across multiple websites. As a result, many users are confused about its implications (Carnavalet and Mannan 2015). In addition, users' perception of information security has been shown to mismatch reality (Ur et al 2016).…”
Section: Introductionmentioning
confidence: 99%