作者
Saranga Komanduri, Richard Shay, Patrick Gage Kelley, Michelle L. Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Serge Egelman
发表日期
2011/5
期刊
Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
页码范围
2595-2604
简介
Text-based passwords are the most common mechanism for authenticating humans to computer systems. To prevent users from picking passwords that are too easy for an adversary to guess, system administrators adopt password-composition policies (e.g., requiring passwords to contain symbols and numbers). Unfortunately, little is known about the relationship between password-composition policies and the strength of the resulting passwords, or about the behavior of users (e.g., writing down passwords) in response to different policies. We present a large-scale study that investigates password strength, user behavior, and user sentiment across four password-composition policies. We characterize the predictability of passwords by calculating their entropy, and find that a number of commonly held beliefs about password composition and strength are inaccurate. We correlate our results with user behavior and …
引用总数
2011201220132014201520162017201820192020202120222023202451649395156515254645231398
学术搜索中的文章
S Komanduri, R Shay, PG Kelley, ML Mazurek, L Bauer… - Proceedings of the sigchi conference on human factors …, 2011
S Komanduri, R Shay, PG Kelley, ML Mazurek, L Bauer… - Proceedings of the SIGCHI Conference on Human …