Of Passwords and People:
Measuring the Effect of Password-Composition Policies
Text-based passwords are the most common mechanism for
authenticating humans to computer systems. To prevent users
from picking passwords that are too easy for an adversary
to guess, system administrators adopt password-composition
policies (e.g., requiring passwords to contain symbols and
numbers). Unfortunately, little is known about the relationship
between password-composition policies and the strength
of the resulting passwords, or about the behavior of users
(e.g., writing down passwords) in response to different policies.
We present a large-scale study that investigates password
strength, user behavior, and user sentiment across four
password-composition policies. We characterize the predictability
of passwords by calculating their entropy, and
find that a number of commonly held beliefs about password
composition and strength are inaccurate. We correlate our
results with user behavior and sentiment to produce several
recommendations for password-composition policies that result
in strong passwords without unduly burdening users.
Of Passwords and People:Measuring the Effect of Password-Composition PoliciesText-based passwords are the most common mechanism forauthenticating humans to computer systems. To prevent usersfrom picking passwords that are too easy for an adversaryto guess, system administrators adopt password-compositionpolicies (e.g., requiring passwords to contain symbols andnumbers). Unfortunately, little is known about the relationshipbetween password-composition policies and the strengthof the resulting passwords, or about the behavior of users(e.g., writing down passwords) in response to different policies.We present a large-scale study that investigates passwordstrength, user behavior, and user sentiment across fourpassword-composition policies. We characterize the predictabilityof passwords by calculating their entropy, andfind that a number of commonly held beliefs about passwordcomposition and strength are inaccurate. We correlate ourresults with user behavior and sentiment to produce severalrecommendations for password-composition policies that resultin strong passwords without unduly burdening users.
การแปล กรุณารอสักครู่..
