An Empirical Analysis on the Usability and Security of Passwords

Kanwardeep Singh Walia, Shweta Shenoy, Yuan Cheng

Research output: Chapter in Book/Conference proceedingConference contributionpeer-review

12 Citations (Scopus)

Abstract

Security and usability are two essential aspects of a system, but they usually move in opposite directions. Sometimes, to achieve security, usability has to be compromised, and vice versa. Password-based authentication systems require both security and usability. However, to increase password security, absurd rules are introduced, which often drive users to compromise the usability of their passwords. Users tend to forget complex passwords and use techniques such as writing them down, reusing them, and storing them in vulnerable ways. Enhancing the strength while maintaining the usability of a password has become one of the biggest challenges for users and security experts. In this paper, we define the pronounceability of a password as a means to measure how easy it is to memorize-an aspect we associate with usability. We examine a dataset of more than 7 million passwords to determine whether the usergenerated passwords are secure. Moreover, we convert the usergenerated passwords into phonemes and measure the pronounceability of the phoneme-based representations. We then establish a relationship between the two and suggest how password creation strategies can be adapted to better align with both security and usability.

Original languageEnglish
Title of host publicationProceedings - 2020 IEEE 21st International Conference on Information Reuse and Integration for Data Science, IRI 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-8
Number of pages8
ISBN (Electronic)9781728110547
DOIs
Publication statusPublished - Aug 2020
Externally publishedYes
Event21st IEEE International Conference on Information Reuse and Integration for Data Science, IRI 2020 - Virtual, Las Vegas, United States
Duration: 11 Aug 202013 Aug 2020

Publication series

NameProceedings - 2020 IEEE 21st International Conference on Information Reuse and Integration for Data Science, IRI 2020

Conference

Conference21st IEEE International Conference on Information Reuse and Integration for Data Science, IRI 2020
Country/TerritoryUnited States
CityVirtual, Las Vegas
Period11/08/2013/08/20

Keywords

  • authentication
  • passwords
  • phonemes
  • security
  • usability

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Networks and Communications
  • Information Systems
  • Decision Sciences (miscellaneous)
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'An Empirical Analysis on the Usability and Security of Passwords'. Together they form a unique fingerprint.

Cite this