Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
@article{Kelley2012GuessA, title={Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms}, author={P. Kelley and Saranga Komanduri and Michelle L. Mazurek and R. Shay and Timothy Vidas and L. Bauer and N. Christin and L. Cranor and J. Hernandez}, journal={2012 IEEE Symposium on Security and Privacy}, year={2012}, pages={523-537} }
Text-based passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform password cracking. [...] Key Method We develop an efficient distributed method for calculating how effectively several heuristic password-guessing algorithms guess passwords. Leveraging this method, we investigate (a) the resistance of passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training…Expand Abstract
Supplemental Presentations
Presentation Slides
Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
376 Citations
Reasoning Analytically about Password-Cracking Software
- Computer Science
- 2019 IEEE Symposium on Security and Privacy (SP)
- 2019
- 2
- PDF
Skeptic: Automatic, Justified and Privacy-Preserving Password Composition Policy Selection
- Computer Science
- AsiaCCS
- 2020
- 1
- PDF
Measuring Real-World Accuracies and Biases in Modeling Password Guessability
- Computer Science
- USENIX Security Symposium
- 2015
- 128
- PDF
Designing Password Policies for Strength and Usability
- Computer Science
- ACM Trans. Inf. Syst. Secur.
- 2016
- 77
- PDF
References
SHOWING 1-10 OF 67 REFERENCES
Of passwords and people: measuring the effect of password-composition policies
- Computer Science
- CHI
- 2011
- 347
- PDF
Password Cracking Using Probabilistic Context-Free Grammars
- Computer Science
- 2009 30th IEEE Symposium on Security and Privacy
- 2009
- 384
- Highly Influential
- PDF
Testing metrics for password creation policies by attacking large sets of revealed passwords
- Computer Science
- CCS '10
- 2010
- 370
- Highly Influential
- PDF
Encountering stronger password requirements: user attitudes and behaviors
- Computer Science
- SOUPS
- 2010
- 312
- PDF
Improving computer security for authentication of users: Influence of proactive password restrictions
- Medicine, Computer Science
- Behavior research methods, instruments, & computers : a journal of the Psychonomic Society, Inc
- 2002
- 104
- PDF
Multiple password interference in text passwords and click-based graphical passwords
- Computer Science
- CCS
- 2009
- 209
- PDF