How Does Your Password Measure Up? The Effect of Strength Meters on Password Creation
@inproceedings{Ur2012HowDY, title={How Does Your Password Measure Up? The Effect of Strength Meters on Password Creation}, author={B. Ur and P. Kelley and Saranga Komanduri and J. Lee and Michael Maass and Michelle L. Mazurek and Timothy Passaro and R. Shay and Timothy Vidas and L. Bauer and N. Christin and L. Cranor}, booktitle={USENIX Security Symposium}, year={2012} }
To help users create stronger text-based passwords, many web sites have deployed password meters that provide visual feedback on password strength. Although these meters are in wide use, their effects on the security and usability of passwords have not been well studied.
We present a 2,931-subject study of password creation in the presence of 14 password meters. We found that meters with a variety of visual appearances led users to create longer passwords. However, significant increases in… CONTINUE READING
Supplemental Video
Figures, Tables, and Topics from this paper
270 Citations
Does my password go up to eleven?: the impact of password meters on password selection
- Computer Science
- CHI
- 2013
- 187
- PDF
Designing Better Password Strength Meters by Incorporating Contextual Information
- Computer Science
- 2017
- 1
Using Context-Based Password Strength Meter to Nudge Users' Password Generating Behavior: A Randomized Experiment
- Computer Science
- HICSS
- 2017
- 10
- PDF
Designing Password Policies for Strength and Usability
- Computer Science
- ACM Trans. Inf. Syst. Secur.
- 2016
- 77
- PDF
Enhancing Operational Security by Redesigning Password Strength Meters: Evidence from Randomized Experiments
- Computer Science
- 2019
- 1
Password Meters and Generators on the Web: From Large-Scale Empirical Study to Getting It Right
- Computer Science
- CODASPY
- 2015
- 15
- Highly Influenced
- PDF
References
SHOWING 1-10 OF 47 REFERENCES
Of passwords and people: measuring the effect of password-composition policies
- Computer Science
- CHI
- 2011
- 347
- PDF
Encountering stronger password requirements: user attitudes and behaviors
- Computer Science
- SOUPS
- 2010
- 312
- PDF
Improving computer security for authentication of users: Influence of proactive password restrictions
- Medicine, Computer Science
- Behavior research methods, instruments, & computers : a journal of the Psychonomic Society, Inc
- 2002
- 104
- PDF
Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
- Computer Science
- 2012 IEEE Symposium on Security and Privacy
- 2012
- 376
- PDF
Improving password security and memorability to protect personal and organizational information
- Computer Science
- Int. J. Hum. Comput. Stud.
- 2007
- 192
Testing metrics for password creation policies by attacking large sets of revealed passwords
- Computer Science
- CCS '10
- 2010
- 370
- Highly Influential
- PDF